Kindal
Legal

Privacy Policy

This policy says what data Kindal collects, why, which providers process it, how long we keep it, and what you can ask us to do with it. It is written to be read, not skimmed: if a sentence is unclear, tell us and we will fix it.

1. Who we are

This Privacy Policy explains how the operator of the Kindal service (“Kindal”, “we”, “us”) collects, uses, shares and protects personal data when you use the website at https://kindal.ai, the application at https://app.kindal.ai, and the related emails, feeds, bots and APIs (the “Service”). We are the data controller for this processing. You can reach us at hello@kindal.ai.

This policy applies to our own processing. When Kindal publishes to X, LinkedIn or another platform on your behalf, or reads public content from them, those platforms process data under their own policies, which you accepted when you opened your accounts with them.

2. What we collect

Account data. Your email address, an optional display name, your plan, your settings (email preferences, language, theme), and the time your account was created. There is no password: you sign in with a one-time code sent by email.

What you set up. The topics you follow, the sources and accounts you chose for them, keywords, trackers, companies and tickers on your watchlist, competitors, collections, folders, brand kit (name, tagline, site, handle, logos, colours, fonts), writing instructions and automation rules.

What the Service produces for you. Briefs, one-off briefs from URLs, Analyst conversations (your questions and the answers), drafts and content in every format, reply proposals, insight cards, syntheses, podcasts, videos, images and charts, and whether you opened, saved or turned a brief into content.

Connected platforms. When you connect X or LinkedIn we store the account identifier, handle, and the access and refresh tokens the platform issues, encrypted at rest. For posts published through Kindal we store the post identifier, text, time and the public engagement numbers the platform reports (views, likes, replies, reposts, quotes, bookmarks), read at 24 hours, 7 days and 30 days after posting and then frozen. When you connect Telegram or Slack we store the chat identifier or webhook address.

Public content from third parties. To write briefs and replies we read publicly available content from the sources you chose: articles, feeds, public posts and their authors’ public profile details, transcripts, datasets, filings. This may include personal data of people who are not Kindal users (for example the author of a post). We process it only to produce your briefs and drafts, we do not build profiles of those people, and we do not use it for any other purpose.

Technical and usage data. Server logs (IP address, browser and device type, pages and endpoints requested, timestamps, errors), the session cookie, and internal usage records such as which features you used and the computing cost of each operation (used for plan limits and our own accounting).

Payment data. When paid plans are enabled, our payment processor collects your billing name, address, email and payment method. We receive only a token, the last digits of the card, and the transaction status. Card numbers never reach our systems.

Communications. Emails you send us, feedback and support requests.

We do not deliberately collect special categories of data (health, religion, politics, sexual orientation and similar). If your topics or sources touch such subjects, that content is processed only as part of the briefs you asked for.

3. Why we use it and on what legal basis

  • Providing the Service you asked for (reading sources, writing briefs, answering questions, drafting and publishing content, delivering emails and chats, enforcing plan limits): performance of our contract with you.
  • Security, abuse prevention and debugging (logs, rate limits, session management, fraud checks): our legitimate interest in running a safe and reliable service, and legal obligations.
  • Billing and accounting: performance of the contract and legal obligations (tax and bookkeeping rules).
  • Improving the Service (measuring which features are used, fixing quality problems in briefs and drafts, tuning prompts): our legitimate interest. We do this on aggregated or pseudonymised data where possible. We do not train our own foundation models on your content.
  • Service messages (sign-in codes, brief emails you enabled, notices about your account, changes to terms or pricing): performance of the contract and legal obligations. Marketing emails, if any, are sent only with your consent or where the law allows it for existing customers, and every one has an unsubscribe link.
  • Legal claims and compliance: our legitimate interest in establishing, exercising or defending claims, and legal obligations.

Where we rely on consent (for example for optional cookies or marketing), you can withdraw it at any time without affecting processing done before the withdrawal.

4. How AI processing works

Kindal uses third-party language, embedding, image, speech and vision models to read sources, write briefs, answer questions and draft content. To do that we send the relevant source text, your instructions and questions, and the briefs and drafts being worked on to the model providers listed below, through their business APIs. We choose providers whose API terms commit them not to use customer data to train their models, or we configure the accounts so that training is excluded, wherever the provider offers that option; the exact commitments are in each provider’s terms. Model providers may retain requests for a limited time for abuse monitoring under their policies.

We do not use your content to train our own models. Automated processing here produces information and drafts; it does not make decisions with legal or similarly significant effects on you. You decide what to publish, either by reviewing each draft or by configuring an automation to publish in your name.

5. Who we share it with

We do not sell personal data and we do not share it with advertisers or data brokers. We share it only:

  • with processors that provide the Service under our instructions and a data-processing agreement (list below);
  • with the platforms you connect (X, LinkedIn, Telegram, Slack), when you publish or deliver through them: they then act as independent controllers;
  • with professional advisers, insurers and authorities where necessary to comply with the law, to respond to a lawful request, to enforce our terms, or to protect the rights, safety and property of Kindal, our users or others;
  • with a successor in a merger, acquisition, financing or sale of assets, under this policy, with notice to you where the law requires it.

Processors and sub-processors

The following providers process personal data on our behalf. The list changes as the Service evolves; the current version is always on this page.

ProviderWhat it doesWhat it receives
Railwayhosting of the application, worker and databaseall Service data
Google (Sign in with Google)signing in with your Google account, when you choose ityour Google account identifier, name, email and profile picture
Google (Gemini API)language and embedding models: briefs, Analyst answers, drafts, search over your briefs, speechsource text, your instructions and questions, briefs and drafts
DeepSeeklanguage models used for parts of brief and draft generationsource text, your instructions, briefs and drafts
Anthropic (Claude API)language models used for some generation and analysis taskssource text, your instructions, briefs and drafts
Resendtransactional email: sign-in codes, brief emails, notificationsemail address, brief content
X Corp. (X API) and twitterapi.iosigning in with X when you choose it; reading public posts, publishing and scheduling on your behalf, post metricsyour X account identifiers and tokens, name, profile picture and confirmed email if X shares it, posts you publish, target accounts and keywords
LinkedInpublishing on your behalfyour LinkedIn account identifiers and tokens, posts you publish
Telegram and Slackdelivering briefs to a chat or channel you connectedchat identifiers, brief content
Tavilyweb search when the Analyst or the engine needs itsearch queries derived from your topics and questions
SupadataYouTube transcripts for video sourcesvideo identifiers
ZenRowsfetching web pages that block direct readingsource URLs
Pexelsstock photos for draftsimage search terms derived from drafts
Redditreading public posts from subreddits you followsubreddit names and search terms
logo.devcompany logos on company and market pagescompany domains
Stripe (when payments are enabled)subscriptions and paymentsname, email, billing details; card data is handled by Stripe only and never reaches us

6. International transfers

Our infrastructure and several processors are in the United States or other countries outside the European Economic Area, the United Kingdom and Switzerland. Where personal data of people in those regions is transferred there, we rely on an adequacy decision where one exists (including the EU-US Data Privacy Framework for certified providers) and otherwise on the European Commission’s Standard Contractual Clauses or the UK addendum, with additional safeguards where needed. You can ask us at hello@kindal.ai for a copy of the relevant safeguards.

7. How long we keep it

  • Account, settings, topics, briefs, drafts, conversations: for as long as your account exists. When you close it, we delete or anonymise them within 30 days, except as noted below.
  • Reply proposals that you did not use are deleted after 7 days. Post metrics are frozen 30 days after posting and kept with the post record.
  • Platform tokens are deleted immediately when you disconnect the platform or close your account.
  • Server logs are kept for up to 90 days for security and debugging, unless needed for an ongoing investigation.
  • Sessions expire after 90 days and can be revoked at any time from your settings.
  • Billing records are kept for the period required by tax and accounting law (typically 10 years).
  • Backups may hold copies for up to 35 days after deletion; they are not used to restore individual accounts.
  • Aggregated statistics that no longer identify anyone may be kept indefinitely.

Where we must keep data to comply with a legal obligation or to establish, exercise or defend legal claims, we keep it only for that purpose and for as long as necessary.

8. How we protect it

All traffic is encrypted in transit (TLS). Platform tokens are encrypted at rest with a key held separately from the database. Sessions use signed, HTTP-only, secure cookies with an issue date and can be revoked centrally. We apply rate limits, strict content-security policies, request validation, per-user data isolation on every route, and least-privilege access for staff. Outbound fetches are restricted to prevent access to internal networks. No system is perfectly secure; if we learn of a breach affecting your personal data we will notify you and the competent authority as the law requires.

9. Cookies and local storage

The application uses one strictly necessary cookie to keep you signed in (HTTP-only, secure, expiring after 90 days). The website and the application also store your theme preference and small interface conveniences in your browser’s local storage; they never leave your device and identify no one. We do not use advertising cookies, cross-site tracking, or third-party analytics scripts. Because we use only strictly necessary storage, no cookie banner is shown. If we ever add optional cookies we will ask for your consent first.

10. Your rights

Depending on where you live, you have the right to:

  • access the personal data we hold about you and get a copy;
  • rectify inaccurate or incomplete data;
  • erase your data (“right to be forgotten”), subject to legal retention duties;
  • restrict or object to processing based on our legitimate interests, including profiling; and object at any time to direct marketing;
  • portability: receive the data you gave us in a structured, machine-readable format, and have it sent to another controller where technically feasible;
  • withdraw consent where processing is based on it;
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects; we make no such decisions;
  • lodge a complaint with a supervisory authority, in particular in the EU or UK country where you live or work or where the alleged infringement happened. In Italy that is the Garante per la protezione dei dati personali.

Residents of California and other US states have equivalent rights under state privacy laws, including the right to know, delete and correct, and the right to opt out of “sale” or “sharing” of personal data and of targeted advertising. We do not sell or share personal data in that sense and we do not use it for targeted advertising. We will not discriminate against you for exercising your rights. You may use an authorised agent, and we will verify requests.

To exercise any right, write to hello@kindal.ai from the email address on your account, or use the account settings where the option exists. We answer within one month (extendable by two months for complex requests, with notice), free of charge unless requests are manifestly unfounded or excessive.

11. People who are not our users

If your personal data appears in public content that Kindal reads for one of its users (for example because you posted publicly on X or wrote an article), we process it only to produce that user’s briefs and drafts, on the basis of our and our users’ legitimate interest in reading and discussing public information, and we keep it only as part of those briefs. You may object to this processing or ask us to remove your data from our systems at hello@kindal.ai; we will assess the request against the freedom of expression and information and respond within one month.

12. Children

The Service is for adults. We do not knowingly collect personal data from anyone under 18 (or under the age of digital consent where you live). If you believe a child has given us data, contact us and we will delete it.

13. Changes to this policy

We may update this policy as the Service, the law or our providers change. For material changes we will notify you by email or in the app before they take effect. The “Effective” date at the top shows the current version; earlier versions are available on request.

14. Contact

Kindal
hello@kindal.ai