Privacy Policy

Your privacy is
built into the design.

Khamli was architected so you never have to trust us with your identity. Here is exactly how your data is handled — no fine print, no surprises.

Overview

Khamli is a zero-identity, ephemeral sharing tool. We designed it so you never have to reveal who you are — no account, no email, no phone number, no sign-up of any kind. This privacy policy explains what little data touches our servers and exactly what happens to it.

Because we collect nothing from you personally, there is very little to say. But we believe in being transparent, so here is the full picture.

Information We Collect

We collect nothing that identifies you.

  • No names, no email addresses, no phone numbers.
  • No IP addresses are logged or stored.
  • No browser fingerprints or device identifiers are recorded.
  • We do not use cookies, localStorage, or any other client-side storage for tracking purposes. (See the Google AdSense section below for third-party advertising cookies.)

The content you choose to share — text messages, files, images, PDFs — is the only data that enters our system. And even that is temporary.

How Your Data Is Stored

All content is encrypted in transit via HTTPS. Once it reaches our infrastructure:

  • Text messages are stored in a Neon PostgreSQL database.
  • Files (images, PDFs, any format) are uploaded directly to AWS S3 via short-lived pre-signed URLs. Our application server never touches the file bytes.

Both the database and S3 buckets are configured with strict access controls. Only our application backend can read or delete the data — and it automatically deletes everything on schedule.

Data Retention & Automatic Deletion

This is the most important part. Every message and file you share on Khamli has an expiration time. You choose it when you send — 30 minutes, 2 hours, 12 hours, or 24 hours.

When that time is up, a scheduled cleanup job permanently deletes your data:

  • Database records are hard-deleted (not soft-deleted, not archived).
  • S3 objects are permanently removed from AWS.
  • There is no backup that retains your data beyond expiry.
  • Once deleted, the data is irrecoverable — by us or by anyone else.

The 4-character access code that mapped to your content is also removed from the database. Entering an expired code returns nothing.

Cookies & Google AdSense

Khamli itself does not use any cookies. However, we display advertisements through Google AdSense, which uses cookies to serve relevant ads.

Third-Party Advertising Cookies

  • Google and other third-party vendors use cookies to serve ads based on your prior visits to Khamli and other websites.
  • Google's use of advertising cookies enables it and its partners to serve ads based on your visit to Khamli and other sites on the internet.
  • You may opt out of personalized advertising by visiting Google Ad Settings or aboutads.info.
  • Third-party ad networks we work with include Google AdSense. For a full list of Google's ad technology providers and their privacy policies, visit Google's Ad Technology Providers page.

You can also manage cookie preferences through your browser settings. Most browsers allow you to block third-party cookies or clear them on exit.

No Tracking or Analytics

We do not use any third-party analytics services that track your behavior across the site. We do not know which pages you visited, how long you stayed, or what you clicked on. We have no way to connect your activity on Khamli to your real-world identity.

The Vercel deployment platform may collect aggregated, anonymous metrics (such as total request counts) for operational purposes. These metrics do not identify individual users.

Third-Party Services

Khamli relies on the following infrastructure providers:

Each of these providers has its own privacy and data handling policies. We recommend reviewing them if you have concerns about how they process data at the infrastructure level.

Data Security

We take reasonable measures to protect the content you share while it is stored on our infrastructure:

  • All data is transmitted over HTTPS (TLS).
  • Database and S3 access is restricted to the application backend via IAM roles and connection credentials.
  • Files are uploaded via single-use pre-signed URLs that expire shortly after issuance.
  • A cleanup process runs regularly to purge expired content on schedule.

However, no system is perfectly secure. Do not use Khamli to share information that would cause harm if exposed. The automatic expiry mechanism reduces the window of risk, but it does not eliminate it entirely.

Children's Privacy

Khamli is not directed at children under the age of 13. We do not knowingly collect or store any personal information from children. Since we do not collect any personal information from anyone, the risk is minimal — but parents and guardians should be aware that content shared on Khamli is publicly accessible to anyone who has the 4-character code during the expiry window.

Changes to This Policy

We may update this privacy policy from time to time. When we do, we will update the date at the bottom of this page. Continued use of Khamli after changes means you accept the revised policy.

This policy was last updated on June 20, 2026.

Contact

If you have questions about this privacy policy, how your data is handled, or anything else about Khamli, you can reach us at:

privacy@khamli.com

We respond to all inquiries within 48 hours.

Got it — take me back

Open Khamli