- We don't train models on your memories.
- Your data lives in Singapore or US-East — your pick.
- Export everything as JSON at any time.
- Delete everything in one click. 30-day soft-delete window first.
- Sub-processors: Lemon Squeezy (billing), Resend (email), Clerk (auth). Full list below.
What we collect
The minimum needed to operate Kireo. Specifically: your email (to sign in), your memories (the whole reason you're here), API keys (hashed), and basic billing data (handled by Lemon Squeezy, our merchant of record, never stored on our servers).
We do not collect: IP-based location, browser fingerprints, third-party tracking IDs, or any inferred attributes about who you are.
Why we collect it
Only what's required to authenticate you, store and recall your memories, and bill your plan. No analytics profiling, no ad targeting, no data brokering. If a piece of data isn't needed to run the service, we don't ask for it.
Where it lives
You choose your region at signup: Singapore (ap-southeast) or US-East. Your memory content and its embeddings stay on our own infrastructure (Hetzner compute); account metadata lives in Neon Postgres; encrypted off-site backups go to Cloudflare R2. Your memory text is never sent to a third-party AI or embedding provider.
We never train on memories
Period. Embeddings are computed on our own infrastructure at write time (we self-host the embedding model — your memory text is never sent to a third-party AI provider), used only for recall, and never fed into any training pipeline. If a future feature would require deviation from this, you'll receive an explicit opt-in prompt with 30 days notice.
Your rights
Export, delete, rectify, port, restrict. Full GDPR + CCPA-equivalent rights regardless of where you live. Email privacy@kireo.app — we respond within 72 hours.
Data export
Export everything as JSON at any time, from your dashboard or via the API. No lock-in: your memories are portable and stay yours.
Data deletion
Delete any single memory, or your whole account, in one click. Deletions enter a 30-day soft-delete window so you can recover from mistakes, after which the data is permanently purged from primary storage and rotated out of backups.
Sub-processors
The third parties that process data on our behalf, and what each sees:
- Clerk — authentication (your email + login identity).
- Lemon Squeezy — payments & merchant of record (billing data; we never store card details).
- Resend — transactional email delivery.
- Neon — Postgres for account metadata (never your memory content).
- Hetzner — compute/hosting for the API and the memory store.
- Cloudflare R2 — encrypted off-site backups.
Note: embeddings are generated on our own self-hosted model, so no third-party AI/embedding provider is a sub-processor. Your memory text stays on our infrastructure.
Analytics
We run a self-hosted Umami instance (stats.kireo.app) for basic, aggregate site analytics. It is cookieless, does not store IP addresses, and does not track you across sites. No analytics data is shared with any third party.
What we store & how to delete it
What we store: the memory text you explicitly save, its metadata (namespace, tags, timestamps), your account email, and hashed API keys.
What we never store: your source code — code-index keeps only derived embeddings and file paths — your prompts or conversations, or any data your MCP client does not explicitly send to the store/recall tools.
Export: a full export of all your memories is available as JSON, from your dashboard or via the export API. No lock-in — your memories stay yours.
Delete: delete any single memory, any namespace, or your entire account from the dashboard. Deletion is permanent after the 30-day soft-delete window.
Contact
Questions about privacy, or want to exercise any of the rights above? Email privacy@kireo.app and we'll respond within 72 hours.