Privacy policy
What Kairo stores, why, who else is involved and how to delete it.
Last updated: 23 September 2026
1. Who handles your data
| Controller | Craft Lab, SLU |
|---|---|
| Spanish tax ID | B42627893 |
| Address | Calle Leonardo Da Vinci 12A, Nave 8, 03203 Elche, Alicante, España |
| Contact | info@mykairo.app |
We are not required to appoint a data protection officer, so for anything about privacy write to that same address.
2. What we store
What you give us when you sign up
- Email address, name and, if you sign in with Google or Apple, the profile picture they give us.
- Your password is never stored in the clear: we keep a bcrypt hash, which cannot be reversed.
- If you turn on two-factor authentication: the TOTP secret — encrypted — and hashes of your recovery codes.
Your preferences
Time zone, language, theme, first day of the week, daily goal, start section, the shortcuts on the bottom bar and the sidebar, the transcription language and any custom vocabulary you write so the engine gets names right.
What you create in the app
Tasks, descriptions, lists, sections, labels, saved filters, comments, reactions, reminders, dependencies between tasks, summary templates, the activity log and the completed tasks behind your stats and streak.
Files
The documents and images you attach to tasks and comments, with their name, size and type. They are stored encrypted with AES-256-GCM when the service has an encryption key configured.
Recordings and transcripts
The audio of conversations you record, the transcript broken into turns (with timestamps and speaker), the names you give each speaker, the summary, key points, detected tasks, mind map, translations, your notes and the questions you ask a recording. Audio is encrypted just like files.
Technical and security data
- Security log: every sign-in, failed attempt, password change, token use or denied access is recorded with the date, the action, the email tried, the IP address and the browser user agent. You can read it yourself in Settings.
- Push notifications: if you enable them, we store your browser's push endpoint and the two keys needed to encrypt the message.
- Sessions and tokens: the session lives in a signed cookie, and we store hashes of your capture tokens (plus their last few characters so you can tell them apart) and the secrets behind your email capture address and your subscribable calendar feed.
- Server logs: service errors and warnings are written to our hosting provider's log and may contain email addresses.
- Support conversations: if you write through the chat on these pages or by email, we keep the conversation so we can help you and know what we told you last time. The chat is an app of ours — there is no chat provider in between — and what you write in it reaches the same servers as everything else.
Other people's data that you enter
When you invite someone you give us their email. When you record a meeting, write a name in a task or label a speaker, you are entering third-party data. In that case you are the one deciding about that data, and it is up to you to inform those people and to have a legal basis for it; we process it on your behalf, as a provider.
3. Why, and on what legal basis
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Creating and running your account, and providing the service: tasks, lists, files, sharing, recording and transcription. | Performance of the contract (art. 6(1)(b)) — the terms of service. |
| Service emails: welcome, invitations, password reset and notices about things that need you. | Performance of the contract. Email notices can be turned off in Settings. |
| Push notifications on your phone or desktop. | Consent (art. 6(1)(a)) — the permission you grant in the browser or on your iPhone. Withdrawn from Settings, the browser itself or iOS Settings. |
| Transcribing and summarising your recordings using external engines. | Performance of the contract: it is the feature you asked for when you pressed record. |
| Security log, attempt throttling and protection against unauthorised access. | Legitimate interest (art. 6(1)(f)) in the security of the service and of accounts, and GDPR art. 32. |
| Backups and disaster recovery. | Legitimate interest in service continuity, and GDPR art. 32. |
| Handling your requests and rights. | Legal obligation (art. 6(1)(c)). |
We do no profiling and make no automated decisions with legal effects on you. We do not sell or share your data, and we do not use it to train artificial intelligence models.
4. Who else is involved
To run Kairo we rely on providers who process data on our behalf, under a data processing agreement. This is all of them:
| Provider | What for | What they receive |
|---|---|---|
| Railway (USA) | Hosting, database and file storage. | Everything the app stores, plus server logs. |
| AssemblyAI, Deepgram or Groq (USA) | Audio transcription. Which one is used depends on how the service is configured at the time. | The recorded audio and any vocabulary you wrote as a hint. |
| Anthropic (USA) | Summaries, key points, mind maps, translation, questions about a recording, and interpreting dictated input. | The transcript and your notes, or the dictated phrase along with your list and label names. |
| OpenAI (USA) | The same, only as a fallback when the provider above is unavailable. | The same. |
| Resend (USA) | Sending the service's emails. | The recipient address, the subject and the body of the email. |
| Apple, Google or Mozilla | Delivering push notifications through your browser's push service. | Your device endpoint and the message, which travels end-to-end encrypted: they cannot read it. |
| Apple (APNs) | Delivering notifications in the Kairo iOS app. | Your iPhone's notification token and the notification itself: its title and text, usually the task name. It is encrypted in transit to Apple, but not end-to-end: Apple sees it in order to deliver it. |
| Google and Apple | Only if you use their sign-in buttons: identifying your account. | They give us your email, name and picture. Showing an avatar hosted on their servers makes your browser request that image from them. |
If no transcription engine is configured, the audio never leaves our server and the browser's own recogniser is used instead. Worth knowing: that recogniser is not local on Chrome or Safari either — the browser sends the audio to Google or Apple. That is the browser's doing, not ours.
We may also disclose data to courts, law enforcement and public authorities where a legal rule requires it.
5. Transfers outside the European Union
The providers in the table above are based in the United States, so there is an international transfer. It relies on the safeguards in chapter V of the GDPR: the European Commission's standard contractual clauses or the provider's participation in the EU-US Data Privacy Framework, depending on the case, plus the technical measures we apply on our side — encryption in transit and at rest. You can ask us for a copy of those safeguards at info@mykairo.app.
6. How long we keep each thing
| What | How long |
|---|---|
| Your account and your content | As long as the account exists. Deleting it removes everything attached to it. |
| Bin: deleted tasks and recordings | 30 days, then really deleted. You can empty it earlier from the app. |
| Files and audio no longer referenced by anything | A sweep removes them from disk within hours. |
| Security log (IP and user agent) | 90 days. |
| In-app notifications | 90 days, or 30 once you have read them. |
| Backups | The last 14 daily copies, encrypted. What you delete stays in them until that copy ages out. |
| What the app stores on your device to work offline | Up to 30 days, and cleared when you sign out. Detailed in the cookie policy. |
One honest caveat: the security log survives account deletion with the link to the user broken, but it keeps the email, the IP and the browser until its 90 days are up. It works that way because a log you can erase by deleting your account is useless for investigating unauthorised access.
7. Your rights
You can exercise your GDPR rights at any time:
- Access: find out what we hold. Much of it is already visible in the app.
- Rectification: fix anything wrong, from Settings or by asking.
- Erasure: delete your account and its content. You do it yourself, with nobody to ask, in Settings → Profile → Delete my account.
- Portability: take your data with you. Settings → Account exports everything as JSON or CSV without asking us; audio is downloaded separately from each recording.
- Restriction and objection: ask us to stop processing certain data, or object to processing based on legitimate interest.
- Withdraw consent where the processing relies on it, without affecting what came before.
How: write to info@mykairo.app from your account's email address, or by post to Craft Lab, SLU, Calle Leonardo Da Vinci 12A, Nave 8, 03203 Elche, Alicante, España, saying which right you are exercising. If we cannot identify you with confidence we will ask for more. We reply within one month of the request, extendable by two more for complex cases, telling you if so.
Account deletion is immediate and cannot be undone: export anything you want to keep first. Note that your content stays in the encrypted backups for the period given above.
8. Complaints
If you believe we have not handled your request properly, you can complain to the Spanish Data Protection Agency (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es. Do write to us first if you like: most things are settled there.
9. Children
Kairo is not aimed at children under 14, the age from which Spanish law allows a person to consent to the processing of their own data. If we find an account belonging to someone younger without a parent or guardian's authorisation, we will delete it. If you think one has been created, tell us.
10. How we protect all this
- All traffic runs over HTTPS, with HSTS.
- Passwords are stored with bcrypt; tokens as hashes.
- Audio, uploaded files, backups and the two-factor secret are encrypted with AES-256-GCM when the service has an encryption key configured.
- Optional two-factor authentication, with recovery codes.
- Rate limits by IP address and by account against blind password guessing.
- A content security policy with a per-request nonce, the app cannot be framed, and the browser can only connect to our own server: provider keys never leave it.
- Every access to a file or a task is checked against who is asking, not against whatever id arrives.
No system is infallible. Should a breach occur that poses a high risk, we will tell you.
11. Cookies and data on your device
We only use cookies that are strictly necessary to keep you signed in: no analytics, no advertising, no third-party cookies. What the app stores on your device to work offline is explained in the cookie policy.
12. Changes
If we change this policy we will update the date above and, when the change matters, tell you in the app or by email before it takes effect.