Privacy Policy

This policy explains what data Kairos collects when you use our platform, how we use it, and the choices you have. Kairos is an AI gateway designed to minimize the data that ever reaches third-party model providers.

Last updated: June 2026

Data we collect

We collect only what we need to operate the service:

  • Account data: name, email, and organization details provided at sign-up (via our auth provider, Clerk).
  • Usage metadata: token counts, model used, latency, cost, and routing decisions for each request.
  • Configuration: routing rules, compliance policies, API keys (stored only as salted hashes), and command-center settings.
  • Billing data: plan and payment details processed by our payment provider, Stripe. We do not store card numbers.

Prompt and content handling

Kairos processes prompt content in transit to apply routing, context compression, and DLP redaction. Detected PII/PHI is stripped before content is forwarded to a model provider.

We do not use your prompts or completions to train any model. Short-lived DLP "strip proof" records (a redaction summary plus a SHA-256 hash of the original) are retained for audit and auto-purged after four hours.

How we use data

We use collected data to provide and secure the service, meter usage and bill accurately, enforce your compliance and budget policies, and produce audit trails. We do not sell personal data.

Sharing and sub-processors

We share data only with sub-processors required to run the service — including model providers you route to, Clerk (authentication), Stripe (billing), and our cloud infrastructure provider. Each is bound by data-processing terms.

Data retention and your rights

Usage and audit records are retained for the period configured by your organization (default 30 days for raw logs). You can request access to, export of, or deletion of your personal data by contacting us.

Contact

Questions about this policy or your data can be sent to [email protected].

This document is provided for transparency and does not constitute legal advice. For contractual data-processing terms (DPA), contact our team.