Last updated: October 7, 2026

Privacy Policy

Effective Date: May 22, 2026

1. Introduction

This Privacy Policy describes how Pure Reason Inc. (“Pure Reason,” “we,” “us,” or “our”), a Delaware corporation, collects, uses, discloses, and protects personal information through our product Kylon and our website at kylon.io (collectively, the “Service”).

Kylon provides individuals and teams with a platform to build and manage Agent Teams.

This policy explains our data practices. Reading this policy or continuing to use the Service does not, by itself, authorize a new use or sharing of your Google user data. Where consent is required, it must be obtained separately before that processing begins.

This Privacy Policy applies to all users of the Service, including workspace administrators, members, and any individuals whose information may be processed through the Service.

2. Information We Collect

We collect information in the following categories:

2.1 Account Information

When you create an account or are invited to a workspace, we collect:

  • Name and display name
  • Email address
  • Avatar image URL
  • Authentication provider information (e.g., SSO provider, session identifiers)

Account creation and authentication are managed through our authentication partner, Clerk. Please refer to Section 6 and Clerk’s own privacy policy for details on their data handling practices.

2.2 User Preferences

We store your configurable preferences, which may include:

  • Timezone and language settings
  • User interface preferences
  • Notification preferences

2.3 Device and Session Information

When you access the Service, we automatically collect:

  • Device information: installation identifier, platform (web, macOS, iOS, Android), client type, device name, and application version
  • Session information: authentication provider used, session identifiers, session issuance time, last activity time, and session expiration time
  • First and last seen timestamps for each device

2.4 Content Data

The Service is designed for collaboration, and we process content you and other workspace members create, including:

  • Messages: text messages sent in rooms and threads
  • Files: documents, images, and other files you upload, along with associated metadata (file name, MIME type, file size)
  • Table data: structured data entries you create in workspace tables
  • Voice and audio data: audio from voice meetings and calls conducted through the Service

2.5 Connection and Integration Data

When you connect third-party services to your workspace (e.g., Gmail, GitHub, Notion, Twitter/X), we collect:

  • OAuth tokens and API keys for the connected service (stored in encrypted form)
  • External account identifiers and remote user identifiers
  • Connection metadata (service type, connection status)

We do not access data from connected third-party services beyond the scope of permissions you grant during the connection process.

2.6 Usage and Analytics Data

We collect product usage data to improve the Service, including:

  • Feature usage patterns and interaction events
  • Performance metrics
  • Error reports (error messages, page URLs, HTTP status codes, request identifiers)

2.7 Push Notification Tokens

If you enable push notifications, we collect device tokens necessary to deliver notifications via:

  • Web Push (VAPID protocol)
  • Firebase Cloud Messaging (FCM) for Android
  • Apple Push Notification Service (APNs) for iOS and macOS

2.8 Phone Number and SMS Verification Data

If you choose to verify a phone number, we collect:

  • The mobile phone number you enter
  • Your consent to receive a verification text message at that number, and the date and time that consent was given
  • Delivery and verification records for the messages we send (such as sent, delivered, verified, or failed)

Providing a phone number is optional. We use it only to send one-time verification codes, never for marketing or promotional messages. We send one message per verification request you make, so message frequency depends on how often you request a code. Message and data rates may apply. Reply STOP to any message to opt out, or HELP for help. The full program terms are in our Terms of Service.

2.9 Google Integrations and Google User Data

Connecting a Google account is separate from signing in to Kylon with Google. For a Google connection, we process account identifiers and authorization tokens, and access the categories below only as permitted by the Google products you connect, the permissions you grant, and the features you request or enable. A connection does not mean every category or every item in your account is always read.

  • Gmail: messages and threads, message bodies, attachments, labels, drafts, and send-as aliases, for requested email search and summaries, drafting and sending messages, and authorized labeling and email management.
  • Google Calendar: calendar lists, events and attendees, availability (free/busy), settings, and sharing permissions, for calendar queries, scheduling or changing events, and authorized calendar and sharing management.
  • Google Drive: file contents and metadata, folders, and permissions, for searching and reading files, uploading, creating or modifying files, and sharing management you request.
  • Google Docs: document contents, structure, and formatting, for reading, creating, and editing documents.
  • Google Sheets: cell contents and formulas, worksheet structure, and formatting, for reading, creating, and editing spreadsheets.

Features such as stored email activity and Email Understanding can retain retrieved email content and derived information to support the feature you enable. Email Understanding can analyze sent-mail and thread history to help draft replies in your context; this is not limited to the single message in your current request. Sections 5, 6, and 8 explain AI processing, sharing, and deletion boundaries.

3. How We Collect Information

We collect information through the following means:

  • Directly from you: when you create an account, configure your profile, send messages, upload files, set preferences, or connect third-party services.
  • Automatically: through your use of the Service, including device information, session data, and usage analytics.
  • From authentication providers: account information is synchronized from our authentication provider, Clerk, based on your sign-up or SSO login.
  • From third-party integrations: when you authorize connections to external services, we receive authentication credentials and identifiers from those services via OAuth or API key exchange. Our native Google integrations use Google OAuth and call Google APIs directly. Composio supports some other integrations; it is not the intermediary for these native Google connections.
  • From AI model providers: responses generated by AI agents in your workspace are received from third-party AI model providers (see Section 5).

4. How We Use Information

PurposeLegal Basis (GDPR)
Providing the Service: creating and managing your account, enabling workspace collaboration, processing messages, storing files, and facilitating AI agent interactionsPerformance of contract
AI Processing: sending user content to third-party AI model providers to generate agent responses, summaries, and automated actions within workspacesPerformance of contract; Legitimate interest
Authentication and Security: verifying your identity, managing sessions, preventing unauthorized access, and detecting abusePerformance of contract; Legitimate interest
Third-Party Integrations: connecting your workspace to external services you authorize, executing workflows, and synchronizing dataPerformance of contract; Consent
Push Notifications: delivering real-time notifications about workspace activity to your devicesConsent; Performance of contract
Voice Communications: facilitating voice meetings and calls within workspacesPerformance of contract
Analytics and Improvement: understanding how the Service is used, diagnosing technical issues, and improving features and performanceLegitimate interest
Error Reporting and Debugging: collecting and analyzing error data to identify and resolve technical issuesLegitimate interest
Compliance: meeting legal obligations, responding to lawful requests, and enforcing our terms of serviceLegal obligation; Legitimate interest
Communications: sending you service-related communications (e.g., security alerts, policy changes)Performance of contract; Legitimate interest
SMS Verification: sending a one-time code by text message to a phone number you have provided, to confirm you control that numberConsent

We do not sell your personal information for money, and we do not use the content of your workspace for advertising. On our marketing website (kylon.io) we use advertising tools from Google and Meta to measure and improve our ads, and in the United States RB2B to identify business visitors. Section 10 lists each tool and how to turn it off. Some US state laws may treat this as “selling” or “sharing” personal information; you can opt out at any time (Section 9.2). We do not use mobile phone numbers, SMS opt-in data, or messaging consent for marketing or promotional messaging.

4.1 Google API Limited Use

Use and transfer of information received from Google APIs is subject to the Google API Services User Data Policy, including its Limited Use requirements, and the Google Workspace API User Data and Developer Policy. These restrictions apply to the original Google data and information derived from it, including summaries, extracted content, and aggregated or de-identified information.

Google user data is limited to providing or improving the user-facing features you authorize and that are described in this policy. It must not be sold, used for advertising or targeted marketing, or repurposed for unrelated uses. The Google-specific restrictions in this policy govern notwithstanding the general purposes or legal bases described elsewhere in this policy.

5. AI Processing Disclosure

5.1 How AI Agents Work in Kylon

Kylon’s core functionality includes AI agents that operate as workspace members. These agents can read messages, generate responses, process files, execute workflows, and interact with connected services — all within the permissions and context of your workspace.

5.2 Data Sent to AI Model Providers

To enable AI agent functionality, user-generated content — including messages, file contents, table data, and related workspace context — is transmitted to third-party AI model providers listed on our Subprocessors page. The specific provider used may vary depending on the task, model routing configuration, and availability.

When you request or enable an Agent feature that works with Google data, relevant email messages or attachments, calendar events, Drive files, documents, spreadsheet contents, and information derived from them may be included in the task context sent to the AI service executing that task. The purpose is to carry out the requested search, summary, draft, edit, scheduling, or other authorized function, not to send your entire Google account to every provider on the list.

Kylon supports AI services including Anthropic, OpenAI, Google (Gemini / Vertex AI), and Cerebras, as well as model-routing services such as OpenRouter. The selected model and route determine the recipients; a routing service may also pass task context to the model provider. The Subprocessors page identifies services used by Kylon, not a promise that every service receives every task.

An Agent brought by a workspace member may run in that member’s local or separately hosted environment. Context delivered to that Agent can be processed in that environment and sent to its configured AI services. Its operator and service configuration therefore matter in addition to Kylon’s subprocessor list. Granting an Agent access can enable its future tasks to use that connection until access is removed.

5.3 What AI Providers Do with Your Data

Provider terms, account settings, and the selected processing route determine input and output retention. The following restrictions govern processing of Google user data by Pure Reason and its recipients:

  • We do not use Google Workspace API data, including derived information, to develop, improve, or train general-purpose or non-personalized AI or machine-learning models. We do not permit AI service providers, routing services, or Agent operators receiving that data for a Kylon task to use it for those purposes. Task-specific context and personalized responses are not permission to train a general-purpose model.
  • Kylon uses encrypted HTTPS/TLS connections to Google APIs and its AI service APIs. An Agent’s local storage and separately configured services have their own controls, which must be reviewed before enabling Google-data processing there.
  • Providers may temporarily retain input and output data for abuse monitoring and safety purposes, in accordance with their policies. Depending on the API route and settings, response records and cached task context may also be retained for service operation. We do not represent that storage is disabled on every route; any retention of Google data must remain limited to permitted purposes and the same Google-data restrictions.
  • Google data may be sent to a provider or Agent environment only under terms and settings consistent with these restrictions and the authorized feature. This policy is not a zero-retention guarantee for Kylon, AI providers, or Agent operators.

5.4 Your Control Over AI Processing

Workspace administrators can configure which rooms and workflows involve AI agent interactions. If you have questions about AI processing in your workspace, please contact your workspace administrator or reach out to us at the contact information provided in Section 15.

Before Google data is shared for AI processing, the product flow must disclose the relevant data, recipients, purpose, and sharing and obtain your informed, affirmative consent where required. This must be an in-product disclosure before authorization or the relevant processing, not merely a link to this policy, acceptance of general terms, or continued use of Kylon.

6. Information Sharing and Sub-processors

We share personal information only as described in this policy. We do not sell personal information.

6.1 Sub-processors

We use a number of third-party service providers (“sub-processors”) to operate the Service. A current, maintained list of our sub-processors — including their function — is available at: kylon.io/subprocessors. We update that page whenever our sub-processors change; we do not separately notify workspace administrators by email.

6.2 Other Disclosures

We may also share personal information:

  • With your workspace administrator and members: content you contribute to a workspace is visible to other members of that workspace, subject to workspace and room access controls.
  • As directed by you: when you connect third-party services or authorize specific data sharing.
  • With analytics and advertising providers on our marketing website: PostHog, Google, Meta and, in the United States, RB2B and its identity partners receive the information described in Section 10, subject to your choices there.
  • For legal compliance: to comply with applicable law, regulation, legal process, or governmental request.
  • To protect rights and safety: to enforce our agreements, protect the rights, privacy, safety, or property of Pure Reason, our users, or the public.
  • In business transfers: in connection with a merger, acquisition, reorganization, or sale of assets, in which case personal information may be transferred to the successor entity. Transfer of Google user data in a merger, acquisition, or sale of assets requires your explicit prior consent, and remains subject to the Google-specific restrictions below.

6.3 Mobile Phone Numbers, SMS Opt-In Data, and Messaging Consent

We do not sell, rent, or share mobile phone numbers, SMS opt-in data, or messaging consent with third parties or affiliates for marketing or promotional purposes. This information is disclosed to our messaging service providers only as needed to deliver and support phone verification, or where disclosure is required to comply with law. It is never shared with third parties for their own marketing purposes.

6.4 Google Data Access and Sharing Boundaries

A Google authorization grants access to the connection; it does not make your Google account public to the workspace. Connection access grants and task authorization control which members and Agents may use it. Content you choose to bring into a Room, file, App, or other workspace resource is then subject to that resource’s access controls. People who can use an Agent with a persistent connection grant may ask it to access data through that connection. Review both the connection grants and the Agent’s audience before sharing access.

For an Agent running outside Kylon’s managed environment, the operator may receive the task context even if they are not a member of the Room. Room permissions alone do not prevent access by that runtime or its configured AI services. The required disclosure and consent must cover this processing boundary.

Transfers of Google user data are limited to those necessary for the authorized user-facing feature with appropriate consent, for necessary security purposes, to comply with applicable law, or for a qualifying business transfer with your explicit prior consent. Recipients remain subject to the same Google data-use restrictions. General legal, safety, or business-transfer language elsewhere in this policy does not authorize unrestricted use or disclosure.

Human reading of Google user data is limited to Google-policy permitted circumstances: your affirmative agreement to view specific data (for example, to help resolve a support request), necessary security investigations such as abuse investigation, or applicable legal obligations. Routine human review of private Google content for unrelated purposes is not permitted.

7. Data Storage and Security

7.1 Where We Store Data

Your data is stored primarily on Google Cloud Platform infrastructure in the United States. Specific storage mechanisms include:

  • PostgreSQL database (with pgvector extension) hosted on GCP for structured data (accounts, messages, tables, metadata)
  • Google Cloud Storage (GCS) for uploaded files
  • Redis for caching and ephemeral data

7.2 Security Measures

We implement technical and organizational measures designed to protect your personal information, including:

  • Encryption at rest and in transit: data is encrypted in transit using TLS. Sensitive credentials (OAuth tokens, API keys) are encrypted at rest using pgcrypto.
  • Authentication and access control: Clerk-based authentication with session management, API key authentication with rotation support, and role-based access control scoped to workspaces and rooms.
  • Session management: device tracking, session expiration, and session revocation capabilities.
  • Network security: CORS restrictions and API gateway protections.
  • Secrets management: production secrets are managed through Doppler and GCP Secret Manager, with separation from application code.
  • Monitoring: error reporting and logging infrastructure for incident detection.

While we take reasonable measures to protect your information, no method of transmission or storage is completely secure. We cannot guarantee absolute security.

7.3 SOC 2 Type II in Progress

Pure Reason's SOC 2 Type II is in progress to demonstrate our commitment to security, availability, and confidentiality.

8. Data Retention

We retain your personal information for as long as your account is active or as needed for the authorized purposes described in this policy, subject to your deletion rights and applicable law. Different categories are handled separately:

  • Account data: retained for the duration of your account and handled through account-deletion procedures when you request deletion.
  • Content data (messages, files, table data): retained for the duration of the workspace in which the content resides. Workspace administrators may delete content within the Service, subject to their permissions. Copies incorporated into other workspace resources need to be considered separately.
  • Session and device data: session records are retained as needed for authentication, session management, and security.
  • Usage and analytics data: retained in forms used for service analytics. Google user data and its derivatives remain subject to Section 4.1, including when aggregated or de-identified.
  • Logs and backups: diagnostic records and backup copies have separate retention and deletion processes. Removing active content does not mean all logs or backups are immediately erased.
  • Connection credentials: OAuth tokens and API keys are removed from the active connection record when an authorized user disconnects the connection. This is separate from deletion of retrieved content and backup copies.

We may retain certain information as required by applicable law or for necessary security investigations. Any exception for Google user data must also satisfy the Google-specific restrictions in this policy; it is not permission for indefinite or unrelated use.

This policy does not promise immediate erasure from every system, a uniform retention period across providers, or zero retention.

8.1 Disconnecting Google and Requesting Deletion

  • Disconnect in Kylon: remove the relevant connection through its connection controls, using an account authorized to manage it. This removes the active connection and its credentials. Kylon attempts to revoke the Google token and clean up connection-specific stored content; those remote and storage cleanup steps are best-effort, not a guarantee that every copy is erased at the moment of disconnect.
  • Revoke at Google: in your Google Account third-party connections, select the relevant Kylon connection and remove its access to your Google Account. This stops further access under that authorization; it does not delete data already stored in Kylon.
  • Previously imported content and derived information: emails, files, events, spreadsheet content, summaries, drafts, or other results copied into workspace resources may remain after disconnect or revocation. Use the relevant resource’s deletion controls where available, or request deletion from us. Deleting a Kylon copy is distinct from deleting the original in your Google account.
  • Deletion requests: email privacy@kylon.io to request deletion of Google data and its derivatives, identifying the connected account and relevant workspace. Do not send passwords or tokens. Our engineering and technical team handles these requests. To verify your identity and authority, we may contact an email address already associated with your Kylon account or the relevant connected account and ask you to reply with a temporary verification code and confirm the account, workspace, and data covered by your request. We do not rely solely on the sender address of the initial email. Logs, backups, and copies held by task recipients require separate handling; legally required records and necessary security records remain subject to the narrow exceptions above.

9. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information:

9.1 Rights Under the EU/EEA General Data Protection Regulation (GDPR)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the right to:

  • Access: request a copy of the personal data we hold about you.
  • Rectification: request correction of inaccurate or incomplete personal data.
  • Erasure (“right to be forgotten”): request deletion of your personal data, subject to legal exceptions.
  • Restriction: request that we restrict processing of your personal data in certain circumstances.
  • Data portability: receive your personal data in a structured, commonly used, machine-readable format.
  • Object: object to processing based on legitimate interests, including profiling.
  • Withdraw consent: withdraw consent at any time where processing is based on consent.
  • Lodge a complaint: file a complaint with your local data protection authority.

To exercise these rights, contact us at the address provided in Section 15. We will respond within 30 days (or as required by applicable law).

Data Protection Officer: Quinn — privacy@kylon.io

9.2 Rights Under the California Consumer Privacy Act (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know: request disclosure of the categories and specific pieces of personal information we have collected about you.
  • Delete: request deletion of your personal information, subject to legal exceptions.
  • Correct: request correction of inaccurate personal information.
  • Opt out of sale/sharing: the advertising and visitor-identification tools on our marketing website (Section 10) may count as “selling” or “sharing” personal information for cross-context behavioral advertising. Use Privacy choices at the bottom of any kylon.io page to turn advertising off, or turn on Global Privacy Control in your browser, which we honor as an opt-out: we stop personalized ads and remarketing, keep ad measurement only under Google’s restricted data processing and Meta’s Limited Data Use, and do not load RB2B. RB2B also offers its own opt-out at app.retention.com/optout.
  • Non-discrimination: we will not discriminate against you for exercising your privacy rights.
CCPA CategoryExamples
IdentifiersName, email address, device identifiers, account ID
Internet or electronic network activityUsage data, error logs, session information
Professional or employment-related informationWorkspace membership, role within workspaces
Geolocation dataTimezone setting (approximate location only)
Audio, electronic, or visual informationVoice call audio, uploaded files
InferencesAI-generated content based on workspace data

To submit a CCPA request, contact us at the address provided in Section 15. We will verify your identity before processing your request.

9.3 Rights Under Singapore’s Personal Data Protection Act (PDPA)

If you are located in Singapore, you have the right to:

  • Access: request access to your personal data held by us and information about how it has been used or disclosed in the past year.
  • Correction: request correction of any error or omission in your personal data.
  • Withdrawal of consent: withdraw your consent for collection, use, or disclosure of your personal data (subject to legal and contractual restrictions).
  • Data portability: request a copy of your data in a commonly used machine-readable format (where applicable under the PDPA’s data portability provisions).

To exercise these rights, contact our Data Protection Officer at the address provided in Section 15.

9.4 How to Exercise Your Rights

You may exercise your rights by contacting us using the information in Section 15. We may need to verify your identity before fulfilling your request. We will respond within the timeframe required by applicable law.

10. Cookies and Tracking Technologies

10.1 How we ask on kylon.io

Where the law asks for consent first (the European Economic Area, the United Kingdom, Switzerland, Singapore, Brazil, Quebec, Turkey, Nigeria, Vietnam, China, Israel, the United Arab Emirates, Saudi Arabia and Thailand, and any visitor whose country we cannot tell), nothing optional runs on our marketing website until you choose in our cookie banner, and rejecting is as easy as accepting. In Canada outside Quebec, Australia, Mexico and some other countries, analytics and advertising are on by default and a short notice says so on your first visit. In the United States, Japan, India, South Korea and the other places where no notice is required, they are on by default without a banner. Wherever you are, you can change your choice at any time under Privacy choices at the bottom of every page.

If your browser sends Global Privacy Control, we treat it as an opt-out of selling and sharing: we do not personalize ads or add you to remarketing lists, ad measurement continues only under Google’s restricted data processing and Meta’s Limited Data Use, and RB2B does not load. We do not respond to browser Do Not Track signals, which have no agreed meaning; Global Privacy Control and Privacy choices are how to opt out.

Until you choose in the banner, our analytics provider (PostHog) counts visits without storing anything on your device: it combines your IP address and browser details with a value that changes every day, does not keep your IP address, and receives no campaign tags, ad click identifiers or referring page beyond its domain. We can see how many people visited a page, not who they are. If you reject, or turn analytics off, your visits are not counted at all.

When advertising is on, other parties, including Google, Meta and, for visitors in the United States outside California, RB2B and its identity partners, may collect information about your online activities over time and across different websites.

When you make a choice, we keep a record of it (a random identifier, the time, your region, the version of the banner and what you chose) so we can show what you agreed to. A consent lasts 12 months (6 months in France) and a refusal 6 months; then we ask again, or sooner if we add a partner.

Open Privacy choices

10.2 What kylon.io uses

Category and toolWhat it doesWhat it stores, and for how longWho receives data
Strictly necessary: KylonRemembers your region and your privacy choicekylon_region (1 day), kylon_consent (up to 12 months, with a random ID); a record of each choice in our consent logNo one
Strictly necessary: Clerk, only if you have signed in to Kylon on this browserShows Open App instead of Sign in__client_uat (on kylon.io) and __client (on clerk.kylon.io), set when you sign in to KylonClerk
Strictly necessary: CloudflareProtects sign-in and booking from automated abuse__cf_bm (30 minutes) on clerk.kylon.io and cal.comCloudflare
Functional: KylonRemembers, in one browser tab, that you arrived from an ad or a partner campaign, to show the matching sign-up button or offerkylon_paid_session, kylon_offer_campaign (session storage, closes with the tab)No one
Analytics: PostHogPage views, clicks and site performanceWith analytics on: ph_phc_..._posthog (cookie and local storage, 1 year). Before you choose in the banner: nothing (visits counted without cookies). After you reject or turn analytics off: nothing, and visits are not countedPostHog (United States)
Analytics: KylonA one-time code added to the link when you go from kylon.io to app.kylon.io, so a click can be matched to a sign-upNot stored on kylon.ioKylon
Advertising: Google AdsMeasures ad clicks and conversions and builds remarketing audiences (with Global Privacy Control: measurement only)_gcl_au, _gcl_aw (90 days), _gcl_ls (local storage), and cookies on Google domainsGoogle
Advertising: Meta PixelMeasures and improves our ads on Facebook and Instagram_fbp, _fbc (90 days), local storage entries, and cookies on facebook.comMeta
Advertising: KylonRemembers the ad or campaign that brought you, so a later sign-up can be credited to itkylon_ft, kylon_lt (90 days, shared with app.kylon.io, set by our server when you arrive from a campaign)Kylon; ad click identifiers may be reported to Google Ads
Advertising, United States outside California only, and not with Global Privacy Control: RB2B with LiveIntent and other identity partnersIdentifies the business, and in some cases the person, visiting the site, from browser and IP data_reb2b cookies (up to 1 year), _lc2_fpi (up to 400 days), and cookies on the partners' own domainsRB2B (GetEmails, LLC) and its identity partners
Advertising: XShows posts from X embedded in some blog articlesCookies on x.com, only once the post is shownX
Booking: Cal.comThe Book a demo calendar, when you open it__cf_bm on cal.com (30 minutes)Cal.com

10.3 Turning things off

Use Privacy choices on any kylon.io page, or turn on Global Privacy Control in your browser (which turns off ad personalization, remarketing and RB2B). Turning a category off removes the cookies those tools left on kylon.io; cookies on the providers’ own domains are removed through your browser settings or the providers’ controls: Google Ads settings, Meta ad preferences, RB2B opt-out, LiveIntent opt-out, aboutads.info/choices and youronlinechoices.eu.

10.4 Product (app.kylon.io)

TypePurposeDuration
Strictly necessaryAuthentication, session management, securitySession / persistent
FunctionalUser preferences, language, timezonePersistent
AnalyticsProduct usage analytics (PostHog), enabled after sign-inPersistent

Our authentication provider (Clerk) may set cookies inside the product (app.kylon.io) for authentication and session management. Once you sign in, our analytics provider (PostHog) may set cookies to associate product usage with your account. When you sign up, the product also reads the kylon_ft and kylon_lt cookies and Meta’s _fbp and _fbc cookies, if your choices on kylon.io allowed them, to record which ad or campaign brought you.

11. Children’s Privacy

The Service is not intended for use by individuals under the age of 16 (or under 13 in the United States). We do not knowingly collect personal information from children under these ages.

If we become aware that we have collected personal information from a child under the applicable age threshold, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at the address provided in Section 15.

12. International Data Transfers

Your personal information may be transferred to, stored in, and processed in countries other than your country of residence, including the United States, where our primary infrastructure is located. Our Data Processing Agreement, available at kylon.io/dpa, sets out the safeguards that apply to such transfers, including the EU Standard Contractual Clauses where applicable.

By using the Service, you acknowledge that your information may be transferred to and processed in jurisdictions with different data protection laws than your own.

13. Data Processing Agreement

Where Pure Reason processes Personal Data as a processor on behalf of a Customer, our Data Processing Agreement, available at kylon.io/dpa, sets out our processing terms — including our roles, sub-processor arrangements, and the EU Standard Contractual Clauses that apply to international transfers — and is incorporated by reference into our agreement with that Customer.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make material changes, we will:

  • Update the “Last Updated” date at the top of this policy.
  • Notify workspace administrators via email and in-app notification.
  • Disclose material changes to Google-data uses or sharing before implementing them and obtain explicit consent before the new processing where required by Google policy or applicable law.

We encourage you to review this Privacy Policy periodically. Continued use is not consent to a new Google-data purpose, a new recipient or sharing arrangement that requires consent, or additional Google permissions. Any required consent must be obtained separately before the affected processing begins.

15. Contact Information

If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about our data practices, please contact us at:

Pure Reason Inc.
privacy@kylon.io

For GDPR inquiries: Quinn — privacy@kylon.io

For CCPA requests: privacy@kylon.io

16. Supplemental Notices

16.1 For Workspace Administrators

As a workspace administrator, you may have additional responsibilities under applicable data protection laws regarding the personal data of members in your workspace. You act as a data controller (or equivalent) for content data created within your workspace, and Pure Reason acts as a data processor on your behalf. Our Data Processing Agreement is available at kylon.io/dpa.

16.2 For AI Agent Developers

If you develop or configure AI agents within Kylon, you are responsible for ensuring that the agents you deploy comply with applicable data protection laws and do not process personal data beyond the scope authorized by your workspace’s data governance policies.

© 2026 Pure Reason Inc. All rights reserved.