Privacy Policy
Last updated: June 11, 2026
Introduction
Kairo is an AI assistant that lives inside the messaging apps you already use — Telegram, WhatsApp, and Slack. Instead of asking you to install another app or remember another password, Kairo meets you where you are: just send a message.
This Privacy Policy explains what information Kairo collects when you interact with it through those platforms, how that information is used to deliver the service, and the rights you have over your data. It applies to all interactions via Telegram, WhatsApp, and Slack, as well as use of the Kairo web dashboard at usekairo.ai.
By using Kairo you agree to the practices described here. If you do not agree, please stop using the service and contact us at the address below to request deletion of any data we hold.
Information We Collect
We collect only the information necessary to provide Kairo's features. Specifically:
- Messages. Text messages, voice notes, and documents (e.g. PDFs) that you send to Kairo. Voice notes are transcribed in order to process your request; the transcription is stored alongside the original message record.
- Platform identifiers. Your messaging-platform user ID, chat ID, and display name as provided by Telegram, WhatsApp, or Slack. These are used to route replies back to you and to associate your data with your Kairo account.
- Timezone preference. The IANA timezone you set (or that Kairo infers), used to fire reminders and automations at the correct local time.
- OAuth tokens. If you explicitly connect a third-party service — Google (Calendar, Docs, Sheets, Gmail, Drive), Notion, Linear, GitHub, Figma, or Canva — we store the OAuth access and refresh tokens needed to act on your behalf. You control which services are connected and can revoke access at any time from the Integrations page.
- Reminders, todos, and memory entries. Items you explicitly ask Kairo to remember, track, or schedule on your behalf.
- Conversational context. A rolling history of your conversations with Kairo, plus semantic summaries of older conversations, used to maintain context across sessions.
We do not collect payment card numbers directly (billing is handled by a third-party processor), and we do not sell your personal data to advertisers or data brokers.
How We Use Your Information
Your data is used solely to deliver and improve Kairo's service:
- Process your messages through Anthropic Claude to understand your intent and generate responses.
- Transcribe voice notes using OpenAI Whisper so that spoken instructions receive the same treatment as text.
- Parse and index uploaded documents (PDF) so you can ask questions about their content.
- Execute tasks you request — setting reminders, managing todos, searching the web, performing actions in connected integrations (Google Workspace, Notion, Linear, etc.).
- Maintain conversational context across messages so Kairo can refer back to earlier instructions and avoid asking you to repeat yourself.
- Fire reminders and run scheduled automations at the times you specify.
- Improve reliability and diagnose errors through anonymized operational logs.
Third-Party Services (Sub-Processors)
Delivering Kairo's features requires sharing data with the following sub-processors. Each receives only the data necessary for its specific function:
- Anthropic — Large language model (Claude) inference for task planning, response generation, and conversation summarization.
- OpenAI — Voice transcription (Whisper) and text embeddings for semantic memory retrieval. Audio data is not used to train OpenAI models under the current API terms.
- Perplexity — Web search via the Sonar API, used only when you explicitly request a web search.
- Firecrawl — Web scraping, used only when you ask Kairo to summarize or monitor a specific URL.
- Supabase — Primary database (PostgreSQL), vector store (pgvector), and authentication. All data at rest is stored in Supabase.
- Vercel — Hosting for the Kairo web dashboard (usekairo.ai).
- Telegram, WhatsApp / Meta, Slack — Messaging platforms through which you interact with Kairo. Your use of these platforms is also subject to their respective privacy policies.
- Google, Notion, Linear, GitHub, Figma, Canva — Only when you explicitly connect these services via OAuth. We access only the scopes you grant and only to fulfill your specific requests.
Data Retention
We retain your data for as long as your account is active and for a reasonable period afterward to allow for account recovery. Specific retention rules:
- Conversation history is retained to provide context across sessions. Inactive conversations are archived automatically; archived conversations are retained as semantic summaries.
- Reminders are deleted automatically after they fire or are cancelled.
- OAuth tokens are retained until you disconnect the integration from the Integrations page, at which point the tokens are deleted from our database.
- Account deletion. You may request full deletion of your account and all associated data at any time by emailing [email protected]. We will process deletion requests within 30 days.
Your Rights
Depending on where you are located, you may have the following rights regarding your personal data:
- Access. Request a copy of the personal data we hold about you.
- Correction. Ask us to correct inaccurate or incomplete data.
- Deletion. Request erasure of your personal data (subject to legal retention obligations).
- Disconnect integrations. Remove OAuth access for any connected service at any time from the Integrations page in the dashboard.
- Delete your account. Close your account and have all associated data deleted.
To exercise any of these rights, email us at [email protected]. We may need to verify your identity before fulfilling a request.
Security
We take reasonable technical measures to protect your data:
- All data in transit is encrypted using HTTPS/TLS.
- OAuth tokens are encrypted at rest using AES-256-GCM before being stored in our database. The encryption key is stored separately from the database.
- Our database and authentication infrastructure are provided by Supabase, which maintains its own security certifications and practices. Details are available at supabase.com/security.
- Webhook authentication tokens are hashed (SHA-256) before storage so that a database compromise does not expose live token values.
No system is perfectly secure. If you believe your account has been compromised, please contact us immediately at [email protected].
Children's Privacy
Kairo is not directed at children under the age of 13, or under 16 in the European Union. We do not knowingly collect personal data from minors. If we become aware that an account belongs to a person under the applicable age threshold, we will delete that account and its associated data. If you believe a minor has used Kairo, please contact us at [email protected].
International Data Transfers
Kairo is operated from the United States. Our sub-processors — including Anthropic, OpenAI, Vercel, and Supabase — may process your data in the United States or other countries whose data-protection laws may differ from those in your home country.
Where required by applicable law (for example, for transfers from the European Economic Area), we rely on Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms to safeguard your data. You can request information about the specific safeguards in place by contacting us at the address below.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes — such as collecting new categories of data or sharing data with new third parties — we will notify you through Kairo itself (via a message in your connected platform) and update the “Last updated” date at the top of this page.
Continued use of Kairo after a policy change takes effect constitutes acceptance of the revised policy. If you do not accept the changes, you may stop using the service and request deletion of your data.
Contact
For privacy questions, data access or deletion requests, or any concerns about how we handle your information, please reach out:
Kairo Labs
Email: [email protected]