Terms & Privacy
Impressum
Information pursuant to §5 ECG and §25 MedienG.
IKANGAI e.U.
Blütengasse 8
8010 Graz
Austria
Owner and responsible for content: Martin Treiber
Email: hello@ikangai.com
Terms of use
What this service does
It stores a self-contained HTML file you send it and serves that file back at a URL. That is the whole service. It does not run your document, does not read it, and has no model of its own — the AI features in a rewritable run in your browser using your credentials, which never reach this server.
Publishing is anonymous, and yours to keep lawful
No account is required, so nothing verifies who published what. By publishing you confirm you have the right to distribute the content and that it does not break the law where this service is hosted. Anything that phishes, impersonates, attacks a viewer, or targets a private individual is out of bounds.
Removal
Published snapshots expire on their own: 24 hours for an ordinary publish, 90 days of inactivity for a connected share. A connected share can be withdrawn at any time by the browser that created it, which holds the update token. Anyone can report a document; reports are read by a person and never trigger automatic removal. The operator may remove any published document at any time, particularly on a credible abuse report or legal notice.
No warranty
This is provided as-is, with no guarantee of availability, durability, or fitness for anything. Do not treat a published URL as storage. The durable copy of a rewritable is the file on your own disk — that is the entire design, and this service is a convenience on top of it.
Privacy
What is stored
- The file you publish, verbatim, plus a small metadata record. For a connected share that record holds a SHA-256 hash of the update token — never the token itself.
- Aggregate counters: how many requests each route family received since the process started. These are integers in memory with no per-visitor dimension — no IP address, no user agent, no referrer, no timestamps, no per-document identifier — and they reset on restart.
- Abuse reports and takedowns, queued to a log with the reported short code, the stated reason, and any contact the reporter chose to give.
What is not stored
- No accounts. There is no sign-up, so there is no profile to keep.
- No analytics or tracking. No third-party scripts, no cookies for tracking, no advertising identifiers, no cross-site anything.
- No API keys and no document content in transit to a model. The model call happens in your browser, directly to whichever backend you configured. This service is not in that path and could not read it if it wanted to.
- No per-request logging beyond the aggregate counters above.
Rate limiting examines the requesting IP address in memory to enforce a per-hour limit. It is not written to disk and not retained.
Your content is public
A published document is served to anyone with the link. There is no access control. Do not publish anything you would not put on a public web page.
Retention
Published files are deleted by an automatic sweep once they expire (24 hours, or 90 days of inactivity for a connected share). Abuse-report and takedown logs are kept while they are operationally useful.
Contacting us
Use the address in the impressum above. For security issues specifically, follow SECURITY.md rather than emailing details in the clear.