Privacy
What KAIROS stores
This page covers the two things KAIROS puts in your browser, what it counts, what it measures only if you agree, what happens to the video you upload, and who else touches it.
Cookies and browser storage
Two things are always stored in your browser, and two more only if you agree to them:
- A sign-in cookie,
sb-…-auth-token. It keeps you signed in between page loads, and without it you cannot use the app. It goes when you sign out, or when it expires. - Your theme choice,
kairos-theme. It remembers whether you picked light, dark, or following your device, and it stays until you clear your browser storage. - A Google advertising cookie,
_gcl_au, and only if you agreed when asked. It is how Google can tell that an advert led to an account. Refuse, and it is never set. - A PostHog cookie,
ph_…, on the same answer. It is how the measurement below can tell one visit from the next. Refuse, and it is never set.
The first two do not ask for your consent, because both exist only to do what you asked for — staying signed in, and keeping the theme you picked. Neither is shared with anyone, and neither follows you to other sites.
Counting visits to the front page
The front page of this site — this page and the app itself are not counted — reports a page view to Vercel Web Analytics, so we can tell whether anyone is finding us. It stores nothing in your browser: no cookie, no identifier, nothing to clear. Each view records the page address, the site that linked you here, your country, and your browser and device type. Your IP address is not stored, and the counter cannot tell that two visits on different days came from the same person.
The same page also reports how quickly it loaded and responded — Vercel Speed Insights, measured from your browser as you use it. It records timings, the page address, and your browser and device type, so we can tell whether the page is slow for real visitors rather than only on our own machines. It stores nothing in your browser either, and carries nothing about what you did on the page.
Because neither stores anything on your device and neither follows you to another site, they ask for no consent. Together they give us a visitor count and load times, and nothing that could identify you. Vercel, who host the site, process both on our behalf.
Measuring which adverts work
We advertise KAIROS on Google. If you accept when the bar at the bottom asks, the public pages load Google’s advertising tag, which sets a cookie in your browser and tells Google that someone who clicked an advert went on to create an account. That is the whole purpose: to know which adverts are worth paying for.
When you create an account after accepting, the sign-up report also carries your email address in a hashed form, so Google can attribute the sign-up to its advert where the cookie alone cannot. Google calls this enhanced conversions; the address is hashed before it leaves the page, is used only for that matching, and is sent only if you accepted when asked.
If you refuse, the tag is never loaded and no request is made to Google — refusing is remembered, and nothing about the product changes. Nothing else on the site depends on that answer, and you can change it here at any time:
The signed-in app never loads it, whichever you chose. Google is the processor for this and describes it in their own advertising terms.
Measuring which parts of KAIROS get used
The same answer also decides PostHog, which counts pages opened and whether an upload, a search, a saved edit or a reel finished. It is how we can tell which parts of the product are worth the work. It runs on PostHog’s servers in the EU, and unlike the advertising tag it covers the signed-in app as well as the public pages.
If you refuse, nothing of it is loaded and no request is made — and the control above withdraws the answer for both. If you accept while signed in, your account id, your email address and your workspace’s plan travel with the measurements, so one person’s use can be told from another’s.
What you search for, what your clips are called and the files you upload are never sent. Those are your material, and a count of results answers the question without them.
Keeping automated abuse out
The sign-up, password-reset and feedback forms are checked for automated traffic before they do anything — Vercel BotID, alongside the puzzle you may already have seen on sign-up. It looks at how the request itself was made, not at what you typed, and it stores nothing in your browser: no cookie, nothing to clear. This is what keeps the forms from being used to send mail to strangers or to create accounts in bulk, so it is not something you can turn off.
Signing in
Sign-in is Google OAuth or an email address and password, both handled by Supabase Auth. We never see your Google password. Stored against your account: your email address, and a workspace created on your first sign-in and named after that email.
Video you upload
- Your file is stored privately. It never sits at a public web address, and it plays back only for you.
- KAIROS keeps what it found in the video: where each shot and key moment starts and ends, a description of each, and the transcript.
- Only your own workspace can see your uploads and their results. No other workspace can.
- the KAIROS team can see them too.
- KAIROS analyses your video; it does not publish it. What you upload stays private to your workspace, and you are responsible for it — including holding the rights to the material you analyse. To report content that should not be here, email privacy@kairosapp.tech and it will be reviewed and, where justified, removed.
Feedback you send
- We keep what you wrote, and the email address you gave us if you gave one. If you were signed in, we keep the address on your account instead.
- If you sent it from a clip’s page, we keep which clip it was about, so the note makes sense.
- When you send feedback without signing in, we keep a scrambled form of your IP address for one hour. It is how we stop the form being used to send us floods of mail. We cannot read the address back out of it, and we never store the address itself.
- It is emailed to the person who maintains KAIROS, and it is not used for anything else.
Who processes it for us
| Service | Does what |
|---|---|
| Supabase | Sign-in, and the Postgres database holding accounts and analysis output |
| Google Cloud | Storage for uploaded video, and the AI models that analyse it |
| PostHog | Measures which parts of KAIROS get used, on EU servers. Only with your agreement |
| Google Ads | Tells us which advert brought someone here. Only with your agreement |
| Vercel | Hosts the web app, serves its requests, and counts front-page visits |
| Resend | Delivers feedback and upgrade requests to the maintainer as email |
Your responsibilities
- Do not upload anything you would mind the KAIROS team seeing.
- Do not upload broadcast material you do not hold the rights to.
- Uploads and analysis output stay in your workspace until you delete them, or until you ask for your account to be removed.
Asking what is stored, or having it deleted
To ask what is held about you, to correct it, or to have your account and uploads deleted, email privacy@kairosapp.tech.