Legal
Privacy Policy
Effective Date: August 9, 2026
Kyrigo LLC (“Kyrigo,” “we,” “us,” or “our”) operates the website www.kyrigo.com, the Kyrigo client portal, and provides AI consulting services (collectively, the “Service”). Kyrigo helps businesses adopt AI through environment setup, reporting, and business automations. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you visit our website, use the client portal, or engage us for consulting work.
By accessing or using the Service, you agree to the terms of this Privacy Policy. If you do not agree, please do not access or use the Service.
We Do Not Sell Your Personal Data
Kyrigo LLC does not sell, rent, lease, or trade your personal information or your business data to third parties for monetary or other valuable consideration. We have never sold personal data and have no plans to do so.
Information We Collect
Account Information
When you create or are invited to a client portal account, we collect your name, email address, and (optionally) your company name. You may sign in via Google OAuth or directly with an email and password. Passwords are hashed and never stored in plaintext.
Contact & Verification Information
If you contact us or we verify your identity, we may collect your name, email address, phone number, and the contents of your message. Where phone verification is used, your phone number is processed by our verification provider to send a one-time code.
Payment Information
When you pay for an engagement, payment details are collected and processed directly by Stripe. Kyrigo does not store your card numbers or full payment instrument details on our servers.
Portal & Engagement Data
- Portal records: Information about the environments, reports, and automations associated with your account.
- Client Data: Data, documents, credentials, and materials you provide to us during an engagement so we can perform the Services.
- Billing records: A history of invoices and payments associated with your account.
Device and Technical Information
- Device and browser info: Browser type, operating system, device type, screen resolution, and language preferences.
- IP addresses: Logged with each request for security and fraud prevention.
- Cookies: We use Supabase authentication cookies to maintain your session. See the Cookies section below.
How We Use Your Information
- Service delivery: To perform consulting engagements and to build, operate, and maintain your environments, reports, and automations.
- Payment processing: To issue invoices and process payments through Stripe.
- Account management: To create and authenticate your portal account and provide access to your engagement data.
- Service improvement: To analyze usage patterns and improve platform performance, reliability, and features.
- Fraud and abuse prevention: To detect and prevent unauthorized access, misuse, and fraudulent activity.
- Communication: To send transactional and service-related messages (account alerts, billing, engagement updates, policy updates). We do not send unsolicited marketing without your consent.
- Legal compliance: To comply with applicable laws, regulations, and legal processes.
Client Data & Confidentiality
We treat the business data you entrust to us as confidential. The following practices govern how we handle it:
- You own your data: You retain all rights to the Client Data you provide. We use it only to deliver the Services to you.
- Access controls: Portal data is protected by database row-level security so each client can access only their own records.
- No training for others: We do not use your Client Data to train AI models for other clients, and we do not sell it.
- Third-party AI providers: Where an engagement uses third-party AI models, relevant inputs may be transmitted to those providers to deliver the Service. We select providers whose terms are consistent with this policy, but they operate under their own terms — see the Third-Party Services section.
Third-Party Services
We rely on the following third-party providers to operate the Service. Each provider has its own privacy policy governing how they handle data.
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Authentication, database, and file storage | Account data, portal and engagement records |
| Stripe | Payment processing | Name, email, payment details |
| Twilio | Phone / identity verification | Phone number |
| AI Model Providers | AI features within an engagement | Inputs required for the requested task |
| Vercel | Web hosting and CDN | IP address, request logs |
Note on subprocessors: The specific third-party platforms used for a given engagement may vary based on the work involved. We can provide a current list of subprocessors relevant to your engagement on request.
Data Retention
- Account data: Retained while your account is active.
- Client Data & portal records: Retained for the duration of your engagement and returned or deleted afterward in accordance with your Engagement Agreement or upon request, subject to legal retention requirements.
- Payment records: Retained as required by applicable tax and financial regulations (typically 7 years).
- Inactive accounts: We may delete accounts inactive for 12 or more consecutive months, with prior email notice.
Data Security
We take the security of your data seriously and employ the following safeguards:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS/SSL.
- Encryption at rest: Data stored in Supabase is encrypted at rest using AES-256 encryption.
- Row-level security: Our database enforces row-level security policies so that each client can access only their own data.
- Least-privilege access: Administrative access to Client Data is limited to personnel who need it to deliver the Services.
- Payment security: All payment processing is handled by Stripe (PCI DSS Level 1 certified). Kyrigo never handles or stores raw card data.
No system is perfectly secure. While we work hard to protect your information, we cannot guarantee absolute security.
Cookies
We use a minimal set of cookies required to operate the Service:
- Supabase auth cookies: Essential session cookies used to keep you logged in. These are required for the Service to function and cannot be disabled without logging out.
We do not use advertising cookies or third-party ad-tracking cookies. You can control cookies through your browser settings, though disabling essential cookies will prevent you from using authenticated features.
Your Rights
You have the following rights with respect to your personal information:
- Access: Request a copy of the personal information we hold about you.
- Deletion: Request that we delete your account and associated personal data, subject to legal retention requirements.
- Correction: Request that we correct inaccurate or incomplete personal information.
- Export: Request a machine-readable export of your data.
- Restriction: Request that we restrict processing of your data in certain circumstances.
To exercise any of these rights, contact us at support@kyrigo.com. We will respond within 30 days.
Children's Privacy
The Service is intended for business users who are 18 years of age or older. We do not knowingly collect personal information from anyone under the age of 18. If you believe a child has provided us with personal information, please contact us at support@kyrigo.com and we will delete it promptly.
California Privacy Rights — CCPA/CPRA
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected, the sources, the purposes for collection, and the categories of third parties with whom we share it.
- Right to Delete: Request deletion of your personal information, subject to certain exceptions.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt Out of Sale or Sharing: Kyrigo does not sell or share your personal information. No opt-out action is required.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights.
To submit a CCPA/CPRA request, email us at support@kyrigo.com. We will respond within 45 days.
International Users
Our Service is operated in the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country. By using the Service, you consent to this transfer. We take steps to ensure your information receives an adequate level of protection wherever it is processed.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date at the top of this page and notify account holders via email where practicable before changes take effect. Continued use of the Service after the effective date constitutes acceptance of the revised policy.
Contact Us
This Privacy Policy was last updated on August 9, 2026.
Kyrigo LLC — AI Consulting