KybernAI

Legal

Privacy Policy

This policy explains how KybernAI handles personal data across accounts, workspaces, support, analytics, integrations, AI-assisted product features, and workspace-configured storage flows.

Last updated

September 10, 2026

This page is designed to give users a clear overview of how personal data and customer content may be processed and stored where reasonably necessary when using KybernAI.

1. Scope of this policy

This Privacy Policy explains how KybernAI collects, uses, stores, and shares personal data when you use kybern.ai, the KybernAI platform, related applications, APIs, and support services.

This policy is intended to provide a general explanation of KybernAI's data handling practices. Additional contractual terms, data processing agreements, or product-specific notices may apply depending on how your organization uses the service.

2. Personal data we collect

KybernAI may collect personal data directly from you, from your organization, from usage of the service, and from third-party integrations you choose to connect.

Depending on how the platform is used, the categories of data may include account details, profile information, contact details, workspace membership information, authentication data, billing details, communications, uploaded files, prompts, generated outputs, support requests, device information, usage logs, analytics events, integration metadata, file metadata, and service records associated with the features enabled for the relevant workspace.

3. How we use personal data

KybernAI uses personal data to provide, secure, maintain, and improve the service; authenticate users; manage accounts and subscriptions; respond to support requests; operate AI-assisted features; monitor reliability and performance; prevent abuse; comply with legal obligations; and communicate service-related information.

Where permitted by law, KybernAI may also use limited service and usage information to develop, troubleshoot, and enhance platform functionality, security, and user experience.

4. Customer content and AI processing

KybernAI processes customer-submitted data, files, messages, prompts, and documents in order to provide the requested platform functionality. This may include transmission, indexing, transformation, summarization, classification, generation of outputs through AI-assisted tools, and the creation or maintenance of service records associated with those activities.

Depending on workspace configuration, customer-uploaded business files and assets may be stored in AWS S3 or comparable object storage configured for the relevant customer or company workspace. KybernAI may also store related metadata and service records reasonably necessary to index, secure, retrieve, display, administer, support, and manage those files and the associated services.

Where applicable features are enabled, those records may include file indexes, message content, support records, HR conversation archives, AI call records, notifications, and audit events. Not all features are enabled in every workspace. You and your organization remain responsible for determining whether the data you submit to KybernAI is appropriate for processing and whether additional notices, consents, contracts, or legal safeguards are required for your specific use case.

5. Google Calendar data

KybernAI accesses Google Calendar data only when a user actively connects their Google account and grants permission through Google's OAuth consent flow. The Google Calendar integration uses the https://www.googleapis.com/auth/calendar scope so that KybernAI can show calendars and events selected by that user and, when requested by the user, create, update, or delete events in calendars for which that Google account has the necessary permission.

The raw Google user data accessed by the integration may include the connected Google account email address; calendar identifiers, names, colors, visibility, and access permissions; and event titles, start and end dates or times, all-day status, and the calendar to which an event belongs. KybernAI reads provider event information live for the date range being displayed and does not create a permanent copy of Google Calendar event content in its database.

KybernAI stores only the connection records needed to operate the integration: the connected account email address, provider connection metadata, the user's selected calendar visibility and color preferences, and an encrypted Google refresh token. KybernAI does not use raw or aggregated/anonymized Google Calendar data to train generalized AI or machine-learning models, for advertising, profiling, or sale.

Google Calendar data is used solely to provide the Calendar functionality requested by the connected user: listing available calendars, displaying selected events, allowing the user to choose visible calendars and colors, and completing user-requested event actions. KybernAI does not share Google Calendar data with unrelated third parties. Where infrastructure or database subprocessors process the connection records, they do so only to host, secure, and operate KybernAI on its behalf.

Google refresh tokens are encrypted at rest using AES-256-GCM and are not returned to browsers after storage. Access to connection records is restricted to the connection owner through application authorization and database row-level security. A user can disconnect a Google account from Calendar Settings at any time; this deletes the live connection record, encrypted refresh token, and related saved calendar preferences. Google event content is not retained by KybernAI after the live provider request completes, subject only to transient technical processing and standard security logging.

6. Legal bases for processing

Where applicable data protection law requires a legal basis, KybernAI generally relies on one or more of the following: performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, and consent where consent is specifically required.

If KybernAI relies on consent for a particular processing activity, you may withdraw that consent subject to applicable law.

7. Sharing of personal data

KybernAI may share personal data with subprocessors, infrastructure providers, analytics providers, customer support tools, communication providers, payment providers, and other service providers that help operate the platform.

This may include cloud and object storage providers, database providers, email or messaging providers, AI providers, telephony providers, and other technical vendors needed to provide the specific services enabled in your workspace.

KybernAI may also share data when required by law, to enforce rights, to protect users or the public, in connection with a corporate transaction, or where you or your organization instructs KybernAI to connect with a third-party integration or customer-controlled storage destination.

8. International data transfers

KybernAI may process or store personal data in countries other than the country where the data was collected. When cross-border transfers occur, KybernAI aims to use appropriate safeguards required by applicable law, which may include contractual protections or equivalent transfer mechanisms.

9. Data retention

KybernAI retains personal data for as long as needed to provide the service, comply with contractual and legal obligations, resolve disputes, enforce agreements, and maintain appropriate security and backup practices.

Retention periods may vary depending on account status, the type of data involved, customer instructions, configured storage destinations, enabled features, technical requirements, and legal obligations. Where customer files or assets are stored in customer-configured AWS S3 or comparable object storage, retention may also depend on that storage configuration, lifecycle policies, and deletion practices.

10. Security

KybernAI uses technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, and disclosure. However, no service can guarantee absolute security, and you should also take appropriate steps to secure your own accounts, devices, and internal access controls.

11. Your rights and choices

Depending on your location and applicable law, you may have rights to request access to personal data, correction of inaccurate data, deletion, restriction of processing, portability, objection to certain processing, or withdrawal of consent.

If your personal data is controlled by an organization that uses KybernAI, you may need to contact that organization first. KybernAI may require reasonable verification before fulfilling direct privacy requests.

12. Cookies and similar technologies

KybernAI may use cookies, local storage, session identifiers, and similar technologies to keep users signed in, remember preferences, maintain security, analyze performance, and improve usability.

You can manage certain browser-based storage controls through your browser settings, though disabling some technologies may affect functionality.

13. Children's data

KybernAI is intended for business and organizational use and is not directed to children. If KybernAI becomes aware that personal data has been collected from a child in violation of applicable law, KybernAI will take reasonable steps to delete that information.

14. Changes to this policy

KybernAI may update this Privacy Policy from time to time to reflect legal, technical, or product developments. When changes are material, KybernAI will post the updated version on this page and may provide additional notice through the service or by other reasonable means.

15. Contact

If you have questions about this Privacy Policy or would like to submit a privacy-related request, please contact the KybernAI team through the support channel available in your workspace or through the contact options published on kybern.ai.

© 2026 DIGILOGIX LIMITED. All rights reserved. KybernAI ™ – Simply Centralised is a trademark of DIGILOGIX LIMITED, pending registration with the Intellectual Property Office of Ireland (IPOI) under Class 42 (SaaS). All original software code, interface designs, and text content are protected under copyright law. Brand assets and graphical icons may contain third-party licensed materials used under attribution compliance.