Privacy policy
Last updated: 2 October 2026
What Kaiku collects, why, who else receives it, how long it is kept and how to have it deleted. It describes what the service actually does; when that changes, this page changes with it.
Who is responsible
Kaiku is operated by PE Stanislav Vorobev, which decides what personal data the service processes and is responsible for it. This policy covers the kaiku.tech website, every workspace on a kaiku.tech address, and the Kaiku apps for iOS and Android.
Inside a workspace, the company that owns it decides who is invited and what is written there. For that content we act on the company’s behalf: it is theirs, and we hold it to run the service for them.
Write to hello@kaiku.tech with any question or request about your data.
What we collect
Your account: email address, display name, and how you sign in — a password (stored only as a hash), a Google or Apple account identifier, or a passkey. A two-step verification secret is stored encrypted, and API tokens only as a hash.
What you put into a workspace: projects, issues, comments, wiki pages, attachments and anything else you or your colleagues write or upload. Your name appears on what you write. Colleagues in the same workspace can see whether you are online right now and when you were last active.
Sign-in records: when you signed in, how, from which IP address, and a device description such as “Chrome · macOS”. They let us warn you about a sign-in from a device you have not used before, and let you see where your account is signed in.
Signing up: the email address and the IP address the request came from and, if you arrived from this website, the button you pressed, the campaign tags in the link and the site that sent you — and, if you followed a partner’s link, that partner’s code. The partner is told only totals: how many companies came through the link, how many pay and what was credited, never who.
Signing up through an AI agent: you can also sign up by asking an AI agent connected to our MCP server. The agent sends us what you tell it for this — your email address, your name, the name and address of your company and your language — and the name of the program it runs in, such as “claude-code”, which we record as where the account came from. Your agreement to the terms of service and this policy is recorded with its time and a note that the agent passed it on; the agent is asked to show you both documents and to ask you first. The account is created only after you read the code from our email to the agent.
Payments: the invoices issued to a workspace, their amounts and what was received. Crypto payments are made on the payment provider’s page; we never see or hold wallet keys.
Service records: server logs (the request, its result and the account id — no IP address, no email address) and error reports, from which email addresses, IP addresses, cookies and request bodies are removed before they are stored.
Visits to this website: pages opened, the referring site or campaign, country and device type. They are counted by Vercel Web Analytics without cookies, without identifying anybody and only as totals.
The mobile apps
The apps open the same workspaces as the website, so everything above applies to them. In addition they keep:
A push token, on iPhone and iPad, if you allow notifications — it is how Apple delivers them to your device — with the device type (“iPhone” or “iPad”). The Android app does not receive push notifications yet.
A random identifier created on the device and sent with requests, so that your own devices are recognised and a sign-in from a new one can be flagged. It is not derived from anything about you or your device.
An error report when the app itself fails, sent to our own server the way the website sends its own: the error and where in the code it happened, the screen it was on, the workspace address, your account’s numeric id, and the versions of the app and of the operating system. It is cleaned and kept like the error reports above, for 30 days, and nobody outside Kaiku receives it.
The apps contain no advertising and no third-party analytics, tracking or crash-reporting code. They do not access your location, contacts, camera, microphone or photo library; a file is uploaded only when you pick it yourself.
AI features
Some features send text to a language model provider, DeepSeek or Anthropic: translating an issue or a comment, the assistant, turning a question into a search, agents you call or hand work to, and replies suggested in the support desk. What is sent is the text the feature works on, when it works on it.
One of them runs without a click. So that search finds an issue written in another language, the title and description of new and changed issues are sent to a model in the background, which writes a short English summary for the search index.
Voice input on the website sends the recording to OpenAI for speech recognition and gets the text back; we do not keep the audio.
Search by meaning is computed on our own servers, and nothing is sent out for it.
If a company connects its own AI provider key, its text goes to that provider under the company’s own agreement with it.
We do not use your content to train models, and we do not sell personal data.
Who else receives data
We use the following services to run Kaiku. Each receives only what its job needs.
Hetzner (Germany and Finland): the servers that run the service, the database and its backups.
Cloudflare: storage of attachments and export archives, and the DNS of our domain.
Postmark: sending email — confirmations, notifications, billing reminders, and tips for a new workspace’s owner, each with its own unsubscribe link — and receiving mail sent to the support address.
Our crypto payment provider: the invoice amount and a reference to the workspace.
DeepSeek and Anthropic (language models) and OpenAI (speech recognition), as described above.
Apple: push notifications to iPhone and iPad, and Sign in with Apple. Google: Sign in with Google. Browsers’ own push services deliver notifications on the website, encrypted so that only your browser can read them.
Vercel: hosting of this website and its visit counts.
Integrations a workspace connects — GitLab, GitHub, a Jira import, an MCP connection — exchange data with those services under the workspace’s own account there.
Some of these companies are outside the European Union: Anthropic, OpenAI, Postmark, Cloudflare and Vercel are in the United States, DeepSeek is in China. What is sent to them is processed there.
How long we keep it
Workspace content: as long as the workspace exists. A workspace whose subscription has lapsed is kept read-only for 12 months and then deleted, together with its attachments and export archives.
Your account and its sign-in records: until the account is deleted.
Server logs and error reports: 30 days.
Database backups: up to 6 months — daily copies for two weeks, weekly for two months, monthly for six. A deleted record leaves the backups when the last copy that holds it expires.
Invoices and payment records: as long as accounting rules require, including after a workspace is deleted.
Online status: only the moment you were last active, overwritten each time — there is no history of it.
Your rights
On the website, Settings → Account & sign-in → “Download my data” gives you everything we hold about you as one file. The same tab changes your password and your ways of signing in; to correct your name or email address, write to us.
Any project can be exported as a zip with structured JSON, readable Markdown and every attachment — also while a workspace is read-only.
You may ask us for access to your personal data, to correct or delete it, to restrict or object to its processing, or for a copy to take elsewhere. Write to hello@kaiku.tech; we answer within 30 days. You may also complain to a data protection authority.
Deleting your account
Yourself, at once: on the website or in the Kaiku Tasks app for iOS or Android, open Settings → Account & sign-in → “Delete my account…”, and type your email address to confirm. The account is deleted there and then.
Without the app, or if you cannot sign in: write to hello@kaiku.tech from the email address of the account with the subject “Delete my account”. We confirm the request and delete the account within 30 days.
What is deleted: your ways of signing in, tokens, sessions, devices and push tokens, notifications and subscriptions, workspace memberships and sign-in records. Your name and email address are removed from the account, and your email address and mentions of you are replaced in the texts of the workspaces you worked in.
What stays: issues, comments, pages and files you wrote in a workspace belong to the company that owns it. They remain there, shown as written by “Former user”. A name typed as a plain word inside a text is not found and replaced.
If you own a workspace, hand it over or ask us to delete the workspace first: a company is not left without an owner. A workspace owner can ask us to delete the whole workspace at any time.
Backups that hold the account expire within 6 months.
Children
Kaiku is a tool for work and is not meant for children. Do not use it if you are under 16.
Changes
When this policy changes, the date at the top changes. If a change affects what we collect or who receives it, we tell workspace owners by email before it takes effect.