Every vendor with access, listed.
- Effective
- June 3, 2026
- Last reviewed
- June 3, 2026
- Entity
- Kairo Labs LLC · Chicago, IL
A small set of vendors processes data on our behalf, in categories: hosting, database + auth, AI inference, payments, transactional email. We list categories here so you know what flows where. Customers under a DPA can request the current named vendor list.
The full document below is the legal version. The TL;DR is our reading of it, in plain English.
Kairo relies on a small set of vendors who process data on our behalf to deliver the product. We list them by category here rather than by vendor name — we vet and rotate vendors regularly, and the categories below describe what data flows where. Customers under a signed DPA can request the current named list at any time.
What sub-processors are
A sub-processor is a third-party service that processes personal data on Kairo's behalf to deliver part of the product. Each one is contractually bound to the same data-handling commitments Kairo makes to you.
Categories
1. Cloud hosting & CDN
Runs the application servers, edge network, and static asset delivery that make Kairo reachable. Region: United States.
- What flows: All requests and responses, in transit only.
- Retention: Operational logs ≤ 30 days.
2. Managed database & storage
Stores spaces, notes, tasks, decisions, polls, and uploaded files. Postgres with row-level security and pgvector for context retrieval.
- What flows: Workspace content (encrypted at rest).
- Retention: For the life of the account; deleted within 30 days of account deletion.
3. AI inference providers
Generate Kairo AI replies, run semantic search, auto-extract structure from captures, and produce embeddings. We route to providers configured for zero data retention: prompts and responses are not stored, logged, or used for training.
- What flows: The prompt context for a given AI request — never your full workspace.
- Retention: Zero on the provider side; Kairo retains the assistant reply tied to the originating thread.
- Training: No customer content is ever used to train any model — ours or our providers'.
4. Authentication & identity
Email magic-link delivery, password sign-in, OAuth flows for connected calendars and integrations, and bot-protection challenges on signup/sign-in (which run a short visual probe and a per-session token; no behavioural fingerprinting).
- What flows: Email addresses, session tokens, OAuth refresh tokens (encrypted), short-lived bot-challenge tokens.
- Retention: Session tokens expire on logout; refresh tokens revoked on disconnect; bot-challenge tokens are single-use.
5. Transactional email
Sign-in links, billing receipts, comment notifications, daily digests.
- What flows: Email address, subject + body of the message.
- Retention: Delivery logs ≤ 30 days.
6. Payments & billing
Processes subscription payments and stores billing details.
- What flows: Card or bank details, billing address, invoice line items.
- Retention: As required for tax/legal recordkeeping (≥ 7 years).
7. Analytics & product telemetry
Privacy-respecting page-view counts and aggregate feature usage. No cross-site tracking. No advertising IDs.
- What flows: Anonymized event names, page paths, coarse geography.
- Retention: 12 months rolling.
8. Customer integrations (only when you connect them)
Calendars (Google two-way sync, Apple via iCloud share link, any generic ICS feed). Data only flows when you explicitly connect the integration in Settings.
- What flows: Only the fields the integration requires — never your full Kairo workspace.
- Retention: OAuth tokens stored encrypted; revoked when you disconnect.
9. Error monitoring
Crash and unhandled-error reports from the app, including stack traces, the user account id the error happened for, the route in question, and the browser. We scrub message bodies, doc contents, and any other workspace text before send.
- What flows: Stack trace, user id, route, browser/OS, anonymized session id.
- Retention: 30 days.
Where data lives
Primary region: United States (East). Edge nodes (CDN) cache static assets only — never workspace content.
Changes to this list
We'll update this page when we add or remove a category of sub-processor. Customers under a DPA receive 30 days' advance notice of material changes via email.
Requesting the named list
Customers under a signed DPA may request the current named sub-processor list at any time. Email legal@heykairo.io from the billing contact on file.
Legal questions: legal@heykairo.io. General questions: hello@heykairo.io. We read every message.
Browse the rest of the trust center: Trust Center.