Kaido is a customer-care platform. That means we hold two kinds of trust at once: the trust of the businesses who use Kaido, and the trust of the customers they support. This policy explains — in plain language — what we collect, why, and what control you have over it.
Who this policy covers
Account holders — people who sign up for Kaido and work in a workspace (owners, admins, agents, viewers).
End customers — people who contact a business that uses Kaido, via web chat, WhatsApp, Messenger, Instagram, email or voice. For their data, the business is the controller and Kaido is the processor: we handle it only on the business's instructions.
Visitors — people who browse this website without an account.
Data we collect
- Account data: name, email address, password (stored as a salted hash — we can never read it), avatar, workspace membership and role.
- Conversation data: messages, attachments, internal notes and whispers, contact profiles (name, phone, email, company, tags), and conversation metadata such as status, priority and assignment.
- Chat visitor context: when someone uses a business's chat widget we record technical context — IP address, device type, browser, operating system, the page they were on, referrer and browser language — so agents can help them faster. See section 05.
- Billing data: plan, seat count and invoices. Card numbers go directly to our payment processor and never touch our servers.
- Usage data: aggregate product analytics (feature usage, error logs) to keep the service reliable.
How we use data
- To provide the service: routing conversations, notifying agents, syncing channels.
- To secure it: authentication, rate limiting, fraud and abuse prevention, audit logs.
- To improve it: aggregate, de-identified analytics only.
- To bill for it and to meet legal obligations.
We do not sell personal data. We do not use your conversations for advertising.
AI features
Kaido's AI drafts replies, summarises threads and answers common questions. It is grounded in the workspace's own knowledge base and conversation history. Three commitments:
- Workspace data is never used to train shared models across customers.
- Every AI-sent message is labelled and logged, and workspace admins choose per channel whether the AI may answer automatically.
- Content sent to the model is treated as untrusted reference material — it cannot change the AI's instructions or access anything beyond the workspace it belongs to.
Chat visitor data
The chat widget records the visitor's IP address, device, browser, operating system, current page, referrer and language. This exists so support teams can resolve issues ("you're on Android, on the pricing page — here's the right link") and to fight spam. It is visible only to members of the workspace the conversation belongs to, and it follows the same retention and deletion rules as the conversation itself.
Retention & deletion
- Conversation data is kept while the workspace is active.
- Deleting a contact or conversation removes it from active systems immediately and from backups within 30 days.
- Closing a workspace deletes all of its data after a 30-day grace period (so an accidental deletion can be undone).
Your rights
Depending on where you live (GDPR, and similar laws elsewhere), you can ask for access, correction, deletion, portability, or restriction of your personal data. Account holders can do most of this directly in workspace settings. End customers should contact the business they spoke with first — as controller, the business directs us; we support every such request within the required timelines.
Security
Encryption in transit and at rest, workspace-level isolation enforced in the database itself (row-level security), role-based access, signed webhooks and audited admin access. The full picture lives on our Security page.
Contact
Privacy questions or requests: hello@kaido.app. We reply to every privacy request within 7 days. If this policy changes materially, we announce it in-product and by email at least 14 days before it takes effect.