Privacy Policy

Last updated August 22, 2026

This policy explains what information KAAL AiOS collects, how it's used, and how you can control it.

Information we collect

Account information: your name, email, and workspace details when you sign up.

Business profile information: anything you provide about your business — description, target audience, contact details — so your AI employees can act with accurate context.

Integration data: information your connected tools (CRM, email, social platforms) share with KAAL AiOS so agents can act on your behalf.

Usage data: how you interact with the product, used to improve the AI Operating System and diagnose issues.

How we use your information

To operate your AI employees — running tasks, drafting outreach and content, and generating briefings on your behalf.

To maintain the Approval Queue, so high-stakes agent actions are reviewed before they reach your customers.

To bill your subscription and communicate about your account.

To improve KAAL AiOS's agents and product based on aggregated, de-identified usage patterns.

Google account data (Gmail, Calendar, and Sheets)

KAAL AiOS requests access to your Google account only if you explicitly connect a Google integration from Settings → Integrations. Nothing is requested or accessed until you complete Google's own consent screen, and you can decline at any point.

Gmail: if you connect Gmail, KAAL AiOS requests permission to send email on your behalf and to read your Gmail profile. Sending is used so your Sales agent can deliver outreach you have configured or approved. Reading is used to confirm the connection is working and to identify the sending address.

Google Calendar: if you connect Calendar, KAAL AiOS requests permission to view and manage calendar events. This is used to find available meeting slots and to create bookings your agents schedule with leads.

Google Sheets: if you connect Sheets, KAAL AiOS requests permission to view and manage your spreadsheets. This is used only for the specific spreadsheet and tab you select when configuring the integration — for example, exporting your leads to a sheet you nominate.

KAAL AiOS does not request or receive access to Google Drive. We do not browse, list, or access files in your Drive.

We only access the Google data needed for the specific integration you have enabled. Connecting one Google service does not grant KAAL AiOS access to the others.

You can disconnect any Google integration at any time from Settings → Integrations. When the last connected Google service is disconnected, KAAL AiOS asks Google to revoke its access and deletes the stored authorization from our systems. You can also revoke KAAL AiOS's access directly from your Google Account's security settings.

How KAAL AiOS handles Google authorization

KAAL AiOS never sees or stores your Google password. Access is granted through Google's standard OAuth 2.0 flow, and the authorization is exchanged on our servers — never in your browser.

The long-lived authorization token KAAL AiOS stores is encrypted at rest, is never exposed to client-side code or included in any web address, and is used only to obtain short-lived access tokens when an enabled feature actually runs.

Limited Use disclosure

KAAL AiOS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically: we use Google user data only to provide and improve the features you have connected; we do not transfer it to others except as needed to provide those features, for security purposes, or to comply with applicable law; we do not use it for advertising; and no human reads it except with your explicit consent, for security purposes, to comply with applicable law, or where the data has been aggregated and de-identified.

Google user data is not used to train any AI or machine-learning model, including third-party foundation models.

AI processing and third-party models

If you bring your own AI model (BYOK), your prompts and the content your agents generate are processed by the model provider you've selected (OpenAI, Anthropic, Google, etc.) under that provider's own terms.

KAAL AiOS does not use your business data to train third-party foundation models.

Data sharing

We don't sell your data. We share data with the integrations you explicitly connect (so your agents can act through them) and with infrastructure providers who help us run the service, under standard confidentiality terms.

Data retention

Your business data — leads, AI-generated lead scoring and content, objectives and tasks, approvals, uploaded documents, and WhatsApp conversation history — is retained for as long as your organization exists on KAAL AiOS. We don't automatically delete this data based on age.

A small set of purely operational records — outbound-webhook delivery logs and internal task-execution event logs — are automatically purged after a bounded window (90 days by default) once they're no longer useful for debugging. This does not apply to any of the business data listed above.

Security and audit records (a log of high-stakes actions such as approval decisions, billing changes, and account deletions) are retained permanently, including after an organization is deleted, for security and compliance purposes. These records are append-only at the database level and cannot be altered or deleted through the application.

Your rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data.

Organization owners can permanently delete their organization and all of its data at any time from Settings → Account → Delete organization, which requires a typed confirmation before it takes effect. This removes your organization's business data, documents, and associated files. As noted above, our security/audit records of account-level actions are retained afterward for compliance purposes.

If you're not an organization owner, or prefer we handle deletion directly, contact us and we'll process your request.

Security

We use industry-standard encryption in transit and at rest, and credentials (API keys, integration tokens) are encrypted and never displayed in plaintext after entry.

Changes to this policy

We'll update the date at the top of this page when this policy changes, and notify you of material changes via email or in-app notice.

Contact us

Questions about this policy, or want to request access to or deletion of your data? Email us at contact@kaalaios.online.

You can also reach us through the details on our Contact page.