privacy
Privacy Policy
Last updated: May 25, 2026
This policy is tailored to Kumo's Slack-native agent runtime, workspace memory, connected tools, traces, billing, and AI processing model.
1. Scope
This Privacy Policy explains how Kumo collects, uses, discloses, and protects personal data and customer data when you use our website, onboarding flow, agent workspace, Slack app, runtime, integrations, billing, and related services.
Customer data means data submitted to Kumo or processed by Kumo for your workspace, including Slack messages, connected tool data, OAuth tokens, secrets, Gbrain files, traces, reports, artifacts, approval decisions, runtime logs, and agent outputs.
2. Information We Collect
Account and workspace information
- Google sign-in identifiers, such as name, email address, user ID, and avatar if provided.
- Company URL, workspace name, tenant identifiers, onboarding state, billing state, and administrative settings.
- Slack workspace identifiers, channel identifiers, Slack user identifiers, display names, emails if provided by Slack, and installation metadata.
Slack and conversation content
When Kumo is installed and used in Slack, we process messages, thread replies, direct messages to Kumo, channel context, files, reactions, and metadata where Kumo is invited, mentioned, addressed, or otherwise authorized. We use this to understand requests, maintain context, post replies, create traces, and run tasks.
Connected tool data
When you connect a tool, Kumo may process the data made available by the scopes and permissions you grant. This can include repository data, documents, spreadsheets, calendars, CRM records, analytics, ad accounts, product data, tickets, invoices, billing metadata, and other business data depending on the integration.
Secrets, tokens, and credentials
Kumo may store OAuth tokens, refresh tokens, API keys, webhook secrets, and runtime secrets that you provide or authorize. These are used to keep integrations working and are protected with access controls appropriate to their sensitivity.
Operational data
- Runtime logs, traces, tool calls, model calls, errors, audit events, task status, credit usage, and diagnostic data.
- Billing contact information, subscription metadata, checkout status, and payment events. Full payment card details are handled by our payment processor, such as Stripe.
- Website and product analytics, device/browser metadata, referral and attribution data, cookies, and similar technologies used to operate, measure, secure, and improve Kumo.
- Support messages and other communications you send us.
3. How We Use Information
- Provide Kumo, authenticate users, create tenants, operate the Slack app, maintain integrations, and run tenant runtimes.
- Respond to Slack messages, perform tasks, generate reports and artifacts, write code or campaigns, maintain company memory, and provide trace visibility.
- Secure the Service, detect abuse, debug failures, enforce limits, prevent unauthorized access, and maintain audit records.
- Process trials, credits, subscriptions, invoices, checkout, billing portals, and payment-related communications.
- Send administrative, security, support, product, and billing communications.
- Improve reliability, usability, performance, and product quality.
- Comply with law, enforce our Terms, and protect users, Kumo, and third parties.
4. AI Processing and Model Training
Kumo sends only the context reasonably needed for a task to AI providers and runtime systems. That context may include prompts, Slack messages, company memory, connected tool results, files, traces, and prior outputs relevant to the task.
- We do not use customer data for advertising.
- We do not sell Slack messages or connected tool content.
- We do not train our own or third-party foundation models on customer data.
- AI providers may temporarily retain API inputs and outputs for security, abuse monitoring, or reliability according to their own API retention terms.
- Slack APIs, Google Workspace APIs, and other connected platform APIs are not used by Kumo to develop, improve, or train generalized AI or machine learning models.
5. Sharing and Subprocessors
We share information only as needed to provide, secure, support, measure, bill for, or improve Kumo, or where required by law. Categories of recipients may include:
- Cloud hosting, database, storage, observability, logging, queueing, security, and infrastructure providers.
- AI model and inference providers used to generate responses and run tasks.
- Slack and other connected platforms you authorize.
- Integration providers and APIs used at your direction.
- Payment processors, tax, accounting, and subscription management providers.
- Analytics, attribution, and product measurement providers, where enabled.
- Support, communications, and customer operations tools.
- Professional advisors, acquirers, successors, regulators, courts, or law enforcement where legally appropriate.
We do not disclose customer data to subprocessors for their independent advertising purposes. If we publish a subprocessor list in the product or on an order form, that list controls for your workspace.
6. Slack and Connected Platform Controls
You can revoke Kumo's Slack access through Slack App Management. You can disconnect many other integrations through Kumo or through the third-party service. Revocation stops new collection from that source, but does not automatically delete data already stored in Kumo.
Because integrations are workspace-shared, your workspace administrators are responsible for deciding which tools to connect, which scopes to grant, which Slack channels Kumo may access, and which users may approve or pre-authorize actions.
7. Storage and Security
Kumo is designed around isolated tenant runtime state and controlled access to customer data. We use safeguards such as encryption in transit, restricted access, service monitoring, audit logs, and least-privilege operational practices appropriate to the nature of the data.
No system is perfectly secure. You are responsible for maintaining secure Slack workspaces, connected accounts, credentials, secrets, and user permissions. Do not authorize Kumo for data or actions your workspace is not prepared to expose to authorized Kumo users.
8. Retention and Deletion
We retain customer data for as long as needed to provide Kumo, maintain traces and auditability, comply with law, resolve disputes, enforce agreements, secure the Service, and operate billing and support.
- If an integration is disconnected, Kumo stops collecting new data from that source but may retain prior traces, outputs, logs, memory, and artifacts according to workspace retention settings and operational needs.
- If an account is closed or we receive a valid deletion request, we delete or de-identify customer data from active systems within a commercially reasonable period, unless retention is required for security, legal, billing, backup, or dispute reasons.
- Backups, logs, and derived technical data may take longer to expire on normal rotation.
- Deletions may not remove data that your workspace exported, copied, posted in Slack, committed to a repository, sent to a connected tool, or otherwise placed outside Kumo.
9. Your Choices and Rights
Depending on your location, you may have rights to access, correct, delete, export, object to, or restrict processing of personal data. You may also have rights to opt out of certain targeted advertising, sale, or sharing activities as those terms are defined by applicable law.
To exercise privacy rights, contact the Kumo team through the support or privacy contact made available in the product or in your applicable order form. We may need to verify your request and your authority for the relevant workspace.
You can opt out of non-essential marketing communications through unsubscribe links or by contacting us. Essential security, billing, legal, and service communications may still be sent.
10. International Users
Kumo may process and store information in the United States and other countries where we or our providers operate. If GDPR, UK GDPR, or similar laws apply, our legal bases may include contract performance, legitimate interests, consent, legal obligations, and protection of vital interests where applicable.
Where required, we use appropriate safeguards for international transfers, such as contractual commitments from providers or other lawful transfer mechanisms.
11. Children
Kumo is a business service and is not intended for children. We do not knowingly collect personal data from anyone under 18, or the age of majority in their jurisdiction if higher. If we learn that we collected such data, we will delete it promptly.
12. Changes and Contact
We may update this Privacy Policy from time to time. If changes are material, we will use reasonable efforts to notify workspace administrators or account contacts. Continued use of Kumo after the updated policy is posted or communicated means the updated policy applies.
For privacy questions, deletion requests, or rights requests, contact the Kumo team through the support or privacy contact made available in the product or in your applicable order form.