Privacy Policy

Last updated: August 20, 2026

This privacy policy describes how Kairos Intelligence ("Kairos", "we", "us") collects, uses, discloses and protects personal data in connection with the kairosintelligence.ca web application ("the dashboard") and the Kairos browser extension ("the extension"), together referred to as "the Service".

Kairos is an artificial-intelligence governance tool for agencies and their teams. Its design rests on a simple principle: the most sensitive data never leaves your device. Privacy is built in from the start (privacy by design).

1. Who we are

Kairos Intelligence is a project currently being incorporated, based in Montreal (Quebec), Canada.

For any question regarding the protection of personal information (within the meaning of Quebec's Law 25), to exercise your rights, or to reach the person responsible for the protection of personal information, write to confidentialite@kairosintelligence.ca.

2. The founding principle: PII detection is local

Kairos's PII guard feature analyzes your prompts entirely within your browser, before they are sent to the AI service you are using (ChatGPT, Claude, Gemini, Perplexity):

  • Pass 1: local rules (emails, phone numbers, IBAN, SIRET, card numbers, API keys, etc.);
  • Pass 2: an entity-recognition model run locally (WebAssembly). The model is downloaded once and then cached on your device; no data from your prompt is transmitted for this analysis.

As a result, the content of your prompts and the personal data they contain are never transmitted to Kairos's servers. The only exception is described in section 4 (the "Improve" button).

3. Information we collect

Information you provide to us:

  • Account: email address, name, password (stored in hashed form, never in clear text), membership in an agency and workspaces, role. If you sign in via Google, we receive your email address, your name and an account identifier.
  • Library content: the templates, reusable blocks (snippets) and frameworks (frameworks) created by agency administrators.
  • Payment information (where applicable): processed by our payment provider. Kairos does not store your card numbers.

Information collected automatically:

  • AI usage data (anti-"shadow AI" feature): the extension records which AI services are used and when, along with associated technical metadata — but not the content of your prompts.
  • Product telemetry: aggregated counters (number of assisted prompts, number of PII items blocked, average quality score, Pass 2 deactivation rate). These metrics contain no prompt content.
  • Technical data: server logs, IP address, browser type, device or extension identifier, timestamps — used for the security and proper operation of the Service.

4. What we do not collect

  • The content of your prompts is neither collected nor stored by Kairos during PII analysis (see section 2).
  • Exception — the "Improve" button: if, and only if, you click "Improve" in the dashboard, the text of the relevant template is sent to Mistral AI (European Union) in order to propose an optimized version. This action is always triggered by you.

5. The purposes for which we use this information

  • to provide, maintain and secure the Service;
  • to authenticate you and manage your account;
  • to manage your agency's prompt library;
  • to provide agency administrators with AI-usage governance dashboards (see section 6);
  • to improve the product based on aggregated metrics;
  • to process payments, where applicable;
  • to comply with our legal obligations and to prevent fraud and abuse.

We do not sell your personal data and do not use it for targeted advertising.

6. Governance data and your employer's role

When an agency deploys Kairos to its teams, it may consult dashboards on AI usage by its employees. For this data, the agency is the controller and Kairos acts as a processor, processing the data according to the agency's instructions. If you are an employee of a client agency, direct your questions about this governance to your agency first.

7. Disclosure to third parties and sub-processors

We disclose your data only to the providers strictly necessary for the operation of the Service, bound by confidentiality commitments:

  • OVHcloud — hosting of the application server, the database, uploaded files and encrypted backups — Beauharnois (Quebec, Canada);
  • Mistral AI — optimization of a prompt template from your library, only when you click "Improve" — European Union;
  • Resend — sending transactional emails (verification, security) — United States;
  • Stripe — payment processing, where billing is enabled — United States;
  • Google — authentication, only if you choose to sign in with a Google account — United States;
  • ImprovMX — routing of inbound mail addressed to our aliases, including your rights requests — United States;
  • Microsoft — hosting of the mailbox that inbound mail is forwarded to — United States;
  • Hugging Face — distribution of the PII detection model downloaded once by the extension; no prompt content passes through it — United States.

The current list, with each provider's role and location, is published on the sub-processors page.

We may also disclose information if required by law, to enforce our terms, or in the context of a corporate reorganization (in which case this policy would continue to apply).

8. Hosting and transfers

  • Account data, library content and uploaded files are hosted in Quebec, in OVHcloud's data centers in Beauharnois (Quebec, Canada). Encrypted backups are kept in a separate object store, with the same provider and in the same Canadian region: they do not leave Canada.
  • Our application infrastructure is self-hosted on those servers: we do not entrust your account data or your library to a third-party cloud platform.
  • Processing by Mistral AI (the "Improve" button) takes place in the European Union.
  • Some ancillary providers (transactional email delivery, inbound mail routing, payment processing, Google authentication, detection-model distribution) are companies established in the United States. The information sent to them is limited to what is strictly necessary for their function — an email address, billing data, and the content of the messages you send us when you write to us — and never includes the content of your library or of your prompts. In accordance with Law 25, we carry out a privacy impact assessment before any disclosure of information outside Quebec.

9. Retention period

We retain data only for as long as necessary for the purposes described, or as required by law:

  • Account: for the entire duration of the relationship, then for a limited period after the account is closed;
  • Library: until deleted by your agency;
  • Session tokens: at most 20 days, renewed as you keep using the Service;
  • Technical logs and usage data: for a limited period, after which they are deleted or anonymized.

10. Your rights

In Quebec (Law 25) and Canada (PIPEDA), you may: access your information, have it corrected, withdraw your consent, request that its dissemination cease or that it be de-indexed, and file a complaint with the Commission d'accès à l'information du Québec (CAI) (https://www.cai.gouv.qc.ca).

In the European Union (GDPR), you additionally have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to lodge a complaint with your supervisory authority (in France, the CNIL).

To exercise these rights, write to confidentialite@kairosintelligence.ca. We will respond within the time limits set by applicable law. If your request concerns governance data held on behalf of your agency, we will direct you to it (see section 6).

11. Automated decisions

Kairos makes no decision based solely on automated processing that produces legal effects or significantly affects you. PII detection and the quality score are assistance tools: the final decision (send, anonymize, cancel) always belongs to you.

12. Security

We implement reasonable security measures: encryption in transit (TLS), strict data isolation between tenants (agencies and workspaces) enforced server-side on every read and every write, authentication via signed tokens, one-way password hashing and restricted staff access. As no method of transmission or storage is perfectly secure, we cannot guarantee absolute security.

13. Cookies

We use only strictly necessary or preference cookies: maintaining your authenticated session, remembering the language you chose and the state of the interface. These cookies are exempt from prior consent; we use neither advertising cookies nor third-party analytics.

14. Security incidents

In accordance with Law 25, we maintain a register of privacy incidents and, in the event of an incident presenting a risk of serious harm, we notify the Commission d'accès à l'information du Québec (CAI) as well as the individuals concerned.

15. Information concerning minors

The Service is a professional tool that is not intended for minors and is not designed to knowingly collect information concerning persons under 14 years of age.

16. Changes

We may amend this policy. The update date appears at the top of the page; in the event of a material change, we will inform you by an appropriate means.

17. Contact us

Kairos Intelligence — Montreal (Quebec), Canada. For any question regarding the protection of your data: confidentialite@kairosintelligence.ca.