MEGA

Kayl · data use

How Kayl uses your data

Version 17-Sep-2026

Kayl is run by MEGA (megaiq.co). This page says what we keep, why, for how long and how to delete it. Questions go to hello@megaiq.co.

In short: Your answers and reports stay until you delete them, and you can delete everything at any time. When Level 2 opens, uploaded files are deleted within about 30 days. Backups are kept for up to 30 days. We never sell your data or use it for anyone else's report.

What we collect

  • Your work email, name, company, country and what you sell.
  • Your answers to the Kayl questions, and the reports built from them.
  • For Level 2, the stock, sales and location files you choose to upload.
  • Sign-in records and a shortened network address, used only to stop abuse.

What we use it for

  • To build your reports and show them to you.
  • To sign you in and to email you about your reports.
  • For Level 2, a MEGA reviewer checks your report before you see it. Every view is recorded.

We do not sell your data, share it with other companies, or use it for anyone else's report. Kayl pages run no analytics or advertising scripts.

How long we keep it

DataKept for
Uploaded files, as you sent themAt most one day
The cleaned copies we analyseDeleted 29 days after upload
Report details that name a SKU, store or supplierRemoved 30 days after upload
Your account, answers and report totalsUntil you delete them
Server logsUp to 30 days
Database backupsUp to 30 days

Deleting everything

In My reports, choose Delete my data and confirm with a code we email you. We sign you out everywhere straight away, delete your account, answers and reports, and email you when it is done. We keep only a scrambled record that lets us repeat the deletion if a backup is ever restored.

Cookies

Kayl uses two cookies, both needed for sign-in and both limited to our own site:

  • __Host-kayl_sid keeps you signed in, for up to 30 days.
  • __Host-kayl_cn ties a sign-in code to your browser, for up to one day.

The security check on the sign-in page is provided by Cloudflare Turnstile, which may use its own cookies for that check only.

Companies that process data for us

We run the Kayl service and its database ourselves, on hardware we control in the United Arab Emirates. A few other companies handle specific jobs for us:

CompanyWhat for
CloudflareBackups (R2), encrypted in transit and kept in a private bucket, plus the deletion record, the sign-in security check (Turnstile), DNS and the tunnel that carries traffic to our API
ResendSends sign-in codes and report emails
SentryError tracking, set up to exclude personal data
VercelHosts this website

Changes

If this page changes in a way that matters, we ask you to agree again the next time you sign in.

Start the check