Kyvvo

Privacy Policy

Last updated: February 6, 2025

1. Introduction

Welcome to Kyvvo ("Company," "we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our feedback management platform and related services (collectively, the "Service").

By accessing or using Kyvvo, you agree to the terms of this Privacy Policy. If you do not agree with the practices described in this policy, please do not use our Service.

2. Information We Collect

2.1 Information You Provide

  • Account Information: When you create an account, we collect your name, email address, and password. If you sign up using Google OAuth, we receive your name, email, and profile picture from Google.
  • Profile Information: You may provide additional information such as your job title, company name, and profile photo.
  • Workspace Information: When you create or join a workspace, we collect the workspace name, settings, and member information.
  • Feedback Data: We collect the feedback content you submit, including text, categories, tags, and any associated metadata.
  • Payment Information: If you subscribe to a paid plan, our payment processor (Stripe) collects your payment card details. We do not store complete credit card numbers on our servers.
  • Communications: When you contact us for support or other inquiries, we collect the content of your messages.

2.2 Information Collected Automatically

  • Usage Data: We collect information about how you interact with our Service, including pages visited, features used, and actions taken.
  • Device Information: We collect information about the device you use to access our Service, including device type, operating system, browser type, and screen resolution.
  • Log Data: Our servers automatically record information including your IP address, access times, and referring URLs.
  • Cookies and Similar Technologies: We use cookies and similar tracking technologies to collect information about your browsing activities. See Section 7 for more details.

2.3 Information from Third Parties

  • OAuth Providers: If you authenticate using Google or other OAuth providers, we receive basic profile information as authorized by you.
  • Integration Partners: If you connect third-party services to Kyvvo, we may receive data from those services as configured by you.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Provide and Maintain the Service: To operate, maintain, and improve our feedback management platform.
  • Account Management: To create and manage your account, authenticate users, and provide customer support.
  • AI-Powered Features: To provide AI-powered feedback analysis, categorization, and insights using third-party AI service providers.
  • Communications: To send you service-related communications, including account notifications, security alerts, and workspace invitations.
  • Analytics: To understand how users interact with our Service and to improve user experience.
  • Security: To detect, prevent, and respond to fraud, abuse, security risks, and technical issues.
  • Legal Compliance: To comply with legal obligations and enforce our terms of service.
  • Marketing: With your consent, to send promotional communications about new features and services. You can opt out at any time.

4. How We Share Your Information

We may share your information in the following circumstances:

  • Within Your Workspace: Information you submit may be visible to other members of your workspace based on role permissions.
  • Service Providers: We share information with third-party vendors who perform services on our behalf, including:
    • Supabase (database and authentication)
    • Vercel (hosting and deployment)
    • Stripe (payment processing)
    • Brevo (email communications)
    • OpenAI (AI-powered analysis - see Section 9 for details)
  • Legal Requirements: We may disclose information if required by law, legal process, or government request.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
  • With Your Consent: We may share information with third parties when you give us explicit consent to do so.

We do not sell your personal information to third parties.

5. Data Retention

We retain your personal information for as long as necessary to provide our Service and fulfill the purposes described in this Privacy Policy. Specifically:

  • Account Data: Retained while your account is active and for a reasonable period afterward for legal and business purposes.
  • Feedback Data: Retained according to your workspace settings and applicable data retention policies.
  • Usage Data: Generally retained for up to 24 months for analytics purposes.
  • Backup Data: May be retained in backups for up to 90 days after deletion from active systems.

You may request deletion of your data at any time by contacting us at hello@kyvvo.com.

6. Data Security

We implement appropriate technical and organizational measures to protect your personal information, including:

  • Encryption of data in transit using TLS/SSL
  • Encryption of sensitive data at rest
  • Regular security assessments and penetration testing
  • Access controls and authentication mechanisms
  • Employee security training and confidentiality agreements
  • Incident response procedures

While we strive to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

7. Cookies and Tracking Technologies

We use the following types of cookies:

  • Essential Cookies: Required for the Service to function properly, including authentication and security.
  • Functional Cookies: Remember your preferences and settings to enhance your experience.
  • Analytics Cookies: Help us understand how users interact with our Service to improve performance.

You can control cookies through your browser settings. However, disabling certain cookies may limit your ability to use some features of our Service.

8. Your Rights and Choices

Depending on your location, you may have the following rights:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request correction of inaccurate or incomplete information.
  • Deletion: Request deletion of your personal information, subject to certain exceptions.
  • Portability: Request a copy of your data in a portable format.
  • Objection: Object to certain processing of your personal information.
  • Restriction: Request restriction of processing in certain circumstances.
  • Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.

To exercise these rights, contact us at hello@kyvvo.com. We will respond to your request within 30 days.

9. AI-Powered Features and Third-Party Processing

We use third-party AI service providers (such as OpenAI) to power certain features of our Service, including feedback categorization, sentiment analysis, urgency detection, and the AI assistant. This section explains how your data is processed by these providers.

9.1 What Data is Sent to AI Providers

When you use AI-powered features, the following data may be sent to our AI service providers:

  • Feedback content you submit for analysis
  • Questions or prompts you enter in the AI assistant
  • Contextual information needed to provide accurate responses (such as category labels or product modules)

We do not send personal account information (such as your name, email, or password) to AI providers unless it is contained within the feedback content you submit.

9.2 How AI Providers Process Your Data

Our AI service providers process your data to:

  • Categorize feedback (Bug, Feature Request, UX Improvement, etc.)
  • Analyze sentiment and determine urgency levels
  • Generate tags and identify relevant product areas
  • Respond to queries in the AI assistant

9.3 Data Retention by AI Providers

We use OpenAI's API services with data retention settings configured to minimize storage. Per OpenAI's current data usage policies for API customers:

  • Data sent through the API is not used to train OpenAI's models
  • API data may be retained for up to 30 days for abuse and misuse monitoring, after which it is deleted
  • We have opted out of any data sharing for model training purposes

For the most current information about OpenAI's data practices, please refer to OpenAI's Privacy Policy.

9.4 Processing Location

AI processing is performed on OpenAI's infrastructure, which is primarily located in the United States. By using our AI-powered features, you consent to the transfer and processing of your data in the United States.

9.5 Opting Out

You can choose not to use AI-powered features. Manual feedback entry without AI analysis is available, and you can disable auto-triage in workspace settings. However, certain features like the AI assistant and automatic categorization require AI processing to function.

10. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. When we transfer data internationally, we implement appropriate safeguards to protect your information, including standard contractual clauses approved by relevant authorities.

11. Children's Privacy

Our Service is not intended for children under the age of 16. We do not knowingly collect personal information from children under 16. If you believe we have collected information from a child under 16, please contact us immediately at hello@kyvvo.com, and we will take steps to delete such information.

12. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information is collected, used, shared, or sold
  • Right to delete personal information held by businesses
  • Right to opt-out of sale of personal information (we do not sell personal information)
  • Right to non-discrimination for exercising CCPA rights

To exercise your CCPA rights, contact us at hello@kyvvo.com.

13. European Privacy Rights (GDPR)

If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR) as described in this section. Our legal bases for processing your information include:

  • Contract: Processing necessary to perform our contract with you
  • Legitimate Interests: Processing for our legitimate business interests
  • Consent: Processing based on your explicit consent
  • Legal Obligation: Processing necessary to comply with legal requirements

You have the right to lodge a complaint with your local data protection authority.

14. Third-Party Links

Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party services you access.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We may also notify you via email for significant changes. Your continued use of the Service after any changes constitutes acceptance of the updated Privacy Policy.

16. Contact Us

If you have any questions about this Privacy Policy or our privacy practices, please contact us at:

Kyvvo
Email: hello@kyvvo.com
Website: https://kyvvo.com