LAST UPDATED · JULY 28, 2026
Privacy Policy
Kipuly's whole premise is that your business data deserves receipts, permissions, and restraint. This policy explains what we collect, why, where it goes, and what we will never do with it — in the same plain language we use everywhere else.
1.0Who this covers, and our roles
This policy covers visitors to kipuly.com and customers of the Kipuly service, operated by [legal entity name — complete before production] ("Kipuly", "we").
We wear two hats. For your account data (who you are, your subscription, your sign-ins) we decide how data is used — we are the controller. For the records inside your workspace — which may include personal data about your customers — you decide; we process that data only to provide the service, on your instructions. You are the controller of your workspace's contents.
2.0What we collect
- Account data — your name, email address, and organization, handled through our sign-in provider (WorkOS); no passwords are stored by Kipuly itself.
- Workspace records — the business data you and your team (human and AI) create, import, or receive in your workspace: customers, invoices, notes, documents, handbook entries, and similar.
- The audit log — an immutable, hash-chained event for every write and action: who (which human or AI principal), what, when, and under which policy decision. Inputs recorded for verification are stored as hashes, not plaintext.
- Billing data — your plan and subscription state via Stripe. Card numbers go directly to Stripe; we never see or store them.
- Email interaction data — for approval links and workspace email features: delivery, bounce, and complaint signals, and inbound replies you send to workspace addresses.
- Technical logs — request metadata (route, status, timing) needed to run and secure the service. We do not log secrets or token contents.
3.0What we never do
- We never sell your data, rent it, or share it for advertising. There are no ads.
- We never use your data to train AI models — ours or anyone else's. Kipuly runs no AI inference at all.
- We never send your workspace data to an AI provider on our own initiative — data reaches your assistant only through the connection you authorized (see 4.0).
- We put no analytics or tracking scripts on our pages.
4.0How your AI assistant reaches your data
Kipuly connects to AI assistants you already subscribe to — for example Claude or ChatGPT — through a connection you explicitly authorize. When your assistant reads records or drafts an action, the data it retrieves enters your conversation with your AI provider and is from that point governed by your agreement and privacy settings with that provider. Kipuly's role is to gate what the assistant can touch (deny-by-default policies, server-side checks on every action, approvals for anything world-facing) and to record what it did.
5.0Why we process data (legal bases)
- To provide the service you signed up for — hosting your records, executing gated actions, sending approval links, billing (performance of a contract).
- To keep the service secure and honest — tenancy isolation, abuse prevention, the audit chain, technical logs (legitimate interests).
- To meet legal obligations — tax, accounting, and lawful requests.
- With your consent, where we ask for it explicitly — which we rarely need to.
6.0Who processes data for us
We use a small set of infrastructure providers under data-processing agreements:
| PROVIDER | PURPOSE | DATA INVOLVED |
|---|---|---|
| Amazon Web Services | Hosting, storage, email delivery (SES) | All service data; outbound email |
| Managed Postgres hosting | Primary database | Workspace records, audit log, account data |
| WorkOS | Authentication (sign-in) | Name, email, sign-in events |
| Stripe | Payments and subscriptions | Billing identity and payment details |
| Google Fonts | Typefaces on our public pages | Your IP address when fonts load |
We add or replace providers only under equivalent protections, and this table stays current. The fully named sub-processor list, including our database provider, is available to customers on request at privacy@kipuly.com. Beyond these processors, we disclose data only if the law compels us to — and where permitted, we will tell you first.
7.0How long we keep data
- While your workspace is active — your records and audit log are retained as the product's core function; audit retention length is a plan feature (up to seven years on Pro).
- After you leave — your data stays exportable for thirty days after your subscription ends, then is deleted from live systems in the ordinary course of operations.
- Longer only when the law requires it — for example invoicing and tax records about our relationship with you.
8.0How we protect data
- Every workspace is isolated at the database layer by row-level security; every query runs inside your tenant's boundary.
- Data is encrypted in transit (TLS) and at rest with our infrastructure providers.
- AI principals are deny-by-default; world-facing actions require out-of-band approval via signed links; every action is policy-checked server-side.
- Secrets live in managed key stores, never in code or logs; audit-log inputs are stored as hashes.
- The audit chain is append-only and hash-linked — tampering would be evident.
9.0Your rights and choices
Depending on where you live, you may have rights to access, correct, export, delete, or restrict processing of your personal data. For your account data, contact us directly. For personal data held inside a customer's workspace (for example, if you are a client of a business that uses Kipuly), the workspace owner is the controller — we will refer your request to them and support them in honoring it.
Workspace export is built in: you can take your data with you at any time. You may also lodge a complaint with your local data-protection authority.
10.0Cookies and third-party requests
The marketing site sets no cookies. The console sets essential, host-only session cookies required to keep you signed in — nothing else, and nothing third-party for tracking. Our public pages load typefaces from Google Fonts, which involves your browser requesting files from Google (disclosing your IP address to them). Stripe and WorkOS may set their own cookies on their hosted checkout and sign-in pages under their own policies.
11.0Where data lives
The service runs in the United States (AWS us-east-1). If you use Kipuly from outside the US, your data is transferred to and processed in the US; where European or UK law applies, we rely on our processors' standard contractual clauses and equivalent safeguards.
12.0Children
Kipuly is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16; if you believe we have, contact us and we will delete it.
13.0Changes to this policy
When this policy changes materially we will notify you by email or in the console before the change takes effect, and the "last updated" date above always tells you which version you are reading.
14.0Contact
Privacy questions and requests: privacy@kipuly.com.