Privacy Policy
Last updated 27 September 2026
We collect what we need to run your workspace and publish on your behalf — nothing more. We don't sell personal data, we don't use your content to train AI models, and we only send content to an AI provider when you choose to.
1. Who we are
Kairo Post (“Kairo Post”, “we”, “us”) provides a publishing workspace for X. This policy explains how we handle personal data when you use our website and app. For questions, contact privacy@kairopost.com.
2. What we collect
Account information
Your name, email address and password (stored only as a salted hash), two-factor settings, and the workspaces and roles you belong to.
Connected X accounts
When an account owner authorizes Kairo Post on x.com, we receive the account's handle, X user ID, granted permissions and OAuth access tokens. Tokens are encrypted at rest and are never shown to users or returned to the browser. We never receive X passwords.
Content you create
Drafts, threads, templates, revisions, brand profiles, writing examples, knowledge documents, media you upload and the approvals and comments your team adds.
Research sources
The feeds you add, along with titles, short summaries and links collected from them. You tell us the permission basis for each source.
Billing
Payments are processed by Whop. We receive confirmation of purchases, subscription status and amounts — not your full card details. We keep a credit ledger of grants, holds, charges and releases.
Security and usage records
Sign-in history (success or failure, approximate device and browser family, coarse network information), active sessions, audit events for important changes, and operational logs. Logs are designed to exclude secrets such as tokens and passwords.
3. How we use it
- To provide the service: authenticate you, run your workspace, and publish, schedule or delete posts you or your automations are authorized to act on.
- To bill correctly: quote, hold and settle credits, and reconcile payments with Whop.
- To keep accounts safe: detect abuse and credential stuffing, enforce permissions and keep an audit trail.
- To communicate: transactional emails such as verification, invitations, publishing outcomes, billing and security notices. You control non-essential notifications in settings.
- To improve reliability: diagnose failures and plan capacity using operational data.
We do not sell personal data, and we do not use your content to train AI models.
4. AI providers
Some features draft text or images using AI models. Content is sent to a model provider only when you (or an automation you authorized) request it, and only the material you selected — for example specific research excerpts, writing examples or knowledge passages. Where you connect your own provider key, your use is also governed by that provider's terms.
5. Legal bases
Where the GDPR or similar laws apply, we process data to perform our contract with you, to meet legal obligations (such as tax and accounting records), and for our legitimate interests in securing and improving the service. Where we rely on consent — for example, recording your authorization for an automation — you can withdraw it at any time.
6. Sharing
We share data only with service providers who help us run Kairo Post, listed on our subprocessors page, with X when publishing on your behalf, when required by law, or as part of a business transfer with equivalent protections. Content you publish to X becomes public under X's terms.
7. Retention
We keep workspace content while your account is active. Temporary data — such as import previews, generated drafts you didn't save, and export files — expires automatically, typically within 24 hours. Sign-in history is kept for a limited period. Billing and audit records are retained as long as required for legal, tax and fraud-prevention purposes. Backups are overwritten on a rolling schedule.
8. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to or restrict certain processing. You can export content and close your account from settings, or email privacy@kairopost.com. You may also complain to your local data protection authority.
9. Security
We use encryption in transit and for sensitive data at rest, strict workspace isolation, role-based access, two-factor authentication and audit trails. See our security page for details.
10. International transfers
Our providers may process data in countries other than yours. Where required, we rely on appropriate safeguards such as standard contractual clauses.
11. Children
Kairo Post is not intended for anyone under 18, and we don't knowingly collect their data.
12. Changes
We'll post updates here and, for material changes, notify workspace owners by email before they take effect.