Privacy
Last updated 18 September 2026. This page describes what Kordarna does today, not what it might do later.
This page describes how Kordarna handles your information, and it is accurate as of the date above. If we change it in a way that affects you, we will tell you rather than quietly updating this page.
Kordarna is a creative planning tool. You write things in it that may be unfinished, unpublished and personal, and that shapes everything below. This page says plainly what we hold, where it sits, and what we can and cannot promise about it.
Who we are
Kordarna is operated by Kordarna Pty Ltd, an Australian company: ACN 701 850 982, ABN 80 701 850 982. Contact us through the help page.
What we hold
- Your account. Your email address, a username you choose, and your password. Passwords are hashed by our authentication provider and are never visible to us in readable form. If you add a profile picture it is stored with your account, and anybody on a team with you can see it.
- Your work. Projects, scripts, storyboards, shot lists, budgets, schedules, notes, ideas and any images you upload. How much of this we can actually read is the subject of the next section, and it is worth reading.
- Earlier versions of your work. Every project keeps up to 30 earlier copies of its document, at most one per ten minutes of editing. They are what a rollback restores. Deleting a paragraph does not immediately remove it from your account.
- Your preferences. Writing targets, spellcheck, your chosen colour and similar settings.
- Technical records. Sign-in times, and the ordinary server logs that come with running a service, which include IP addresses.
- Crash reports. When something in the app breaks, it sends us the error message, where in the code it happened, which page you were on and what browser you were using. Addresses are stripped of anything after a question mark and sign-in tokens are removed before the report is stored. Reports are only kept while you are signed in, and at most 20 an hour.
- Support messages. Anything you send us through the help page, and the address we reply to.
- Team invitations. If you invite somebody to a team we store the email address you typed, before they have an account with us.
- Your subscription. If you subscribe, we keep which plan you are on, whether it is active, when it renews and how many seats you have, along with an identifier that lets us find you at Stripe. We never see or store your card number.
We do not run advertising, we do not sell or share your information with anyone for marketing, and there is no third party analytics on this website. This website sets no cookies at all, which is why there is no cookie banner on it.
Where it is stored
On servers in the United States, operated by our hosting provider. If you are in Australia, the UK or the EU, your information is therefore transferred and stored overseas. The app also keeps a working copy on whatever device you write from, so it still works with no connection. That copy on your own device is not encrypted by us: the encryption described below happens on the way out. Your device's own disk encryption and screen lock are what protect it there.
Encryption, and exactly what it covers
Since 16 September 2026 a private project's planning and everything written in it are encrypted on your own device, with a key that is made there and never sent to us. We store those without being able to open them. That is a real change and we would rather be precise about its edges than let the word "encrypted" do work it cannot do.
Everything we can still read, and why:
- Projects shared with a team. The key belongs to one account, so nobody else on the team could open a project locked with it. Shared projects are encrypted in transit and at rest with keys we hold, as all work was before this change.
- A project you have made a read-only link for. The copy behind the link is sealed with a key we are able to work out, which is what lets it open for somebody who has no account with us. Nobody reading our database could open it, but we are not in that position. Deleting the link destroys that copy.
- Images, including storyboard frames and references. They are encrypted on your device too, but under a key our server hands your device rather than one only you hold.
- The name of everything, and its shape. Project titles, how large a document is, how many lines a script has, when you last changed it, whether it is in the Trash. For ideas, the words are encrypted but the map is not: where each idea sits and what it hangs off stay readable.
- Earlier versions saved before 16 September 2026. They were stored under a key we hold, and they stay that way so a rollback can still reach them.
The short version, which is the one we would want to read: what you write in a private project is now beyond us; what it is called, how big it is, and when you touched it are not. If our database were ever stolen, the honest description would be "contents encrypted, everything around them readable", never "only ciphertext".
One more thing, because leaving it out would make the paragraph above worth less than it looks. Your password is one of the ways you unlock your own work on a new device, which means a copy of your key, locked with your password, is stored with us. We do not know your password and cannot read that copy. But anybody who held our database could sit and guess at it, and a password that is short or reused would eventually give way. That is the trade for being able to get back in with a password at all. Use a long password you use nowhere else, and add a passkey.
This cuts both ways, and it is the part to be sure of. Before this change, if you forgot your password and lost every other way in, we could still give your work back. For private projects we no longer can. A way in that we cannot provide is a way in that nobody can provide for you, so keep more than one: a passkey, and a recovery key somewhere you will find it.
When a member of staff does need to reach key material, to restore a project or to pass a shared project's key to a colleague, that hand-out is written to an append-only log in the same action, so a failed write stops the read. Those records are kept indefinitely and are not visible to you.
Teams, and links you share
A team project is readable by everyone on that team. Sharing a project into a team hands over the key to it; removing somebody takes their copy of that key away, and they keep nothing they had not already read.
A read-only link is a copy, not a window. When you make one, your device takes a snapshot of just the parts you chose and encrypts it; the key to it lives in the part of the link after the "#", which browsers never send to any server, so link previews and chat apps that unfurl the address cannot show your work. Anybody with the whole link can open it, so treat it as published. We count how many times a link has been opened and when it was last opened, and nothing about who opened it. Deleting the link destroys the copy.
Who else touches it
We use a small number of providers to run the service, and they hold information only to do that job:
- Supabase, our hosting and database provider, which stores your account and your work.
- Netlify, which serves this website and the app itself, and runs the domain. Like any web host it sees the ordinary details of a request.
- Resend, which sends account emails such as password resets and sign-up confirmations.
- Stripe, which handles payments if you subscribe to a paid plan. Your card details go directly to Stripe and never reach us. We pass Stripe your email address so it can find your account; Stripe tells us which plan you are on, when it renews and how many seats you have, and that is all we keep.
- YouTube, but only if you paste a YouTube link into an Inspiration tab. Your own browser then fetches that video's thumbnail from Google, which means Google sees the request. Nothing is sent to them if you never paste one.
We do not give your information to anyone else except where the law requires it.
Your rights
You can ask us to give you a copy of what we hold, correct it, or delete it. You can also export your entire workspace to a file yourself at any time, from Settings, without asking us.
You can delete your account yourself, from Settings, without asking anyone. You confirm by typing your own email address, and we check it against the account you are signed in to, so the request cannot be aimed at somebody else. It removes your profile, your projects, scripts, images, ideas and settings, the keys to them, and your billing records with us. It cannot be undone and we cannot recover it for you afterwards, so export a copy first if there is any chance you want one.
Three things outlive it, and we would rather say so here than have you find out: support messages you sent us, including the address you sent them from, because they are a conversation with another person at our end; crash reports and staff access records, which stay but stop being connected to you. Deleting your account also only clears the working copy on the device you do it from. If you are signed in on another device, sign out there as well.
If you are in Australia and you are unhappy with how we have handled your information, you can complain to the Office of the Australian Information Commissioner. If you are in the UK or the EU, you can complain to your local data protection authority.
How long we keep it
Your work stays until you delete it. A deleted project sits in Trash for 30 days so you can change your mind, and then leaves the app, every device you use, and our servers. Deleting your whole account removes everything at once instead of waiting.
Earlier versions of a document are kept up to 30 per project, and older ones drop off as new ones are made. Once a project has been gone for 90 days we destroy its key as well, which makes any remaining trace of it unreadable by anyone, including us. Crash reports are kept for 60 days and a team's activity feed for 120. Support messages are kept so we can follow up on the conversation. Backups held by our hosting provider expire on their own schedule, which is theirs rather than ours, so a deletion can take a little longer to reach every copy than it takes to reach us.
Children
Kordarna is not intended for children under 13, and we do not knowingly collect information from them. If you believe a child has created an account, tell us and we will remove it.
If something goes wrong
If information is lost or exposed in a way likely to cause serious harm, we will notify the people affected and the relevant regulator, as Australia's Notifiable Data Breaches scheme requires.
Changes
If we change this page in a way that matters, we will say so in the app rather than quietly editing the date at the top.