Privacy Policy
Last reviewed:
This page tells you what Kiantu collects about you and your team, why we collect it, and what control you have. The short version: we collect only what we need to run the product, we don't sell anything to anyone, and the data you produce inside Kiantu (sessions, goals, comments, documents) belongs to you.
Who we are
Kiantu is operated by Kiantu Inc., a US-incorporated company. If you need to contact us about your data, privacy@kiantu.com is the right address.
What we collect
Information you give us directly
- Account info. Your email address, display name, and the OAuth profile data you authorise (name, avatar). If you sign in with a magic link, we store only your email address; we never store a password because we don't have one.
- Workspace content. The sessions you start, the goals and projects you create, the comments and documents you write, the attachments you upload, the tags you apply. This is the data the product is for.
- Preferences. Timezone, working hours, notification preferences, theme.
Information from connected services
- Calendar (Google / Outlook). When you connect a calendar, we read event metadata (title, time, attendee count) so the product can show meetings in your timeline. We do not read event bodies. You can disconnect at any time in Settings → Connectors. Google Calendar specifics are in the "Google user data" section below.
- GitHub. When you connect GitHub, we read commits, PRs, reviews and issue comments associated with the user/orgs you authorise. We do not read repository contents.
Google user data
When you connect Google Calendar, Kiantu requests the
calendar.events.readonly scope. Here is exactly what that
means:
- What we access. Read-only event metadata from your calendars. What we store is narrower still: the event title, start/end time and duration, the number of attendees (not who they are), whether you accepted, and whether you're the organizer. We do not store event descriptions, attendee names or email addresses, locations, or attachments. We never modify or delete events, and never access anyone else's calendar.
- How we use it. To display your own meetings in your personal timeline and time reports, to reconcile tracked work sessions against meetings, and to power AI features (entity extraction, insights, and the "Ask Kiantu" assistant) that help you make sense of your work. Google Calendar data is never used for advertising and never sold.
- AI processing. Some features send a limited, derived form of your calendar data — primarily the event title — to our AI provider, OpenAI, through its API. Per OpenAI's API data usage policies, data submitted through the API is not used to train OpenAI's models and is retained only briefly for abuse monitoring. We use the OpenAI API platform, never the consumer ChatGPT product, and org-level data sharing for model improvement is disabled. The vector embeddings we use for search and matching are generated by a model that runs entirely on our own infrastructure and are never transmitted to OpenAI or any other third party. Neither raw nor derived Google user data is used to train, create, or improve any foundational or generalized AI/ML model.
- How we store it. Synced event metadata is stored encrypted at rest in your workspace and is visible only to you. You can disconnect the connector at any time in Settings → Connectors, which stops all syncing, or revoke Kiantu's access entirely from your Google Account permissions page. Disconnecting stops all syncing; to have previously synced events erased, write to privacy@kiantu.com and we will complete the deletion within 30 days.
- Who we share it with. Never other workspace members or advertisers. The only third parties involved are the sub-processors listed at /sub-processors — our encrypted database host, and OpenAI for the AI processing described above — each contractually bound not to train on or otherwise repurpose your data.
Kiantu's use and transfer of raw or derived user data received from Google Workspace APIs, including any use by AI/ML models, will adhere to the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.
Information collected automatically
- Activity heartbeat. While you're using Kiantu we record when you're active vs idle so the product can build your timeline. This is per-actor and visible only to you.
- Usage analytics. Pseudonymised events about which features are used, sent to PostHog. No email addresses, no session contents, no goal/task titles — only the workspace and actor identifiers. On the marketing site this is consent-based — in the EU/EEA, the UK and Switzerland nothing runs until you accept, and you can change your choice at any time on /cookies. You can also block it with any standard ad blocker.
- Logs. Standard server logs (timestamp, request method, response code, IP address) retained for up to 30 days for debugging and abuse prevention.
How we use it
- To operate the product (showing your data back to you, building your timeline, generating insights).
- To authenticate you (magic-link emails, OAuth round-trips).
- To improve the product (pseudonymised usage analytics).
- To send you the notifications you've opted into.
- To respond to your support requests.
We do not sell your personal data, train third-party AI models on your data, or use your sessions / comments / documents for advertising.
How we share it
We share data only with the sub-processors listed at /sub-processors, each scoped to the data described there. We share with law-enforcement only when required by a valid legal process; we will notify you unless prohibited from doing so.
How long we keep it
Workspace content lives as long as the workspace exists. Archiving a workspace or scheduling it for deletion takes it out of use immediately — syncing stops and it no longer appears in the product — but the erasure of the underlying records is currently performed by us on request rather than automatically. To have your data erased, write to privacy@kiantu.com and we will complete the deletion within 30 days. Automated purge on the scheduled date is in active development. Detailed per-entity retention policies (sessions, audit events, notifications) are also in development; the trust page at /security tracks current state.
Your rights
Depending on where you live (EU/EEA, UK, California, others) you have rights to access, correct, export and delete your personal data. To exercise any of these, write to privacy@kiantu.com and we will respond within 30 days. Self-service export and deletion are on the roadmap; until they ship, the email address is the route.
Cookies and similar technologies
See /cookies.
Security
See /security for an honest description of what we have in place today and what's coming.
International transfers
Kiantu is hosted in the United States. If you're in the EU/EEA or UK, your data is transferred to the US under standard contractual clauses where applicable.
Changes
When we change this policy in a meaningful way we will update the "Last reviewed" date at the top and notify active workspaces in advance of the change taking effect.
Contact
Questions: privacy@kiantu.com
Security disclosures: security@kiantu.com