Privacy Policy for HelloKai

Last updated: July 31, 2025

1  Who we are

Kai is an AI personal-assistant service operated by TAYLOR TRIP PTE LTD, a company incorporated in Singapore. For any privacy questions, e-mail contact@hellokai.ai.

2  The Google data we access

We request only the Google OAuth scopes needed to deliver Kai's features. We never store full e-mail bodies or attachments — only encrypted tokens, message/event metadata and AI-generated summaries.

Google serviceOAuth scopesWhat we readWhy we need it
Gmailgmail.readonly, gmail.modify, gmail.sendMessage headers, body text, labels• Organise inbox & archive
• Draft reply suggestions (sent only after you press "Send")
Google Calendarcalendar.events.readonlyEvent titles, times, attendeesShow your daily schedule & create reminders
Google Peoplecontacts.readonlyContact names & e-mail addressesIdentify VIP contacts for prioritisation

3  How we use — and never use — your data

  • We use Gmail, Calendar and Contacts data solely to deliver inbox triage, calendar summaries and draft e-mail replies.
  • We do not sell, rent or use your data for ads.
  • Kai personnel do not read your messages or events unless you request troubleshooting help.

4  Storage, security & sub-processors

ComponentProvider / RegionPurposeRetention
DatabaseSupabase (AWS ap-southeast-1, SG)Store encrypted OAuth tokens, metadata & settingsUntil disconnect or account deletion
AI inferenceOpenAI (USA)Generate e-mail summaries & draftsPrompts retained ≤ 30 days (abuse monitoring)
PaymentsStripe (global)Process subscription payments (card data never stored by Kai)As required by payment law
Application hostingVercel (edge), Render & RailwayHost Kai back-end & workersRuntime only — no user data persisted
LoggingSupabase & Vercel function logsDiagnose errors & audit securityPurged after 30 days

All traffic uses TLS 1.3. Data at rest is protected with AES-256. Access to production systems requires SSO and MFA.

5  International transfers

If you access Kai from outside Singapore, your data may be transferred to and processed in Singapore and the United States where our sub-processors operate. We rely on contractual safeguards and industry-standard encryption to protect your data in transit and at rest.

6  Retention & deletion

  • Server logs containing message IDs or subject lines are retained up to 30 days then permanently purged.
  • When you disconnect Google or delete your Kai account, all tokens, cached metadata and AI summaries are deleted within 24 hours.
  • Revoke access anytime in the dashboard (Settings → Disconnect) or your Google Account (Security → Third-party access).

7  Children's privacy

Kai is intended for users aged 18 and over. We do not knowingly collect personal information from children. If we learn that data from a user under 18 has been collected, we will delete it within 24 hours.

8  Cookies & analytics

Our marketing site uses essential cookies and Google Analytics. See our Cookie Notice for details and opt-out options.

9  Google API Limited-Use

Kai's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

10  Your rights & legal bases (GDPR/PDPA/CCPA)

Depending on your jurisdiction, you may request access, correction, deletion, portability, restriction or objection to our processing of your personal data. We process data on the following legal bases: (i) Contract — to provide the Kai service you sign up for; (ii) Legitimate interests — product security and improvement; (iii) Consent — marketing communications (you may withdraw at any time).

To exercise any right, e-mail contact@hellokai.ai. We respond within 30 days.

11  Changes to this policy

We will e-mail you and post a notice on the Kai dashboard 30 days before any material changes take effect. Continued use of Kai after the effective date constitutes acceptance of the updated policy.

Contact

TAYLOR TRIP PTE LTD
160 Robinson Road, #14-04
Singapore Business Federation Center
Singapore 068914
contact@hellokai.ai

By using our services, you consent to the collection and use of information in accordance with this Privacy Policy.