Kaia AI, Inc. — Legal

Privacy Policy

Last updated: July 2026

This policy explains what Kaia AI, Inc. (“Kaia”) collects across kaiaai.ai and the client portal at portal.kaiaai.ai, how it is used and protected, and the choices your organization controls. It works together with the Terms of Service and the Data Processing Addendum.

1. What we collect

  • Account data. Name, work email, and a password. Passwords are stored only as a cryptographic hash (bcrypt), never in plaintext. If you sign in with Google single sign-on, we receive your name, email, and avatar from Google instead of a password.
  • Workspace profile. Organization name, industry, team size, buyer context, and the contracted service scope and operating role selected at signup — these scope what each user sees in the product.
  • Customer workspace content. Documents and data your organization uploads into its own tenant workspace. This content is processed only to provide the service to that tenant, as described in Section 3.
  • Audit trail records — a product feature. Actions taken in a workspace (uploads, workflow actions, corrections, sign-offs, exports, sign-ins) are written to an append-only audit log together with request context such as IP address, browser user agent, and session identifier. The audit trail exists so regulated customers can evidence who did what, when.
  • Acceptance records. Your acceptance of the Terms of Service, this Privacy Policy, and the Data Processing Addendum is required at signup, enforced server-side, and recorded on the signup audit record.
  • Inquiries. Information you submit through the contact form (email, company, role, and the details of your inquiry).

We do not collect or process payment card data through the service; fees are invoiced under ordered agreements. The marketing site does not run third-party advertising trackers; the portal uses authentication cookies to keep you signed in.

2. How we use information

  • to provide, operate, and secure the service;
  • to scope every authenticated request to your organization and role — access control is part of the product, not an afterthought;
  • to maintain the audit trail your organization relies on as evidence;
  • to respond to inquiries and provide support;
  • to meet legal obligations.

3. Customer content, learning, and consent

Kaia’s products improve through recorded human corrections — but what is learned from, and how far it travels, is controlled by each organization’s data-sharing consent setting, which defaults to the most restrictive level:

  • Private-only (the default). Corrections and content stay within your tenant. Nothing is shared outside your organization, and shared models are not trained on your content.
  • Structural sharing (opt-in). Anonymized structural patterns — never content — may enter a vertical-shared pool, and only once at least five independent organizations have hit the same pattern (k-anonymity), so no pattern can be traced back to a contributing organization.
  • Full sharing (opt-in). Adds anonymized correction text for model adaptation, with personally identifiable information scrubbed before any sharing and the sharing itself recorded on the audit trail.

In short: we do not train models shared across customers on your workspace content without your organization’s explicit consent.

4. Tenant isolation

Every customer workspace is isolated by row-level security enforced at the database layer, and every authenticated query is scoped to the requesting organization. The audit trail is append-only, enforced by a database trigger that blocks updates and deletes to audit records.

5. Sharing and subprocessors

We do not sell personal information. We share information only with the subprocessors that run the service, with professional advisers under confidentiality, when required by law, or in connection with a corporate transaction. Our subprocessors:

  • Vercel — website and application hosting.
  • Amazon Web Services — cloud infrastructure: database, document storage, email delivery, and model inference via Amazon Bedrock.
  • Anthropic — the Claude models that power AI processing, accessed through Amazon Bedrock.
  • Inngest — background job orchestration.

The Data Processing Addendum carries the same list with processing roles and locations.

6. Retention

Account data is retained while your account is active. Audit records are written append-only; the platform’s retention design classifies each audit record by the regulatory regime it serves (for example, multi-year retention classes for correction and document events, with legal-hold support), reflecting the record-keeping obligations of the regulated industries Kaia serves. Deletion requests are honored subject to those legal retention obligations.

7. Security

Security measures include database-enforced row-level tenant isolation, an append-only audit trail enforced by a database trigger, role-gated access on every authenticated call, bcrypt-hashed credentials, and encrypted connections (TLS) to the platform. The full security-measures summary lives in the Data Processing Addendum.

Kaia tracks SOC 2 and related industry standards in its platform standards registry and maintains a control inventory mapped to them, in which a control counts as satisfied only when it cites live, verifiable evidence in the platform itself. Kaia does not currently hold a SOC 2 attestation and does not represent one as held; the live state of each platform control — including any open control — is disclosed in-product to customers.

8. Your rights and choices

Depending on where you are, you may have rights to access, correct, export, or delete personal information, and to object to or restrict certain processing. For workspace content, Kaia acts on the instructions of the customer organization that owns the workspace — requests about content in a customer workspace are routed to that organization. To exercise rights over your own account information, contact us as described below and we will respond as applicable law requires.

9. International processing

Kaia is a US company and processes data in the United States. Where law requires a transfer mechanism for personal data, it is put in place through the Data Processing Addendum.

10. Children

The service is a business product and is not directed to children. We do not knowingly collect personal information from anyone under 16.

11. Changes and contact

We will post updates to this policy on this page and provide notice of material changes through the service or by email. Questions or requests: use the contact form or email support@kaiaai.ai. Kaia AI, Inc. is a Delaware corporation.