Privacy Policy
Last updated: August 25, 2026
1. Data We Collect
We collect the following data when you use Kaylio:
- Account data: Email address, subscription status
- Conversation data: Messages you send and receive from your AI companion
- Memory data: Facts, preferences, and emotional context extracted from conversations, stored as semantic vector embeddings
- Usage data: Message counts, session duration, feature usage
- Payment data: When paid checkout is enabled, Stripe processes payment details; we store billing identifiers and subscription state, not card numbers
2. How Memories Work
Kaylio may propose key information from eligible conversations to help your companion remember you. New proposals remain pending until you approve them. Approved memories are stored as:
- Short text summaries (e.g., "User is allergic to peanuts")
- 768-dimensional vector embeddings used for semantic search
- Importance scores and type classifications
Pending and deleted memories are excluded from recall. You can approve, reject, edit, pin, and delete memories through the Memory Journal in your companion's chat.
3. Third-Party Services
We use the following third-party services to operate Kaylio:
- Supabase: Database and authentication
- Google Gemini / OpenRouter: AI language-model processing for conversations and eligible memory extraction
- Stripe: Payment processing when paid checkout is enabled
- Vercel: Website hosting and infrastructure
- Sentry: Error monitoring — technical error reports and diagnostics; never the content of your conversations
- PostHog: Product analytics — feature usage and signup-funnel events tied to a pseudonymous account identifier; never the content of your conversations
- Microsoft Clarity: Session replay and heatmaps on our public marketing pages only — never inside the logged-in app and never your conversations — to understand how visitors use our site
- Reddit: Advertising conversion pixel on public marketing pages, reporting anonymized signup conversions so we can measure our ads
- Telegram: Operational alerts to the Kaylio team about account activity — signups, onboarding, first messages, subscription changes — and the text of any feedback you submit. Includes a shortened account identifier, your chosen companion type, and the page you were on (e.g. when submitting feedback); never your account email address, and never the content of your conversations.
Voice and generated-image features are disabled in the current concierge beta, so product requests do not send conversation content to OpenAI text-to-speech or Replicate image-generation services. We will update this notice before those features are made available.
4. Data Retention
Your records are retained while your account is active. Plan memory windows control which approved memories are eligible for recall (Free: 30 days and Core: 1 year); they do not automatically delete older records. Approved pinned memories remain eligible. Deep's full-relationship window is a catalog definition for a plan that is not currently available for purchase.
5. Your Rights
You have the right to:
- Export your data: Download all your data as JSON from Settings
- Delete your account: Permanently delete all data from Settings — this is irreversible and cascades to all companions, messages, and memories
- Edit or delete memories: Through the Memory Journal
6. Safety Logging
When our crisis detection system identifies potential signs of distress, we create a pseudonymous safety record containing account and companion identifiers, category, severity, detector source, classifier version, timestamp, and whether resources were shown. New safety-event records do not include raw crisis message text by default. Historical records created before August 17, 2026 may contain an excerpt of up to 200 characters while retention cleanup is reviewed. This data is used for safety operations and is not sent to advertising analytics providers.
7. Contact
For privacy inquiries, contact privacy@kaylio.app.