Skip to content
Legal & Compliance

Privacy Policy

This policy explains what KWS Everywhere collects, how authentication tokens and search queries are processed, and how your privacy is protected.

Last updated 30 August 2026

Who we are

Tahir Tech Labs operates the KWS Everywhere SaaS platform, web dashboard tools, and the official Google Chrome Extension. For data protection and GDPR purposes, we are the data controller of your account information.

What we collect

Account & Authentication Data

  • Your name and verified email address upon registration.
  • A securely hashed password (bcrypt) and 2FA secrets if enabled.
  • A unique, private 64-character authentication token bound to your user record.
  • Pass records, expiration dates, and the Stripe or PayFast transaction reference for each payment. We never store raw credit card numbers or bank account numbers.

Extension & Google search data

The KWS Everywhere Chrome Extension operates strictly on Google Search Engine Result Pages (SERPs) when you submit a search query.

  • The search query keyword is sent securely to our API to fetch search volume, CPC, and competition metrics.
  • The domain names appearing in search results are analyzed to return live Ahrefs DR and Moz DA badges.
  • The extension never tracks your browsing history across other websites, logs visited URLs outside Google, or sells user telemetry.

Incognito & 24h temporary caching

Every dashboard tool offers a "Save to search history" toggle switch (enabled by default).

When toggled off, your queries and research results are never written to permanent database tables. Instead, ownership is cached in temporary in-memory Redis keys for 24 hours so you can inspect your active results, after which the data expires automatically.

Security & DPoP request signing

Chrome extension requests are secured with Demonstrating Proof-of-Possession (DPoP) cryptographic signing. The background service worker generates a non-extractable ECDSA P-256 keypair in your browser's IndexedDB and signs each request with a compact JWS in the X-KWS-DPoP header, ensuring unauthorized parties cannot impersonate your token.

Third-party processing

We partner with trusted enterprise service providers solely to deliver platform functionality:

  • Stripe — PCI-compliant card processing for one-time pass checkouts worldwide. Card details are entered on Stripe's own checkout and never pass through our servers.
  • PayFast — payment processing for customers paying from Pakistan in rupees. You are sent to PayFast's own hosted checkout to choose and enter your payment method, so card numbers, bank account numbers and one-time passcodes are handled by PayFast and never pass through our servers. We receive only the outcome of the payment and its reference.
  • Google Ads API — official historical search volume and commercial bid metrics. Your keyword is sent; your identity is not.
  • Google Autocomplete — the Keyword Generator's suggestions. Unlike every other item on this list, this request is made by your own browser, directly to Google, and is not proxied through our servers: we never see the seed you typed or the suggestions that came back, and Google sees the request the same way it sees any search you make from that browser.
  • Ahrefs — live Domain Rating (DR) authority scores for the domains you look up.
  • Keywords Everywhere link-metrics API (data.keywordseverywhere.com) — Moz Domain Authority, PageRank, backlink and spam-score figures. Only bare domain names are sent.
  • Domain name registries — registration dates, requested from the registry that issued each domain over RDAP, or WHOIS where a registry publishes no RDAP service. Only the bare domain name is sent, and the date we get back is cached so the same domain is not looked up twice.
  • Cloudflare — DDoS mitigation, TLS encryption, and CDN caching.

If you are ever asked to submit proof of a payment — for example a transaction reference or a screenshot, where a payment could not be confirmed automatically — those files are stored on our own private storage, readable only by you and our administrators, and are never served from a public URL.

Your rights & data deletion

You have the complete right to export your search history, modify your profile, or permanently delete your account and all associated query logs directly from your user dashboard under Settings > Delete Account.

How long we keep things

  • Account records — for as long as your account exists. Deleting the account removes them.
  • Search history — kept until you delete it, either entry by entry or all at once from /dashboard/history.
  • Results cached for speed — a shared, keyword-keyed result cache with its own short expiry. It holds keyword metrics, not any identifier of who searched for them.
  • Payment records — retained after account deletion where tax and accounting law requires it.

If you are in the EU or UK and believe we have handled your data improperly, you may also lodge a complaint with your national data protection authority.

Contact

For privacy inquiries, GDPR data requests, or compliance questions, email us directly at [email protected].