The cookies we use, and why.
- Effective
- June 3, 2026
- Last reviewed
- June 3, 2026
- Entity
- Kairo Labs LLC · Chicago, IL
Essential cookies only — for sign-in, preferences, and security. No advertising cookies. No cross-site tracking. No third-party analytics that watch you across the web.
The full document below is the legal version. The TL;DR is our reading of it, in plain English.
Kairo uses a small set of cookies — only the ones needed to run the product and to remember your preferences. We do not use cookies for advertising or cross-site tracking.
What we know about you, and why
Before the lawyer-y list, here is the same thing in plain Kairo voice. If a category lives on this page, it is here for a real reason — we wrote it down.
What we collect
- Your email + name · so you can sign in and your teammates can find you. You decide who sees which contact field — Hidden / Team / Everyone — in Settings → Profile.
- The space you were last in · stored in a first-party cookie (
kairo_active_space) so you land back there on the next visit. - What you typed, drafted, captured · tasks, notes, docs, decisions, polls, announcements. Kairo cannot do its job without these. They live in your spaces, scoped to membership.
- Anonymous product analytics · which pages loaded, which buttons got clicked, how long a brief took to render. First-party PostHog only — no third-party pixels, no profile across the web. Lets us see when a surface is broken without watching individual users.
- AI usage · for every Kairo AI turn we log model, token count, and cost. This drives your monthly cap, your BYOK dashboard, and our spend visibility. Bodies of the AI turns are stored too — they ARE the conversation; you can read them in /kairo-ai and delete them.
- Errors that hit your browser · stack traces, the URL where it broke, and your anonymized device fingerprint go to Sentry so we can fix it. PII is off by default; we never ship your messages, captures, or AI replies to Sentry.
- Approximate IP location · only when Stripe asks during checkout (for tax + payment risk). Never sold, never used to advertise.
- Calendar + contact data · only if you connect Google or Microsoft. Then we read the calendar windows + contact list scoped to what you authorized. Disconnect any time → we forget within 24h.
What we don't collect
- Browsing history outside Kairo.
- Precise GPS location.
- Microphone, camera, or screen unless YOU initiate talk-to-type / a voice flow per session.
- Anything sold to a third party. Ever.
- Anything used to train someone else's AI model without explicit per-account opt-in.
Why we collect it
Three reasons cover everything above: (1) you ask Kairo to remember it (your tasks, your notes, your AI turns); (2) we need it to keep the product running (auth cookies, AI usage logs, error reports); (3) we need to see when something is broken (anonymous analytics + Sentry). No fourth reason.
What you can do about it
- Adjust visibility on identity fields in Settings → Profile.
- Export everything Kairo has on you from Settings → Account → Data & export.
- Delete your account from Settings → Account → Delete account. We purge within 30 days; backup retention details on /privacy.
- Pause Kairo Agent at Settings → Privacy & AI so AI never proposes drafts on your behalf. Reads still work; nothing writes to your workspace without you.
- Opt out of analytics entirely at Settings → Privacy & AI → Anonymous product analytics. PostHog stops capturing for you on the next page load.
What is a cookie
A cookie is a small piece of data stored by your browser. Websites use cookies to remember things between visits (like that you're logged in) and to support core features. Some cookies are set by the site you're on (first-party); others are set by services embedded in the site (third-party). We use only first-party cookies.
Cookies Kairo uses
Strictly necessary (always on)
Kairo only sets first-party, strictly-necessary cookies. We do not ship analytics cookies, tracking pixels, or third-party cookies of any kind today — so there's no consent banner. If that ever changes, we'll add one before the new category goes live.
- Authentication session cookies (set by our identity provider) — keep you signed in. Cleared on logout or expiry.
- OAuth state cookies — anti-CSRF on integration connect flows. Cleared after the redirect completes.
- Active space cookie (
kairo_active_space) — remembers which space you were last in so you land back there. - Sidebar collapsed state (
kairo_sidebar_collapsed) — remembers your sidebar preference between page loads.
localStorage (preference, not cookies)
Theme + accent + a few UI preferences live in browser localStorage — not cookies. They never leave your device. Clear them in browser settings any time.
Anonymous analytics (PostHog, no cookies)
Kairo's product analytics use PostHog configured in localStorage-only mode — no cookies, no third-party domains, no advertising identifiers. PostHog stores an anonymized session id locally so we can see which surfaces load and which break, never to identify individual users. Opt out at Settings → Privacy & AI → Anonymous product analytics; clears on the next page load.
Cookies Kairo does not use
- Advertising cookies.
- Analytics cookies (Google Analytics, Plausible, etc.).
- Cross-site tracking pixels.
- Third-party social media trackers.
- Fingerprinting.
How to opt out
- Clear cookies in your browser settings — you'll be signed out.
- Use private/incognito browsing — cookies are cleared at session end.
Changes to this list
When we add or remove a category of cookie, we update this page with a new effective date and (if a non-essential category gets added) ship a consent banner at the same time.
Legal questions: legal@heykairo.io. General questions: hello@heykairo.io. We read every message.
Browse the rest of the trust center: Trust Center.