Privacy Policy
Kordo is operated by Proof Industries ("we", "us"). Kordo gives a small business a team of AI agents that handle its marketing, content and administration. This policy explains what we collect, why, who else processes it, and how to get it removed.
1. What we collect
When you sign up for Kordo, we collect:
- Account information: your name, email address and Google account identifier, received when you sign in with Google. We never receive your Google password, and we do not request access to your Gmail, Drive or Contacts in order to sign you in.
- Business information: the name, address, category, website and public contact details of your business — from Google Places when you select it, or from a link you provide.
- Publicly available information about your business: so your agents can write in your voice from the first day, we read publicly accessible sources — your website, your public social profiles and public reviews. We collect only what any visitor to those pages could see, and we do not log in to any account to do it.
- Payment information: processed securely by Stripe — we never see or store your card number.
- Connected service data: when you connect Instagram, Google Workspace or another service, we access the data you authorise (posts, analytics, reviews, calendar).
- Usage data: how you interact with your AI team — messages, approvals, preferences — and how much AI processing your account uses.
2. Google user data
This section describes specifically how Kordo accesses, uses, stores and shares Google user data, as required by the Google API Services User Data Policy.
- What we access. When you sign in with Google we request only the
emailandprofilescopes. From these we receive your email address, your name, your profile picture URL and your Google account identifier. We do not request or receive access to Gmail, Drive, Calendar or Contacts in order to sign you in. If you separately choose to connect Google Workspace, we access only the data you explicitly authorise at that point, and we tell you what it is before you approve it. - How we use it. Solely to create and secure your Kordo account, to identify you when you return, to show your name and email in your team, and to contact you about your account. We do not use Google user data for any other purpose.
- How we store it. Your email, name and Google account identifier are stored in our control-plane database, hosted on Hetzner in the European Union, encrypted in transit over TLS. Access is restricted to authorised personnel using SSH key authentication.
- How we share it. We do not share Google user data with any third party, other than the hosting provider that stores it on our behalf, or where the law requires it. Google user data is never sent to our AI model providers.
- Retention and deletion. We hold it for as long as your account is open. Email privacy@kordo.ai and we delete it within 30 days. You can also revoke Kordo's access at any time from your Google account permissions page.
Kordo's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to data brokers, use it for advertising, or use it to train generalised AI or machine-learning models.
3. How we use your data
- To operate your AI agent team: creating content, monitoring reviews, tracking performance.
- To set your agents up so they know your business before you start.
- To improve the quality of your agents' output based on your feedback.
- To process payments via Stripe.
- To send you operational notifications such as morning briefs and approval requests.
- To monitor system health and prevent abuse.
We do not sell your data, we do not use it for advertising, and we do not use your business content to train our own models.
4. Where your data lives
Each customer gets a dedicated server instance — your data is not shared with other customers.
- Your instance: hosted on Hetzner in the European Union. Agent data, knowledge base and conversation history live here.
- OAuth tokens: stored on your instance only. Our control plane relays tokens during initial setup and does not retain them.
- Control plane: hosted on Hetzner. Stores account information, subscription status and usage metrics.
- Payments: processed by Stripe. We do not store card information.
5. Third-party services
We use the following providers to operate Kordo, and share with each only what its purpose requires:
- Google: sign-in, and business lookup via Google Places.
- Anthropic and OpenRouter: the AI models behind your agents.
- Hetzner: customer instance and control-plane hosting.
- Stripe: payment processing.
- Resend: transactional email, such as team invitations.
- Telegram: your chat channel, if you choose it.
- Brave Search and Browserbase: retrieving publicly available information about your business.
When your agents interact with AI models, the content of those interactions is processed by the model provider. We use models that do not train on customer data.
6. Data sharing
We do not sell your data. We share it only:
- with the service providers listed above, strictly to operate Kordo;
- when required by law (subpoena, court order);
- with your explicit consent.
7. Your rights
- Access: you can view all your data through the dashboard and chat.
- Export: on cancellation you can export your content, drafts and contact lists.
- Delete: request account deletion by emailing privacy@kordo.ai — we will delete your data within 30 days.
- Correction: update your information through the dashboard, or by messaging your team lead.
- Disconnect: revoke any connected service at any time from Settings.
If you are in the UK or EU you have these rights under the UK GDPR and GDPR, including the right to complain to your data protection authority.
8. Security
- All data encrypted in transit (TLS/HTTPS).
- Dedicated instance per customer — full tenant isolation.
- OAuth tokens stored with restricted file permissions on your instance.
- Admin access restricted to authorised personnel using SSH key authentication.
- Daily automated backups with 30-day retention.
9. Cookies
We use one cookie:
- clawmark_session_v2 — keeps you signed in. HTTP-only, secure, expires after 7 days.
We do not use advertising or analytics cookies on this site.
10. Children
Kordo is designed for businesses and is not intended for use by individuals under 18.
11. Changes
We may update this policy from time to time. If we make material changes we will notify you by email or through your team lead before they take effect.
12. Contact
Questions about privacy? Email
privacy@kordo.ai.
Proof Industries.