KordiKordi
Privacy Terms Sign in

Privacy Policy

Effective 14 September 2026 · Kordi is operated by seo2agents (Ziv Kaspersky), Israel

This policy explains what personal data Kordi collects, why, and how it is handled. Kordi is a private, invitation-only dashboard at app.kordi.win that shows companies how AI coding agents and chat assistants describe their products. It is not offered to the general public.

1. Who we are

Kordi is operated by seo2agents, a consulting business run by Ziv Kaspersky in Israel. For anything in this policy, contact kasperskyziv1@gmail.com.

2. What we collect

  • Account data. When you sign in with Google, we receive your name, email address and profile picture from Google. When you sign in with an emailed link, we use the email address we invited. We do not receive or store your Google password.
  • Session data. A session cookie that keeps you signed in, the time of sign-in, and the pages you open inside the dashboard.
  • Edits you make. Labels, notes, prompt wordings and settings you change in the dashboard are stored with your user id and a timestamp so changes can be audited.
  • Research data. The dashboard shows transcripts of questions we asked AI agents and the answers they gave. These are generated by us and do not contain your personal data.

We do not use advertising trackers, we do not run analytics from third parties on the dashboard, and we do not sell data.

3. Why we use it

  • To let invited people sign in and to keep the dashboard private to them.
  • To show each client only their own data.
  • To record who changed what, so shared judgement calls in the dashboard can be reviewed.
  • To send sign-in links and, if you opt in, occasional summaries of your results.

The legal basis is our legitimate interest in operating a secure service for the clients we work with, and the contract we have with each client.

4. Google sign-in

Kordi uses Google OAuth only to confirm who you are. We request the basic profile and email scopes and nothing else. We do not access your Gmail, Drive, contacts or calendar. Our use of information received from Google follows the Google API Services User Data Policy, including its Limited Use requirements.

5. Where data lives and who can see it

  • Account, session and dashboard data are stored in a managed PostgreSQL database hosted by Neon in Frankfurt, Germany (EU).
  • The dashboard runs on Cloudflare's network. Sign-in emails are sent through Resend.
  • Only the seo2agents team and the people a client has asked us to invite can access that client's data. We do not share personal data with anyone else, except where the law requires it.

6. Retention

Account data is kept while you have access to the dashboard and deleted within 30 days of your access being removed. Sign-in links expire shortly after they are sent. Audit records of edits are kept for as long as the client's dashboard exists.

7. Your rights

You can ask us at any time to see the personal data we hold about you, to correct it, or to delete it and remove your access. Email kasperskyziv1@gmail.com and we will respond within 30 days. If you are in the EU or UK you also have the right to complain to your data protection authority.

8. Cookies

Kordi sets one strictly necessary cookie: the session cookie that keeps you signed in. It is not used for tracking and there is nothing to opt out of beyond signing out.

9. Security

All traffic is encrypted in transit. Sign-in link tokens are stored hashed. Every request to the dashboard is checked against your invitation before any data is returned. We review access regularly and remove accounts that are no longer needed.

10. Changes

If this policy changes in a way that matters, we will update the effective date above and tell signed-in users on their next visit.

Kordi by seo2agents Home · Terms of service