Legal
Privacy policy
What Kildr collects, how analytics works, what it refuses to do with your data, and how a recipient removes themselves completely.
Last updated 25 August 2026
Scope
This policy covers the Kildr website and the paid message request service offered on it. It applies both to senders, who write and pay for a request, and to recipients, who receive a request and decide what to do with it.
Kildr is operated as a small independent service. If anything here is unclear, treat the stricter reading as the one we intend.
What we collect
- Phone numbers. The recipient number you enter, and your own number once you confirm it after payment. Numbers are stored in hashed form for matching and in usable form where the service needs them for delivery, access and deletion.
- Message content. The single message you write, held so that the recipient can read it if they choose to open the request and return to it later.
- An optional nickname and sender name. Only what you type. If you send anonymously, no name is shown to the recipient.
- Payment records. Amount, currency, status, payment type and the payment reference, including separate message, premium-theme and read-receipt purchases. Card details are handled entirely by our payment processor and never reach Kildr servers.
- Delivery and decision events. Timestamps for queued, sent, delivered, request viewed, message opened, declined, blocked, opted out and recipient responses, including response-change timing and whether a no-contact response is final.
- Basic technical data. Request logs and coarse error information needed to keep the service running and to detect abuse.
- Analytics data. The Google tag uses Consent Mode with Analytics and advertising storage denied by default. In that state Google receives basic cookieless page measurement. If you accept analytics cookies, Google Analytics also measures navigation, form interaction, scroll, engagement, downloads, outbound links and coarse client errors, and TikTok Pixel measures product usage and campaign attribution. We do not send form values, message content, phone numbers, private access codes or raw private message/status tokens to either analytics service.
Google Analytics and TikTok Pixel
The Google tag loads with Analytics and advertising storage denied by default. Before you make a choice, and if you choose "Essential only", it sends basic cookieless measurement without setting Google Analytics cookies. Full Google Analytics storage and TikTok Pixel are enabled only after you choose "Accept all" in the cookie banner.
You can change your cookie choice at any time using the Cookie settings link at the bottom of the website or by selecting here. Choosing "Essential only" keeps Google Analytics storage denied, disables TikTok Pixel for future browsing on that device and clears Kildr's Google Analytics cookies where possible.
Google Analytics is configured for product measurement rather than advertising. Google signals, ad storage, ad-user-data and ad-personalization signals are disabled. Kildr removes query parameters from Google Analytics page locations and replaces private message and status identifiers with generic route placeholders before Google Analytics events are sent.
TikTok Pixel is used for website measurement and campaign attribution. Kildr does not run the TikTok Pixel on private message or status-token routes, and it does not trigger TikTok page tracking on URLs containing query parameters. This prevents private Kildr tokens and payment-return identifiers from being sent through the browser pixel.
What we do not do
- We do not sell, rent or trade phone numbers or message content.
- We do not use your message content to advertise to you or to anyone else.
- We do not show the sender phone number to the recipient unless the sender explicitly chooses to share it. Choosing Text me does not reveal a number that the sender kept private.
- We do not build marketing lists from recipient numbers. A number that received a request is not a number we contact again on our own initiative.
- We do not use Google Analytics for ad personalization.
- We do not send message content, phone numbers, access codes or raw private route tokens to TikTok Pixel.
Why we process it
We process service data to perform the service you asked for: to deliver one request, to confirm that you are the person who paid for it, to let the recipient make an informed decision, to provide the private message and status pages, to take payment, to prevent abuse and fraud, and to meet legal and accounting obligations. Optional analytics storage and TikTok measurement are processed only after consent so we can understand how the website and product are used, measure campaigns and improve them. Basic cookieless page measurement is used to understand aggregate site traffic. Where the law requires a lawful basis, ours is contract performance for delivery and payment, legitimate interest for abuse prevention and aggregate site measurement, and consent for analytics storage and TikTok Pixel.
How long we keep it
- Message requests do not automatically expire. The private recipient link, message access code, sender status link and status access code remain usable so the relevant person can return to the content later.
- Kildr does not automatically delete a request because it was opened, declined, blocked or because time passed. Safety and moderation controls can restrict delivery or visibility without automatically deleting the stored request.
- A person can remove the Kildr data associated with their phone number through the self-service Delete my data flow. The deletion flow verifies control of the phone number before removing the associated records.
- Payment or accounting information that must be retained independently for legal or accounting reasons may be subject to separate retention obligations.
- Optional analytics data is subject to the retention settings of the connected Google Analytics and TikTok services and is separate from the Kildr message-data deletion flow.
Your choices
Recipients can decline a request, use a reversible normal sender block, opt out of Kildr entirely, report an opened message, or after opening send one of the structured responses Text me, I need to think, or Never contact me again. The first two may be switched only after a 10-minute cooldown. Never contact me again is final and can be paired with a permanent sender block or Kildr-wide block that cannot be undone through the normal unblock flow.
You can keep Analytics storage denied and TikTok Pixel disabled by choosing "Essential only", and you can reopen those choices at any time using . To delete Kildr data associated with your phone number, use the self-service Delete my data feature. For access, correction, privacy, or other questions, please use our contact page. Read more about the protections built into the product on our safety page.
Security
Message content and private links are protected by access rules that keep them unreadable to anyone without the private link and its access code. Private links use high entropy tokens that cannot be guessed, are stored only as hashes, and are excluded from search engine indexing. Access codes are stored as hashes and are designed to be reused when the intended user returns to their private page. Analytics code is designed not to send message bodies, phone numbers, form values, access codes or raw private route identifiers to Google Analytics or TikTok Pixel. No system is perfect, and we do not claim otherwise. If you believe you have found a vulnerability, please report it through our contact page before disclosing it publicly.
Children
Kildr is not intended for anyone under eighteen. We do not knowingly collect data from children. If you believe a child has used the service, contact us and we will handle the report appropriately.
Current message controls and add-ons
Kildr records the service data needed for current recipient responses and sender add-ons. After opening, a recipient can choose Text me, I need to think, or Never contact me again. We store the selected response, when it was made, whether it is final, and the timing needed to enforce the 10-minute change cooldown between Text me and I need to think.
Never contact me again is a final recipient response. If the recipient then chooses a permanent sender block or a Kildr-wide block, we store that block as permanent so it cannot be removed through the normal unblock flow. Normal sender blocks remain reversible by the recipient.
Successful message, premium-theme and read-receipt payments are stored as separate payment records. A premium theme can increase the Amount paid displayed with the request. A read receipt affects only what lifecycle information the sender can see. It does not charge the recipient, and opening or reading a message is completely free for the recipient.
A sender phone number is disclosed to the recipient only when the sender explicitly chooses to share it. If the sender keeps the number private, choosing Text me does not reveal it; the recipient is only reminded that they may need to unblock the sender on their own phone.
Changes to this policy
If this policy changes in a way that affects how your data is used, the updated date at the top of this page will change and the new version will apply from that date. Requests already sent remain governed by the protections in place when they were sent.