Kwop › Privacy Policy

Privacy Policy

Last updated: October 4, 2026. This page explains what data Kwop collects about you, what it records on our customers’ websites, which services it relies on, and how to have data deleted.

Kwop (kwop.io) records visits to a website so the owner can watch them back like a video (session replay), and ties each visit to the revenue it brought. This policy has two parts. Part 1 is about you as a visitor of kwop.io or as a Kwop customer. Part 2 is about the data Kwop processes for customers on their own websites.

Part 1: visitors of kwop.io and Kwop customers

Your account

When you create an account, we store your name, your email address and your password. The password is hashed with scrypt and a random salt, so the password itself is never stored. We also keep the address of the site you add, your plan, your language and, if you add one, a profile picture. To understand our own sign-up funnel, we also note where you first came from (the flow_src cookie below), whether you signed up on a phone or a computer, and when you reached the test, plans, checkout and dashboard pages. At sign-up we send a 4-digit code to confirm your email; it expires after 15 minutes. You can change your name, email and password at any time in your settings.

Billing through Whop

Kwop plans are sold through Whop. You enter your payment details on Whop’s checkout, so Kwop never sees your card number. Whop receives the plan you pick, your Kwop account ID and, if a partner referred you, that partner’s Whop username, and tells us when a payment goes through or fails. We keep your plan, billing period, amounts paid and dates. Plans are listed on the pricing page.

Emails we send

We send emails through Resend, and only about your account and plan: the sign-up code, payment confirmations, renewal reminders, failed payments, a plan paused after an unpaid renewal, and the end of a cancelled plan.

Cookies and browser storage

NameWhat it doesLasts
flow_authKeeps you logged in. HttpOnly, so page scripts cannot read it.30 days
flow_vidA random ID that counts visits to our pages once per person and keeps you in the same version of a page we are testing.1 year
flow_srcWhere you first came from: the site that sent you (for example google or x), a utm_source, a partner link, or “direct”.90 days
flow_refThe partner link you arrived from, if any, so that partner is credited.30 days

Affiliates who sign in with Whop get a login cookie, flow_aff (90 days), plus short-lived sign-in cookies (flow_invite for 1 hour, flow_oauth_state and flow_oauth_v for 10 minutes). The public demo dashboard sets flow_demo_plan (30 days). Our own tracker (below) also keeps a random visitor ID and session ID in your browser’s local storage, under keys that start with flow_.

How we measure our own site

We run Kwop on kwop.io. Your visit to our pages is recorded the same way Kwop records visits on customer sites (Part 2): pages, clicks, scrolls, mouse moves and the page as a replay, with every typed field masked. If you type your email in our sign-up or log-in form, our tracker can tie it to your visits. While a tab is open, our pages also send a small “still here” signal (a random tab ID, the page path and whether the tab is visible), kept only in memory, so we can see how many people are on the site right now. We also count a few product events, such as an upgrade offer seen or clicked, a plan clicked or our video played, tied to your random visitor ID and, if you are logged in, to your account. Our pages load fonts from Google Fonts. We use no advertising pixels.

The Kwop chat

When you use the Kwop chat in the dashboard, your messages, any images you add and the site data needed to answer (which can include visitor emails and payments) are sent to the AI model provider that runs the chat: Anthropic (Claude), or Google (Gemini) when Claude is not set up. Chats and images are saved in your account so you can come back to them. You can delete any chat.

Test visits

When you paste a link to try Kwop, our automated browser visits that site 3 times and records those visits. These test visitors are not real people: the names and emails shown on them are generated.

Part 2: data Kwop processes on customers’ websites

Customers add one line of code, the Kwop tracker, to their website. For that data, the customer is the controller: they decide to record their site and what to do with the data. Kwop is their processor: we store and analyze it on their behalf, to show it in their dashboard. If you visited a site that uses Kwop and have a question about your data, contact that site first. They can delete your visits from their dashboard, and we will help them answer.

What the tracker records

What the tracker does not record

Emails typed in the site’s own forms

One exception to masking: when a visitor types an email address into an email field on the site (for example a sign-up or checkout form), the tracker reads that email so the customer can tie that person’s visits to their payment. Password and hidden fields are never read. A site can turn this off with data-capture-email="off" on the tracker line, or with data-flow-no-capture on a single form. A site can also identify a visitor itself with Flow.identify(), which can include a name.

Consent

A site can add data-consent="required" to the tracker line. Then nothing is recorded until the site calls Flow.consent(), for example when the visitor accepts its cookie banner.

Payments from the customer’s own Stripe, Whop or Shopify

On the Pro plan, a customer can connect their own Stripe, Whop or Shopify account with a key that can read payments. Kwop only reads: it never charges, refunds or changes anything in those accounts. The first sync reads the last 90 days.

Visitor scores and follow-up emails

Kwop scores each visitor’s buying intent, explains why they stopped and writes a follow-up email from what they actually did. This runs on Kwop’s own servers, without an outside AI model. Kwop does not email visitors: the customer copies the email and sends it themselves. Kwop notes that a follow-up was copied, to show whether that visitor came back or paid afterwards.

AI assistants connected through MCP

On the Pro plan, a customer can connect Claude, ChatGPT, Gemini or Cursor to Kwop through our MCP server, using a private link from the dashboard’s MCP page (or the token in that link, sent as a Bearer token). Its 9 tools read data, and one of them drafts a follow-up email; none of them sends anything or changes the connected Stripe, Whop or Shopify accounts. What the assistant reads, which can include visitor emails and payments, then goes to the assistant the customer chose, under that provider’s own terms. The customer can regenerate the link at any time, and the old one stops working right away.

Services we use

ServiceWhat forWhat it receives
CloudflareNetwork between browsers and Kwop’s serversWeb traffic to kwop.io
WhopKwop’s own billingThe plan you pick, your Kwop account ID, and the payment details you enter on Whop
ResendAccount and plan emailsYour email address and the email content
Anthropic (Claude) or Google (Gemini)The Kwop chatYour messages, images you add, and the site data needed to answer
Google FontsFonts on our pagesThe standard request your browser makes to load a font
Your own Stripe, Whop or ShopifyRevenue, only if you connect itRead requests made with your key

The database and the replays are stored on servers operated by Kwop, reached only through Cloudflare over HTTPS. We do not sell personal data.

Deleting data

How long we keep data

We keep account data, recordings and payments while the account is active, and delete them on request. Some things expire on their own: login sessions after 30 days, sign-up codes after 15 minutes, and a visit ends after 30 minutes without activity.

Security

Your choices

You can see and change your account details in your settings, cancel your plan at any time, and ask us about your data or for its deletion by email. If we change this policy, we update the date at the top of this page.

Contact

Questions about privacy at Kwop: [email protected]. You can also read our terms of service and learn about Kwop.

FAQ

Does Kwop record what visitors type?

No. The values of every form field are masked inside the visitor’s browser, so passwords and card numbers typed there never leave the page. The one exception is an email typed into an email field on the site, which ties visits to payments. Sites can turn that off.

Can Kwop wait for consent before recording?

Yes. With data-consent="required" on the tracker line, nothing is recorded until the site calls Flow.consent(), for example from its cookie banner.

How do I delete one visitor’s data?

Open the visitor in your dashboard and click Delete. Their visits, replays and email are erased for good, and their payments stay as anonymous amounts.

Does Kwop see card numbers?

No. Kwop’s own plans are paid on Whop’s checkout, and from connected Stripe, Whop or Shopify accounts Kwop keeps the email, amount, currency, product and date of each payment, never card or bank details.

Where is the data stored?

On servers operated by Kwop. Traffic reaches them through Cloudflare, over HTTPS.

See who pays on your site

Paste your link: Kwop shows 3 test visits of your site in about a minute. No card.