Legal

Privacy Policy

Effective July 12, 2026. This explains what KernelFold AI collects, why, and what control you have. Questions? Contact us.

The short version

  • We collect what we need to run the service — your account, your conversations, and usage records — and nothing more.
  • Your prompts are sent to the third-party AI model providers needed to answer them. We don't sell your data or use it for advertising.
  • Payment card details never touch our servers; they go directly to Stripe.
  • You can delete your conversations or your entire account at any time.

What we collect

Account data

Email address, display name, and a hashed password (we never store the password itself). If you sign in through a third-party provider, we receive the email and profile name that provider shares.

Content you create

Your conversations — prompts, uploaded images, and the responses generated for you — are stored so you can return to them. Conversations you explicitly share via a share link become readable by anyone who has that link until you revoke it.

Usage and billing records

For each request we record metadata needed for billing and reliability: which models ran, token counts, token cost, latency, and success or failure. Payments are processed by Stripe; we store your plan, subscription status, and the last four digits of your card — never the full card number.

Technical data

Standard server logs (IP address, user agent, timestamps) kept for security and abuse prevention. We use browser storage (localStorage) to keep you signed in. We do not run third-party advertising or cross-site tracking scripts.

How your prompts are processed

KernelFold is an orchestration layer: to answer you, we transmit your prompt (and relevant conversation context) to the upstream AI model providers selected by our router for that request. These providers process the content under their own terms as data processors for the request. We select routing per task; the models that handled your request are shown in the pipeline view for that answer.

We do not use your conversations to train models, and we do not sell or rent your personal data to anyone.

Retention and deletion

  • Conversations: kept until you delete them; deleting a conversation removes it from our database.
  • Account: deleting your account removes your profile, conversations, and API keys. Billing records are retained as long as tax and accounting law requires.
  • Server logs: retained for a limited period for security, then rotated out.

Security

All traffic is encrypted in transit (TLS). Passwords are hashed with a modern algorithm; API keys are stored hashed; third-party credentials we hold on your behalf are encrypted at rest. Access to production systems is restricted. If we learn of a breach affecting your data, we will notify you without undue delay.

Your rights

You may access, correct, export, or delete your personal data. Most of this is self-serve in your account settings; for anything else, or to exercise rights under the GDPR, UK GDPR, or CCPA/CPRA (access, deletion, portability, objection, non-discrimination), contact us and we will respond within the legally required window.

Children

KernelFold is not directed at children under 16, and we do not knowingly collect their data. If you believe a minor has created an account, contact us and we will delete it.

Changes

If we change this policy in a material way, we will update the effective date above and, for significant changes, notify you by email or an in-product notice before the change takes effect.