Last updated · 2026-08-20
What we collect, why, and how to take it back.
The data flows behind the Kayanintrust layer — account data, payment events, identity verification, contact-form messages, and the 0–100 score inputs — written out plainly so a reader does not need a lawyer or an engineer to follow it.
The policy
Nine sections, in plain language.
01
Information we collect
Kayanin collects what it needs to run the trust layer — account identity, profile content you choose to add, and usage signals that power the three peer scores on the platform (Worker Trust, Employer Score, Agency Score).
Concretely, that is:
- Account data — the email address and hashed password you provide at sign-up (handled by better-auth; passwords are hashed with bcrypt, not stored in plain text).
- Optional profile content — a profile photo, a short bio, a resume you may upload, and any optional fields you complete in the /login/member/profile editor.
- Education and assessment data — course progress, completion marks, and assessment scores recorded as you move through the AI Course and the Practice / Toolkit surfaces.
- Application history — every job you apply to, every status change, and any messages you send through the platform.
- Agency directory data — for an Agency-owner account, the agency profile fields (name, services, industries, locations, worker types, communications, available workforce). The Agency row gates directory placement by the agency's registered plan.
- Payment events — only the event type, the Stripe session / event identifier, and the success/cancelled status. Kayanin never receives, stores, or sees card numbers; all card data is held by Stripe under their own privacy terms.
- Contact-form messages — submissions from the contact page are delivered to the team running the platform and persisted with them as the canonical record of inbound contact.
- Scam-check pasted text is NOT stored. The /scam-check API runs the rules in-memory, returns the verdict, and discards the input. No write to the database, no external forward, no AI call.
02
How we use it
The data above is used for four jobs, and only those four:
- Operating the platform — sign-in, profile rendering, application flow, payment reconciliation, customer support, and (for Agency accounts) the /agencies directory surface.
- Computing the trust scores — the 0–100 Worker Trust score (Worker-side identity, employment history, profile, mock interview, application history, daily-login streak); the 0–100 Employer Score (registration, migrant-licence cross-reference, advisories, posted-pay honesty, ghosting, applicant reviews); and the 0–100 Agency Score (registration, placement rate, ghosted workers, cross-company history, reviews, advisories).
- Transactional email — sign-up confirmation, sign-in alerts on a new device, payment receipts, application status updates, and the contact-form routing above.
- Identity verification — the registration / tax-id and POEA / DMW licence checks that gate posting on the platform.
- Kayanin uses Worker data for job search and applications only. Kayanin does NOT charge Workers for job access or applications and does NOT take a cut of wages. Worker ↔ Employer (direct hire) and Worker ↔ Agency (intermediary introductions) are the two peer relationships Worker data feeds; Kayanin itself does not place Workers. Employer data is used to post listings, support hiring decisions on the platform, and feed the Employer Score. Agency data is used to score the agency peer and gate directory placement.
03
Legal basis
Kayanin leans on two legal bases under the General Data Protection Regulation:
Legitimate interest — for fraud prevention, the trust scores (Worker Trust, Employer Score, Agency Score), identity verification at sign-up, and the scam-check pipeline. Fraud prevention is a legitimate interest under GDPR Article 6(1)(f), and the data minimised for these jobs is the minimum needed to score listings safely.
Consent — for any future marketing email. Kayanin sends no marketing email today; the moment it does, consent will be collected explicitly and an unsubscribe link will be present in every message.
04
Sharing
Kayanin does not sell, rent, or trade personal data. The platform shares the minimum required to operate, with three categories of partner:
- Payment processor — Stripe, for billing. Stripe receives only the data their checkout requires and may store their own records under their own privacy terms.
- Identity-verification partner — the registration / tax-id and POEA / DMW licence lookup services the trust score depends on. These partners see name and licence number only at the moment of the look-up; Kayanin does not send a full profile.
- Transactional-email relay — for contact-form messages and the operational email surface (sign-in alerts, payment receipts, application status). Submissions are delivered to the team running the platform through standard transactional email infrastructure.
- No advertising, remarketing, social-media, or analytics partners receive any data. There is no advertising, remarketing, or analytics surface on the site to share data with.
05
Storage & retention
Data is stored in a Postgres database managed via Prisma. Backups are encrypted at rest and held by the platform host.
Session cookies used for sign-in expire on sign-out or after a short idle period; they are not retained once the session ends.
Account data is held for the life of the account. You can request deletion of your account (and all data tied to it) at any time, per the rights section below. Destructive actions are processed within 30 days and confirmed by email.
Contact-form messages may persist with the team running the platform for as long as we keep our operational archive; that archive is the canonical record of inbound contact.
06
Your rights
You can exercise the following rights at any time, by emailing kayanin@proton.me:
- Access — receive a copy of the personal data Kayanin holds about you.
- Correction — fix inaccurate or incomplete data, including data scored into the trust layer.
- Deletion — close the account and have all data tied to it erased. We confirm by email when the deletion is complete.
- Objection or restriction — object to processing, or ask that it be limited while a request is being resolved.
- Portability — receive your data in a machine-readable format. We package the data on request rather than maintain an always-on export tool.
There is no fee for exercising these rights. We respond within 30 days; if the request is complex, we will tell you why and when to expect a complete answer.
07
Children
Kayanin is built for adults in the workforce. The platform is not directed at children, and Kayanin does not knowingly collect personal data from anyone under 18. If a parent or guardian believes a minor has signed up, write to kayanin@proton.me and the account will be closed and the data erased.
08
Changes to this policy
We update this page when the data we collect, how we use it, or how we share it changes — for example, if a new third-party processor is added for embedded content, or if the marketing programme is opened. The "Last updated" date at the top of this page is the source of truth for the current revision.
Material changes are also announced on the Kayanin home page. Continuing to use the platform after a change takes effect signals acceptance of the new policy.
09
Contact
Questions, access requests, and deletion requests go to kayanin@proton.me. We answer every request; nothing routed to that address is ignored.