Privacy Policy
Last Updated: August 31, 2026
1. Controller and Contact
The controller and operator responsible for OwedNext is Pei Guoqiang (裴国强), an individual operator located in Binjiang District, Hangzhou, Zhejiang, China (中国浙江省杭州市滨江区). Privacy questions and rights requests may be sent to support@kekelabs.com.
2. Scope and Current Demo
This Policy covers the OwedNext website, support contact, public interactive demo, authentication, and the limited signed-in product workspace. The public demo uses fixed sample data and does not save its sample workflow as customer invoice records. No live checkout, accounting connection, automated invoice email sending, or production AI service is connected. Sign-in emails are delivered through Resend.
Do not enter real customer, invoice, payment, card, bank, or other financial information into the public demo. Only the authenticated product workspace is designed to save the customer and invoice fields described below.
3. Data Categories, Purposes, and Legal Bases
Support and contact information
If you contact us, we receive your email address, name if provided, message, and related correspondence. We use it to answer your request, keep an appropriate record, handle disputes, and comply with legal obligations. Processing is based on your request or consent, steps needed to provide the service you request, and applicable legal obligations, as relevant.
Optional product update information
If you previously asked for product updates, we may use your name, email, and update preferences to send product and timing updates. Optional updates rely on your separate consent; you can unsubscribe at any time. Any future paid-service communications will be described in the policy shown before a paid service is introduced.
Previous research submissions
An earlier version of the website displayed a Design Partner research form. It is no longer part of the public sign-up flow. If you previously submitted it, we received: name, work email, business type, business location, company size, current invoicing tool, monthly follow-up volume, typical overdue balance range, an optional description of your invoice follow-up challenge, interview choice, optional update consent, page and UTM source fields, and the Privacy Policy version accepted. We use this information to keep an appropriate record of the request, prevent duplicate entries, understand earlier demand, arrange any requested interview, and send optional updates when separately authorized. Processing is based on the consent given with that form.
Account and workspace information
When you request and use a magic-link login, we process your email address, hashed single-use login token, session identifier, user ID, Workspace ID, membership role, and login or session timestamps. Hashed email and network identifiers and temporary request counters are used to limit sign-in email abuse. These counters expire and are removed on subsequent requests. We use these fields to authenticate you, create your first Workspace, keep tenants separated, maintain a signed-in session, and protect the service. Processing is necessary to provide the account and Workspace you request, administer the service under the Terms, and meet applicable security or legal obligations.
Authenticated invoice data
In the signed-in product workspace, you may save a customer name, customer email, invoice amount in USD, due date, payment status, payment timestamp, and record timestamps. You may also save an internal owner identifier, amount paid, last-contact date and channel, next-action date, promised-payment date, short reply summary, and internal notes. CSV imports contain only the basic invoice fields. OwedNext also records a limited activity timeline for important changes, including status, next-action date, promise date, partial-payment amount, paid/undo actions, and whether a reply summary was changed. The timeline does not duplicate the reply-summary text. We use this data to provide invoice tracking, explain the Today queue, let an authorized user update workflow and payment status, export Workspace records to CSV, and measure whether a Workspace has reached the internal activation condition of three invoices plus one next action. You are responsible for having authority to provide this business contact and invoice information, giving any required notice to the people concerned, and keeping payment status accurate. Do not upload card numbers, bank credentials, tax identifiers, invoice attachments, or unrelated sensitive information. Processing is necessary to provide and secure the Workspace workflow you request under the Terms.
Technical and security data
Hosting and network providers may process IP address, browser and device details, requested page, timestamp, referrer, and security logs to deliver the site, diagnose faults, prevent abuse, and maintain security. This processing is limited to what is necessary to deliver and secure the requested site or service and to meet applicable legal obligations.
If it was enabled for the previous research form, Cloudflare Turnstile may process a verification token and limited device or network signals to detect automated abuse. The token is used only for verification and is not stored with the research table.
Demo request data
When a draft is generated, the selected sample client name, sample amount, sample days overdue, tone, and template variant are sent to the application server. They are used only to return the deterministic demo draft you request.
Possible future paid-service data
No payment provider is connected today. The planned commercial offer is a 14-day free trial followed by $19 USD per month only after active subscription, but that pricing decision does not change the data currently collected. OwedNext does not receive or store full card numbers in the current demo. Before payment information is requested, this Policy will be updated to identify the selected provider and the actual account, order, and transaction fields OwedNext receives.
4. Retention
- Demo request fields are processed to generate the response and are not intentionally written to a production customer database. Limited server or security logs may still contain request metadata under the hosting provider's retention settings.
- Magic links expire after 15 minutes and signed-in sessions expire after 30 days. Expired records can no longer be used for authentication and are periodically reviewed for deletion or anonymization based on security, troubleshooting, and abuse-prevention needs.
- Account, Workspace, membership, authenticated invoice records, and their activity history are kept while the Workspace is active and needed to provide the requested service. Following a verified deletion or account-closure request, records are deleted or anonymized after completing the request and any necessary security, dispute, or legal checks. Residual backups, if used by the selected production host, follow that provider's backup cycle.
- Support correspondence is reviewed and removed when it is no longer needed to answer the request, document a decision, handle a dispute or security incident, or meet a legal obligation.
- Previous research-submission details are reviewed after the last meaningful contact. They are deleted or anonymized when no longer needed for interviews, product research, disputes, security, or legal obligations. You may request earlier deletion. Optional update details are no longer used for marketing updates after you unsubscribe.
- If a paid service is introduced later, order and financial records will be retained only for the period required by applicable tax, accounting, fraud-prevention, and dispute rules. The final period will be confirmed before payments are accepted.
5. Service Providers and Recipients
Resend receives the destination email address and one-time sign-in link to deliver login emails. Data may be received by providers that support website hosting, content delivery, network security, error or security logging, authentication and email-link delivery when enabled, optional abuse-prevention verification (such as Cloudflare Turnstile when enabled), and PostgreSQL database hosting for previous research submissions, account, Workspace, and invoice records when a production host is selected, support or email infrastructure, future payment processing, and professional legal, tax, or accounting advice. We may also disclose information to authorities when legally required or to protect rights and security. We do not sell personal data or share it for cross-context behavioral advertising.
6. International Processing
The controller is located in China. Website and future service providers may process data in other countries or regions. Laws in those locations may differ from those where you live. Before public production data is transferred across borders, we will identify the relevant provider, recipient location, data categories, purpose, and safeguard, and obtain any separate consent required by applicable law. Production provider locations and safeguards have not yet been finalized.
7. Online Tracking and Do Not Track
OwedNext does not currently use advertising pixels or collect browsing activity over time across unrelated websites for behavioral advertising. We do not currently allow third parties to conduct that kind of tracking through OwedNext. Because this tracking is not used, browser Do Not Track signals do not change the site's current behavior. This section will be updated before any materially different tracking is introduced.
8. Your Rights and Complaints
Depending on your location, you may have rights to access, correct, delete, or receive a copy of your personal data; restrict or object to processing; withdraw consent; and complain to a competent privacy or data protection authority. Legal exceptions may apply, including required recordkeeping. Email support@kekelabs.com to exercise a right. We may need to verify your identity before acting on a request.
9. Optional Product Update Unsubscribe
Optional product update emails will include an unsubscribe method when email updates are enabled. You may also unsubscribe at any time by emailing support@kekelabs.com. We may still send non-marketing messages necessary to handle your account, rights request, prior research request, or a security matter.
10. Security and Changes
We use reasonable safeguards appropriate to this pre-launch product, including single-use login links, hashed authentication tokens, expiring sessions, and Workspace-scoped database access. No internet service can be guaranteed completely secure. OwedNext is intended for business users, not children. This Policy will be updated before new production integrations or materially different data practices begin, with the revision date shown above.