Skip to content
Kimiko
FeaturesLocal & cloudPricingDocsSupport
Try for free Account
Back to Kimiko

Privacy policy

What stays on your computer, what information reaches us, and the choices you have along the way.

Last updated 4 October 2026

Privacy policyTerms of serviceCookie policy

On this page

  • Who we are
  • Your desktop data
  • Optional connections
  • Desktop health signals
  • Accounts & purchases
  • Support requests
  • Website analytics
  • Why we process data
  • Providers & transfers
  • How long we keep data
  • Your choices & rights
  • Children & policy changes
  • Contact

A question about these policies?
Get in touch

Local by default. Connected by choice.

Your meeting library lives on your computer. Cloud processing is optional. Website accounts, purchases, and support involve separate information, and website analytics starts only with your permission.

Who we are

Kimiko is owned and operated by Inovia AI Solutions LTD, incorporated in the Republic of Cyprus (“Inovia”, “we”, “us”). We are the controller of personal information we use to operate the website, customer accounts, licensing, and support described in this policy.

This policy covers the Kimiko desktop application, kimiko.app, and our documentation. For privacy requests, contact kimiko@inoviatech.io. The Privacy & data guide explains the app’s practical settings.

Your desktop data

Recordings you choose to retain, transcripts, notes, summaries, tasks, chat history, speaker labels, remembered voice signatures, and search data are stored locally. Kimiko uses an encrypted database and encrypted retained audio; the encryption keys are held by your operating system’s keychain.

Saving meeting audio and sharing health signals are off by default. Remembering a voice requires your explicit choice. A website account does not upload or sync your desktop meeting library to us.

You decide which conversations to record and how to use or share the results. You are responsible for the required recording permissions and lawful handling of other people’s information. Protect your device and backups. Exported files and copies you share have their own storage and access protections.

Trial expiry and subscription cancellation do not remove your existing content. Library mode keeps it available. Deletion, Trash retention, audio retention, and Wipe all data controls manage local copies; they do not remove exports, backups, or information already sent to another service.

Optional connections

Local processing does not mean the app never uses a network. The app’s Settings → Privacy inventory shows the destinations associated with your configuration.

  • Cloud transcription: audio is sent to the speech provider you select, using your account or API key.
  • Cloud AI: the prompt and relevant transcript or note context are sent to the provider you select for that task.
  • Calendars: connecting Google or Microsoft uses that provider’s authorization flow and calendar information, including relevant event and attendee details.
  • Shared spaces: configured collaboration relays receive end-to-end encrypted synchronization data. Meeting audio is not included in those sync frames.
  • Downloads and updates: model hosts and release servers receive the request, network address, and relevant file, version, or platform information.
  • Paid license checks: Keygen receives the license key, a random installation identifier, app version, and validation requests. The installation identifier is not a hardware serial number.

Third-party services you connect act under your own agreements with them. Their retention and use of submitted content depend on those agreements. Local-only mode blocks connections outside your computer, including cloud services, downloads, telemetry, and license verification. It permits supported local processing and loopback model servers; it does not extend subscription entitlement indefinitely.

Desktop health signals

If you enable “Share anonymous health signals”, the app sends a limited set of diagnostic events to PostHog EU Cloud. These include app version and operating system, coarse license and feature state, setup milestones, and scrubbed error information. You can inspect the event list in the app before enabling it.

These signals use a random identifier created when you opt in, separate from your license installation identifier. They exclude recordings, transcripts, notes, meeting titles, prompts, names, email addresses, API keys, and calendar content. Desktop location lookup is disabled.

Opting out stops new events and deletes the local telemetry identifier and queued events. Opting in again creates a new identifier. Local-only mode blocks telemetry even if it is enabled. This setting is separate from website cookie consent.

Website accounts & purchases

The desktop trial does not require an account. If you create a website account, WorkOS handles identity and authentication; Resend delivers our custom sign-in codes. We store your account identifier, verified email, sign-in and security records, purchase and license references, computer labels, and support ownership so you can manage these services.

Stripe handles checkout and billing as merchant of record for Managed Payments purchases. Stripe processes payment and billing details under its own privacy policy. We receive the customer, purchase, and subscription information needed to deliver and manage your license, including purchase email, payment status, and paid-through date. We do not receive or store your full card details.

Keygen manages license records and device activations. Resend delivers license-key emails. These services do not receive your meeting library through the purchase or activation flow. Private account and checkout pages do not load website analytics.

Support requests

When you contact us, we process your email address, message, optional technical details, purchase references, and attachments to investigate and reply. Please omit passwords, API keys, license keys, full card details, and private meeting content you do not need to share.

Support conversations are handled in a separate PostHog EU Cloud support project. Website requests pass through a delivery queue and private file storage on Railway. Cloudflare Turnstile processes browser and network signals to prevent automated abuse. Direct support email can pass through Cloudflare Email Routing.

Website attachment links expire after 30 days. Images have their metadata removed during upload. A shared download link may give its recipient access until expiry, so share it only with people who should see the file.

Support works independently of analytics consent. We do not send your message, identity, receipt details, attachments, or signed download links to the website analytics project or link them to desktop telemetry.

Website analytics

With your consent, we use PostHog EU Cloud to understand visits to the website and documentation: pages viewed, referrals and campaign tags, browser and device information, visit duration, scroll depth, and marked download and checkout clicks. Cookies recognize a returning browser across kimiko.app and docs.kimiko.app. We do not join this identity to your website account or desktop telemetry.

Your browser sends accepted analytics events to k.kimiko.app, an address on our domain that PostHog runs for us. PostHog estimates country, region, and city from your IP address, then discards the raw IP from stored analytics events. We do not request GPS or precise device location. There is no session replay, form-content capture, or automatic tracking of every click. Page and referrer query strings and fragments are removed; campaign tags are retained.

Optional analytics stays off until acceptance and stays off when your browser sends Do Not Track or Global Privacy Control. You can change your choice through Cookie settings. Withdrawal stops further collection and clears this project’s browser identifiers; it does not automatically erase events already sent. See our Cookie policy for storage details.

Why we process data

Where data-protection law requires a legal basis, we rely on:

  • Performance of a contract, or steps you request before a contract: providing accounts, delivering purchases, validating licenses, and handling service and billing requests.
  • Consent: optional website analytics and optional desktop health signals. You can withdraw consent without affecting the lawfulness of earlier processing.
  • Legitimate interests: securing the service, preventing abuse, responding to general enquiries, and investigating faults or legal claims, balanced against your rights.
  • Legal obligations: required financial, tax, regulatory, and consumer-rights records and responses.

Account and purchase information is needed to provide the corresponding service. Declining optional analytics or health signals does not prevent use of Kimiko. We do not sell personal information or use it for cross-context behavioral advertising.

Providers & international transfers

We use Railway for website hosting, account and support databases, and private attachments; WorkOS for identity; Stripe for payments; Keygen for licensing; Resend for transactional email; PostHog for the separate analytics, desktop diagnostics, and support services; and Cloudflare for security and support email routing. Download services also receive normal network requests when you download Kimiko or a model.

Providers receive the information needed for their function. Infrastructure providers may process technical connection and security information such as IP addresses, request times, and browser details. We may also disclose information when legally required, to protect legal rights, or as part of a business transfer with applicable protections.

Although our PostHog projects and current support storage use EU regions, providers may process some information outside your country, including outside the EEA. Where required, transfers must use a recognized legal mechanism, such as an adequacy decision or approved standard contractual clauses. Contact us for information about the safeguards applicable to your data.

Provider details are available in the privacy notices of Stripe, WorkOS, Keygen, Resend, PostHog, Railway, and Cloudflare.

How long we keep data

Local content follows the deletion and retention settings you choose in the app. Account and licensing records are retained while needed to operate your account and entitlement, resolve disputes, prevent abuse, and meet legal obligations. Deleting an identity account does not automatically delete separate payment, license, or support records.

Website attachment access ends after 30 days, and a daily cleanup removes expired files; an outage can delay physical deletion. Delivered request and reply text is removed from the delivery queue after seven days. Undelivered requests remain for recovery. Request references, subjects, original requester email, recipient identity, and ownership remain as support metadata.

Support conversations, email copies, and backups have separate retention. Attachment expiry does not delete those copies. Stripe retains payment records under its own legal obligations. Analytics cookie lifetimes are listed in the Cookie policy; those lifetimes are separate from provider-side event retention. Contact us about retention or deletion of the records relevant to you.

Your choices & rights

Depending on applicable law, you may request access, correction, erasure, restriction, or portability of personal information we control, object to processing based on legitimate interests, and withdraw consent. Some requests are subject to legal exceptions or record-retention duties. Deleting licensing information may prevent us from validating that license.

Write to kimiko@inoviatech.io. We may request proportionate information to verify your identity and will respond within the applicable statutory period. For content that stays only on your device, use the app’s controls; we cannot remotely retrieve or erase that library.

You may complain to your local data-protection authority, including the Office of the Commissioner for Personal Data Protection in Cyprus. You do not need to contact us first to exercise that right.

Children & policy changes

Kimiko is not directed at children under 16, and we do not knowingly collect their personal information. Contact us if you believe a child has provided information so we can address it.

We will post policy changes here and update the date. We will provide additional notice of material changes where appropriate and request fresh consent where required.

Contact

Inovia AI Solutions LTD, Republic of Cyprus.
Privacy and legal requests: kimiko@inoviatech.io.
General enquiries: info@kimiko.app.

Inovia AI Solutions LTD · Republic of Cyprus

Kimiko

Your notes, meetings, and next steps, connected in one desktop app.

Private by default. Yours by design.

Product

  • Download
  • Meeting notes
  • Ask your notes
  • Voice dictation
  • Pricing

Resources

  • Documentation
  • Choosing your models
  • Changelog
  • FAQs

Kimiko

  • Your account
  • Support
  • Contact us
  • Privacy & your data

© 2026 Inovia AI Solutions LTD.

Privacy policyTerms of serviceCookie policyCookie settings

A little cookie housekeeping.

With your OK, we use PostHog analytics cookies to understand visits, traffic sources, and approximate city or country on our website and docs. It helps us make Kimiko’s corner of the internet better.

Optional analytics stays off until you accept. Essential storage keeps your preferences and sign-in working. Cookie policy

Your choice. Change it any time in Cookie settings.