How Kami handles information.
Effective August 9, 2026. This notice explains the information Kami AI processes, why it is used, and the choices available to customers and users.
Where this notice applies
This notice covers the Kami AI website, customer administration experience, and the Kami agent embedded in a customer's software. When a customer provides Kami inside its product, that customer controls the user relationship and determines the permitted purposes for processing; Kami processes that data to provide the contracted service.
A customer's own privacy notice may also apply. Customers are responsible for giving their users appropriate notice and for supplying lawful, accurate identity and access context.
Information we process
- Account and tenant context supplied by the customer, such as a tenant identifier, signed user identifier, role, and permitted origin.
- Requests typed or spoken to Kami, the responses returned, and the page context needed to understand and complete the requested work.
- Task, action, confirmation, verification, latency, error, and security records used to operate, protect, and improve the service.
- Contact details and messages you choose to send through our contact or sales channels.
- Technical data such as browser type, IP address, timestamps, and service logs needed for security and reliability.
Voice and page context
With microphone permission, live voice audio and transcripts are processed to conduct the conversation. Kami does not activate a wake word in the current production configuration. Users can end voice mode and continue in text at any time.
The embedded agent receives the visible application context needed for the request. Known sensitive fields are minimized or redacted before model use where supported. Customers should not expose data to Kami that their signed-in user is not authorized to access.
How information is used
- Provide, secure, troubleshoot, and support Kami.
- Understand a request, plan a task, operate the customer's interface, and verify the observed result.
- Enforce tenant, identity, origin, confirmation, and abuse-prevention controls.
- Measure reliability and improve product quality using appropriately controlled operational evidence.
- Meet legal obligations and protect users, customers, Kami, and the public.
Service providers and disclosure
Kami uses service providers for infrastructure, AI processing, security, communication, and business operations. They receive only the information needed to perform their services under applicable contractual controls. Current model credentials remain server-side.
Information may also be disclosed when required by law, to protect rights and safety, in connection with a corporate transaction, or at a customer's documented direction. Kami does not sell personal information or use it for cross-context behavioral advertising.
Retention, security, and location
Information is retained for the period configured for the service or as reasonably necessary for security, support, legal obligations, and dispute resolution. Deletion from active systems may be followed by expiry from protected backups under their retention schedule.
Kami uses access controls, encryption in transit, tenant separation, server-side secrets, backups, and operational logging. No system can be guaranteed completely secure. Processing may occur in countries where Kami or its providers operate, subject to applicable transfer safeguards.
Your choices and requests
Users of a customer-hosted Kami integration should normally send access, correction, export, restriction, objection, or deletion requests to that customer. Customers can use Kami's administration and support channels for verified data requests.
You can decline microphone permission, end a voice conversation, use text instead, and limit information sent through contact forms. Use the contact page for privacy questions or a verified request.
Questions about this notice?
Use the contact page to ask a question or submit a verified request.
Contact Kami