Where AI runs, and where it doesn't.
- Effective
- June 3, 2026
- Last reviewed
- June 3, 2026
- Entity
- Kairo Labs LLC · Chicago, IL
Kairo uses third-party large-language models for Kairo AI, extraction, and small auto-link tasks. AI sees only what you can see (RLS-enforced). We never train models on your content. Web search is opt-in via tool use. Costs are metered per plan. Current named providers available on request under a signed DPA.
The full document below is the legal version. The TL;DR is our reading of it, in plain English.
Kairo uses AI as infrastructure — not identity. The product is the intelligence layer wrapping the work: memory, permissions, structure, context. The models do the language part. This page describes exactly where AI runs, what it does, and the limits to keep in mind.
Where AI runs in Kairo
- Kairo AI reply pane — generates responses to your questions, grounded in your workspace context.
- Home Ask box — short answers about today, this week, what changed, what's due.
- Slash command expansion — turns
/meeting prep,/summarize this week, and the rest into full prompts. - Auto-titling — generates conversation titles, doc titles when you leave them blank.
- Semantic retrieval — embeds your content so search finds things by meaning, not just keywords.
- Auto-relationship inference — quietly links related notes, tasks, decisions, and meetings.
- Kairo Agent extraction — pulls dates, tasks, and people out of free-form input.
Everywhere else in Kairo is deterministic code.
Categories of AI we use
We name categories, not vendors. The current named list is available on request under a DPA — see Sub-processors.
- Reasoning & generation — large language models for conversational responses, summaries, and structured extraction.
- Embeddings — vector representations of text for semantic search and clustering.
- Speech & transcription — only when you explicitly opt in (not on by default in beta).
What we don't do
- We do not train models on your content. Ours or our providers'. Zero exceptions.
- We do not share your content with other customers. Workspace boundaries are enforced at the database layer via row-level security.
- We do not let AI take destructive actions without explicit approval. Sensitive operations (when AI proposes them) route through a review queue with an audit trail before anything dispatches.
- We do not run advertising, AI-driven or otherwise.
Zero-retention configuration
Our AI providers are configured with zero data retention. The prompts we send for a given AI request are not stored on the provider's side, not logged for human review, and not used to train any model. Kairo retains the assistant's reply attached to the originating thread (or transient feature use), and that reply is governed by the same privacy + retention rules as the rest of your workspace content.
What gets sent to the model
Only what's needed to answer the current request:
- The text of your message or the input you provided.
- A pruned context window of related entities the system surfaces — never your full workspace.
- The conversation history (for persistent threads).
- System instructions describing how Kairo wants the model to behave.
Your account email, billing info, and integration tokens are not passed to the model.
When AI is wrong
The model can hallucinate. It can be confidently incorrect about dates, attributions, and quotes. It can repeat a misinformed take from somewhere on the internet. Treat anything generated as a draft. Review before sending to anyone, committing as a fact, or acting on it.
Changes to this disclosure
When we add a new AI surface, change providers, or change what gets sent to the model, we post the update here with a new effective date.
Legal questions: legal@heykairo.io. General questions: hello@heykairo.io. We read every message.
Browse the rest of the trust center: Trust Center.