Customer policy

Privacy Policy

This policy explains what the Communication Suite stores, why it is used, and the choices available to account holders.

Effective August 12, 2026

Information we process

We process account identity, organization membership, business communication settings, optional sender profile information, request inputs, generated outputs, usage events, invitations, and limited billing-reconciliation references. We do not store payment card or bank credentials.

How information is used

Information is used to authenticate users, keep organizations separate, personalize requested communication, enforce subscribed access, provide history selected by the user, support the service, detect failures, and maintain security and audit records.

Service providers

The Suite currently relies on infrastructure and processing providers including Vercel, Supabase, OpenAI, Resend, and FreshBooks. Providers receive only the information needed for their role in hosting, authentication, generation, email delivery, or billing administration.

Retention

New communication requests are private by default and scheduled to expire after 24 hours. A user may choose saved history for up to 30 days. Security, usage, billing reconciliation, and append-only commercial audit records may be retained longer for legitimate operational, accounting, fraud-prevention, or legal purposes.

Email notifications

When a completed communication is delivered to an account user by email, the generated copy is processed by our email-delivery provider and stored in the recipient's mailbox according to that provider and account's settings. Deleting an expired request from the Suite does not delete a copy already delivered to an external mailbox.

Customer responsibilities

Customers should not submit payment credentials, government identification numbers, medical records, legal case materials, or other sensitive information that is unnecessary to create the requested communication.

Access and deletion requests

Account holders may request access, correction, export, or deletion by emailing support@kiteandkeyconsulting.com. Some records may be retained where required for security, billing, legal obligations, or immutable audit history.

Security

We use organization-scoped authorization, row-level database controls, protected server credentials, authenticated callbacks, and limited retention. No internet service can guarantee absolute security.

Changes

We may update this policy as the service changes. Material updates will be posted here with a revised effective date.