# Privacy Policy

**Kyroco, LLC** - Korium · Effective July 21, 2026 · Last updated **July 31, 2026**

Kyroco, LLC (“Kyroco,” “we,” “us,” or “our”) provides Korium, a hosted graph-memory service for AI agents and applications (the “Service”). This Privacy Policy explains what personal information we collect, how we use and share it, and the choices and rights you have.

This Policy covers our websites, the Korium sign-up and pricing pages, the customer dashboard and console, and our sales, support, and marketing activities (together, the “Sites and Services”). Capitalized terms not defined here have the meanings given in our [Terms of Service](terms.html).

Important scope note: content you store in Korium

When you use Korium, you submit data to your memory store (“Customer Content”) that may contain personal information about you or about third parties. **We process Customer Content on behalf of our customers, as a service provider / data processor, under our [Terms of Service](terms.html) and [Data Processing Addendum](dpa.html) - not under this Privacy Policy.** For that data, the customer (your organization) is the controller and decides how it is used; this Policy does **not** govern it, and if you are an end user or data subject with a request about Customer Content, you should contact the relevant customer directly. **We do not use Customer Content to train, fine-tune, or improve general-purpose or foundation AI models.**

This Privacy Policy governs the personal information for which **Kyroco is the controller** - for example, account, billing, usage, support, and marketing information about the individuals and organizations that visit our Sites or administer the Service.

#### Contents

1. Personal Information We Collect
2. How We Use Personal Information
3. Legal Bases (EEA/UK)
4. How We Share Personal Information
5. International Data Transfers
6. Cookies and Similar Technologies
7. Data Retention
8. Your Privacy Rights
9. Security
10. Children’s Privacy
11. Third-Party Sites and Services
12. Changes and How to Contact Us
13. California Privacy Notice (CCPA/CPRA)

## 1. Personal Information We Collect

### Information you provide to us

- **Account and identity data** - name, email address, organization name, username, and authentication data (including passkey registration metadata and, where you use social/OAuth sign-in, the identifiers those providers return). We do not receive or store your OAuth provider password.
- **Billing and transaction data** - your plan, subscription and usage records, billing contact, and the last four digits and metadata of your payment method. **Full payment-card details are collected and processed directly by our payment processor (Stripe); we do not store full card numbers.**
- **Communications and support data** - messages, requests, and attachments you send us through support, email, sales conversations, or forms.
- **Marketing data** - preferences, event or newsletter sign-ups, and survey responses.

### Information we collect automatically

- **Usage and log data** - actions taken in the Service and dashboard, feature usage, request volumes, seat and Memory Operation counts (used for billing), timestamps, and diagnostic and error data. This is “Usage Data” as described in the Terms of Service and generally reflects configuration and performance rather than the substance of Customer Content.
- **Device and connection data** - IP address, browser and device type, operating system, and similar technical identifiers.
- **Cookies and similar technologies** - see Section 6.

### Information we receive from third parties

- **Identity/OAuth providers** (e.g., Google, Apple, GitHub) when you choose to sign in or connect through them;
- **Payment processor** (Stripe) - transaction status and limited payment metadata;
- **Service providers and analytics** that help us operate and secure the Sites and Services; and
- **Business sources** such as referrals and publicly available professional information for sales and marketing.

We do **not** intentionally collect special-category or highly sensitive personal information about you through our Sites and Services, and you should not submit it to us except through channels designed for it.

## 2. How We Use Personal Information

We use the personal information we control to:

- provide, operate, maintain, secure, and support the Sites and Services, and create and administer your Account;
- process subscriptions, calculate seat and usage-based fees, and take payment;
- authenticate users, manage passkeys and devices, and prevent fraud, abuse, and security incidents;
- respond to your requests and provide customer support;
- understand how the Sites and Services are used and improve and develop our products (using Usage Data and aggregated or de-identified data);
- send administrative, transactional, and (where permitted) marketing communications, and personalize those communications;
- comply with law, enforce our agreements and policies, and establish, exercise, or defend legal claims.

**AI model training.** We do not use Customer Content to train, fine-tune, or improve general-purpose or foundation AI models. We may use Usage Data and aggregated or de-identified data to analyze and improve the Service, as described in the Terms of Service.

## 3. Legal Bases for Processing (EEA/UK)

Where the EU or UK GDPR applies, we rely on the following legal bases: **performance of a contract** (to provide the Sites and Services you request and administer your Account and billing); **legitimate interests** (to secure, analyze, and improve our products, prevent fraud and abuse, and conduct direct marketing to business contacts, balanced against your rights); **consent** (for certain marketing, cookies, or optional features, which you may withdraw at any time); and **legal obligation** (to comply with applicable law). Where we rely on legitimate interests, you may object as described in Section 8.

## 4. How We Share Personal Information

We do **not sell** your personal information, and we do **not share** it for cross-context behavioral (targeted) advertising, as those terms are defined under U.S. state privacy laws. We disclose personal information only as follows:

- **Service providers / subprocessors** who process personal information on our behalf under contract and confidentiality and data-protection obligations, including cloud infrastructure (e.g., Amazon Web Services), our payment processor (Stripe), AI model and embedding providers used to perform Memory Operations, identity/OAuth providers, error-monitoring and analytics providers, and communication and support tools. A current list of subprocessors is available in our [Subprocessors list](subprocessors.html).
- **AI model providers** - we contract with model and embedding providers on terms intended to prohibit their use of Customer Content to train their models.
- **Affiliates** that help us operate the business, under this Policy.
- **Professional advisors and authorities** - where required to comply with law, legal process, or a lawful government request, or to protect the rights, safety, and property of Kyroco, our customers, or others. Where legally permitted, we will give affected customers reasonable notice.
- **Business transfers** - in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy or a successor policy with equivalent protections.

## 5. International Data Transfers

We are based in the United States, and by default the Service operates in the United States (additional regions and data-residency options are available to enterprise customers). If you access the Sites and Services from outside the United States, your personal information may be transferred to, stored in, and processed in the United States or other countries where privacy laws may differ from those in your location. Where required, we use appropriate safeguards for international transfers. Our primary safeguard is the European Commission’s **Standard Contractual Clauses** (with the UK Addendum and Swiss adjustments as applicable), incorporated into our [Data Processing Addendum](dpa.html). In addition, several of our subprocessors are certified under the **EU-US Data Privacy Framework** (and its UK extension), which we may also rely on for transfers to those providers; the Standard Contractual Clauses remain in place regardless. You may request a copy of the relevant safeguards using the contact details in Section 12.

## 6. Cookies and Similar Technologies

Our websites use cookies and similar technologies to keep you signed in, remember preferences, secure the Service, and measure and improve site performance. We use strictly necessary cookies to operate the Sites, and, where you consent (where required), analytics or preference cookies. You can control cookies through your browser settings and, where offered, our cookie banner or preference center. Details are in our [Cookie Notice](cookies.html). We do not currently respond to browser “Do Not Track” signals; where required by law, we treat recognized opt-out preference signals (such as Global Privacy Control) as a valid opt-out of “sale”/“sharing.”

## 7. Data Retention

We retain personal information for as long as needed to provide the Sites and Services, maintain your Account, comply with our legal obligations, resolve disputes, and enforce our agreements. Account and billing records are generally retained for the life of the Account and for a reasonable period afterward as required for tax, accounting, and legal purposes. **Customer Content is retained and deleted as described in the Terms of Service (including the post-termination retrieval period and deletion), not under this Policy.** When personal information is no longer needed, we delete or de-identify it, subject to residual copies in routine backups that are deleted on our standard cycle.

## 8. Your Privacy Rights

Depending on where you live and the applicable law, you may have some or all of the following rights regarding personal information we control:

- **Access / know** - request confirmation of, and access to, the personal information we hold about you and how we use and share it;
- **Correction** - request that we correct inaccurate personal information;
- **Deletion** - request that we delete your personal information;
- **Portability** - request a copy of certain information in a portable format;
- **Objection / restriction** - object to or ask us to restrict certain processing (including processing based on legitimate interests, and direct marketing);
- **Withdraw consent** - where we rely on consent, withdraw it at any time (without affecting prior processing);
- **Opt out** - opt out of marketing communications (via the unsubscribe link or by contacting us) and, to the extent applicable, of any “sale,” “sharing,” or “targeted advertising” and of certain profiling; and
- **Non-discrimination** and, where applicable, the right to **appeal** a decision on your request.

**How to exercise your rights.** Contact us at [reports@kyroco.ai](mailto:reports@kyroco.ai). We will verify your request and respond within the time required by applicable law. You may use an authorized agent where the law permits. If you are an end user or data subject and your request concerns Customer Content held by one of our customers, please contact that customer, who is the controller of that data; we will assist them as their processor.

**EEA/UK complaints.** If you are in the EEA or UK, you may lodge a complaint with your local supervisory authority, though we encourage you to contact us first.

**U.S. state privacy laws.** If you are a resident of California or another U.S. state with a comprehensive privacy law, you have the rights described above to the extent that law provides. We do not sell personal information or share it for cross-context behavioral advertising, and we do not use or disclose sensitive personal information for purposes that require an opt-out right under those laws.

## 9. Security

We maintain administrative, technical, and organizational measures designed to protect personal information, as described in our [Terms of Service](terms.html) and at [kyroco.ai/legal/security](security.html). No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Please protect your credentials and notify us promptly of any suspected compromise.

## 10. Children’s Privacy

The Sites and Services are intended for business and professional use by individuals who are at least 18 years old. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact us and we will take appropriate steps to delete it.

## 11. Third-Party Sites and Services

The Sites and Services may link to, or interoperate with, third-party websites, agents, tools, and model providers that we do not control. Their privacy practices are governed by their own policies, and we are not responsible for them. Please review the privacy policies of any third party before providing your information.

## 12. Changes to This Policy and How to Contact Us

We may update this Privacy Policy from time to time. If we make a material change, we will update the “Last Updated” date and, where required, provide additional notice. Your continued use of the Sites and Services after an update takes effect constitutes acceptance of the updated Policy.

**Contact us:**\
Kyroco, LLC\
Attn: Privacy\
Peachtree Corners, GA 30092\
Email: [reports@kyroco.ai](mailto:reports@kyroco.ai)

Kyroco offers the Service to individuals in the EEA and UK. Our Article 27 EU/UK Representative will be identified here upon appointment. Kyroco has not designated a Data Protection Officer, as one is not required for its current processing.

## 13. California Privacy Notice (CCPA/CPRA)

This section supplements the Policy for California residents and describes how we handle personal information under the California Consumer Privacy Act, as amended by the CPRA. It applies to personal information we collect as a **business**; it does not apply to Customer Content we process as a **service provider** on behalf of our customers.

### Categories of personal information we collect

In the preceding 12 months we have collected the following categories of personal information about individuals who visit our Sites or administer the Service, for the business and commercial purposes in Section 2 and from the sources in Section 1:

- **Identifiers** - name, email, account/username, IP address, and online identifiers.
- **Customer records / commercial information** - billing contact, plan, subscription and usage records, and payment metadata (full card data is handled by Stripe).
- **Internet or network activity** - usage, log, diagnostic, and device/connection data.
- **Professional information** - organization and role, for business accounts and sales.
- **Inferences** - limited inferences drawn from the above to operate and improve the Service.

We disclose these categories to service providers / subprocessors for business purposes (see Section 4 and our [Subprocessors](subprocessors.html) list), and we retain them as described in Section 7. We do **not** knowingly collect **sensitive personal information** for purposes that would trigger the right to limit its use, and we do not use or disclose it for such purposes.

### No sale or sharing

We do **not sell** personal information and do **not share** it for cross-context behavioral advertising, as those terms are defined under the CCPA, and we have not done so in the preceding 12 months. We honor a recognized **Global Privacy Control (GPC)** signal as a valid opt-out of any “sale” or “sharing.”

### Your California rights

- **Know / access** the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients;
- **Delete** personal information we collected from you, subject to legal exceptions;
- **Correct** inaccurate personal information;
- **Opt out** of sale or sharing - not applicable, as we do neither;
- **Limit** the use of sensitive personal information - not applicable, as described above;
- **Non-discrimination** for exercising your rights; and
- **Appeal** a decision on your request, where the law provides.

**How to exercise.** Submit a request using the contact details in Section 12 or the request method in Section 8. We will verify your request (and an authorized agent’s authority, where one is used) and respond within the timeframes required by law.

Related policies

[Data Processing Addendum](dpa.html)

How we process personal data on your behalf, with SCCs and TOMs.

[Subprocessors](subprocessors.html)

The third parties that help us provide Korium.

[Cookie Notice](cookies.html)

How we use cookies and how to manage your choices.

[GLBA Safeguards Addendum](glba.html)

For financial-institution customers (precautionary draft).

[Subscription Terms of Service](terms.html)

The master agreement governing your use of Korium.

[Acceptable Use Policy](acceptable-use.html)

What’s prohibited when using Korium.
