Privacy Policy

Last updated 2026-09-26

This page explains what personal data Kirality collects, why, who we share it with, and what controls you have. Plain-language summary first, full detail after.

Summary

  • We collect what we need to run your account: email, name, billing data, and your workspace's content.
  • We never sell your data.
  • We share with sub-processors only as required (Stripe for billing, Anthropic / OpenAI for AI calls you initiate, Sentry for error tracking, and analytics only if you turn it on).
  • If you connect Google Drive or Google Calendar, we use that data only for the features you use — see Google user data.
  • You can export or delete everything at any time. Contact privacy@kirality.com.

1. What we collect

Account data

  • Email, password (stored hashed — we never see the plaintext), display name
  • Tenant (workspace) name, plan tier, billing cadence
  • Stripe customer + subscription IDs (we don't store card numbers — Stripe does)

Workspace data

  • Your business records: customers, tasks, goals, and the other work you keep in Kirality
  • Documents and files you upload or generate
  • Credentials for the tools you connect, and your AI provider keys — encrypted at rest

Usage data

  • Server access logs (IP, path, status, timestamp) — retained 30 days
  • Application errors via Sentry (sampled, scrubbed of secrets)
  • AI usage records (how much was used and what it cost) — kept for billing accuracy
  • Product analytics (Google Analytics and PostHog) — only if you turn analytics on in the cookie banner

2. Why we collect it

  • Provide the service — running your agents, billing your subscription, supporting tickets
  • Keep it secure — rate limiting, fraud detection, abuse prevention
  • Improve the product — aggregated, de-identified usage patterns only. We do not train models on your content unless you explicitly opt in from your account (it is off by default, and you can turn it off at any time).

3. Sub-processors

The third parties that may receive your data when you use specific features:

ProcessorPurposeData shared
StripePayment processingEmail, name, card (held by Stripe), subscription metadata
AnthropicClaude API callsPrompts you submit + results — only when you trigger them
OpenAIGPT API callsSame as above, only if you opt into OpenAI
GoogleGoogle Drive, if you connect itYour Google name, email and profile picture, and the files you choose — only if you connect Drive
GoogleGoogle Calendar, if you connect itYour Google email and the events on your primary calendar; the details of meetings booked through your booking page — only if you connect Calendar
GoogleGoogle Analytics (site analytics)Pages visited and usage trends — only if you turn analytics on
PostHogProduct analyticsPages visited and features used — only if you turn analytics on
VercelHosting the website and the appRequest data needed to serve each page, plus anonymous page-view and performance counts
SupabaseDatabase hostingYour account and workspace data
SentryError trackingStack traces, scrubbed request context
ResendTransactional emailEmail address + message content

4. Google user data

This section covers the data Kirality receives when you connect a Google account. It applies only if you connect Google Drive or Google Calendar, and only to the account you connect.

What Kirality accesses

  • Google Drive — only the files you choose with the Google file picker inside Kirality. Kirality cannot see the rest of your Drive. Google also lets Kirality open files that Kirality itself creates in your Drive; Kirality's screens do not create any today. For each file you choose, Kirality keeps its Google file id, name and type, and when you chose it. A Drive connection made before 26 September 2026 was granted access to the whole Drive, and keeps it until it is reconnected. Reconnecting limits what Kirality holds to the files you choose; the earlier whole-Drive permission stays listed on your Google Account until you remove Kirality there (see below).
  • Google Calendar — the events on your primary calendar for the next seven days (title, time, place, who is invited, the meeting link, and whether the event is confirmed or cancelled), and the ability to add, change and remove events on that calendar.
  • Your Google profile — your name, email address, profile picture and Google account id for Drive, and your email address for Calendar.

How Kirality uses it

  • Drive files you choose: to list them in Kirality, so you can see exactly which files Kirality can open. Today Kirality does not open or read what is inside them. Searching them and answering questions from them are not switched on yet, and this page will be updated before they are.
  • Calendar: to show your week in Kirality, read from Google when you press Sync now; to add a meeting to the connected calendar when someone books it through your Kirality booking page; and to move or remove that meeting when it is rescheduled or cancelled, by the person who booked it or by someone in your workspace.
  • Your profile: to show which Google account is connected.
  • We use Google data only for these features. We do not sell it, use it for advertising, or use it to develop, improve or train AI or machine-learning models. People at Kirality do not read it unless you ask us to (for example, in a support request), it is needed for security, or the law requires it.

Where it goes

  • It is stored in our database (Supabase), inside your workspace, kept apart from every other workspace. The tokens Google issues to Kirality for Drive and for Calendar are stored encrypted, with a key for your business alone.
  • The list of Drive files you chose is shown only to you.
  • Calendar events are shown only to the person who connected that calendar. The one exception is a calendar connected before Kirality began recording who connected it (August 2026): its events are shown to everyone in the workspace until it is reconnected.
  • AI providers: Kirality does not send your Google Drive files, their names, or your Calendar events to any AI provider. If that changes, this page will say so first, and will name who receives them: the AI provider your workspace uses, which is Anthropic or OpenAI by default, or xAI or DeepSeek if your workspace added its own key for one.

Keeping and deleting it

  • A workspace admin can disconnect Google Drive in Kirality. That deletes the connection's stored Google tokens and its list of chosen files. A workspace admin can disconnect Google Calendar too, which deletes its stored Google tokens.
  • Calendar events already shown in Kirality stay in your workspace after Calendar is disconnected, until you delete the workspace or ask us to remove them at privacy@kirality.com.
  • Disconnecting in Kirality does not remove Kirality from your Google Account. You can remove Kirality's access at any time at myaccount.google.com/permissions. After that Kirality cannot read anything more from your Google account.

Kirality's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. Your rights (GDPR / CCPA)

Regardless of where you live, you can:

  • Access — request a copy of all data we hold on you
  • Delete — request permanent deletion of your account and tenant
  • Export — get your workspace's data as a JSON file
  • Object — opt out of any processing not strictly required for the service

Contact privacy@kirality.com with your request. We respond within 30 days.

6. How long we keep data

  • Active accounts: indefinitely while you have an active subscription
  • After cancellation: your data is retained so you can reactivate or export it. You can permanently delete the whole workspace at any time from your account, or by emailing us — we action it within 30 days.
  • Logs of the automated work run for you: 90 to 180 days rolling
  • Activity history and outbound delivery logs: 30 days rolling
  • Stripe records: 7 years (legal requirement)

7. Security

  • Passwords are stored hashed, never in plain text
  • Your AI keys and the instructions you write are encrypted at rest, with a key for your business alone
  • HTTPS everywhere, enforced
  • Protection against cross-site request forgery on every change you make
  • Rate limits against abuse
  • Your stored data is encrypted at rest

8. Cookies

We use a small number of strictly necessary cookies and browser storage to keep you signed in and to remember your consent choice. Analytics (Google Analytics and PostHog) stays off until you turn it on in the cookie banner, and we do not run advertising trackers. The full list, and how to change your choice, is on our cookie page.

9. Children

Kirality is not directed at children under 16. We don't knowingly collect data from minors.

10. Changes

If we make material changes we'll email account owners and update the date at the top of this page. Continued use of the service after changes means you accept the new terms.

11. Contact

Privacy questions: privacy@kirality.com
Data Protection Officer: same address.