Privacy Policy
Last reviewed:
This page tells you what Kiantu collects about you and your team, why we collect it, and what control you have. The short version: we collect only what we need to run the product, we don't sell anything to anyone, and the data you produce inside Kiantu (sessions, goals, comments, documents) belongs to you.
Who we are
Kiantu is operated by Kiantu Inc., a US-incorporated company. If you need to contact us about your data, privacy@kiantu.com is the right address.
What we collect
Information you give us directly
- Account info. Your email address, display name, and the OAuth profile data you authorise (name, avatar). If you sign in with a magic link, we store only your email address; we never store a password because we don't have one.
- Workspace content. The sessions you start, the goals and projects you create, the comments and documents you write, the attachments you upload, the tags you apply. This is the data the product is for.
- Preferences. Timezone, working hours, notification preferences, theme.
Information from connected services
- Calendar (Google / Outlook). When you connect a calendar, we read event metadata (title, attendees, time, location) so the product can show meetings in your timeline. We do not read event bodies. You can disconnect at any time in Settings → Connectors.
- GitHub. When you connect GitHub, we read commits, PRs, reviews and issue comments associated with the user/orgs you authorise. We do not read repository contents.
Information collected automatically
- Activity heartbeat. While you're using Kiantu we record when you're active vs idle so the product can build your timeline. This is per-actor and visible only to you.
- Usage analytics. Anonymised events about which features are used, sent to PostHog. No email addresses, no session contents, no goal/task titles — only the workspace and actor identifiers. On the marketing site this is consent-based — in the EU/EEA, the UK and Switzerland nothing runs until you accept, and you can change your choice at any time on /cookies. You can also block it with any standard ad blocker.
- Logs. Standard server logs (timestamp, request method, response code, IP address) retained for up to 30 days for debugging and abuse prevention.
How we use it
- To operate the product (showing your data back to you, building your timeline, generating insights).
- To authenticate you (magic-link emails, OAuth round-trips).
- To improve the product (anonymised usage analytics).
- To send you the notifications you've opted into.
- To respond to your support requests.
We do not sell your personal data, train third-party AI models on your data, or use your sessions / comments / documents for advertising.
How we share it
We share data only with the sub-processors listed at /sub-processors, each scoped to the data described there. We share with law-enforcement only when required by a valid legal process; we will notify you unless prohibited from doing so.
How long we keep it
Workspace content lives as long as the workspace exists. When a workspace is archived or scheduled for deletion, the contents are removed within 30 days. Detailed per-entity retention policies (sessions, audit events, notifications) are in active development; the trust page at /security tracks current state.
Your rights
Depending on where you live (EU/EEA, UK, California, others) you have rights to access, correct, export and delete your personal data. To exercise any of these, write to privacy@kiantu.com and we will respond within 30 days. Self-service export and deletion are on the roadmap; until they ship, the email address is the route.
Cookies and similar technologies
See /cookies.
Security
See /security for an honest description of what we have in place today and what's coming.
International transfers
Kiantu is hosted in the United States. If you're in the EU/EEA or UK, your data is transferred to the US under standard contractual clauses where applicable.
Changes
When we change this policy in a meaningful way we will update the "Last reviewed" date at the top and notify active workspaces in advance of the change taking effect.
Contact
Questions: privacy@kiantu.com
Security disclosures: security@kiantu.com