Privacy
Last updated 14 September 2026
This describes what pass stores, who processes it, and how to get it back or get rid of it. It covers the hosted service operated by Kelihi.
What we collect
Your account
Your email address and display name, from the identity provider you sign in with. If you sign in with Google, we receive your email address, name and profile picture from Google; we never receive your Google password.
What you put in
The documents you publish and their assets, the comments you write, the names of your workspaces and folders, and any screenshots you attach to a bug report. TL;DR summaries that agents write of your documents and their comment threads are stored alongside each document, with earlier revisions kept as history. We treat this as yours. We do not read it except when you ask us to for support, and we do not use it to train models.
Agent connections
When an agent connection asks pass to publish, search, or comment, pass receives the resulting tool call and returns only the data needed for that operation. The AI provider processes the prompts and tool results under your agreement with that provider; it is a service you choose to connect, not a subprocessor that Kelihi appoints for every workspace. Do not send credentials or content you are not authorised to share in an agent prompt.
How documents get used
We record which version of a document was viewed, by whom and when, so authors can see that their work was read. Views through a public share link are recorded as anonymous. We do not store IP addresses or browser user-agent strings against those views.
Operational logs
Our infrastructure keeps ordinary server logs, which include IP addresses, for security and debugging. These are held by our hosting provider and are not joined to your document activity.
Product analytics
To understand how pass is used and where people get stuck, we send usage records to PostHog, linked to your account id. Your email address and name are stored on that analytics profile. We record:
- Which pages of the product you visit, with share-link secrets and every URL query string removed.
- Clicks and form submissions on product controls — never the text on the page or anything you type.
- Product actions such as publishing, commenting, routing a comment to an agent, sharing, signing up and billing changes.
We do not send:
- The content of your documents or their titles.
- The text of comments.
- What you search for.
- The names or email addresses of other people.
Visitors to a public share link are not tracked in the browser; we only count the view, anonymously. IP addresses are truncated before they reach PostHog, and actions recorded by our servers carry no location. Preview deployments send nothing.
Cookies
We set one essential cookie, htmlshare_token, to keep you signed in, plus a short-lived cookie during the sign-in exchange itself and one remembering your light or dark theme preference. There are no advertising cookies. For product analytics, the product also keeps analytics state in your browser’s storage, including an identifier, which is your account id once you are signed in, your workspace id, a session id, and the address, including any query string, of the page you arrived on and of the page that sent you there. If your browser refuses that storage but accepts cookies, the analytics library keeps this state in a first-party cookie instead.
Who else processes it
| Provider | What they do | Where |
|---|---|---|
| Google Cloud Platform | Hosting, database and file storage | United States (us-central1) |
| WorkOS | Authentication and identity (including Google sign-in) | United States |
| PostHog | Product usage analytics | United States |
pass content is stored in the United States. We do not sell personal data, and we do not share it with anyone beyond the providers above except where the law requires it.
How long we keep it
Your content stays until you delete it or ask us to close your workspace. Document versions are immutable by design: publishing a change adds a version rather than overwriting the previous one, so deleting content means deleting the document, not editing its history.
Your choices
You can ask for a copy of your data, correction of it, or its deletion, by writing to privacy@kelihi.com. Depending on where you live you may have these as legal rights; we honour the requests either way. Deletion is handled manually today — we will confirm when it is done rather than leaving you guessing.
Security
Each workspace’s data is isolated at the database level, and published documents are served from a separate sandboxed domain so one customer’s content cannot reach another’s session. To report a vulnerability, see security.txt.
Changes
If this changes materially we will update the date above and tell account owners by email rather than changing it quietly.