kaia
ProductUse casesIntegrations
Log inSign up
← Back to Kaia

Privacy Policy

This policy explains what information Kaia handles, why we handle it, and the choices available to you.

Last updated: 18 August 2026

Contents

01Who we are and scope02Information we collect03Connected services04Google user data05How we use information06Legal bases07AI processing08Sharing and providers09Cookies and analytics10Data retention11Security12International transfers13Your rights14Children15Changes to this policy16Contact and complaints
01

Who we are and scope

Kaia Technologies ("Kaia", "we", "us" or "our"), ABN 46 603 121 960, is based in Tasmania, Australia. We provide AI agents and workflow automation tools for businesses.

This Privacy Policy applies to personal information handled through our websites, applications, customer support, and related services (together, the "Services"). It does not govern third-party products you choose to connect to Kaia, which remain subject to their own privacy policies.

If an organisation provides you access to a Kaia workspace, that organisation may control the workspace and the information within it. In that context, Kaia generally processes personal information on the organisation's instructions, and questions about its use of your information should first be directed to that organisation.

02

Information we collect

Information you provide

  • Account details, such as your name, email address, profile image, login method, and organisation.
  • Workspace details, team membership, roles, permissions, and invitations.
  • Prompts, conversations, agent instructions, uploaded files, approvals, and other content you submit.
  • Support requests, product feedback, and other communications with us.
  • Billing contact and subscription details. Payment card data is handled by our payment provider rather than stored directly by Kaia.

Information collected automatically

  • Device, browser, operating system, IP address, language, and approximate location derived from IP.
  • Pages viewed, features used, actions taken, referring URLs, timestamps, and diagnostic events.
  • Security, authentication, audit, and error logs.
  • Cookie and similar technology identifiers, subject to your browser settings and applicable consent requirements.
03

Connected services and customer content

You may authorise Kaia to connect to services such as email, calendars, CRM, documents, spreadsheets, analytics, accounting, messaging, inventory, or advertising platforms. Depending on the connection and permissions you choose, Kaia may read, create, update, send, or otherwise process data in those services to carry out your requests.

Each service is connected separately. Kaia requests only the access scopes needed for the connection you are enabling, at the time you enable it, and shows you the permissions before you approve them. Workspace owners and users are responsible for choosing appropriate permissions and ensuring they have authority to provide the data to Kaia.

Connected data may include messages, contacts, events, files, records, transactions, reports, and metadata. For Google services, the exact categories, uses, and limits are set out in Google user data below.

You can disconnect an integration through the Services or the third-party provider. Disconnecting stops future access and causes Kaia to delete the stored credentials and connection records for that integration. See Data Deletion Instructions for how to remove content that has already been incorporated into conversations or audit records.

Shopify data

When a merchant connects a Shopify store, Kaia receives data from that merchant's Shopify Admin API connection. Depending on the scopes granted by the merchant and Shopify's protected-customer-data approval, this may include:

  • the store's Shopify identifier, domain, settings, and account metadata;
  • products, variants, inventory items and quantities, locations, and fulfillment locations;
  • orders, line items, fulfillment orders, fulfillments, tracking information, and order reports;
  • customer identifiers, names, email addresses, phone numbers, postal addresses, order history, spending summaries, and related customer records; and
  • other records or store-credit information exposed by a scope that the merchant has approved.

Kaia uses Shopify data only to carry out the merchant's request, return a report or result in the Kaia workspace, prepare or perform an action that the merchant has approved, secure and operate the connection, and comply with law. Kaia does not sell Shopify data, use it for advertising or marketing profiles, or use it to train or improve a general-purpose AI model.

Kaia requests only the Shopify scopes needed for the enabled actions. Shopify may require additional approval for customer contact, address, order-history, fulfillment-destination, or analytics fields. The merchant controls whether to grant those permissions and can disconnect the store at any time.

Kaia uses Nango to complete Shopify OAuth and transport requests to Shopify. Shopify data may also be processed by the infrastructure, database, AI, background-job, and observability providers described in section 8, only to provide and secure the Services.

04

Google user data

This section describes exactly what Kaia accesses through Google APIs, why, where it goes, how long it is kept, and what we will never do with it. It applies in addition to the rest of this policy, and prevails over any more general statement here if the two conflict.

What Kaia accesses, and why

Google services are connected individually. Connecting one Google service does not grant Kaia access to any other. Kaia only accesses the services listed below, and only after you complete Google's consent screen for that service.

Google user data accessed by Kaia, by service
Google serviceInformation Kaia can accessWhat Kaia does with it
GmailMessage and thread contents, subject lines, senders and recipients, dates, attachments, labels, and drafts in the mailbox you connect.Searches, reads and summarises mail you ask about; applies or removes labels; creates drafts; and sends messages you have asked it to send.
Google CalendarThe list of calendars you subscribe to, calendar metadata such as name, description and time zone, free/busy availability, and event details including title, description, time, location, attendees and conferencing links.Lists your calendars, reads calendar settings, checks availability, and reads, creates, updates and deletes events on calendars you can access — including calendars shared with you by other people.
Google SheetsStructure, sheet names and cell values of spreadsheets you identify by link or ID in a conversation, and of spreadsheets Kaia creates for you.Reads and analyses spreadsheet data; writes, updates and clears values; adds, renames and removes sheets; and creates new spreadsheets when you ask.
Google AnalyticsYour GA4 account, property and data stream list, and aggregated report data such as sessions, users, traffic sources, events and conversions.Read-only. Finds the right property and runs the reports you ask for. Kaia does not request any Analytics write access.
Google AdsAccount structure, campaigns, ad groups, ads, keywords, budgets and performance reports for the accounts you connect.Reports on performance, and creates or updates campaigns, ads, keywords and experiments. Changes to your account require your approval before they run.
YouTubeChannel details, video metadata, captions, playlists and comments for the channel you connect.Reads channel and video information and captions; creates and modifies playlists; and updates video details and comments at your direction.

Kaia uses Google user data only to carry out the request you made in your workspace: to answer your question, produce a summary or report, or perform an action you asked for. Kaia does not build advertising or marketing profiles from it, and does not create aggregated or anonymised datasets from Google user data.

Kaia requests the narrowest scope that supports the features above. Where a broader scope is unavoidable, it is because the narrower alternative cannot perform a function you rely on — for example, read-only calendar scopes cannot create or update an event on a calendar shared with you, and file-picker-only Drive access cannot open a spreadsheet you paste into a conversation as a link.

Limited Use

Kaia's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

What Kaia never does with Google user data

The commitments below apply to raw Google user data and to anything derived, aggregated or anonymised from it.

  • We do not sell it.
  • We do not transfer, license or disclose it to advertisers, advertising networks, data brokers, information resellers, or any other party for their own purposes.
  • We do not use it for advertising of any kind, including targeted, retargeted, personalised or cross-context behavioural advertising.
  • We do not use it for credit, lending, insurance, tenancy or employment eligibility decisions.
  • We do not use it to develop, train, retrain, fine-tune or improve generalised artificial intelligence or machine learning models, whether our own or a third party's.
  • We do not use it to build or improve products or services unrelated to the Kaia workspace through which you connected it.
  • We do not allow humans to read it, except: with your explicit consent for a specific message or file; where necessary for security purposes such as investigating abuse or a suspected incident; to comply with applicable law; or where the data has been aggregated and anonymised and is used for internal operations. Kaia does not currently produce aggregated or anonymised datasets from Google user data.
  • In a merger, acquisition, financing or sale of assets, Google user data is transferred only where we have obtained your explicit prior consent, as the Limited Use requirements demand. The general business-transfer disclosure in section 8 does not override this.

Where Google user data goes

Google user data is processed by the following providers, solely to deliver the Services to you and under contractual confidentiality and security terms:

  • Nango — authorises the connection and carries API requests to and from Google.
  • Vercel — hosts and runs the application that processes your request.
  • Supabase — stores the conversations, outputs and audit records that may contain Google content.
  • OpenAI — processes the content needed to answer your request, under its business/API terms, which do not permit use of API content to train its models.
  • Trigger.dev — runs scheduled and background jobs you have configured.
  • Langfuse — receives diagnostic traces of agent runs, where enabled, under a short retention period.

PostHog receives product-event metadata only — such as which feature was used and when — and does not receive Google message, file, event, or report content. Stripe never receives Google user data. Google user data is not transferred to any other third party except where you direct Kaia to send it, or as required by law.

Retention and deletion of Google user data

  • Kaia revalidates your authorisation with Google at least every 30 days. Google user data that Kaia has stored is refreshed from Google or deleted within 30 days.
  • When you disconnect a Google integration in Kaia, or revoke Kaia's access from your Google security settings, Kaia deletes the stored credentials, connection records and associated Google user data within 7 days.
  • Google content that has already been incorporated into a conversation or audit record is deleted when you delete that conversation, or when your account or workspace is deleted. See Data Deletion Instructions.

YouTube API Services

Kaia's YouTube features use YouTube API Services. By using them you agree to be bound by the YouTube Terms of Service. Google's handling of your information is described in the Google Privacy Policy.

You can revoke Kaia's access to your YouTube data at any time through the Google security settings page. Kaia deletes stored YouTube API data within 7 days of that revocation, and otherwise refreshes or deletes stored YouTube API data at least every 30 days. Kaia does not use YouTube data for advertising, does not artificially inflate views, likes, subscriptions or other metrics, and does not combine YouTube data with data from other services to build a profile of you.

Google Data Portability APIs

Not applicable. Kaia does not request, access or use any Google Data Portability API scope.

05

How we use information

We use personal information to:

  • Provide, operate, maintain, and personalise the Services.
  • Authenticate users, administer workspaces, and enforce roles and permissions.
  • Run AI agents, retrieve relevant context, generate outputs, and perform actions you authorise.
  • Process subscriptions, measure usage, and manage billing.
  • Respond to support requests and send service, security, and administrative messages.
  • Monitor reliability, troubleshoot errors, prevent abuse, and protect users and the Services.
  • Understand feature use and improve the performance and design of the Services.
  • Comply with law, enforce our terms, and establish or defend legal claims.
  • Send marketing communications where permitted. You may unsubscribe from marketing messages at any time.

Connected-service content, including Google user data, is used only for the first three purposes above and for the security and legal-compliance purposes described. It is not used for marketing, and it is not used to improve the Services beyond operating them for you.

06

Legal bases for processing

Where the GDPR, UK GDPR, or another law requires a legal basis, we rely on one or more of the following: performance of a contract; our legitimate interests in operating, securing, and improving the Services; your consent; and compliance with legal obligations. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.

For customer content processed on behalf of a workspace customer, that customer determines the applicable purpose and legal basis. Kaia acts as a processor or service provider to the extent required by applicable law.

07

AI processing

Kaia sends relevant prompts, instructions, files, connected-service data, and conversation context to AI service providers to generate responses and planned actions. Outputs may be stored with conversation and audit history so you can review what an agent did and why.

Kaia does not sell customer content and does not use it to develop, train, retrain, fine-tune or improve any generalised AI or machine learning model. This applies to raw customer content and to derived, aggregated or anonymised versions of it. Our AI providers process content under business or API terms that do not permit training on it, and we disable any provider setting that would allow content to be used for model improvement.

AI providers may retain request and response state for a limited period under their standard API controls in order to operate the service and monitor for abuse — currently up to 30 days. That state is deleted on expiry, and we request deletion of associated provider state when you delete your account.

Automated outputs can be incomplete or incorrect, so users should review outputs and approvals before relying on them for material decisions or external communications.

08

How we share information

We do not sell personal information. We disclose information only as described below:

  • Service providers. Vendors that provide infrastructure, authentication, AI processing, integrations, billing, analytics, observability, and background processing.
  • Connected services. Third parties you direct Kaia to interact with, including when an agent sends, creates, or updates information.
  • Your workspace. Workspace owners and authorised members may access workspace content, activity, and audit history according to their permissions.
  • Legal and safety reasons. Authorities or other parties where reasonably necessary to comply with law, protect rights and safety, investigate abuse, or enforce agreements.
  • Business transfers. A buyer, investor, adviser, or successor in connection with a financing, reorganisation, sale, or transfer, subject to appropriate confidentiality safeguards. Google user data is included only with your explicit prior consent, as described in section 4.

We do not transfer personal information to advertisers, advertising networks, data brokers or information resellers.

Shopify and integration providers

When you direct Kaia to use Shopify, Kaia sends the relevant request to Shopify and receives the result from Shopify. Nango handles the Shopify authorisation exchange and connection transport. Kaia's hosting, database, AI, background-job, and observability providers — Vercel, Supabase, OpenAI, Trigger.dev, and Langfuse — may process the request, result, or derived response as necessary to operate the Services. These providers may not use Shopify data for their own advertising, data brokerage, or general model training. Shopify remains responsible for its own processing under Shopify's terms and privacy policy.

Core service-provider categories currently used by Kaia
ProviderPurposeMay process Google user data
VercelWebsite and application hosting, delivery, and performance monitoringYes, in transit and during processing
SupabaseDatabase, authentication, and file storage infrastructureYes, where stored in conversations or audit records
OpenAIAI model processingYes, the content needed to answer your request
NangoAuthorisation and connectivity for third-party integrationsYes, credentials and API traffic
Trigger.devBackground and scheduled workflow processingYes, for scheduled runs you configure
LangfuseAI observability and diagnostics, where enabledYes, diagnostic traces, short retention
PostHogProduct analytics and diagnostics, where enabledNo — product-event metadata only
StripeSubscription billing and payment processingNo

Providers and product features may change. We require providers to handle information for the contracted purpose and subject to appropriate confidentiality and security terms.

09

Cookies and analytics

Kaia uses essential cookies and local storage for authentication, security, preferences, and core functionality. Where enabled, analytics technologies help us understand product use, diagnose problems, and improve the Services. We do not use personal information for cross-context behavioural advertising or sell it through advertising cookies.

You can control cookies through your browser. Blocking essential storage may prevent sign-in or other parts of the Services from working. Where law requires consent for non-essential cookies, we will request it before setting them.

10

Data retention

We retain information only as long as needed for the purpose it was collected, then delete or de-identify it. The periods below apply unless a longer period is required by law, or is necessary to prevent fraud or abuse, resolve a dispute, or enforce our agreements.

Retention periods by data type
Data typeRetention
Account and workspace recordsWhile the account is active. Deleted within 30 days of a verified account or workspace deletion request.
Conversations, agent outputs, uploaded filesUntil you delete them, or within 30 days of account or workspace deletion.
Connected-service content held for a connectionRefreshed from the source or deleted within 30 days.
OAuth credentials and connection recordsDeleted within 7 days of disconnection or revocation.
Shopify OAuth credentials and local Shopify connection recordsDeleted promptly, and no later than 7 days, after disconnection, revocation, app uninstall, or a Shopify shop-redaction request. Nango credentials are revoked through Nango.
Shopify customer, order, fulfillment, product, inventory, location, and report data in conversations, action history, or audit recordsRetained only under the applicable conversation, action-history, and audit retention periods in this policy, or until a verified Shopify customer or shop deletion request is completed, whichever is earlier.
Security, authentication, and agent-action audit logs12 months.
AI observability traces, where enabled30 days.
AI provider request and response stateUp to 30 days under the provider's standard API retention controls.
Product analytics events (metadata only)12 months.
Encrypted backupsRolling. Overwritten or deleted within 90 days.

Shopify sends Kaia mandatory privacy requests for customer access, customer deletion, and shop deletion. Kaia verifies the request, records the compliance event without retaining the raw webhook body, and completes the applicable export, redaction, or deletion across Shopify-linked Kaia records within the period required by law and Shopify. Data that remains in Shopify is governed by the merchant's and Shopify's own policies.

You may request deletion of your account or personal information at any time. Deleting Kaia data does not delete copies held in a connected third-party service. See our Data Deletion Instructions for request steps, including for data received through Google, Facebook, Instagram, or Shopify.

11

Security

We use technical and organisational safeguards designed to protect information, including:

  • Encryption of data in transit over TLS, and encryption at rest in our database, file storage, and backups.
  • OAuth credentials held by our integration provider and in encrypted storage, never exposed to browser clients or included in AI prompts.
  • Workspace-scoped authorisation, with roles and permissions enforced on every request.
  • Least-privilege scope requests, made per connection at the time you enable it.
  • Manual approval by default for actions that write to a connected service on a new connection.
  • Authentication, access, and agent-action audit logging.
  • Staff access limited to personnel who need it for support or operations, under confidentiality obligations.
  • Vendor review and data processing agreements with providers that handle customer content.
  • A documented incident response process, including assessment and notification where required by law.

No system is completely secure, and we cannot guarantee that information will never be accessed, disclosed, altered, or lost. You are responsible for keeping your account and devices secure, using appropriate workspace permissions, reviewing agent approvals, and notifying us promptly if you suspect unauthorised access.

12

International data transfers

Kaia is operated from Australia, and our providers may process information in Australia, the United States, the European Union, and other countries. These countries may have different privacy laws from your country.

Where required, we use recognised safeguards for international transfers, such as data processing agreements and standard contractual clauses, and take reasonable steps to ensure overseas recipients handle personal information consistently with applicable law.

13

Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of your personal information; receive a portable copy; withdraw consent; or complain to a regulator. Australian users may request access and correction under applicable Australian privacy law. EEA and UK users may also object to processing based on legitimate interests and lodge a complaint with their local supervisory authority.

California residents may have rights to know, correct, delete, and obtain a copy of personal information, and to receive equal service when exercising those rights. Kaia does not sell personal information or share it for cross-context behavioural advertising.

Shopify customer requests

A Shopify merchant or an authorised data subject may request access to or deletion of Shopify-derived personal information held by Kaia by emailing elliott@usekaia.comwith the store domain, the Shopify customer ID when available, and the relevant email address, phone number, or order IDs. We verify the requester and authority before acting. Do not send a Shopify access token or other credential by email. We will respond within the period required by applicable law and Shopify's compliance requirements. The request may cover Shopify-derived data in Kaia conversations, action history, audit records, and stored connection data; it does not delete the source record held by Shopify.

Email elliott@usekaia.com to make a request, or follow our Data Deletion Instructions. We may need to verify your identity and authority. If your information belongs to a customer-managed workspace, we may direct the request to that customer.

14

Children

The Services are intended for business users aged 18 or older. We do not knowingly collect personal information from children. If you believe a child has provided information to Kaia, contact us so we can investigate and take appropriate action.

15

Changes to this policy

We may update this policy as our Services, providers, or legal obligations change. We will post the revised version here and update the date above. If a change materially affects your rights, we will provide additional notice where reasonably practicable or required by law.

16

Contact and complaints

For privacy questions, requests, or complaints, contact:

Kaia Technologies
ABN 46 603 121 960
Tasmania, Australia
elliott@usekaia.com

We will investigate privacy complaints and respond within a reasonable period. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner or another regulator available in your jurisdiction.

kaia

AI agents for the work that keeps your business moving.

ProductUse casesIntegrationsPrivacyTermsData deletion
© 2026 Kaia Technologies