Xreos LLC ("Xreos", "we", "us") operates Kai. This policy explains what personal data Kai handles, why we handle it, and what rights you have.
- Xreos LLC
- Legalinc Corporate Services, Inc., 651 N Broad St, Suite 201, Middletown, Delaware 19709, United States
- Privacy contact: privacy@kaisupport.com
1. Two kinds of data
Kai handles two kinds of data, and your rights are different for each one.
Account Data is data about the people who use the Kai control plane. This is your name, your work email, your organization, your role, your billing details, and your product usage. For Account Data, Xreos is the controller. This policy is the notice for that data.
Customer Data is the content our business customers put into Kai. This is past conversation exports, live messages from connected channels, attachments, and the Brain that Kai compiles from them. Customer Data usually contains personal data about your end users, not about you. For Customer Data, Xreos is a processor and our customer is the controller. We handle it only under the customer's instructions and under our Terms of Service. If you are an end user who wrote to a business that uses Kai, contact that business first. We will help them answer you.
2. Account Data we collect
| Data | Where it comes from | Why we have it |
|---|---|---|
| Name, email, profile image | You, through our identity provider | To create your account and sign you in |
| Organization name, role, invitations | You and your teammates | To give each workspace its own tenant boundary |
| Billing name, address, tax details | You | To invoice you and to meet tax law |
| Product usage, feature events, dates | Your use of the product | To operate the product and to find faults |
| Server logs, IP address, browser type | Your browser and our servers | Security, abuse prevention, and debugging |
| Support messages | You | To answer you |
We do not buy personal data from data brokers. We do not run advertising networks, and we do not sell personal data.
3. Why we use Account Data
We use Account Data for these purposes only:
- To give you the service. Legal basis: performance of a contract.
- To keep the service safe. This includes rate limits, fraud checks, and audit logs. Legal basis: legitimate interests.
- To bill you. Legal basis: performance of a contract and legal obligation.
- To support you. Legal basis: performance of a contract.
- To improve the product. We look at aggregate usage, not at the content of your customers' conversations. Legal basis: legitimate interests.
- To send service messages. Outage notices, security notices, and changes to this policy. Legal basis: legitimate interests and legal obligation.
- To send product marketing. Only if you opt in, and every message has an unsubscribe link. Legal basis: consent.
4. Customer Data and how Kai processes it
Kai does four things with Customer Data. Each one is limited on purpose.
It compiles. Kai reads the conversation history a customer uploads and turns it into a reviewable Brain of answers, tone rules, playbooks, and escalation rules.
It redacts before any model call. Kai runs a deterministic redaction pass over the corpus before it sends anything to a language model. Phone numbers, email addresses, bank account numbers, payment references, national ID numbers, and names that Kai can identify are replaced with stable placeholders. The redaction is not perfect, and free-text personal data can survive it. It reduces exposure, and it is not a promise of full anonymization.
It drafts and replies. On a connected channel, Kai reads the live thread and either writes a draft for a human agent (copilot) or sends a reply itself (autopilot). The customer chooses which one, per channel and per message source.
It stores. Messages, attachments, drafts, agent actions, and review history are stored so that the customer has an audit trail.
Kai does not use Customer Data to train shared or public AI models. Kai does not mix one customer's data into another customer's Brain. Every query is scoped to one tenant.
5. AI model providers
Kai sends prompts to third-party language model providers to compile a Brain and to write replies. A prompt can contain redacted conversation text, retrieved answer entries, and the live thread.
We use providers under zero-retention or short-retention terms, and we contract with them so that they do not train their models on our prompts. A provider can hold a prompt for a short period for abuse monitoring. The current list of model providers is in the subprocessor table below.
6. Subprocessors
We use these companies to run Kai. Each one is under a written contract with confidentiality terms and data protection terms.
| Subprocessor | What it does | Where it processes |
|---|---|---|
| Supabase | Database, file storage, realtime | European Union |
| Clerk | Sign-in, organizations, sessions | United States |
| Hetzner Online GmbH | Application servers | European Union |
| OpenRouter | Model routing | United States |
| Anthropic | Language models | United States |
| Meta Platforms Ireland | WhatsApp Business Platform, if the customer connects it | European Union and United States |
| Intercom | Intercom channel, if the customer connects it | European Union and United States |
| Stripe | Payments and invoices | United States and European Union |
We tell customers before we add a new subprocessor that handles Customer Data. Write to privacy@kaisupport.com to get the notices.
7. International transfers
Xreos is a United States company. Customer Data and Account Data can move between the European Union, the United Kingdom, Turkey, and the United States.
For transfers out of the European Economic Area, the United Kingdom, and Switzerland, we use the European Commission's Standard Contractual Clauses with the United Kingdom Addendum. For transfers out of Turkey, we rely on the transfer rules of Law No. 6698 (KVKK), which include explicit consent or an approved undertaking, as the case requires. Contact us for a copy of the transfer terms.
8. How long we keep data
| Data | Retention |
|---|---|
| Account Data | For the life of the account, then 90 days |
| Customer Data in a live workspace | Until the customer deletes it, or 30 days after the contract ends |
| Uploaded corpus and compiled artifacts | Same as Customer Data. The customer can delete an import earlier |
| Redaction maps | Same as the corpus they belong to, and deleted with it |
| Billing records | 7 years, because tax law requires it |
| Security and audit logs | 12 months |
| Backups | 30 days, then they expire on their own |
After the retention period we delete the data or make it anonymous. Data in an expiring backup can survive a deletion request for up to 30 days.
9. Security
We apply these controls:
- Encryption in transit with TLS, and encryption at rest.
- Channel credentials sealed with AES-GCM envelope encryption, and never written to logs.
- One tenant boundary, checked on the server for every request. No tenant identifier ever travels in a URL or a form field.
- Least-privilege access for staff, and access only when a support case or an incident needs it.
- Private storage buckets. Media is served through a checked, per-tenant path.
- Webhook deliveries authenticated by signature, or by a secret URL segment when the platform does not issue a signing secret.
No system is fully secure. If we learn of a personal data breach, we notify affected customers without undue delay, and inside the time limits that the law sets.
10. Your rights
If you are in the European Economic Area, the United Kingdom, or Turkey, you have the right to ask for access, correction, deletion, restriction, portability, and objection. You can withdraw consent at any time. Withdrawal does not undo processing that already happened.
If you are in California, you have the right to know, to delete, to correct, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined in the CCPA.
To use a right, write to privacy@kaisupport.com. We answer inside 30 days. We can ask you to prove who you are first.
If you are unhappy with our answer, you can complain to your data protection authority. In Turkey this is the Kişisel Verileri Koruma Kurumu (KVKK).
11. Cookies
The Kai control plane uses cookies that are strictly necessary. These hold your session, your workspace, your language, and a CSRF token. We do not use advertising cookies and we do not use cross-site trackers. If we add analytics cookies later, we will ask for consent first.
12. Children
Kai is a business tool and is not for children. We do not knowingly collect personal data from a person under 16 through the control plane. Customer Data can contain messages from a minor, because a business customer's end users are its own responsibility. That customer is the controller for such data.
13. Automated decisions
Kai writes text. It does not make a decision that has a legal effect on a person, and it does not make a decision of similar significance. Autopilot sends a reply only when the answers behind that reply are approved by a human reviewer. A human can take over any conversation at any time.
14. Changes
We can update this policy. If a change is material, we tell account owners by email at least 14 days before it takes effect. The date at the top shows the last update.
15. Contact
- Privacy questions: privacy@kaisupport.com
- Postal address: Xreos LLC, Legalinc Corporate Services, Inc., 651 N Broad St, Suite 201, Middletown, Delaware 19709, United States