Legal

Privacy Policy

This policy describes how Kai Shade (“we,” “us,” or “our”) handles information when you use K-AI software and related services.

1. Scope

This Privacy Policy applies to:

  • K-AI — the self-hosted desktop and server software you run on your own hardware.
  • K-AI Cloud — our optional hosted service at cloud.getk-ai.com for account sign-in, sync, billing, always-on cloud tasks, and related features.
  • Our websites — including getk-ai.com and related marketing pages.

When you run K-AI locally without linking to K-AI Cloud, most of your workspace data stays on your devices. This policy explains what we do and do not collect in each mode.

2. Information we collect

2.1 K-AI (local / self-hosted)

When you use K-AI on your own machine, we do not operate the application backend for you and we do not receive your chats, documents, email content, notes, files, or other workspace data by default.

  • No product telemetry by default. The local app is designed to run without sending usage analytics to us.
  • Sign in with Google (official desktop builds). If you create your local account with Google, OAuth runs between your device and Google. We store your Google account identifier and tokens on your device so the app can sign you in and, if you approve the requested permissions, connect Gmail, Calendar, and Drive locally. Kai Shade does not receive your chats, documents, email content, notes, or files through sign-in alone.
  • Optional K-AI Cloud during setup. If you choose to connect K-AI Cloud later in onboarding, the same email or Google identity may be sent to K-AI Cloud to create or link a cloud account — see Section 2.2.
  • Your API keys and model providers. If you configure third-party AI or email providers, those services receive data according to their own policies — not through us unless you also use K-AI Cloud features described below.
  • Optional connections. If you connect Google or other external services inside the app, those integrations exchange data directly between your instance and the provider you authorize.
  • Updates. If you download releases from GitHub or our site, those platforms may log standard request metadata (IP address, user agent) under their own policies.

2.2 K-AI Cloud

If you create a K-AI Cloud account or link a device, we collect and process information needed to operate the service, including:

  • Account information — email address, authentication identifiers, password hash (we do not store plaintext passwords), and profile settings associated with your account.
  • Subscription and billing data — plan tier, subscription status, invoices, and payment metadata processed by Stripe. We do not store full payment card numbers on our servers.
  • Synced and cloud-stored content — enabled sync categories are encrypted on your devices before they reach K-AI Cloud. We do not store the key with that copy, so a stolen database is not readable to us. Task schedules (title, schedule, instruction) and billing stay readable so cloud jobs can fire. When you unlock cloud agents, that job decrypts synced data in memory. A live unlocked job on our infrastructure is not invisible to us.
  • Device linking — device identifiers, pairing tokens, and link status for desktops you connect to your cloud account.
  • Usage and quotas — metered consumption such as included AI credits, cloud browser minutes, API call counts, and feature entitlements.
  • Support and communications — information you send when contacting us at team@getk-ai.com.
  • Logs — server logs that may include IP address, timestamps, request paths, error diagnostics, and security events.

2.3 Website visitors

Our marketing site may receive standard web server or CDN logs (IP address, browser type, pages viewed, referrer). We do not use third-party advertising trackers on getk-ai.com.

3. How we use information

We use collected information to:

  • Provide, maintain, and improve K-AI Cloud and our websites.
  • Authenticate users, link devices, and enforce plan entitlements.
  • Process payments and manage subscriptions.
  • Run cloud agents, sync, marketplace, and related hosted features you request.
  • Monitor reliability, prevent abuse, and protect the security of our systems and users.
  • Respond to support requests and communicate service-related notices.
  • Comply with legal obligations.

We do not sell your personal information.

4. AI processing

K-AI sends prompts and context to AI model providers only when you (or an agent you configure) invoke those features.

  • Local mode: requests go from your instance to the model provider or local model you configured.
  • Cloud credits / hosted models: when you use included K-AI Cloud credits, we route completions through our infrastructure and require OpenRouter Zero Data Retention (provider.zdr) on that hop. ZDR is a provider retention promise — OpenRouter and the model still see the prompt to run it. Implicit prompt cache is allowed by OpenRouter’s ZDR stance; tools and plugins are out of scope. We do not keep those prompts (no prompt previews in billing logs).
  • Cloud speech-to-text: live cloud Call Listen audio is processed by Deepgram. Local Whisper is the path that does not send audio to a third party.

Do not submit information you are not permitted to share with us or with model providers.

5. Third-party services

We use service providers that process data on our behalf, including:

  • Stripe — payments and subscription management.
  • Supabase — authentication and cloud database infrastructure.
  • Cloud hosting providers — infrastructure for K-AI Cloud.
  • AI model providers — when you use cloud-routed or configured model APIs (managed cloud credits use OpenRouter ZDR endpoints).
  • Deepgram — only if you use cloud Call Listen speech-to-text.
  • Google — only if you explicitly connect Google services (e.g. Gmail, Calendar, Drive) in the app.

These providers are permitted to process data only as needed to perform services for us or for you, subject to their own privacy policies.

6. Data retention

  • We retain K-AI Cloud account and synced data while your account is active and as needed to provide the service.
  • Billing records may be retained as required for tax, accounting, and legal compliance.
  • Server logs are retained for a limited period appropriate for security and operations, then deleted or aggregated.
  • When you delete your K-AI Cloud account, we delete or de-identify associated cloud data within a reasonable period, except where retention is required by law or legitimate business needs (e.g. fraud prevention, billing disputes).

7. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, export, or restrict processing of your personal information.

  • Account settings — manage profile and connected services in the K-AI app or cloud dashboard where available.
  • Data export — K-AI Cloud may offer export tools for account-associated data.
  • Account deletion — you can delete your K-AI Cloud account from in-app cloud settings. Local data on your devices remains under your control.
  • Marketing email — you may opt out of non-essential marketing messages by replying to unsubscribe or contacting us.

To exercise privacy rights, email team@getk-ai.com. We may need to verify your identity before fulfilling a request.

8. Security

We use administrative, technical, and organizational measures designed to protect information, including encryption in transit (HTTPS/TLS), device-held sealed copies for enabled sync categories, access controls, and monitoring. We do not store the vault key with the sealed replica. Task schedules and billing stay readable so jobs can fire. Unlocking cloud agents decrypts synced data in process for that session; that live job is not operator-invisible. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

9. International transfers

K-AI Cloud may process and store information in the United States and other countries where we or our providers operate. By using K-AI Cloud, you understand that your information may be transferred to jurisdictions that may have different data protection laws than your own.

10. Children

K-AI and K-AI Cloud are not directed to children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. Contact us if you believe a child has provided us information.

11. Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised version on this page and update the effective date. Material changes may also be communicated by email or in-product notice where appropriate. Continued use after changes become effective constitutes acceptance of the updated policy.

12. Contact us

Kai Shade
Email: team@getk-ai.com
Website: getk-ai.com

See also our Terms of Service.