Legal

Privacy Policy

Your privacy matters. This policy explains how KAIROS collects, uses, and protects your personal data.

Effective Date: February 8, 2026Last Updated: April 8, 2026

1. Introduction

Welcome to KAIROS ("we," "us," or "our"), an AI-powered marketing platform available at kairos-ai.co. This Privacy Policy describes how we collect, use, disclose, and protect your personal data when you use our website, platform, and related services (collectively, the "Service").

By accessing or using the Service, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Service.

This policy applies to all users of the Service, regardless of location. Where specific regulations apply (such as the GDPR, CCPA, or EU AI Act), we have included additional sections addressing those requirements.

2. Data Controller

The data controller responsible for your personal data is:

KAIROS

Contact: [email protected]

Website: kairos-ai.co

If you have any questions about this Privacy Policy or our data practices, you may contact us at [email protected].

3. Personal Data We Collect

We collect and process the following categories of personal data:

3.1 Account Data

When you create an account, we collect your email address, full name, password (stored using bcrypt hashing), avatar image, locale preference, and timezone. This data is necessary to provide and personalize the Service.

3.2 Business Data

To deliver relevant marketing insights, we collect information about your business including product type, business model, revenue model, target markets, competitors, industry, primary website URL, distribution channels, conversion events, compliance notes, and marketing maturity level.

3.3 Authentication Data (OAuth)

If you sign in using Google or GitHub, we receive and store OAuth tokens and provider-specific identifiers. We do not receive your passwords from these providers.

3.4 Social Media Connection Data

When you connect social media accounts for content distribution, we store OAuth tokens for the following platforms: Twitter/X, Instagram, LinkedIn, TikTok, Facebook, YouTube, Threads, Reddit, Pinterest, Bluesky, Telegram, Snapchat, Google Business, and WhatsApp. These tokens are stored as JSONB data in our database and are used solely to publish and manage content on your behalf.

3.5 Content Data

We store marketing content you create or that our AI generates on your behalf, including posts, brand voice configurations, conversations, and messages exchanged within the platform.

3.6 Media Data

When you upload or generate images and videos, we store associated metadata including S3 storage keys, image dimensions, file sizes, and content types. Media files are stored in cloud object storage.

3.7 Knowledge Data

If you choose to connect external knowledge sources (such as Notion documents or website content), we ingest and create embeddings of that content to power AI-assisted marketing recommendations. This ingestion is always user-initiated.

3.8 Payment Data

We process payments through Stripe. We store your Stripe customer ID, subscription ID, and billing event records. We do not store, process, or have access to your raw credit card numbers or payment card data. Stripe handles all PCI-DSS compliance obligations.

3.9 Usage and Analytics Data

We collect usage data including page views, clicks, and session recordings through PostHog. All session recordings use input masking (maskAllInputs) to prevent capture of sensitive form data. We also collect general event data related to how you interact with the Service.

3.10 Device Data

We automatically collect technical data including browser type, operating system, IP address, and device identifiers to ensure compatibility, security, and service optimization.

3.11 Notification Data

If you enable push notifications, we store your push subscription endpoints and web push tokens (using VAPID protocol) to deliver notifications to your devices.

3.12 Memory Data

To provide contextual and personalized AI interactions, we maintain graph-based memory of your interactions using Mem0 and Neo4j. This memory helps our AI agents understand your preferences, past decisions, and business context over time.

5. How We Use Your Data

We use the personal data we collect to:

  • Provide, maintain, and improve the Service
  • Generate AI-powered marketing content, strategies, and recommendations
  • Publish content to your connected social media platforms
  • Process payments and manage your subscription
  • Send transactional emails (account verification, billing receipts, service notifications)
  • Deliver push notifications you have opted into
  • Analyze usage patterns to improve features and user experience
  • Monitor and resolve errors and technical issues
  • Maintain AI memory to provide personalized, context-aware interactions
  • Ingest and embed knowledge sources you connect for marketing intelligence
  • Prevent fraud, abuse, and unauthorized access
  • Comply with legal obligations

6. Third-Party Data Processors

We share personal data with the following third-party processors, each bound by data processing agreements. Data is shared only to the extent necessary for each processor to perform its designated function:

6.1 AI and Machine Learning Providers

OpenAI

United States

Text generation, text embeddings for content creation and knowledge processing.

Anthropic (Claude)

United States

Text generation for content creation and AI-assisted marketing.

Google / Gemini

United States

Text generation, image generation, and video generation (Veo) for multimedia marketing content.

DeepSeek

China

Text generation for content creation.

Black Forest Labs / FLUX

Germany

Image generation for marketing visuals.

Kling AI / Kuaishou

China

Video generation and avatar generation for multimedia marketing content.

6.2 Infrastructure and Storage

AWS S3 / MinIO

Cloud object storage for media files, uploads, and generated assets.

BunnyCDN

Content delivery network for media asset distribution.

Cloudflare

United States

CDN, DDoS protection, and CAPTCHA verification (Turnstile).

6.3 Payments

Stripe

United States

Payment processing, subscription management, and billing. Stripe is PCI-DSS compliant and handles all credit card data directly.

6.4 Communications

Resend

United States

Transactional email delivery (account verification, billing receipts, notifications).

6.5 Analytics and Error Tracking

PostHog

United States (us.i.posthog.com)

Product analytics, event tracking, and session recording with input masking enabled.

Sentry

United States

Error tracking and performance monitoring. Configured with send_default_pii set to false to minimize personal data collection.

6.6 Social Media and Integration

Zernio

Social media orchestration for cross-platform content publishing and management.

Composio

Multi-platform API integration for connecting third-party services.

6.7 Knowledge and Memory

Neo4j / Mem0

Graph-based memory storage for personalized AI interactions and contextual understanding.

Tavily

Web search for real-time information retrieval to enhance AI responses.

Notion

Knowledge ingestion from user-connected Notion workspaces (always user-initiated).

7. International Data Transfers

Your personal data may be transferred to and processed in countries outside your jurisdiction, including:

  • United States — Most of our third-party processors (OpenAI, Anthropic, Google, Stripe, Resend, PostHog, Sentry, Cloudflare) are based in the USA.
  • China — DeepSeek (text generation) and Kling AI / Kuaishou (video and avatar generation) process data in China.
  • Germany — Black Forest Labs / FLUX (image generation) processes data in Germany.

7.1 Transfer Safeguards

For transfers outside the European Economic Area (EEA), we implement appropriate safeguards including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data processing agreements with all third-party processors
  • Technical and organizational measures to protect data in transit and at rest

7.2 Transfers to China

China does not currently have an EU adequacy decision. For data transferred to processors in China (DeepSeek, Kling AI), we apply additional safeguards including Standard Contractual Clauses, supplementary measures as recommended by the EDPB, and transfer impact assessments to ensure your data remains protected. We minimize the data shared with these processors to only what is necessary for content generation.

8. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required by law:

Account Data

Retained while your account is active. Upon account deletion, all account data is deleted within 30 days.

Content Data

Retained while your project remains active. Deleted when you delete the project or your account.

Billing Data

Retained as required by applicable tax law, typically for a minimum of 7 years following the transaction.

Analytics Data

Retained per PostHog's configured retention policy.

Session Recordings

Retained per PostHog's session recording retention policy.

Backups

Backup copies of deleted data are purged within 90 days of the original deletion.

9. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

9.1 Rights Under the GDPR (EEA/UK Residents)

  • Right of Access — Request a copy of the personal data we hold about you.
  • Right to Rectification — Request correction of inaccurate or incomplete personal data.
  • Right to Erasure ("Right to Be Forgotten") — Request deletion of your personal data, subject to legal retention requirements.
  • Right to Restriction of Processing — Request that we limit how we process your data in certain circumstances.
  • Right to Data Portability — Receive your personal data in a structured, commonly used, machine-readable format.
  • Right to Object — Object to processing based on legitimate interest or for direct marketing purposes.
  • Right to Withdraw Consent — Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.
  • Right to Lodge a Complaint — File a complaint with your local supervisory authority if you believe we have violated your data protection rights.

9.2 Rights Under CCPA/CPRA (California Residents)

  • Right to Know — Request disclosure of the categories and specific pieces of personal information we have collected.
  • Right to Delete — Request deletion of personal information we have collected from you.
  • Right to Correct — Request correction of inaccurate personal information.
  • Right to Opt-Out of Sale/Sharing — We do not sell your personal information. If this changes, you will have the right to opt out.
  • Right to Non-Discrimination — You will not receive discriminatory treatment for exercising your privacy rights.
  • Right to Limit Use of Sensitive Data — Request that we limit the use and disclosure of sensitive personal information to what is necessary for the Service.

9.3 Right to Opt Out of AI-Powered Profiling

You have the right to opt out of automated decision-making and profiling that produces legal or similarly significant effects. While our AI systems assist with marketing content creation, they do not make automated decisions with legal effects on you. You may contact us to request human review of any AI-driven analysis of your data.

9.4 Exercising Your Rights

To exercise any of these rights, contact us at [email protected]. We will respond to your request within 30 days (or sooner if required by applicable law). We may need to verify your identity before processing your request.

10. Cookies and Tracking Technologies

We use cookies and similar technologies to operate and improve the Service:

10.1 Necessary Cookies

These cookies are essential for the Service to function:

  • next-auth.session-token — Authentication session management
  • KAIROS_LOCALE — Language preference
  • kairos-switch-project — Active project selection

10.2 Analytics Cookies

PostHog sets cookies and uses localStorage to track usage analytics and session recordings. These are only activated with your consent.

For a comprehensive list of all cookies, their purposes, and expiration periods, please refer to our Cookie Policy.

11. Children's Privacy

The Service is not directed at, and is not intended for use by, children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us at [email protected].

12. AI Data Processing Disclosure

In accordance with the EU AI Act and applicable transparency requirements, we disclose the following about our use of artificial intelligence:

12.1 AI-Generated Content

KAIROS uses AI systems (including large language models and generative AI) to process your business data and content inputs in order to generate marketing materials, including text, images, and video. These AI systems are provided by the third-party processors listed in Section 6.

12.2 Human Review

AI-generated content is presented as a draft for your review. You should review all AI-generated content before publication. KAIROS does not automatically publish AI-generated content without your explicit approval.

12.3 User Responsibility

You are responsible for ensuring that AI-generated content published through the Service complies with applicable disclosure requirements. Some jurisdictions require disclosure when content has been generated or substantially modified by AI. It is your responsibility to add appropriate disclosures as required by the laws of the jurisdictions where your content is distributed.

13. Security Measures

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Password Protection — All passwords are hashed using bcrypt before storage. We never store passwords in plain text.
  • Token-Based Authentication — Sessions are managed using secure JWT tokens with httpOnly and Secure cookie flags.
  • Encryption in Transit — All data transmitted between your browser and our servers is encrypted using HTTPS/TLS.
  • Row-Level Security — Database-level access controls ensure users can only access their own data.
  • CAPTCHA Protection — Cloudflare Turnstile is used to prevent automated abuse.
  • Input Masking — Session recordings mask all form inputs to prevent sensitive data capture.
  • Secure Cookies — Authentication cookies are set with httpOnly and Secure attributes to prevent client-side access and ensure encrypted transmission.

While we strive to protect your personal data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

14. Do Not Track

We respect browser Do Not Track (DNT) signals where technically feasible. When we detect a DNT signal from your browser, we will limit non-essential tracking activities in accordance with the signal.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

For material changes, we will provide at least 30 days' advance notice via email to the address associated with your account before the changes take effect. Non-material changes (such as formatting or clarifications) may be made without prior notice.

We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.

16. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

KAIROS Support

Email: [email protected]

Website: kairos-ai.co

We aim to respond to all inquiries within 30 days. For data subject access requests or rights requests, we will respond within the timeframe required by applicable law.