Privacy overview

This public overview explains the main data categories handled by Kavros. Customer-specific terms and deployment configuration are established during onboarding.

Public website

The public website may collect basic request metadata through GoatCounter analytics, such as page path, referrer, screen size, and browser bot indicators. Contact requests may include the information you choose to send to Kavros.

Self-hosted deployments

In a self-hosted deployment, the control plane, database, data plane, and enclave run in the customer AWS account. The customer controls the associated data, provider configuration, retention settings, backups, access roles, and network boundaries.

Employee Chat

Chat messages and metadata are stored in the customer control-plane database to provide chat history and usage attribution. Organization administrators can configure unlimited retention or a supported inactivity window of 7, 30, 90, 365, or 730 days. Expired chats and their messages are deleted server-side. Usage records remain for metering and audit purposes.

Model providers

When a customer configures Anthropic, OpenAI, or another supported provider, requests may be sent to that provider according to the customer’s configuration. Customers are responsible for reviewing provider terms, data-use settings, residency, and retention before enabling a model.

Contact

For privacy questions or a customer data request, contact privacy@kavros.ai. For security vulnerabilities, contact security@kavros.ai.

Last updated: August 22, 2026. This page is an overview and should be supplemented by customer-specific contractual terms before production use.