Legal
Privacy Policy
Last updated: 7 August 2026
What Kylo collects, what we deliberately do not store, how we use and share information, and the choices available to you.
1. Introduction
This Privacy Policy explains how Kylo (“Kylo,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal data in connection with our AI agent platform and related services (the “Services”).
Operator: Kylo, a Company Limited by Shares registered under Innovation City – Ras Al Khaimah, United Arab Emirates (License No. 07011267). Registered office: Office A, Innovation City Business Centre, RAK Bank ROC Office, Ground Floor, Al Rifaa, Sheikh Mohammed Bin Zayed Road, Ras Al Khaimah, UAE. Commercial presence: Dubai / UAE. Privacy and support: support@kylo.ae.
Our privacy stance (messages & leads): We don’t keep a permanent chat transcript archive or lead records in Kylo. We do not collect conversation message bodies into a durable Kylo leads or transcript product. We keep technical IDs needed for delivery, billing credits, and abuse prevention. For reply quality, the Lead Qualifier may retain short-lived session memory keyed by channel thread (for example a WhatsApp id), for up to 24 hours, then erase it. That memory is not sold and is not a browsable lead archive.
Message text is processed in transit by the AI path (Mastra + OpenRouter and the underlying model provider) and by Meta to deliver replies. Processing is not a permanent Kylo archive. CRM requirement: because Kylo is not a first-party leads database, Clients must integrate at least one supported CRM as the main database to store leads. Zoho CRM is live; additional CRM integrations are coming soon. When you connect a CRM and enable sync tools, lead fields may be sent to your CRM under your control. Your connected CRM remains the source of truth and primary store — not Kylo.
- Step 1ChannelMeta (WhatsApp live; more channels soon)Messages per Meta’s / each channel’s policies
- Step 2KyloOps IDs · credits · ≤24h session memoryNo permanent transcript archive
- Step 3AI pathOpenRouter + model providerText processed in transit for the turn
- Step 4Connected CRM≥1 required · Zoho live (more soon)Your CRM is the main lead database
| Stored | Not stored |
|---|---|
| Channel / provider message IDs | Permanent chat transcript archive |
| Conversation thread keys (e.g. wa_id) | Playground chat history in Prisma |
| Timestamps, role, credits charged | Long-term observational / semantic memory |
| Credit ledger + usage events | A browsable Kylo leads product archive |
| Channel / CRM config + encrypted tokens | Lead field copies as first-party CRM data |
| Mastra session memory (≤24h, then pruned) | Selling or advertising use of session memory |
2. Scope and legal basis
This Policy is issued with reference to Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL). Kylo applies core PDPL principles — lawful basis, data minimisation, security, and data subject rights — as good practice. Where relevant to Clients operating internationally, GDPR standards may also be referenced.
This Policy applies to:
- The Kylo web application and related APIs
- Account registration, authentication, billing, and settings
- Channel connections via Meta (WhatsApp Cloud API live; additional Meta messaging channels coming soon)
- Required CRM integration(s) as the main lead store (at least one; Zoho CRM live; other CRMs coming soon)
- Communications we send about the Service (e.g. auth emails via SMTP)
This Policy does not govern:
- How Meta, OpenRouter (and underlying model providers), Stripe, Zoho, your SMTP host, or your own tools process data under their policies
- Content that end-users share with you on WhatsApp or other channels — you are the controller of that relationship
- Data held in your connected CRM after a sync
3. Data we collect
Account & profile. Name, email, company name (as provided), password credentials (no plaintext passwords), profile and security settings, and optional avatar uploads to local application storage.
Billing & credits (when enabled). Subscription and plan status; credit balance, allotments, and ledger entries; usage metering events; payment-related identifiers via Stripe — full card PANs are not stored on Kylo. Billing is priced in AED.
Agent & channel configuration. Agent instructions and routing preferences; channel connection metadata; encrypted integration credentials at rest (AES-256-GCM).
Ops / technical IDs (not message bodies). Provider message IDs, conversation/thread keys, timestamps, message role (inbound/outbound), credits charged, and ops-only metadata — not message body text.
CRM sync (in transit; required main lead store). Clients must keep at least one supported CRM connected as the main database for lead storage. If sync tools are enabled, we may process fields your agent chooses to send solely to deliver them to your connected CRM. Kylo does not retain those fields as a first-party leads product.
Technical & security logs. Standard server/application logs, IP addresses, device/browser signals, and authentication events needed to operate and secure the Service.
4. Data we do not collect or store
We design Kylo so that we do not retain:
- Permanent conversation / chat transcript archives
- Lead / contact records as a Kylo product archive
- Playground chat history as durable Prisma transcripts (playground skips ops transcript rows; metering may still record usage)
- Full copies of channel message bodies for later product replay
Short-lived session memory (exception for reply quality): recent turns may be stored in Mastra agent memory, keyed by channel thread, for up to 24 hours, then erased by scheduled retention prune. Used only to generate better replies for that thread — not sold, not used for advertising, and not a substitute for your CRM.
Processing vs retention: To generate a reply, message text is processed by the AI path (Mastra + OpenRouter and the underlying model provider) for that request. Meta retains messages according to Meta’s policies. Transient server logs may occasionally include sensitive snippets; we treat that as operational risk to minimize, not as a transcript or leads store.
5. How we use data
- Provide, operate, and improve the Service
- Authenticate accounts and protect against abuse
- Meter credits, enforce entitlements, and bill subscriptions / credit packs via Stripe
- Route Meta webhooks and send/receive messages on your connected channels
- Encrypt and refresh connection tokens as needed
- Deliver lead field values to the CRM(s) you connect as your main lead store, when sync tools are enabled
- Send transactional email (verification, password reset, service notices) via SMTP
- Comply with law and enforce our Terms
We do not sell personal data. We do not use Client or End User data to train AI models for anyone other than the Client from whose use the data was generated. Short-lived session memory (≤24 hours) is used only for reply quality on that channel thread.
6. Role of the parties
As between Kylo and its Clients, the Client typically acts as data controller for End User data, and Kylo acts as data processor for the platform — except where Kylo determines purposes for its own account data (billing, security), in which case Kylo acts as controller of that account data. A separate Data Processing Agreement may apply when entered into with the Client.
7. Channels, third parties & subprocessors
Production intent is a self-hosted Docker stack on a Hostinger (or equivalent) VPS — Postgres, Redis, and local file storage with the Kylo app — plus external APIs: Meta (WhatsApp Cloud API live; more Meta channels coming soon), OpenRouter and underlying model providers, Stripe (AED), at least one connected CRM as your main lead store — Zoho CRM when you connect (other CRMs coming soon), your configured SMTP provider, and Better Auth (self-hosted sessions). Each processes data under its own terms. Message content handled by Meta or OpenRouter is subject to their retention and processing rules even though Kylo does not keep a permanent chat transcript product.
Before a new subprocessor is brought into live use in a way that processes Client or End User personal data, Kylo will provide at least thirty (30) days’ prior written notice where required by contract or DPA.
8. Retention
- Account profile & auth — while active; deleted or anonymized after closure subject to legal holds
- Billing / credit ledger / usage — as needed for accounting, disputes, and fraud prevention
- Ops message/conversation rows (IDs, timestamps, credits) — while useful for idempotency, support, and abuse prevention; not a content archive
- Encrypted channel/CRM tokens — until disconnect or account closure
- Auth email / OTP records — short-lived (minutes to hours)
- Server logs — rolling operational windows
- Mastra session memory — up to 24 hours, then pruned
9. Security
- Encryption of WhatsApp / integration tokens at rest (AES-256-GCM)
- TLS for data in transit to our application
- Access controls and account sessions
- Secrets in environment configuration (not in client bundles)
No method of transmission or storage is 100% secure. This Policy does not claim certifications (e.g. SOC 2) or end-to-end encryption of message content unless separately obtained and disclosed. In a breach affecting personal data, Kylo will notify the affected Client without undue delay.
10. AI-generated outputs and marketing
Clients are responsible for lawful submission of personal data for AI processing and for reviewing AI-generated outputs before relying on them. Where the Services send marketing or promotional messages, the Client is solely responsible for TDRA unsolicited-communications rules, Meta policies, and required consent.
11. Your rights & choices
Depending on applicable law (including UAE PDPL where it applies), you may have rights to access, correct, delete, or export certain account data; disconnect channel or CRM integrations (at least one CRM remains required as the main lead database while you use the Services for lead capture); and object to or restrict certain processing where the law allows. Contact support@kylo.ae from your account email. We may need to verify identity before acting.
End-user (contact) data on channels: Requests relating to End User data should generally go to the relevant Client as controller. Kylo does not keep a permanent transcript or leads archive; short-lived session memory (≤24 hours) may exist for reply quality and is then erased.
12. International transfers
Data is hosted primarily on Kylo’s VPS infrastructure (Hostinger or equivalent). Because subprocessors such as OpenRouter, Meta, Stripe, and Zoho operate infrastructure outside the UAE, personal data may be transferred internationally. Where required, we rely on appropriate safeguards permitted by law.
13. Children’s privacy
Kylo is a business service. It is not directed to children under 18. We do not knowingly collect personal data from children.
14. Changes to this Policy
We may update this Policy from time to time. The “Last updated” date will change when we do. Material changes may be notified in-product or by email. Continued use after the effective date constitutes acceptance where permitted by law.
15. Contact
Privacy and data requests: support@kylo.ae. Postal: Kylo, Office A, Innovation City Business Centre, RAK Bank ROC Office, Ground Floor, Al Rifaa, Sheikh Mohammed Bin Zayed Road, Ras Al Khaimah, United Arab Emirates. Related: Terms and Conditions · Cookies.
