Effective Date: October 3, 2026
Your privacy is fundamental to what Kairos stands for. You own your story. This policy explains exactly what data we collect, how we use it, and how we protect it.
This Privacy Policy applies to all users of kairosloom.life and any related services operated by Kairos (“we,” “us,” or “our”).
Contact: privacy@kairosloom.life or hello@kairosloom.life, or by phone at (970) 287-6907.
We do not sell your personal data, and we do not share it with advertisers or any third party for their own purposes — ever.
We may use your data to operate, secure, and improve Kairos. This includes analyzing how Kairos is used — the types of documents people upload, feature usage, and behavioral patterns — to make the product better. We do not mine the contents of your private documents for any purpose beyond building your own Weeks-in-Life, and any improvement work stays within Kairos and is never sold or shared.
Your uploaded documents are processed by an AI model to extract life events and build your Weeks-in-Life. We currently use Google Gemini (via Google’s AI infrastructure) as our processing engine, with Anthropic’s Claude as our production target. The model provider may change as the product evolves; this section will be updated to reflect the current processor.
If you connect your Google Drive, Kairos requests only the drive.file scope. This means Kairos can access only the files and folders it creates in your Drive — never your other files. Your files stay in your Google Drive; we do not copy your wider Drive into Kairos or browse files we did not create.
If you add photos from Google Photos, Kairos requests only the photospicker.mediaitems.readonly scope. You choose photos in Google’s own picker, and Kairos receives only the photos you select — never the rest of your library. Each selected photo is copied, resized, into your private Kairos storage and filed under the week it was taken, using the date Google provides. Kairos does not store your Google Photos access afterwards, and you can remove a copied photo at any time.
Kairos’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data accessed through the Google Drive and Google Photos APIs is used solely to provide and improve the connector feature you asked for, and is never sold, never shared, and never used to train generalized AI models.
All data is stored in Google Cloud infrastructure (us-central1 region). Google Cloud is SOC 2 certified and implements industry-standard security controls.
We do not sell your data. We do not share your data with advertisers. We share data only with the following service providers, solely to operate the Service: Google (Gemini/Cloud/Identity), Stripe (payments), Twilio (phone verification), and FingerprintJS (fraud prevention). Each operates under its own privacy and data terms.
Your Loom is unlisted by default — like a private video. It is not publicly searchable, not indexed by search engines, and not visible to other users. You control sharing: you may generate a shareable link at any time and revoke it at any time. We are not responsible for content you choose to share.
You may upload sensitive personal documents. We treat all uploaded content with the same security standard — encrypted at rest and in transit, accessible only to you via authenticated signed URLs.
HIPAA: Kairos is not a covered entity under HIPAA for Year 1 tiers. Do not upload documents requiring HIPAA-compliant storage unless you are on the Medical/Clinical tier (Year 2) with an executed BAA.
You have the right to:
To exercise any of these rights, contact us at the addresses in Section 1.
California residents (CCPA/CPRA) have the rights to Know, Delete, Correct, Opt Out of Sale or Sharing (we do neither), Limit Use of Sensitive Personal Information, and Non-Discrimination.
European users (GDPR — EEA/UK/Switzerland) have the additional rights to object to processing, restrict processing, and lodge a complaint with a supervisory authority. Our lawful bases are contract performance (account, payments), consent (AI processing of your uploads), and legitimate interests (fraud prevention, product improvement). Data is processed in the United States under Standard Contractual Clauses or equivalent mechanisms. We respond to requests within 30 days.
Kairos is not intended for users under 18. We do not knowingly collect data from minors. If we discover a minor has created an account, we will delete it immediately.
We use minimal cookies — only what is necessary to operate the Service (session authentication). We do not use third-party advertising cookies or tracking pixels.
We implement industry-standard security: encryption at rest and in transit, OAuth 2.0 authentication (no passwords stored), document fingerprinting (SHA-256), IP rate limiting, device fingerprinting, and phone verification. No system is 100% secure; in the event of a data breach affecting your personal information, we will notify you as required by applicable law.
We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notice. The effective date above reflects the most recent update.
Privacy questions or requests: privacy@kairosloom.life or hello@kairosloom.life, or by phone at (970) 287-6907.