Trust · Privacy

How we handle your data.

Effective
June 3, 2026
Last reviewed
June 3, 2026
Entity
Kairo Labs LLC · Chicago, IL
TL;DR

We collect the minimum needed to run Kairo. We never sell or share your personal data. We never train AI on your content. You can export everything or delete your account anytime. Read on for the details.

The full document below is the legal version. The TL;DR is our reading of it, in plain English.

Kairo is built around the principle that your work is yours. This policy explains, in plain language, what we collect, why we collect it, who can see it, and how to take it back.

1. Who we are

Kairo is a product of Kairo Labs LLC, a Chicago-based company. When we say "we", "us", or "Kairo", we mean Kairo Labs LLC. When we say "you", we mean the account holder. Where you sign up under a workspace owned by an employer or school, that organization may be the data controller for your usage.

2. What we collect

Account data

  • Email address, name (or preferred name), profile photo, and timezone.
  • Authentication artifacts: hashed passwords, OAuth refresh tokens (encrypted), session tokens.
  • Billing identifiers (where applicable): plan, customer ID issued by our payment processor.

Workspace content

  • Captures, notes, tasks, calendar events, decisions, polls, documents, comments, and uploaded files.
  • The graph of relationships between those entities (e.g., that task X came from note Y in space Z).
  • Embeddings of the above for semantic retrieval.

Operational data

  • IP addresses, user-agent strings, request timestamps (for security and abuse prevention).
  • Feature-usage events (anonymized, aggregated).
  • Error reports and crash diagnostics.

From integrations you connect

When you connect a calendar, document tool, or chat platform, we receive only the fields that integration sends — never your full account on that platform.

3. What we do not collect

  • Cross-site advertising IDs.
  • Audience segments for ad networks.
  • Special-category personal data (health, biometric, religious, political) — unless you choose to put it into your own notes, in which case it is your responsibility.
  • Children's data (see Children's Privacy).

4. Why we collect it

  • To provide the product: store, sync, search, and recall your work.
  • To run AI-assisted features at your request (see AI Disclosure).
  • To bill you (paid plans only).
  • To detect abuse, fraud, and security incidents.
  • To send transactional emails (sign-in links, billing receipts, comment notifications, daily digests) and product announcements you can opt out of.
  • To meet legal obligations (tax recordkeeping, subpoenas, etc.).

5. Who can see your data

  • You, and members of any workspace you join (according to that workspace's role permissions).
  • Sub-processors — vendors we use to deliver parts of the product. See Sub-processors.
  • Kairo Labs personnel, on a need-to-know basis: responding to a ticket you opened, on-call responding to an incident, or billing for account questions. Production access is logged and time-bound.
  • Law enforcement or regulators, only when legally compelled (and only the minimum data responsive to the order).

6. We never train models on your content

Kairo does not use customer content to train any AI model — ours or our providers'. Our AI providers are configured for zero data retention. See AI Disclosure for the technical details.

7. How long we keep it

  • Workspace content: for the life of the account. Deleted within 30 days of account deletion (backups purged within 90 days).
  • Operational logs: ≤ 30 days.
  • Email delivery logs: ≤ 30 days.
  • Billing records: as required by law (typically 7 years).
  • Operational audit trail: 90 days.

8. Your rights

Wherever you live, you can:

  • Access and export everything you have stored in Kairo (Settings → Data & export).
  • Correct your account details.
  • Delete your account, which deletes your content (Settings → Account).
  • Remove yourself from a workspace.
  • Object to a specific use we make of your data — email privacy@heykairo.io.

Residents of California, Virginia, Colorado, Connecticut, Utah, Texas, the EEA, the UK, and Switzerland have additional rights — see Do Not Sell or Share for the California/CPRA mechanism, and use the same address above to invoke equivalent rights elsewhere.

9. International transfers

Customer Data is processed in the United States. For any cross-border transfer from the EEA/UK/Switzerland to the US, the parties rely on the European Commission's Standard Contractual Clauses, incorporated by reference in our Data Processing Agreement.

10. Cookies

We use a small number of cookies — see Cookies. We do not use cookies for cross-site advertising.

11. Security

Encryption in transit (TLS 1.2+) and at rest (AES-256), row-level access controls, time-bound session tokens, encrypted secret storage, and an incident-response process described in our Security page.

12. Changes to this policy

Material changes — anything affecting your rights or how we handle your data — are announced by email to every registered user at least 30 days before the new effective date and posted here with a new effective date. Non-material changes may take effect immediately. Continued use of Kairo after the effective date constitutes acceptance.

13. How to reach us

Questions?

Legal questions: legal@heykairo.io. General questions: hello@heykairo.io. We read every message.

Browse the rest of the trust center: Trust Center.