Privacy Policy
Effective date: [EFFECTIVE_DATE] · Last updated: [UPDATED_DATE] · Version: 0.2 (draft)
This Privacy Policy explains how [OPERATING_BV_LEGAL_NAME] ("Kyra", "we", "us") collects, uses, and protects personal data when you use the Kyra H.I. voice assistant app, the Kyra portal at kyra-hi.com, and related services (together, the "Service"). We are committed to processing personal data in line with the EU General Data Protection Regulation (GDPR) and the Dutch implementation act (UAVG).
1. Who we are (data controller)
| Controller | [OPERATING_BV_LEGAL_NAME] |
| Registered office | [REGISTERED_ADDRESS] |
| Chamber of Commerce (KvK) | [KVK_NUMBER] |
| Privacy contact | hello@kyra-hi.com |
| Data Protection Officer | [DPO_NAME_OR_"Not appointed — not required under GDPR Art. 37"] |
For organisation / team accounts, see §10 — for content created inside an org workspace, the organisation is typically the controller and we act as a processor under a Data Processing Agreement (DPA, see /legal/dpa).
2. What data we collect, and why
We minimise what we collect. Where a category is processed by a third party on our behalf, see the sub-processor list in §6.
2.1 Account & identity
- What: name, email address, profile picture, and the provider account ID from your sign-in method (Google or GitHub), or a passkey (a WebAuthn public key — we never receive your biometric data or device PIN).
- Why / legal basis: to create and secure your account and provide the Service — performance of a contract (Art. 6(1)(b)).
2.2 Your content (notes, notebooks, files)
- What: the notes, documents, and files you create or sync, including their git history, plus any content you route to a destination you choose (e.g. your own GitHub repository or Obsidian vault).
- Why / legal basis: to store, organise, and display your content — contract (Art. 6(1)(b)).
- Important: the central Kyra-managed notebook is not yet end-to-end encrypted at rest and should not be treated as secure storage during the alpha. Please do not store special-category data (health, etc.) or other highly sensitive information in it. See §7.
2.3 Voice interactions
- What: when you speak to Kyra, your audio is streamed and converted to text (speech-to-text), processed by a large language model to produce a response, and converted back to speech (text-to-speech). This involves your audio, transcripts, and the prompts/responses exchanged with the model.
- Why / legal basis: to provide the voice assistant — contract (Art. 6(1)(b)). Microphone access on your device is controlled by your OS permission and only used during an active session.
- Sub-processors: speech-to-text (Deepgram), text-to-speech (Cartesia), language model (Anthropic), real-time transport (LiveKit). See §6.
2.4 On-device data (calendar, contacts, reminders)
- What: when you grant the app access, Kyra can read and write your device calendar, contacts, and reminders to act on your spoken requests.
- How: this data is processed on your device to fulfil the request and is not stored on our servers as a standing copy. [CONFIRM: verify no server-side persistence of contact/calendar PII for all native skills.]
- Why / legal basis: to perform the action you asked for — contract.
2.5 Billing
- What: your subscription plan, status, billing history, and a Stripe customer identifier. We do not receive or store your full card details — payments are handled by Stripe, our payment processor.
- Why / legal basis: to manage your subscription — contract — and to meet invoicing/tax obligations — legal obligation (Art. 6(1)(c)).
2.6 Communications
- What: emails we send (e.g. account, invitation, and invoice emails) and push notifications (e.g. reminders), including the device push token.
- Why / legal basis: contract and our legitimate interest (Art. 6(1)(f)) in operating and supporting the Service.
2.7 Technical & security data
- What: IP address, device and app version, and server/access logs.
- Why / legal basis: security, abuse prevention, debugging, and reliability — legitimate interest (Art. 6(1)(f)).
2.8 Cookies
- We currently use only strictly-necessary cookies (session, authentication, and security). We do not use advertising or analytics tracking cookies. If this changes, we will publish a separate Cookie Policy and seek consent where required.
3. What we do not do
- We do not sell your personal data.
- We do not use your content or voice data to train our own models. Our AI sub-processors (see §6) process your data only to deliver their service to us, under their own data-processing terms; we do not make representations on their behalf — review their terms for details. [Consider negotiating no-training commitments into each processor DPA and strengthening this statement later.]
- We do not use advertising or marketing trackers (as of this version).
4. How long we keep data (retention)
| Data | Retention | Notes |
|---|---|---|
| Account data | For the life of your account; on deletion, blocked immediately and irreversibly erased within 5–30 days | Self-service — see note below & Terms §9A |
| Your content / notebooks | Until you delete it; on account deletion, erased within the 5–30 day window | Quarantined (unpublished, share links revoked) immediately |
| Voice audio | Not retained after processing; transcripts/summaries kept as part of your content | [CONFIRM streaming-only, no audio at rest] |
| Billing records | 7 years, de-identified | Dutch fiscal-retention obligation (bewaarplicht, AWR art. 52); kept stripped of your identity — see note below |
| Server/security logs | [30–90] days | |
| Backups | Rolling, purged within [35] days |
Account deletion. You can delete your account yourself from the portal (Settings → Danger zone). Deletion blocks the account immediately, quarantines your data (notebooks unpublished, public share links revoked), forfeits remaining credits, and cancels any subscription; your account and Content are then irreversibly erased within 5–30 days — across our databases, file storage, and caches. Backups age out on the rolling cycle above. The one exception is the narrow set of billing records the Dutch tax law obliges us to keep (see the retention table above): in our own databases that record is de-identified — detached from your account and stripped of your name, email and other identifiers, linked only by an internal reference. Because a valid invoice must by law show the customer, the corresponding invoice held by our payment processor (Stripe) necessarily still carries your billing name and details for the retention period; that payment-provider customer record, and our internal reference to it, are both destroyed once the period ends. If you solely own an organisation, you must transfer ownership or delete that organisation first. See Terms §9A.
5. International transfers
We host the core Service in the EU (Google Cloud, europe-west4, Netherlands).
Some sub-processors are located outside the EU/EEA (notably the United States).
Where data is transferred outside the EEA, we rely on an adequacy decision or
the European Commission's Standard Contractual Clauses (SCCs) plus
supplementary measures. [CONFIRM each processor's transfer mechanism.]
6. Sub-processors
We share personal data only with the providers below, only as needed to run the Service, and under data processing terms. [CONFIRM each entry; this is a living list — maintain a versioned sub-processor page.]
| Sub-processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Google Cloud | Hosting, database, storage | EU (europe-west4) | EU |
| Anthropic | Language model (assistant responses, summaries) | US | SCCs |
| Deepgram | Speech-to-text | US | SCCs |
| Cartesia | Text-to-speech | US | SCCs |
| LiveKit | Real-time voice transport | [US/EU] | [SCCs] |
| Stripe | Payments & billing | US / EU | SCCs / adequacy |
| Google (Sign-In, FCM) | Authentication, push notifications | US | SCCs |
| GitHub (Microsoft) | Sign-in; optional notes destination | US | SCCs |
| [Email/SMTP provider] | Transactional email | [TBD] | [TBD] |
7. Sensitive data
The Service is not designed to process special-category data (Art. 9 GDPR — health, biometrics, beliefs, etc.). Because you can dictate or write anything into a note or voice session, please do not input special-category or other highly sensitive data, especially during the alpha. We do not intentionally process such data and disclaim responsibility for sensitive data you choose to enter against this guidance.
8. Your rights
Under the GDPR you have the right to: access your data; rectify inaccurate data; erase ("right to be forgotten"); restrict processing; data portability; object to processing based on legitimate interests; and to withdraw consent where processing is based on consent.
Your right to erasure is not absolute: where we are under a legal obligation to retain certain data — in particular billing records for the Dutch fiscal-retention period (GDPR Art. 17(3)(b)) — we keep that minimal, de-identified subset for the required period instead of deleting it immediately, then destroy it. Everything else about you is erased on the timeline in §4.
To exercise any right, contact hello@kyra-hi.com. You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or your local EU supervisory authority.
You can delete your account and its Content yourself in the portal (Settings → Danger zone); see §4 and Terms §9A for how this works and how long erasure takes. For data access or export requests, contact hello@kyra-hi.com. [CONFIRM in-product export coverage.]
9. Security
We apply technical and organisational measures including encryption in transit (TLS), application-layer encryption of conversation content (transcripts, summaries, and memories) using per-user keys wrapped by a key-management service, access controls, secret management, and least-privilege service accounts. A fuller description is in the Technical and Organisational Measures annex of our DPA (/legal/dpa). Note: end-to-end encryption of the central notebook at rest is on our roadmap but not yet in place; until it is, do not treat the central notebook as secure storage (see §2.2, §7). No method of transmission or storage is 100% secure.
10. Organisation / team accounts (B2B)
When you use Kyra within an organisation/team workspace, the organisation is generally the controller of content and member data created in that workspace, and we process it as a processor on the organisation's instructions under a Data Processing Agreement (/legal/dpa). Organisation administrators may add/remove members and access workspace content consistent with their role. For a signed DPA, contact hello@kyra-hi.com.
11. Children
The Service is intended for users aged 18 and over and is not directed to minors. We do not knowingly collect personal data from anyone under 18. We use proportionate, good-faith age assurance: you confirm you are 18+ when you create an account, and we may ask for age verification where signals suggest a user may be under 18. If we become aware that we hold the personal data of someone under 18, we will delete it and close the account. If you believe a minor has provided us with personal data, contact hello@kyra-hi.com.
12. Automated decision-making
Kyra uses AI models to generate responses and organise your content, but we do not make decisions producing legal or similarly significant effects about you by solely automated means within the meaning of Art. 22 GDPR.
13. Changes to this policy
We may update this policy; we will post the new version with an updated "Effective date" and, for material changes, notify you in-app or by email.
14. Contact
[OPERATING_BV_LEGAL_NAME] · [REGISTERED_ADDRESS] · hello@kyra-hi.com