Privacy policy
Who we are
This policy explains how Kerneltics handles personal data in K-Agent: the website, the dashboard, the API and the widget.
Two different roles
For your account and team data, Kerneltics is the controller. For the personal data of your customers, the people who talk to your agents, you are the controller and we are the processor: we process it only to run your agents, on your instructions.
What we collect
- Account data: name, email, password (stored as an argon2id hash), organization and role.
- Content you add: agent settings, knowledge, tools and secrets (secrets are encrypted).
- Conversations: messages between your agents and your customers, and the end-user details you send, such as name and traits.
- Usage and billing: runs, tokens, AI conversation units and invoices.
- Technical data: request IDs, timestamps, IP addresses and status codes. Our logs don’t contain message text.
How we use it
To provide and secure K-Agent, meter usage and bill you, support you, and meet legal obligations. We don’t sell personal data, use it for advertising or use your content to train AI models.
Model providers and other sub-processors
To write replies, conversation text is sent to the model provider set for your agent: OpenAI, Anthropic, DeepSeek, Google (Gemini) once available, or a provider you connect with your own key. These providers process data outside the Kingdom under their terms. We also use a hosting provider for our server and, when email alerts are on, an email provider. The current sub-processor list is in the docs.
Where data is stored
K-Agent’s database runs on our server. It is not hosted inside the Kingdom yet; in-Kingdom hosting is on our roadmap. When personal data is transferred outside the Kingdom, we apply the safeguards required by the Personal Data Protection Law and its regulations.
How long we keep data
- Conversations and runs: your project’s retention period (365 days by default).
- Run events: 7 days. Event logs and webhook deliveries: 30 days.
- Deleted data can remain in our backups for up to 7 days, until those backups are replaced.
- Account data: while your account is active, then deleted after it is closed unless the law requires us to keep it.
Your rights
Under the Personal Data Protection Law, you can ask to access, correct or delete your personal data, and to withdraw your consent. Email info@kerneltics.com.
If you are talking to a business’s agent, contact that business first: it controls your data and can erase it through our API.
Security
The security page explains in detail how we protect data.
Cookies
The website sets one cookie, kagent_lang, to remember the language you chose. The dashboard sets a session cookie to keep you logged in. We use no advertising or tracking cookies.
Changes and contact
We will post any update to this policy here and tell account owners about material changes. For any question, email info@kerneltics.com.