Privacy Policy
Last updated 27 August 2026
The short version
Kryptonote stores the information needed to run your account and workspace. This includes your account details, the content you add, your conversations, and basic information about how the product is working.
We use that information to provide Kryptonote, process the requests you make, keep the service secure, and improve the product. We do not sell your personal information. We share it only as described below, including with providers that help us complete your requests.
What we collect
- Account details, such as your name, email address, user ID, and session information
- Your work, including files, workspaces, conversations, prompts, responses, and generated material
- Product activity, such as features used, model choices, uploads, messages, errors, and performance information
- Billing details, such as your plan and subscription status
- Messages to us, including support, privacy, and security requests
What we use it for
We use information to:
- Run your account, workspaces, files, and conversations
- Complete AI and agent tasks you ask Kryptonote to perform
- Manage plans, subscriptions, and usage limits
- Find errors, prevent abuse, and keep Kryptonote reliable
- Understand which parts of the product are useful
- Respond to you and meet our legal obligations
When you use AI
An AI request may include your prompt, relevant conversation history, selected files, tool results, and other workspace context needed to answer you.
Requests are sent through OpenRouter or directly to the model provider you choose in Kryptonote. Available providers can include OpenAI, xAI, Moonshot AI, and MiniMax. Their handling can differ, so avoid submitting information that an AI provider should not process.
Kryptonote operates OpenRouter with Zero Data Retention (ZDR) enabled. This restricts our requests to endpoints that do not retain prompt or response content after processing. Those endpoints do not train models on that content. OpenRouter may retain request metadata such as the model used, token counts, and latency. You can read its ZDR documentation.
We do not train AI models on your data. Your prompts, files, conversations, responses, and other workspace content are not used by Kryptonote to train general-purpose AI models.
Connected services
Kryptonote may offer optional connections to external services. Before connecting one, we will show what information it can access and how agents can use it.
Connection credentials are not exposed to the agent's virtual machine, your browser, or the AI model. Relevant service content and tool results may be sent to your selected model provider to complete a task, subject to the AI handling described above.
Provider-specific disclosures and controls will appear when a connection is available. You can disconnect a service to remove its stored credentials. Content already saved to a conversation or workspace remains under your control until you delete it.
Gmail and Google user data
When you connect Gmail, Composio runs the Google authorization flow and stores the OAuth credentials needed to access your account. Kryptonote stores the Composio connection identifier and your Gmail display address, not your Google password or OAuth tokens. Read Composio's Privacy Policy.
Kryptonote currently exposes three Gmail actions: searching email, reading a thread, and saving an attachment to your workspace. Workspace and conversation permissions control which actions an agent can use. We and Composio use Google user data only to provide these connected Gmail functions. We do not sell Gmail data or use it for advertising.
Gmail content returned for a task may become part of the conversation or a file saved in your workspace. It may also be sent to your selected AI provider when needed to complete the task. The AI handling described above applies to that content.
Disconnecting Gmail deletes the connected account and its OAuth credentials from Composio. It does not delete content already saved in a Kryptonote conversation or workspace. You can delete that content using Kryptonote's deletion controls.
Kryptonote's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
Google Tasks
When you connect Google Tasks, Composio runs a separate Google authorization flow and stores the OAuth credentials. Kryptonote stores the Composio connection identifier, not your Google password or OAuth tokens.
Agents can view task lists and tasks, create or change tasks, and delete individual tasks. You control each group of actions in connection settings. Task content may be sent to your selected AI provider when needed to complete a request.
Google Calendar
When you connect Google Calendar, Composio stores the OAuth credentials. Kryptonote stores the connection identifier, not your Google password or OAuth tokens.
Agents can view calendars and events, create or change events, and delete individual events. You control each group of actions in connection settings. Calendar content may be sent to your selected AI provider when needed to complete a request.
Services that help us run Kryptonote
We share only the information each provider needs for its role:
- Clerk for accounts, authentication, and billing features
- Cloudflare for network services and file storage
- Composio for connected-service authorization and Google service access
- Vercel for serving the frontend application
- PostHog for EU-hosted product analytics and diagnostics
- OpenRouter and model providers for AI requests
We may also disclose information when required by law, to protect people or the service, or as part of a business reorganisation.
Cookies and browser storage
Kryptonote uses browser storage to keep you signed in, remember interface preferences, and measure product usage. Clearing it may sign you out or reset parts of the interface.
Keeping and deleting information
We keep account information and workspace content while your account is active or while it is needed to provide Kryptonote. Deleted information may remain temporarily where required for backups, security, billing, disputes, or legal obligations.
You can delete individual files, conversations, and workspaces from the product. For an account-level privacy request, contact us.
Your choices
Depending on where you live, you may have rights to access, correct, delete, restrict, or export your personal information, or object to certain uses of it.
Email privacy@kryptonote.com to make a request. We may need to verify your identity first.
Other details
International processing
Our providers may process information in other countries. Where required, recognised safeguards are used for international transfers.
Children
Kryptonote is not directed to children under 13. Contact us if you believe a child has provided personal information without appropriate permission.
Changes to this policy
We may update this page as Kryptonote changes. The latest revision date will always appear at the top.
Contact
Kryptonote Labs is responsible for the information described here. For questions or privacy requests, email privacy@kryptonote.com.