Last updated 29 September 2026
Account. Your email address, and a password stored only as a bcrypt hash by our authentication provider. If you enable two-factor authentication, that provider generates and holds the authenticator secret — it never reaches our servers. We never see your password in readable form.
Payments. Card details go directly to Stripe and never reach our servers. We store the Stripe identifiers for your customer record and saved payment method, and the amount and date of each top-up. If you pay with cryptocurrency we never hold a wallet or key for you; we store the payment's reference, its status, the dollar amount, and the address the payment came from where the processor reports it. Paying that way also requires you to register a refund address, which we keep so we have somewhere to return unspent balance and so we can tell whether a refund is going back where the money came from.
Agreement records. When you create an account and each time you add funds, we record which version of the terms you agreed to, the time, the IP address the request came from, and your browser's user agent string. This exists to answer a bank if a payment is disputed.
Usage. Records of what you buy and use on your account — your subscription pass and its status, your balance and each top-up, and the usage of any usage-based service you buy, with the resulting charges. You can see your balance and payment history in your account.
Proxies. If you buy proxy data, we keep each order (product, amount, price and outcome) and the login for each proxy plan you hold, so we can show it to you. We do not see or record the websites you visit through a proxy, or anything you send through one.
Figures you choose to share from the desktop apps. The desktop apps keep your data on your own computer, and we do not receive it. Two settings, both off unless you turn them on, send us a little of it so it can appear in your account:
Bug reports from the desktop apps. When you send a report, we receive what you write, the app and its version, your operating system, an identifier for your computer, and a few counts the app keeps about itself — never the contents of your orders. If you attach a screenshot, we receive the image, and it shows whatever was on your screen. If you have turned on “Beta diagnostics” in Smeltery, the report also carries what that setting lists: the account generator's recent page captures and task log, which include the generated accounts' email addresses and the verification codes sent to them. Screenshots and diagnostics are kept in private storage that only Kiln staff can open, with two-factor sign-in, and we record each time one is opened. They are never posted to chat. We are notified of a new report in a private staff channel on Discord with a ticket number and a code for your account — not what you wrote, and not your email address.
Your orders on your phone, if you connect one. Smeltery then sends us a copy of your recent orders (what they are, where they are, what they cost, and tracking numbers) that it has encrypted on your computer before sending. The key stays with you: Smeltery shows it to your phone inside a QR code, and it is never sent to us, so we store the copy but cannot read it. With it we keep which account and computer it belongs to, and when it was last updated.
How the site is used. We record which pages you visit, what you click, and errors the site hits, so we can find and fix problems. We do not record video or replays of your screen. Web addresses are stripped of anything sensitive before they are stored, and event details whose names look like credentials are dropped rather than sent. If you are signed in this is linked to your account id, never your email address.
Fraud and abuse signals. We use your payment and usage history to decide how much verification to require on a payment, and to spot patterns that look like card fraud. This is automated and it can restrict your account without a person reviewing it first — for example pausing your account after an unusually large or fast series of top-ups. We also record whether your account has ever been funded with cryptocurrency, because that payment route carries no trail we can check, and the reason recorded if an account is suspended. You can ask us to review any automated restriction.
If you connect Discord and designate a channel, our bot reads the checkout messages your own bots post there and queues them for the Kiln app on your computer to collect. This is the only feature where we hold a record of what you bought. A queued checkout contains the retailer, the order number, the product, size and price, the account address and profile name the order was placed under, the proxy label, and the product image link.
Card numbers are removed before the message reaches us — the bot strips them, and we store no card number, security code or expiry from a checkout. We do not receive a delivery address or a phone number this way.
We only read channels you designate. Nothing is read from a server or channel you have not chosen, and disconnecting Discord stops it. The queue is a relay, not an archive: see how long we keep it below.
A channel you designate may contain other people’s checkouts, and those are relayed too. If you point Kiln at a shared channel — a cook group, a group chat, anywhere more than one person posts — we read every checkout message in it, not only yours, and each one carries the account address and profile name it was placed under. Those people are not our customers and have not agreed to anything with us. They are relayed to the Kiln app on your computer and become part of your copy of the data, which we cannot reach or delete. If that is not what you want, designate a channel only your own bots post to.
We never ask you for your name, address, phone number, or date of birth, and nothing on this site requires them. If you sign in with Discord or Google we receive whatever profile they return, which usually includes a display name — see section 3. We use no advertising trackers, run no ads, and never sell or share your data for advertising.
Cookies. The ones that keep you signed in, one for the usage analytics described above, and — if you arrive through someone's referral link — one that remembers that code for 30 days so their referral can be credited.
Tools that run on your own machine or accounts. Some of our tools run on your computer or connect to accounts that belong to you. Smeltery is a desktop application: the order and profit data you keep in it stays on your computer and is not sent to us unless you choose to sync it. Where a tool connects to a service that belongs to you, we do not copy or store what is in that service beyond what is needed to provide the feature you asked for.
These providers handle data on our instructions and for our purposes only:Vercel, which hosts this website and therefore handles every request to it; Supabase, which provides authentication, the database and file storage; Cloudflare, which runs our domain's name servers and whose Turnstile provides the anti-bot check on the sign-in form; and PostHog, which receives the site-usage records described above.
If you buy proxies, the plan is supplied by our proxy network provider. We send it only the order itself and a reference code that does not reveal your name, email or account id. Your traffic passes through its network, so, like any proxy, it can see the connections you make and may keep logs of them under its own policy.
These decide for themselves how they use what they receive, so their own privacy policies govern it as well as ours: Stripe, which processes card payments and runs its own fraud checks; Plisio, which processes cryptocurrency payments if you choose that method and receives your email address with the payment request; and Discord, if you sign in with it or join our server.
If you sign in with Discord or Google, they confirm your identity to us and we keep the profile they return — the account id, and depending on the provider your username or name, avatar and email. We use the Discord id to send you service notifications by direct message and, only if you allow it on Discord's own permission screen, to add you to our Discord server. If you become a paid affiliate, a role marking that is applied to your account on our Discord server, which other members of it can see. You can revoke access at any time in Discord, and anything you send us in a Discord conversation is held on Discord's systems, not just ours.
If you dispute a payment, we send Stripe what it needs to answer the dispute: your email address, your account id and when the account was created, every record of you agreeing to the terms with the IP address and browser recorded at the time, and the record of what you bought and used. Without it we cannot answer the dispute.
When you choose a password, we check it against the Have I Been Pwned breach database using a method that sends only the first five characters of its hash. Your password, and its full hash, never leave your browser.
We do not sell personal data, and we do not share it for advertising.
Agreement records, including the IP address recorded with them: 24 months, then deleted automatically. We keep them to administer your account, to answer a bank if a payment is disputed, and to establish or defend a legal claim. Twenty-four months is several times longer than the window in which a card payment can normally be disputed, and we delete them after that rather than holding an address indefinitely for a purpose that has passed. The record of what you actually bought and spent — the ledger and your usage — is kept separately and for longer, under the paragraph below.
Billing and usage records are kept while your account is open and afterwards for as long as tax and accounting rules require.
Operational records are kept indefinitely. These are the log of actions taken on the platform — sign-ins and account changes, purchases, and administrative actions on an account with the reason given. We keep them because they are what lets us investigate an incident or answer a dispute about something that happened long ago. They are not deleted on a timer today.
Checkouts relayed from Discord: 30 days, then deleted automatically, whether or not your computer has collected them. The queue exists to carry a checkout to the Kiln app on your machine — once it is there, the record that matters is the one in your own copy of the app, which is on your computer and not ours. A computer that has been offline for longer than 30 days misses the tail of the queue rather than us holding it indefinitely.
Bug-report screenshots and diagnostics: 30 days, then deleted automatically. They are for fixing the problem you reported, and a problem that is still open after a month gets a fresh report. The written report itself is kept with the operational records above.
The encrypted phone copy: until you disconnect the phone in Smeltery, which deletes it at once, or after 90 days without an update, when it is deleted automatically.
Where it is held. Our website, database and the other providers named above are US-based services.
You can see your balance and payment history, and change your password, from your settings. To change the email address on your account, ask us.
You can ask us to delete your account and the personal data attached to it. We will keep the billing records we are legally required to keep, and nothing else. Your unspent purchased balance is refunded — that is a commitment in section 7 of the terms, not a discretion. Promotional balance has no cash value and is not included, and a refund is never more than you have paid us.
Depending on where you live you may also have the right to a copy of your data, to correct it, or to object to how we use it. Contact us and we will action it.
Access to your account requires your password, and two-factor authentication if you enable it. Card details never reach our servers, and passwords are stored only as a hash by our authentication provider.
No system is perfect. If we discover a breach affecting your personal data we will tell you and the relevant regulator as the law requires.
Questions about any of this, or to exercise any of the rights above: use the contact route for formal notices in section 15 of the terms.