Skip to content

Privacy Policy

Last updated: 2026-03-08 · Version v0.2.0-alpha

Alpha Notice

Kairo is currently in alpha. This document is a draft and will be reviewed by legal counsel before general availability. By using the alpha, you acknowledge this.

1. Introduction

Kairo ("we", "us", "our") operates the Kairo wellbeing tracking platform. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our Service.

This policy applies whenever you interact with the Kairo platform, including through our website, web application, and any connected integrations.

2. Data We Collect

Account data

Email address, name, and password (stored as a secure hash — we never store plain-text passwords).

Wellbeing tracking data

Aims, tracking entries, plan documents, scores, and any content you create within the platform.

AI conversation data

Full conversation transcripts with the AI coach, including your messages and AI responses.

Extracted profile data

Structured facts extracted from your conversations (behavioural patterns, preferences, biographical details). These are stored as individual records you can view, edit, and delete at Settings → Memory.

Third-party integration data

  • Oura — sleep scores, readiness scores, activity data
  • Strava — workout type, duration, distance, and related metrics

Technical data

IP address, browser type, device information, and usage analytics (page views, feature usage).

3. How We Use Your Data

  • Service delivery — tracking, planning, coaching, and displaying your wellbeing data
  • AI processing — generating conversation responses, extracting facts, and injecting context for more personalised coaching
  • Service improvement — aggregate, anonymised analytics to understand usage patterns and improve features

4. AI Data Processing

Kairo uses third-party AI services to provide its coaching features. Understanding these data flows is important:

  • Anthropic Claude API — your conversations are sent to Anthropic's Claude model for response generation. Anthropic processes this data according to their own privacy policy and data retention practices.
  • Voyage AI — text from your conversations and profile is sent to Voyage AI's voyage-3-large model to generate semantic embeddings (1024-dimensional vectors). These vectors are stored in our database using pgvector and are used to improve context relevance.

Fact extraction runs asynchronously after conversations end. You can view, edit, and delete all extracted facts at Settings → Memory. You may also disable AI learning entirely using the learning toggle on that page.

Integration data in AI processing

When you connect third-party integrations such as Strava or Oura, the data synced from those services (e.g. workout metrics, sleep scores) may be included in AI processing pipelines:

  • Analysis requests — when you ask questions on the Analysis page, your integration data is sent to the Anthropic Claude API to generate personalised insights and charts.
  • Weekly fact extraction — a weekly background job summarises your recent tracking data (including integration metrics) and sends the summary to the Anthropic Claude API to extract behavioural patterns and facts.
  • Semantic embeddings — extracted facts are sent to Voyage AI to generate embedding vectors for improved context matching.

Integration data is never used to train AI models. Anthropic and Voyage AI process data according to their respective privacy policies.

User Input ──> Kairo Backend ──> Anthropic Claude API (conversations)
                             ──> Voyage AI (embeddings)
                             ──> PostgreSQL + pgvector (storage)
                             <── Oura API (sleep/activity data)
                             <── Strava API (workout data)

5. Third-Party Data Sharing

  • Oura and Strava — data is pulled via OAuth authorisation. Kairo stores local copies to display within the platform.
  • We do not sell your personal data to any third party.
  • Service providers — hosting, email delivery, and error tracking providers have limited access to data as necessary to operate the Service.

Withdrawing integration access

You can disconnect any integration at any time from Settings → Integrations. When you disconnect:

  • Kairo immediately revokes its OAuth access token with the provider (Strava or Oura).
  • No further data will be synced from that provider.
  • Previously synced data (activity sessions and tracking entries) remains in your Kairo account unless you explicitly request deletion.
  • To delete all previously synced data from a provider, contact us at privacy@kairohq.io or delete your account entirely.

You may also revoke Kairo's access directly from your Strava account at strava.com/settings/apps.

6. Data Retention

  • Account data is retained while your account is active.
  • Conversation data is retained for context continuity and fact extraction.
  • Integration data (Strava activities, Oura sleep scores, etc.) is retained while your account is active and the integration is connected. Disconnecting an integration stops new syncs but does not automatically delete historical data.
  • Profile facts are periodically consolidated — the system deduplicates and decays low-relevance facts automatically.
  • You may request full data deletion at any time (see Your Rights below).

7. Your Rights (GDPR)

If you are located in the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation:

  • Right of access — request a copy of your personal data
  • Right to rectification — correct inaccurate or incomplete data
  • Right to erasure — delete your account and all associated data
  • Right to data portability — receive your data in a structured, machine-readable format
  • Right to restrict processing — disable AI learning via the toggle at Settings → Memory
  • Right to object — contact us to object to specific data processing activities

To exercise any of these rights, contact us at privacy@kairohq.io.

8. Your Rights (CCPA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act:

  • Right to know — what personal information is collected, used, and shared
  • Right to delete — request deletion of your personal information
  • Right to opt-out of sale — Kairo does not sell personal data, so this right is automatically satisfied
  • Right to non-discrimination — we will not discriminate against you for exercising your privacy rights

9. Cookies & Local Storage

  • Session cookies — NextAuth JWT tokens for authentication
  • Local storage — UI preferences such as theme selection, sidebar state, and PWA install prompt status; and, for the free Kairo Poker tool, your locally-saved studies and the 18+ acknowledgement
  • Anonymous poker cookie — a first-party kairo_anon cookie (HttpOnly) set only when you use the free Kairo Poker tool, so your shared hands can move to your account if you sign up (see section 13)
  • No third-party advertising cookies — we do not use advertising trackers or cross-site tracking cookies

10. Data Security

We take the security of your data seriously and implement the following measures:

  • Encryption in transit (TLS/HTTPS for all connections)
  • Passwords stored using secure one-way hashing (bcrypt)
  • Database-level access controls and authentication
  • Rate limiting on authentication and API endpoints
  • Security headers (CSP, HSTS, X-Frame-Options)

11. Children's Privacy

Kairo is not intended for users under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will take steps to delete that information promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through the Service. Your continued use of the Service after notification constitutes acceptance of the updated policy.

13. Kairo Poker — Anonymous Study Data

Kairo Poker is a free, no-login hand-study tool. When you use it without signing in, we process a small amount of data so the tool can work and so your work can move with you if you later create an account. This tool is intended for users aged 18 or older.

What we store, and where

  • Your studies stay in your browser. Hands and ranges you build are saved locally (IndexedDB) on your device. Nothing is sent to our servers until you share a hand or create an account.
  • Anonymous device cookie. We set a first-party kairo_anon cookie (HttpOnly — not readable by scripts) to recognise your device, so that if you sign up we can re-attach the hands you shared to your new account. It is not used for advertising or cross-site tracking.
  • Shared hands. When you share a hand, we store a frozen, redacted copy of that study (private notes are stripped) at a private, unlisted link.
  • Interaction events. Views and votes on a shared hand are counted using a daily-rotating, non-reversible IP hash — we never store your raw IP address, and the hash cannot be traced back to you or correlated across days. Comments you post are stored with the text and an optional display name.

Lawful basis, retention & erasure

  • Lawful basis (GDPR). We rely on our legitimate interest in providing and securing a free study tool, and on your consent (the 18+ acknowledgement you give before using it).
  • Retention. Unclaimed anonymous shares, comments, and interaction events are purged automatically on a schedule. When you create an account and claim your work, your shares become part of your account and follow the account retention rules above.
  • Erasure. You can ask us to erase your device's anonymous data (shares, comments, and interaction events) at privacy@kairohq.io. You can also revoke any hand you shared, and clear local studies by clearing your browser storage.

Sub-processors for the free tool

  • Cloudflare Turnstile — a privacy-respecting bot / abuse check on the share and comment endpoints. It receives limited technical signals to distinguish humans from automated abuse.
  • PostHog — privacy-respecting product analytics used to measure the acquisition funnel (e.g. visit → study → share → sign-up) in aggregate.

14. Contact Information

For privacy-related inquiries, please contact us at: privacy@kairohq.io

For general support: support@kairohq.io