Privacy Policy
Effective 26 July 2026 · Last updated 26 July 2026
Kith ("Kith", "we", "us") is a personal chief of staff operated by DPRC BV (the Netherlands). Kith connects to the accounts and services you choose to link, and uses that information to help you keep track of the people and commitments in your life.
This policy explains what data we access, how we use it, who processes it on our behalf, how long we keep it, and the choices and rights you have. If you have any question, contact us at team@heykith.ai.
1. Summary (the short version)
- We access information only from the accounts and services you connect, and only to provide Kith's features to you.
- We do not train AI models on your data, and we only use AI providers that are contractually prohibited from training their models on it.
- We do not sell your data, do not use it for advertising, and do not use it to build advertising, profiling, or contact-data products.
- We minimize what leaves Kith. Before Kith ever consults an outside service on your behalf (for example, a web lookup), an automated privacy filter removes sensitive and identifying details first (§6).
- Your Google user data is handled in accordance with the Google API Services User Data Policy, including the Limited Use requirements (§4).
- You can disconnect an account or delete your account and all associated data at any time from within the app (§9).
2. Who this policy covers
This policy applies to the Kith web application, the Kith mobile apps, and the Kith backend service. Access to Kith may be offered on a limited or invitation-only basis.
Kith is not directed to children and is not intended for anyone under the age of 16 (or the minimum age required in your jurisdiction). We do not knowingly collect data from children.
3. Information we collect
We collect the following categories of information. We describe them by category rather than by product so this policy stays accurate as Kith adds new connections and features.
3.1 Account & identity
When you sign in through a single-sign-on provider, we receive your name and email address to create and secure your account. We never receive or store your sign-in password.
3.2 Data from the accounts and services you connect
When you connect an account or service, Kith accesses — for your account only, and only for the connections and permissions you grant — the categories of information relevant to that connection. Today, the connections Kith supports involve:
- Email — message content, metadata (senders, recipients, dates, subjects, threading), attachment file names (not attachment file contents), and any calendar invitations contained in email.
- Contacts — names, email addresses, and related contact fields.
- Calendar — events, times, locations, descriptions, and attendees.
Kith accesses this data through each provider's official API, using credentials you authorize. We store those connection credentials in encrypted form. You can connect more than one account, and you can disconnect any of them at any time. As we add new kinds of connections over time (for example, documents, notes, or other tools), this policy will describe the new categories of information they involve.
3.3 Content you create in Kith
Messages you send to the assistant, tasks, notes, preferences, and settings you create while using Kith.
3.4 Location (optional)
If you enable it, the mobile app reads your device location while you are using the app to set a "home base" (a city and coordinates) so your daily brief can include local context such as weather and the correct time zone. Converting your coordinates to a city name happens on your device. We do not track your location in the background.
3.5 Technical data
Basic operational data needed to run the service securely (such as authentication tokens and server logs containing timestamps and error information). We do not use third-party advertising, analytics, or cross-app tracking technologies, and Kith does not track you across other apps or websites.
4. Google user data and Limited Use
Where you connect a Google account, Kith's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, and to Google's requirements for sensitive and restricted scopes.
Scopes we request and why. Kith requests access to your Gmail, Google Contacts, and Google Calendar so that it can read your messages, contacts, and events in order to surface tasks, follow-ups, meeting context, and relationship information back to you. Some of these are Google restricted scopes; Kith requests only the scopes needed to provide these user-facing features.
How we handle Google user data — the Limited Use commitments:
- Only to provide user-facing features. We use Google user data solely to provide and improve the Kith features that are prominent in the app's user interface. We do not use it for any unrelated purpose.
- No transfer for ads or resale. We do not transfer or sell Google user data to third parties for advertising, marketing, or other purposes, and we do not transfer it to data brokers or information resellers.
- No advertising. We do not use Google user data for serving advertisements, including personalized or retargeted ads.
- No human reading. We do not allow humans to read your Google user data, except: (a) with your explicit consent (for specific messages); (b) for security purposes (such as investigating abuse) or to comply with applicable law; (c) where the data has been aggregated and anonymized; or (d) as necessary for internal operations where the data has been de-identified. Automated processing — including by the AI service providers described in §7 — is used to provide the features and is not "human reading."
AI processing of Google user data. To provide the assistant, relevant content (which may include Google user data) is sent to our AI service providers only to generate the assistant's response for you. Those providers act on our behalf, process the data only on our instructions to provide the feature, and are contractually prohibited from using it to train their models. This use is limited to providing the user-facing feature and is consistent with the Limited Use requirements above.
5. How we use your information
We use the information described above to operate Kith's features, which today include: keeping your connected accounts and services in sync; detecting and surfacing tasks, commitments, and relevant context; building your personal contact and relationship view; letting you ask the assistant questions about your own information and draft replies for you to review; and delivering notifications you opt into. We also use it to operate, secure, debug, and improve the service. As Kith adds features, we will use your information to provide those features consistently with this policy.
We process this data to provide the service you have asked for, and — where required by law — on the basis of your consent, which you may withdraw at any time by disconnecting an account or deleting your account.
6. Privacy by design — minimizing what leaves Kith
Kith is built to keep your information inside your own account and to minimize what is ever sent to any outside service.
- Processed for you, not pooled. Your data is strictly isolated to your own account and used only to serve you. It is not combined with other users' data to build shared profiles, datasets, or products.
- Kept in-house where we can. Wherever practical, Kith processes your data within its own systems rather than sending it to third parties — for example, the search index that powers "find that email" and the conversion of your coordinates to a city name are computed without sending your content to an outside service.
- An automated privacy filter on anything that leaves. Some features may need to consult an external service on your behalf — for example, looking something up on the public web. Before any such request leaves Kith, an automated filter runs over it and:
- removes sensitive identifiers — such as payment-card and bank-account numbers, government identifiers, and access credentials — replacing them so they are never transmitted;
- strips personal context, reducing the request to a generic, non-identifying query that does not reveal who you are or whose information it concerns; and
- fails safe — if the request cannot be made safe, Kith does not send it.
We keep only a record of the type of information that was filtered (for security tuning), never the sensitive value itself. The result is that your personal content is not exposed to external search engines or other public services when Kith looks something up for you.
- Least privilege. Each connected account or service is accessed only for the narrow permissions you grant, and only to provide your features.
7. AI processing and service providers (subprocessors)
Kith does not sell your personal data and does not share it with third parties for their own purposes. We share data only with service providers who process it on our behalf, under contract, solely to operate Kith. We engage providers in the following categories:
- AI processing — to understand your requests and generate responses. We only use AI providers that process your data solely to provide the feature and are contractually prohibited from using it to train their models.
- Cloud infrastructure — hosting, database, and storage for the service.
- Messaging delivery — delivering notifications you opt into, if you connect a messaging channel.
Current providers (as of 26 July 2026). The specific service providers we currently engage are:
- AI processing — Anthropic (Claude).
- Cloud infrastructure — Google Cloud.
- Messaging delivery — Meta Platforms (WhatsApp), only if you connect WhatsApp.
We update this list when our providers change, and we will give reasonable advance notice of material changes to the providers that process your personal data.
We may also disclose information if required by law, to enforce our terms, or to protect the rights, safety, and security of our users and the service.
Where we de-identify or aggregate data, we maintain and use it only in that form and do not attempt to re-identify it, except as permitted by law.
8. Security
We protect your data with measures including: encryption in transit and of sensitive credentials at rest; single-sign-on authentication; multi-factor authentication on administrative access; strict per-user data isolation; least-privilege access to connected-account APIs; the outbound privacy filter described in §6; and standard web security controls. No method of transmission or storage is perfectly secure, but we work to protect your information and to limit access to it.
9. Data retention and deletion
- Disconnect an account. Disconnecting a connected account stops further syncing. You can also erase the data ingested from that specific account from within the app.
- Delete your account. You can delete your Kith account at any time from the app's account settings. Deleting your account permanently removes your data from our production systems — including messages, contacts, calendar data, tasks, search indexes, connection credentials, and derived profile information — through a single erasure process, and revokes your sessions.
- Retention. We keep your data only while your account is active or as needed to provide the service. On account deletion we remove it from active systems promptly and purge it from routine backups within 30 days, subject to any narrow legal-retention obligations.
To request help with deletion or to exercise any right below, contact team@heykith.ai.
10. Where your data is processed
Kith's servers and database are hosted in the European Union. Some service providers may process data in other countries, including the United States. Where personal data is transferred internationally, we rely on appropriate safeguards (such as the service provider's standard contractual clauses) as required by applicable law.
11. Your rights and choices
Depending on where you live (including under the EU/UK GDPR and the California CCPA/CPRA), you may have the right to: access the personal data we hold about you; correct or update it; delete it; restrict or object to certain processing; port it; and withdraw consent. Kith is built so you can exercise the core of these rights directly in the app (view your data, disconnect accounts, delete your account). To make any other request, contact team@heykith.ai; we will respond within the timeframe required by applicable law. You also have the right to complain to your local data protection authority.
We do not sell or "share" personal information as those terms are defined under California law, and we do not use your data for cross-context behavioral advertising.
12. Changes to this policy
We may update this policy as Kith evolves. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in the app. Continued use of Kith after an update means you accept the revised policy.
13. Contact
Questions, requests, or concerns about this policy or your data:
DPRC BV Email: team@heykith.ai