Privacy Policy

Last updated: June 28, 2026

This Privacy Policy explains how Kiro ("Kiro," "we," "us," or "our") collects, uses, stores, and shares information when you use our task management and AI-assisted scheduling application (the "Service").

If you do not agree with this policy, please do not use the Service.


1. Information We Collect

1.1 Account Information

We use Clerk as our authentication provider. When you sign up, Clerk collects and processes information such as your name, email address, and authentication credentials (or third-party sign-in details if you use Google/GitHub/etc. login). Clerk's own privacy practices are described at their privacy policy, which we encourage you to review: https://clerk.com/legal/privacy.

1.2 Task and Productivity Data

We store the content you create in Kiro, including but not limited to: tasks, projects, deadlines, schedules, habit data, day logs, and related metadata. This data is retained long-term in our database so the Service can function (e.g., scheduling, neglect scoring, dependency tracking).

1.3 Conversation Data

Kiro includes an AI assistant ("Yuki") and related agents. When you interact with these agents, we store your messages and the assistant's responses as conversation history, so the Service can maintain context across sessions. This data is also retained long-term.

1.4 Cookies

We use cookies set by Clerk to maintain your login session. We do not currently use cookies for advertising, marketing, or analytics purposes, and we do not currently use any third-party analytics or tracking tools.


2. How We Use Your Information

We use the information described above to:

  • Provide, operate, and maintain the Service (scheduling, task tracking, AI chat features)
  • Authenticate you and keep your account secure
  • Generate AI responses and recommendations based on your tasks and conversation history
  • Improve and debug the Service

We do not sell your personal information, and we do not use your data for third-party advertising.


3. Sharing Your Information

We share information with the following categories of third parties, only as necessary to operate the Service:

  • Authentication provider (Clerk): processes your account/login information.
  • AI service providers (Groq, Google Gemini): we use these providers for different, specific purposes, and what is sent to each differs accordingly:
    • Groq is primarily used for intent classification— determining what kind of request you're making so Kiro can route it correctly. This typically involves sending the text of your message. In some cases, fulfilling a request involves a tool call that may include relevant user data (such as task or project details) necessary to complete that specific action.
    • Google Gemini is used for chat summarization and has access to your conversation/chat history in order to generate summaries and maintain context across your sessions with Kiro's AI agents.

    Data sent to either provider is limited to what is necessary for that specific feature to function. These providers process this data under their own privacy and data-handling terms; we encourage you to review their policies directly if you'd like more detail (Groq, Google's privacy policy).

  • Hosting (Vercel):the Service's application/frontend is hosted on Vercel. Vercel may serve and process requests through infrastructure located in various regions as part of its normal operation. Vercel acts as our infrastructure provider — we remain responsible for how your data is handled within the Service, including the data that passes through Vercel's hosting layer.
  • Database (Turso): your task, schedule, and conversation data is stored in our database, hosted via Turso, with our primary database location in Delhi, India.

We do not otherwise share, rent, or sell your personal data to third parties.


4. Data Retention

We currently retain account, task, and conversation data for as long as your account is active, so that Kiro's features (history, scoring, scheduling context) continue to work as intended. We are working on building self-service data export and deletion tools. Until those are available, you can request deletion as described in Section 6 below.


5. Data Security

We take reasonable steps to protect your information, including relying on Clerk's security practices for authentication and standard hosting-provider security for our database and servers. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.


6. Your Rights and Choices

Depending on where you live, you may have rights under applicable law (such as the EU/UK GDPR, California's CCPA, or India's Digital Personal Data Protection Act) to:

  • Request a copy of the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and associated data
  • Object to or restrict certain processing of your data

To make any of these requests, please contact us at pstanwar6747@gmail.com. Because Kiro does not yet have a fully automated self-service deletion flow, deletion requests are currently handled manually. We will confirm and act on verified requests within a reasonable timeframe.

You can also delete your underlying authentication record directly through Clerk's account settings, where available; note that this does not automatically delete the task and conversation data stored in Kiro's own database — please contact us to ensure that data is removed as well.


7. Children's Privacy

The Service is not directed to children under 13 (or the relevant age of consent in your jurisdiction), and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can remove it.


8. International Users

Kiro is available globally. Our primary database is located in Delhi, India, and your task, schedule, and conversation data is stored there. Our application is hosted via Vercel, which may process requests through infrastructure in various regions as part of normal operation, and the AI providers we use (Groq, Google Gemini) may process data in their own respective locations. By using the Service, you understand that your information may be transferred to and processed in countries other than your own, which may have different data protection laws than your country of residence.


9. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above and, where appropriate, notify you through the Service.


10. Contact Us

If you have questions about this Privacy Policy or wish to exercise any of the rights described above, contact us at:

pstanwar6747@gmail.com