Kizzey staff privacy policy
Last updated: 7 October 2026
This policy is for people who hold a Kizzey staff account. It covers the staff dashboard and what it keeps about you as a staff member. What Kizzey keeps about you as a member is in the Kizzey privacy policy, which still applies to you.
Who is responsible
UnpackedX, the founder of Kizzey, is the controller for everything described here, reachable at cryptdex@protonmail.com. Processing happens on Cloudflare Workers and Cloudflare D1, the same server Kizzey itself runs on.
The short version
- A staff account is always linked to your Kizzey member. If you erase your Kizzey data, the staff account is switched off at once.
- Your password is never stored, only a salted hash of it. Your network address is never stored, only a salted hash of it.
- A sign-in from a new browser has to be approved, from your own Kizzey app or by the founder. While it waits, the country and region it was asked from are kept with it, and the row is deleted one day after it ran out.
- What you do with staff powers is written to an audit log that the founder reads. It is kept for one year.
- Nothing here is sold, shared with advertisers or used for analytics.
Your account
- Username, display name, role, title and tag. Set by the founder. The title and tag are shown in Kizzey Chat next to your messages, so members can see that you are staff.
- Your permissions. Which staff tools you may use, either from your role or set for you by hand.
- Roles you made. If you hold Manage roles, every role you make keeps which staff account made it, for as long as the role exists. The founder sees it in his list of roles.
- Your Kizzey member. The install ID of the Kizzey account your staff account is linked to. It is how your name and picture are shown, how the approval of a sign-in reaches your phone, and why the account ends when your Kizzey data is erased. If the founder links the account to another Kizzey member, or unlinks it, its sessions, waiting sign-ins and trusted browsers end at once.
- Your personal sign-in address. A handle chosen by the founder, and a random public ID that is part of the addresses your dashboard calls. Neither is a secret and neither signs anybody in.
- Your password. Stored only as a salted PBKDF2 hash with 100,000 rounds. Kept with it: when it was set, whether it is a temporary one, how many wrong tries there were recently and until when the account is locked after too many.
- Notes and choices. A short note the founder may keep on the account, and which kinds of notification you switched off.
- Dates. When the account was made, when it was last changed and when you last signed in.
- Asking for an account. If you asked for an account on the sign-in page: the name and note you typed and a salted hash of your network address, kept until the founder answers and for 90 days after.
Signing in
- Sessions. For each sign-in: a hash of the session token (never the token), when it started, when it was last used, when it ends, a salted hash of your network address, the name your browser sends about itself, which trusted browser it belongs to and a count of calls made with an address that was not its own. A session ends after 12 hours, or after 4 hours without use, and its row is deleted then.
- Trusted browsers. For each browser you approved: a hash of a random secret kept in a cookie, a short label such as "Chrome on Windows", when it was approved, when it was last used, whether you or the founder approved it, and a salted hash of the network address. A browser stays trusted for 60 days. A trusted browser is recognised by its cookie alone and not by your network: from that browser you sign in with your password only, wherever you are. You can forget a browser on your profile page at any time, the founder can too, and a password reset, switching your account off or linking it to another Kizzey member forgets all of them.
- Sign-ins waiting for approval. The six digit code, the browser label, a salted hash of the network the request came from, the country and (when it is known) the region the request came from as Cloudflare reports them, and how it was answered. Never a city, a postcode, coordinates or the address itself. Deleted one day after it ran out, and at once when you sign out everywhere, when your password is changed or reset, when the account is switched off or when it is linked to another member.
- What the approver is shown. The browser's family and its platform, which are the two halves of the label, such as Chrome and Windows, the country and region, and when the sign-in was asked for. You see them in your Kizzey app when you approve a sign-in, next to the box for the code, so you can tell your own sign-in from somebody else's. The founder sees the same in his list of waiting sign-ins, with the code.
- Your phone. When a new browser asks to sign in, your linked Kizzey app gets a notification that says a sign-in is waiting. It never carries the code or your password. The app keeps nothing about a sign-in: it asks the server for the waiting list while the approval screen is open, and the code you type is sent once and then forgotten. When Kizzey Chat's settings are opened, the app asks the server whether the Kizzey account is linked to a staff account, as it does for every member.
- Wrong sign-ins. A wrong password on your account is written to the audit log under your username. Five wrong passwords lock the account for 15 minutes.
- Cookies. Three, all strictly needed for signing in: the session, the trusted browser and a sign-in that is waiting. No other cookie is set and nothing tracks you across sites.
Counters for the limits
- Sign-in and role counters. How many sign-ins were tried against your account and from one network, how many role changes a holder of Manage roles made (the limit is 20 a minute and 300 a day), and how often an app asked about waiting sign-ins. Numbers under a key, never the address itself, deleted after one day.
- Work counters. How many chat messages, edits, time entries and escalations you made in the current minute, hour or day, for limits such as 12 messages a minute, 60 time entries a day and 20 escalations an hour. Numbers only, deleted after 2 days.
The audit log
- Every change you make with a staff tool is written down: the time, your account, the tool and route used, what it was done to (for example a ticket, or the member acted on), a few plain fields such as the new state, and a salted hash of your network address.
- Also written down: signing in and out, refused sign-ins, password changes, the opening of a ticket attachment, agreeing to this policy, role changes, a call made with another session's address, and what the founder changes on your account, including linking it to another member.
- What you read is not logged, except ticket attachments. Messages you send in the staff chat are not logged here either, because the chat keeps them itself.
- The founder reads the audit log. Other staff do not. Lines are deleted after one year.
Notifications
- Notices for you are kept for 30 days, with whether you have read them: a new ticket, a reply on a ticket you claimed, an escalation, news about a ticket you escalated, a mention in the staff chat, a change to your role, an approved or refused sign-in.
- A notice about a ticket or a mention says who did what to which ticket or in which room: a name, a ticket number, a room name. It never carries the reason of an escalation, a note or the words of a message.
- You can switch off the kinds that are not about the safety of your account.
Tickets
- When you claim a ticket, reply to it or write an internal note, your display name, picture address and tags as shown at that moment are kept with that line of the ticket. The person who opened the ticket sees your replies with that name. Internal notes are seen only by staff.
- When you escalate a ticket: the reason you typed, the time, and your name, picture address and tags at that moment. The person who opened the ticket is told only that it was passed to a senior member of the team.
- What you write for other staff about a ticket (internal notes, time entries, the reason of an escalation) and the figures about your work are not part of the copy of their data that the member who opened the ticket can ask for.
- A ticket and everything in it is deleted 180 days after it is closed, or earlier when the member who opened it erases their data.
KPIs and time on tickets
- For each ticket you worked on, worked out from the ticket's own timeline: when you claimed it, when you first answered, when you marked it sorted, how long you held it, and the moments of your replies and notes. Times only, never the words.
- Minutes and a short note that you enter by hand as time spent on a ticket. You can change or delete your own entries.
- You see your own figures. People holding the team KPI permission and the founder see everybody's.
- These are kept only as long as the ticket itself. No long term history of figures is kept: a report is worked out on request from tickets that still exist.
The staff chat
- Messages. What you write in the staff chat: the text, the room, the time, the message you replied to, who you mentioned and when you edited it. Everybody who can see the room reads them, and so does the founder.
- How long. Messages are deleted after 90 days. The founder can set that between 7 and 365 days. Deleting a message removes its words at once and leaves a marker that a message was deleted, by whom and when, until that time is over.
- Read markers. Per room, the last message you have seen. Shown to nobody else.
- Presence. One row with the last moment your dashboard was open and the last moment it was in front. It is overwritten each time, no history of your online times is kept, and it is written only while the dashboard is open. All staff see whether you are active, away or offline.
What other people see about you
- Members of Kizzey. Your staff tag and title on your chat messages. Anybody can open the tag to see your role card: the tag, the title and the plain list of what your role may do, for example "Moderate chat" or "Manage tickets". Your name and picture there are the ones of your own Kizzey profile. Your username, your permissions in detail and the rest of your staff account are not shown to them.
- Other staff. Your name, picture, role, title, tag, the plain list of what you may do, your handle, your presence, your messages in rooms they can see, and your name on tickets.
- The founder. Everything in this policy. The founder can also view the dashboard as you would see it, without being able to act as you.
What staff see about members
- Staff tools show you members' data only as far as your permissions go. Install IDs are replaced by stand-ins that work only inside your own account. Two tools still show the first 8 characters of a real install ID: the moderation log and the list of stories.
- With "See the room" or "See members" you see members' Kizzey names, Discord names and Discord user ids, and with "See members" also their phone's maker and model, language and app version.
- What you learn about members there is for doing the staff work and for nothing else.
How long, in one place
- Sessions: until they end, 12 hours at most.
- Trusted browsers: 60 days, or until forgotten.
- Sign-ins waiting for approval, with their country and region: one day after they ran out.
- Sign-in and role counters: one day. Work counters: 2 days.
- Notifications: 30 days.
- Staff chat messages: 90 days unless the founder set another time.
- Ticket lines, time entries, figures and escalations: as long as the ticket, which is 180 days after it is closed.
- The audit log: one year.
- Which account made a role: as long as the role exists.
- The account itself, and the record of which revision of this policy you agreed to and when: until the founder deletes the account. A switched-off account has no end date of its own, and its presence row and read markers stay with it.
If you erase your Kizzey data, or leave
- Erasing your Kizzey data, from any phone of your account, switches the staff account off, unlinks it from your member, and removes its sessions, trusted browsers and waiting sign-ins at once. The founder is told that this happened.
- The account, your lines in tickets, your staff chat messages, your time entries and the audit log are not removed by that. They stay until their own time above is over, because they are the record of work done with staff powers.
- On request the founder removes your staff chat messages, time entries, read markers and presence at once, and deletes the account with its notifications and its record of the policy revisions you agreed to. Your name in ticket lines and in the audit log goes when those run out.
Your choices
- You can download what the staff chat and KPI side holds about you from your profile page. The export of your Kizzey data, asked for from any phone of your account, also lists your staff account, its trusted browsers and the policy revisions you agreed to.
- You can forget a trusted browser, sign out everywhere and change your password yourself.
- For access, correction, erasure or any question, write to the founder at the address above.
Agreeing and changes
- You are asked to agree to this policy after you set your own password, and again when it changes. Which revision you agreed to, when, and a salted hash of your network address are kept with your account.
- Every earlier version stays readable.
Back to the sign-in