Privacy Policy — Kamin
Public pilot: Transcript reading and inference run inside the user's browser. The transcript file or image is not uploaded to a Kamin server in this release.
What is stored?
The default is session-only storage. If the user explicitly chooses “Keep my profile on this device,” approved courses, the capability profile, consents, and the usage log persist locally on that device in IndexedDB until persistent saving is disabled or the data are deleted. Kamin does not create a central copy.
Image OCR
Optical character recognition runs in the browser. The hosting origin serves the site, JavaScript, and OCR runtime/language assets only; transcript bytes selected by the user are read in-browser and are not sent to a Kamin server or external OCR API.
Your controls and continuity
You can review and correct extracted data before approval, opt in or out of persistent local-device storage, delete all Kamin profile data from sessionStorage and IndexedDB, and create an encrypted local backup for restore on another device or browser. The backup contains restore state plus the capability JSON-LD graph and is encrypted in-browser with AES-GCM using a key derived from your passphrase.
Digital interests — optional
After separate consent, you may paste short excerpts you choose to suggest technical and career topics. We do not connect accounts, retrieve posts or private messages, or send text to an external analysis service. Text is used temporarily in-browser and the input is cleared after analysis. Original text does not enter storage, backups or graph exports. Do not enter names, identifiers, other people's data, health, financial or violation details.
Only topics you confirm, matching keywords from a limited list, confirmation dates, method version and consent are saved. Using these interests to explain pathway connections is a separate choice and does not change fit or eligibility judgments. You can skip without penalty, delete an interest or withdraw consent and remove this source and its connections through your profile or privacy controls. Deletion does not erase downloaded backups; delete those yourself. We do not infer personality, health or beliefs from your text.
Local storage limits
Session and persistent browser storage are not encrypted by Kamin; use a trusted device and avoid shared devices. Encrypted backups differ from the unencrypted technical JSON-LD export you can choose to download. The host receives website asset requests and ordinary connection metadata; local analysis does not mean that hosting receives no technical data.
Sources that are not enabled
There are no fields for collecting health records, violations or financial transactions, and no connection to health, bank or government systems. A new purpose requires assessment of necessity, lawful basis and risk, with appropriate notice and consent. Existing consent is not open-ended authorization.
Your passphrase
The backup passphrase is never sent to or stored by Kamin. If you lose it, Kamin cannot recover the backup. On import, skills and judgments are recomputed from evidence and external-sharing consents are not automatically restored.
Institutional deployment
Advisor/employer/research sharing and central institutional storage are not operational in the public release. Local profile data are not used to train a central model. Institutional deployment requires approved hosting, retention rules, data agreements and compliance review.
Analytics
Advertising and marketing tracking are not used to build fit judgments. Pilot analytics are disabled by default. If enabled for a defined pilot cohort, only allowlisted funnel events are collected; transcript content and personally identifying academic data are excluded. Feedback/testimonial collection requires separate explicit consent.
Last updated: 27 September 2026.
Responsibility and contact · updated 29 September 2026
Project supervisor: Prof. Adeeb Noor, Jeddah, Saudi Arabia. This identifies project leadership; it is not a legal designation of an institutional controller or university authorization. A controller, responsibilities and a rights-request channel must be identified before any central institutional collection. This release processes profiles in the browser without collecting them for the team.
Contact and privacy questions · Privacy and product change historyRecommendation-review privacy
Saving a review is an explicit choice. It stores the decision, reason, note, reviewer name or alias and self-declared role, rule version and recommendation-context fingerprint. Duration is stored only after enabling the timer. These local records are not anonymous; use an alias if you prefer.
Reviews follow the session/device-persistence choice and enter encrypted backups. They do not enter the knowledge graph or capability-sharing links, and Kamin does not send them to a team or university. History is capped at 200 events; export a private backup and clear reviews when full. Delete reviews separately; withdrawing transcript-analysis or insight consent also clears them. Copies already downloaded to other devices cannot be erased remotely.
Document signals, declared evidence and exports
When you upload a PDF we read its metadata (producer, creation and modification dates) and signature structure locally, and render the first two pages to a local canvas to look for a QR code. Neither the file nor its metadata leaves the browser, and only the displayed signals are kept with the session. A QR link opens only when you click it; the link then reaches the issuer’s site, not Kamin.
Extracted values you edited are stored with the row so the provenance badge can be shown, and they enter encrypted backups and exports. Self-declared applied evidence (title, kind, optional https link, short description, capabilities) is stored locally at the declared-applied level and deleted when transcript-analysis consent is withdrawn or with its remove button. The portable export is an unencrypted, unsigned file you download yourself; treat it as a personal file.