Privacy Policy - Kestral, Co.

Version 2.0
Effective Date: October 2, 2026

This Privacy Policy explains how Kestral, Co. ("Kestral," "we," "us," or "our") collects, uses, shares, and protects personal information in connection with our websites; web, desktop, and mobile applications; APIs; Model Context Protocol ("MCP") server; integrations; and related services (collectively, the "Services").

Kestral is a business product. When an organization (a "Customer") uses the Services, the content its users submit or connect, such as tasks, documents, messages, recordings, and prompts ("Customer Data"), is controlled by that Customer. We process Customer Data on the Customer's behalf, as its processor or service provider, under our Terms of Service or a signed agreement. If you use Kestral through your organization, please direct questions about Customer Data to your workspace administrator. For account information, usage data, website visitors, and marketing, Kestral determines how information is used and is responsible for it under this policy.

Summary

  • We do not sell personal information or share it for cross-context behavioral advertising.
  • We do not use Customer Data to train AI models, and our AI model providers are contractually prohibited from training their models on it.
  • A limited number of Kestral personnel can access Customer Data when needed to provide support, resolve issues, keep the Services secure, or comply with law. Customers can restrict support and troubleshooting access through a signed agreement.
  • Customer Data is hosted in the United States, encrypted in transit and at rest, and protected by a security program audited under SOC 2 Type 2.

1. Information We Collect

Account information

Name, email address, password (stored only as a salted hash), profile image, workspace name and role, and security settings such as two-factor authentication. If you sign in with Google, we receive your name, email address, and profile image from Google.

Customer Data

Content that users submit to or create in the Services, including tasks, projects, comments, documents, files, audio and video recordings and their transcripts, prompts to AI features, and AI-generated output.

Information from connected services

When a Customer connects a third-party service, we access the data the Customer authorizes, within the permissions granted, and treat it as Customer Data. Depending on the integrations enabled, this may include Slack messages and files; Google Drive files, Gmail messages, and Google Calendar events; GitHub, Linear, and Jira issues and pull requests; Notion and Confluence pages; Zendesk, Zoho Desk, and Atlas support tickets; Gong and Granola meeting notes and transcripts; HubSpot and Salesforce CRM records; and app store reviews. We store the credentials for these services encrypted.

Usage, device, and diagnostic information

IP address, browser and device type, operating system, pages and features used, clicks and other interactions, referring URLs, timestamps, performance data, and error reports. We use third-party product analytics and error monitoring providers, whose tools include recordings of how pages are used and replays of sessions in which an error occurs. Form inputs and passwords are masked in these recordings.

Billing information

Payments are processed by a third-party payment processor, which collects your payment card details. We receive limited billing information, such as your plan and payment status, but not full card numbers.

Communications

The contents of support requests, feedback, survey responses, and other communications you send us.

Desktop and mobile apps

Our apps collect the information described above, plus the app and device details needed to run and troubleshoot them. Features that use your microphone, system audio, or screen, such as meeting capture in the desktop app, run only after you enable them and grant permission in your operating system. The mobile app stores a snapshot of your tasks on your device to display home-screen widgets.

2. How We Use Information

We use information to:

  • Provide, operate, and maintain the Services, including AI features and integrations
  • Provide customer support and investigate and resolve issues
  • Monitor the performance, reliability, and usage of the Services
  • Secure the Services and detect and prevent fraud, abuse, and security incidents
  • Understand how the Services are used and improve them, primarily using usage data and aggregated or de-identified data
  • Send service messages, such as account, security, billing, and trial notices
  • Send marketing communications, which you can opt out of at any time
  • Comply with legal obligations and enforce our agreements

We do not use Customer Data for advertising or marketing, and we do not use it to train AI models (see Section 3).

If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases: performance of our contract with you or the Customer; our legitimate interests in operating, securing, supporting, improving, and marketing the Services to business users, balanced against your rights; compliance with legal obligations; and your consent where required, which you may withdraw at any time.

3. AI Features and Model Training

Kestral's AI features send the Customer Data needed for a request, such as a question, relevant documents and tasks, and workspace context, to third-party AI model providers to generate responses, summaries, transcriptions, and other output. To find and use information within a workspace, we also create embeddings (numerical representations of text) and maintain search indexes and AI memory for that workspace.

We do not use Customer Data, including prompts, files, connected-service content, recordings, and AI output, to train, fine-tune, or otherwise develop AI or machine learning models, whether ours or anyone else's. Our AI model providers process Customer Data under commercial terms that prohibit them from training their models on it. Under those terms, providers may retain inputs and outputs for a limited period to monitor for abuse and comply with law. Search indexes, embeddings, and memory that serve only your own workspace are part of providing the Services, not model training, and are deleted with the Customer Data they are derived from.

If you connect a third-party AI assistant or agent to Kestral, such as through our MCP server or our Cursor, Devin, or Claude Code integrations, the data it retrieves from or receives through Kestral is handled under that provider's terms and your organization's settings with that provider.

4. Our Access to Customer Data

Kestral personnel access Customer Data only when reasonably necessary to:

  • Provide support that you or your organization requests
  • Investigate and resolve technical problems affecting the Services, including the quality of AI features
  • Protect the security and integrity of the Services and investigate suspected fraud or abuse
  • Comply with applicable law or legal process

We use what we learn from this work to fix and improve the Services, never to train AI models. Access is limited to authorized personnel with a need to know who are bound by confidentiality obligations, and administrative access is logged. Customers can restrict support and troubleshooting access through a signed agreement with Kestral, or ask us to exclude their workspace from proactive review by emailing privacy@kestral.team; access needed for security and legal compliance cannot be restricted. Additional limits apply to Google user data, as described in Section 9.

5. How We Share Information

We do not sell personal information or share it for cross-context behavioral advertising. We share information only:

  • With service providers that process information on our behalf under written agreements, including the subprocessors listed in Section 6
  • Within your workspace, where content is visible to other users according to workspace and project permissions
  • With connected services and AI clients that you or your organization authorize, when you direct the Services to send data to them
  • When required by law or legal process, or when necessary to protect the rights, safety, or security of Kestral, our users, or others. We will notify the affected Customer before disclosing Customer Data in response to a legal demand unless we are legally prohibited from doing so
  • In connection with a merger, acquisition, financing, or sale of assets, subject to the commitments in this policy
  • With your consent or at your direction

6. Subprocessors

We use a limited set of service providers ("subprocessors") to provide the Services. They fall into the following categories:

  • Cloud infrastructure: hosting, databases, file storage, and job processing
  • AI model providers: generating responses, summaries, and transcriptions, and creating embeddings
  • Search and memory infrastructure: indexing and retrieving workspace content for AI features
  • Web search: retrieving public web results for AI research features (receives search queries generated by AI features, not workspace files)
  • Email delivery
  • Payment processing
  • Product analytics and error monitoring

Customer Data is hosted and processed primarily in the United States. Each subprocessor is bound by a written agreement with confidentiality and data protection obligations, and our AI model providers are contractually prohibited from training their models on Customer Data.

We maintain a current list naming each subprocessor and the data it processes. You can request it through our Trust Center. We update that list before a new subprocessor begins processing Customer Data, and Customers with a Data Processing Addendum receive advance notice and an opportunity to object as described in it.

7. Data Retention and Deletion

  • Account information is kept while your account is active, and afterward as needed to comply with legal obligations, resolve disputes, and enforce our agreements.
  • Customer Data is kept for as long as the Customer's workspace exists or as the Customer's agreement specifies. When a trial or paid subscription ends, the workspace remains available in read-only form so it can be exported or reactivated. When a Customer requests deletion, we delete its Customer Data from our production systems within 30 days, and backup copies are overwritten within a further 30 days, unless the law requires us to keep it.
  • Usage and diagnostic data is kept for limited periods set by us and our service providers, after which it is deleted or aggregated.

To request deletion, email privacy@kestral.team.

8. Security

We protect information with administrative, technical, and physical safeguards, including:

  • Encryption in transit and at rest, with additional application-level encryption (AES-256-GCM) for integration credentials
  • Role-based access controls within workspaces, and restricted, logged administrative access for Kestral personnel
  • Two-factor authentication, which workspace owners can require for members
  • A security program independently audited under SOC 2 Type 2, and third-party penetration testing

Security documentation is available through our Trust Center. No system is perfectly secure. If a security breach results in unauthorized access to Customer Data, we will notify affected Customers without undue delay, and within 72 hours of becoming aware of it.

9. Google and Slack User Data

When you connect Google services, Kestral requests access to your basic profile and, depending on the features you enable, Google Drive, Gmail (read-only), or Google Calendar (read-only). We use this data only to provide and improve user-facing features you enable, such as importing and searching documents and messages, creating and updating tasks, and answering questions with AI.

Kestral's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

  • We do not use Google user data for advertising, and we do not sell it.
  • We do not use Google user data to develop, improve, or train generalized AI or machine learning models. We send it to AI model providers only as needed to provide features you use, under terms that prohibit them from training on it.
  • Kestral personnel do not read Google user data unless you affirmatively agree for specific data, it is necessary for security purposes or required by law, or the data has been aggregated and anonymized for internal operations.

We use data from Slack only to provide the Kestral features your organization enables, and we do not use it to train AI models.

10. Cookies and Similar Technologies

We use cookies and browser storage that are necessary to keep you signed in and to protect your account, such as authentication and cross-site request forgery protection cookies. We also use third-party analytics, including session recording, to understand how our websites and app are used, and error monitoring tools to diagnose errors. We do not use third-party advertising cookies. You can block or delete cookies in your browser settings, but blocking necessary cookies will prevent you from signing in.

11. International Data Transfers

Kestral is based in the United States, and we process information in the United States and other countries where our subprocessors operate. When we transfer personal information from the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, which are included in our Data Processing Addendum.

12. Your Rights and Choices

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information; to object to or restrict certain processing; to withdraw consent; and not to be discriminated against for exercising these rights. To make a request, email privacy@kestral.team. We will verify your identity and respond within the time required by applicable law, and you may use an authorized agent where the law allows. If you are in the European Economic Area or the United Kingdom, you may also lodge a complaint with your local data protection authority.

If your request concerns Customer Data in an organization's workspace, we will refer you to that organization, because we process that data on its behalf, and we will help the organization respond.

California residents: in the past 12 months we collected the categories of personal information described in Section 1 (identifiers, account and commercial information, internet and network activity, audio and visual information you upload, and professional information) for the purposes described in Section 2, and disclosed them to service providers for business purposes. We do not sell or share personal information, and we do not use sensitive personal information for purposes that require an opt-out.

You can unsubscribe from marketing emails using the link in each message. We will still send service messages about your account.

13. Children's Privacy

The Services are intended for business use and are not directed to children. We do not knowingly collect personal information from children under 13, and we will delete it if we learn that we have.

14. Changes to This Policy

We may update this policy from time to time. If we make material changes, we will notify you by email or through the Services at least 30 days before they take effect, unless the law requires a change sooner. The effective date above shows when this policy was last updated.

15. Contact Us

Kestral, Co.
Privacy questions and requests: privacy@kestral.team
Support: support@kestral.team