Privacy Policy
Last updated August 17, 2026
Policy under legal review.This page reflects our current working draft and is being finalized with counsel — it may change before it's final.
This policy explains what information KAAL collects, how it's used, and how you can control it.
Information we collect
Account information: your name, email, and workspace details when you sign up.
Business profile information: anything you provide about your business — description, target audience, contact details — so your AI employees can act with accurate context.
Integration data: information your connected tools (CRM, email, social platforms) share with KAAL so agents can act on your behalf.
Usage data: how you interact with the product, used to improve the AI Operating System and diagnose issues.
How we use your information
To operate your AI employees — running tasks, drafting outreach and content, and generating briefings on your behalf.
To maintain the Approval Queue, so high-stakes agent actions are reviewed before they reach your customers.
To bill your subscription and communicate about your account.
To improve KAAL's agents and product based on aggregated, de-identified usage patterns.
AI processing and third-party models
If you bring your own AI model (BYOK), your prompts and the content your agents generate are processed by the model provider you've selected (OpenAI, Anthropic, Google, etc.) under that provider's own terms.
KAAL does not use your business data to train third-party foundation models.
Data sharing
We don't sell your data. We share data with the integrations you explicitly connect (so your agents can act through them) and with infrastructure providers who help us run the service, under standard confidentiality terms.
Data retention
Your business data — leads, AI-generated lead scoring and content, objectives and tasks, approvals, uploaded documents, and WhatsApp conversation history — is retained for as long as your organization exists on KAAL. We don't automatically delete this data based on age.
A small set of purely operational records — outbound-webhook delivery logs and internal task-execution event logs — are automatically purged after a bounded window (90 days by default) once they're no longer useful for debugging. This does not apply to any of the business data listed above.
Security and audit records (a log of high-stakes actions such as approval decisions, billing changes, and account deletions) are retained permanently, including after an organization is deleted, for security and compliance purposes. These records are append-only at the database level and cannot be altered or deleted through the application.
Your rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data.
Organization owners can permanently delete their organization and all of its data at any time from Settings → Account → Delete organization, which requires a typed confirmation before it takes effect. This removes your organization's business data, documents, and associated files. As noted above, our security/audit records of account-level actions are retained afterward for compliance purposes.
If you're not an organization owner, or prefer we handle deletion directly, contact us and we'll process your request.
Security
We use industry-standard encryption in transit and at rest, and credentials (API keys, integration tokens) are encrypted and never displayed in plaintext after entry.
Changes to this policy
We'll update the date at the top of this page when this policy changes, and notify you of material changes via email or in-app notice.
Contact us
Questions about this policy? Reach us at the details on our Contact page.