This policy explains what data Kairos collects when you use our platform, how we use it, and the choices you have. Kairos is an AI gateway designed to minimize the data that ever reaches third-party model providers.
Last updated: June 2026
We collect only what we need to operate the service:
Kairos processes prompt content in transit to apply routing, context compression, and DLP redaction. Detected PII/PHI is stripped before content is forwarded to a model provider.
We do not use your prompts or completions to train any model. Short-lived DLP "strip proof" records (a redaction summary plus a SHA-256 hash of the original) are retained for audit and auto-purged after four hours.
We use collected data to provide and secure the service, meter usage and bill accurately, enforce your compliance and budget policies, and produce audit trails. We do not sell personal data.
We share data only with sub-processors required to run the service — including model providers you route to, Clerk (authentication), Stripe (billing), and our cloud infrastructure provider. Each is bound by data-processing terms.
Usage and audit records are retained for the period configured by your organization (default 30 days for raw logs). You can request access to, export of, or deletion of your personal data by contacting us.
Questions about this policy or your data can be sent to [email protected].