Skip to content
MyKK
Features How it works Pricing FAQ Install Free
Features How it works Pricing FAQ Install Free

Privacy Policy

Last updated: September 29, 2026

MyKK is a browser start page in two parts: the MyKK Cloud Dashboard at start.mykk.us, which is free and open source and needs no account, and the MyKK.us browser extension, which activates Pro features for subscribers. What you create in the dashboard — bookmarks, notes, widget layout, and theme — is kept in your own browser by default. Our servers hold account, subscription, license, and device-activation records; the settings you choose to sync; and, when a widget refreshes, whatever that widget has to fetch. This policy sets out exactly what leaves your device, where it goes, how long it stays, and how to have it removed.

What the dashboard stores

The dashboard keeps your configuration in your browser’s localStorage: widget layout, bookmarks, notepad contents, calendar feed URLs, stock symbols, theme, custom CSS, and any API keys you enter for the weather and stock widgets. It stays there unless you turn on cloud sync, or unless a widget has to fetch something — see “What leaves your device when a widget refreshes” below, which is the honest answer to what reaches us and when.

Cloud sync is off by default. When you turn it on and sign in with Google, the dashboard uploads your whole settings object to a Google Firebase project we operate (start-mykk-us), stored under your Google account. That object is more than layout: it includes your bookmarks, your calendar and RSS feed URLs, and any weather or stock API keys you have entered. Firebase also records the Google account you sync with — its email address, display name, profile photo, and sign-in times.

You can point the dashboard at a Firebase project of your own in Settings instead, in which case none of it touches our infrastructure.

How signing in to the extension works

This section describes the sign-in the extension performs today. It replaced an earlier design, and the mechanics matter because they determine what each party ever sees.

  1. You press “Sign in with Google” in the extension popup. The extension asks your browser to open a window at api.mykk.us. The extension itself runs no OAuth — it holds no Google client credentials, requests no Google scopes of its own, and never receives a Google access token.
  2. Our server sends that window on to Google. You sign in to Google and approve the access requested, which is openid, email, and profile. Your Google password is entered on Google’s own pages and is never visible to the extension or to us.
  3. Google returns you to api.mykk.us, which creates or finds your MyKK account and sends the window back to the extension carrying a one-time code that expires after sixty seconds and can be used once.
  4. The extension exchanges that code, together with its device identifier, for a MyKK session token. This token is ours, not Google’s; it means nothing outside api.mykk.us. It is stored in chrome.storage.local and sent as an Authorization header on requests to our API.

Your email address therefore reaches the extension from our API, in the response to that exchange — not read out of your Google account by the extension. A MyKK session token is valid for thirty days and is renewed while you keep using it. Our API also still accepts an older session token, issued by the sign-in endpoint this flow replaced, so a copy of the extension that already holds one keeps working until it updates.

What the extension stores on your device

  • Session token — the bearer described above, in chrome.storage.local.
  • Device identifier — a random identifier generated once per browser installation, so we can enforce the per-subscription device limit (three by default).
  • Cached subscription status — your plan, email address, and expiry, so Pro features work without a request on every page load. The extension rechecks this with our API roughly once a day.

The extension does not read your browsing history, the contents of other tabs or windows, or form data.

What our servers store

Our API and database run on Cloudflare. The records are:

  • Account — your email address, and the display name and profile-picture URL Google returns with it, together with whether Google reported the address verified.
  • Sign-in provider record — your Google account identifier, the scopes granted, and the tokens Google issues when you sign in. These are held server-side and are used only to establish and re-establish your MyKK account.
  • Sessions — one record per sign-in, holding the session token, its expiry, and the browser user-agent string the sign-in came from. The record has a field for an originating IP address; our current deployment does not populate it, and no session on record carries one.
  • Subscription and license records — your Stripe customer and subscription identifiers, the billing name Stripe Checkout collected, the plan, status, and the subscription’s amount, currency, and billing interval, together with its trial end, current period end, and cancellation timestamps. The email address and the billing name on these records are stored encrypted, and the address is indexed in a form that allows a lookup without holding it in the clear. The device limit is a property of the product, not of your record.
  • Device activations — one record per activated device, holding a hashed device identifier and first-seen, last-seen, and deactivation timestamps. The raw device identifier is not stored, and neither is your browser’s name or version.

Payment details are never stored by us and never reach our servers. Card numbers are entered directly into Stripe Checkout; after a payment, Stripe notifies our API and we record only the subscription metadata listed above.

Your email address. When you buy or start a trial, Stripe gives us your email address. We use it to send your subscription notices, receipts, and account notices; to answer you; and now and then to thank you or tell you about our other products. Every email that isn’t about your account has a one-click unsubscribe, and we never sell or rent your address, and we share it only with the providers named on this page.

Emails about our other products are sent through MailerLite, which keeps your address only to deliver them and to honor your unsubscribe. MailerLite’s handling of your information is described in its own privacy policy.

What leaves your device when a widget refreshes

This depends on whether you have the extension, and it is the part of this policy most likely to surprise you, so it is set out in full.

With the extension and an active Pro subscription, the stock, RSS, and calendar widgets fetch through our API rather than reaching out from your browser. The stock symbols, RSS feed URLs, and calendar feed URLs you have configured are sent to our server, which fetches them on your behalf. Routing calendar feeds this way is deliberate: a private calendar URL usually has a secret token in it, and this keeps that URL from being handed to a third-party proxy.

Without the extension, the widgets fall back to the paths they used before it existed, and those are different:

  • Stocks reach us anyway. The dashboard calls our API directly with the symbols you have configured — and, if you have entered a Marketstack API key in Settings, with that key. This happens with no extension, no subscription, and no cloud sync.
  • RSS feeds go to api.rss2json.com, a third-party service, which receives the feed URL.
  • Calendar feeds go to corsproxy.io and then api.allorigins.win when the feed itself does not permit a direct browser fetch. Those services receive the feed URL, secret token included. If that matters to you, install the extension or use a feed that does not embed a token.

What our server does with a URL you give it. The RSS and calendar endpoints fetch a URL you supplied, from our infrastructure. The fetch is guarded against being pointed at private networks, is capped at 2 MB, and identifies itself upstream as MyKK/1.0 with nothing about you attached. We do not store the URLs, and we do not store what comes back.

Where stock data comes from. By default we ask Yahoo Finance, sending only the ticker symbol or search text. If you have supplied a Marketstack key, we use Marketstack instead and forward your key to them as the API credential — so Marketstack sees your key and your symbols, and their terms govern what they do with it. Quote responses are cached for up to twenty-four hours, and symbol searches for up to seven days, keyed by symbol alone.

How long we keep it

We do not run an automated deletion schedule, and we would rather say so than imply one. In practice:

  • Local data lasts until you clear your browser storage, sign out in the extension popup, or uninstall the extension.
  • Account, subscription, license, and device-activation records persist until you ask us to remove them. A device you have signed out of is marked deactivated rather than deleted.
  • Sessions are the exception, and they are shorter-lived than the rest. Signing out revokes the session record immediately, and an expired session is deleted the next time it is presented. What lingers is only a session that expired and was never used again.
  • Synced settings stay in our Firebase project until you ask us to delete them. Turning cloud sync off does not remove them — see “Your rights and controls”.
  • Cancelled subscriptions are kept, marked inactive, so access can be restored if you resubscribe.
  • Stripe keeps payment and invoice records under its own retention rules.

Deletion is on request and we act on it — see “Your rights and controls” below.

How we use your data

  • To create your account and sign you in.
  • To verify your Pro subscription and tell the dashboard to unlock Pro widgets.
  • To enforce the per-subscription device limit.
  • To recheck your subscription roughly every twenty-four hours, so a lapsed subscription stops unlocking Pro features.
  • To fetch the Pro data your widgets request, on your behalf.
  • To process payments, and to send the trial, receipt, and expiry emails that go with them.

We do not use any of it for third-party advertising, profiling, or resale.

What we do not collect

  • Your browsing history, or the contents of other tabs or windows
  • The contents of what you write in the dashboard — notes, bookmarks, and layout stay on your device unless you turn on cloud sync
  • Cross-site tracking or advertising profiles
  • Advertising or tracking cookies
  • Your postal address, date of birth, or telephone number
  • Card numbers or any other payment credential

Who we share it with

We do not sell your data, and we do not share it for anyone else’s advertising, analytics, or marketing. It reaches only the providers we depend on to run MyKK:

  • Google — authenticates you at sign-in, and hosts Firebase if you use cloud sync, under its privacy policy.
  • Stripe — processes payments and manages subscriptions, under its privacy policy.
  • MailerLite — sends our emails about other products, under its privacy policy.
  • Cloudflare — hosts our API and database.
  • Plausible Analytics — self-hosted on our own infrastructure, recording anonymous, cookieless usage statistics. No cookies, no personal data, and no cross-site tracking.
  • Yahoo Finance — receives the ticker symbol or search text behind the stock widget, and nothing that identifies you.
  • Marketstack — only if you supply your own API key, in which case it receives that key and your symbols.
  • rss2json, corsproxy.io, and allorigins.win — third-party services the dashboard falls back to for RSS and calendar feeds when the extension is not present. They receive the feed URL. See the section above.

Your rights and controls

  • Sign out — the button in the extension popup deactivates that device and clears the session token and cached subscription data from it.
  • Uninstall — removes every trace of extension data from your device.
  • Turn off cloud sync — in dashboard Settings. This stops further uploads and signs you out of Firebase, but it does not delete what has already been synced; that copy stays in our Firebase project until you ask us to remove it. Use the contact form below.
  • Manage or cancel Pro — through the Stripe customer portal, linked from the subscription email Stripe sends you.
  • See or delete what we hold — ask through our contact form, from the address associated with your subscription. We will remove your account, sign-in provider record, sessions, subscription and license records, device activations, and your synced settings.

Security

All traffic between the extension, the dashboard, and our API uses HTTPS. Our Cloudflare database is encrypted at rest, and the email addresses and device identifiers on subscription and activation records are additionally encrypted or hashed before they are stored. Payment data is handled entirely by Stripe under its PCI-DSS compliance and never reaches us. Sign-in credentials are entered on Google’s pages; we never see your Google password.

Children’s privacy

MyKK is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has signed up for Pro, tell us through our contact form and we will delete the account.

Changes to this policy

We update the “Last updated” date above whenever this policy changes. Where a change materially affects how we use or share your data, we will tell existing Pro subscribers at the address on their subscription.

Contact

Questions, deletion requests, or anything else — reach us through our contact form.

MyKK

Your browser's start page, reimagined. Open source and free forever.

GitHub

Resources

  • Changelog
  • Docs
  • Roadmap
  • Support

About

  • Features
  • How it works
  • Pricing
  • FAQ

Legal

  • Privacy
  • Terms
  • DMCA

© 2026 | Created with ❤️ by Michal Ferber, aka TechGuyWithABeard.