Last updated: October 7, 2026
Privacy Policy
Effective Date: May 22, 2026
1. Introduction
This Privacy Policy describes how Pure Reason Inc. (“Pure Reason,” “we,” “us,” or “our”), a Delaware corporation, collects, uses, discloses, and protects personal information through our product Kylon and our website at kylon.io (collectively, the “Service”).
Kylon provides individuals and teams with a platform to build and manage Agent Teams.
This policy explains our data practices. Reading this policy or continuing to use the Service does not, by itself, authorize a new use or sharing of your Google user data. Where consent is required, it must be obtained separately before that processing begins.
This Privacy Policy applies to all users of the Service, including workspace administrators, members, and any individuals whose information may be processed through the Service.
2. Information We Collect
We collect information in the following categories:
2.1 Account Information
When you create an account or are invited to a workspace, we collect:
- Name and display name
- Email address
- Avatar image URL
- Authentication provider information (e.g., SSO provider, session identifiers)
Account creation and authentication are managed through our authentication partner, Clerk. Please refer to Section 6 and Clerk’s own privacy policy for details on their data handling practices.
2.2 User Preferences
We store your configurable preferences, which may include:
- Timezone and language settings
- User interface preferences
- Notification preferences
2.3 Device and Session Information
When you access the Service, we automatically collect:
- Device information: installation identifier, platform (web, macOS, iOS, Android), client type, device name, and application version
- Session information: authentication provider used, session identifiers, session issuance time, last activity time, and session expiration time
- First and last seen timestamps for each device
2.4 Content Data
The Service is designed for collaboration, and we process content you and other workspace members create, including:
- Messages: text messages sent in rooms and threads
- Files: documents, images, and other files you upload, along with associated metadata (file name, MIME type, file size)
- Table data: structured data entries you create in workspace tables
- Voice and audio data: audio from voice meetings and calls conducted through the Service
2.5 Connection and Integration Data
When you connect third-party services to your workspace (e.g., Gmail, GitHub, Notion, Twitter/X), we collect:
- OAuth tokens and API keys for the connected service (stored in encrypted form)
- External account identifiers and remote user identifiers
- Connection metadata (service type, connection status)
We do not access data from connected third-party services beyond the scope of permissions you grant during the connection process.
2.6 Usage and Analytics Data
We collect product usage data to improve the Service, including:
- Feature usage patterns and interaction events
- Performance metrics
- Error reports (error messages, page URLs, HTTP status codes, request identifiers)
2.7 Push Notification Tokens
If you enable push notifications, we collect device tokens necessary to deliver notifications via:
- Web Push (VAPID protocol)
- Firebase Cloud Messaging (FCM) for Android
- Apple Push Notification Service (APNs) for iOS and macOS
2.8 Phone Number and SMS Verification Data
If you choose to verify a phone number, we collect:
- The mobile phone number you enter
- Your consent to receive a verification text message at that number, and the date and time that consent was given
- Delivery and verification records for the messages we send (such as sent, delivered, verified, or failed)
Providing a phone number is optional. We use it only to send one-time verification codes, never for marketing or promotional messages. We send one message per verification request you make, so message frequency depends on how often you request a code. Message and data rates may apply. Reply STOP to any message to opt out, or HELP for help. The full program terms are in our Terms of Service.
2.9 Google Integrations and Google User Data
Connecting a Google account is separate from signing in to Kylon with Google. For a Google connection, we process account identifiers and authorization tokens, and access the categories below only as permitted by the Google products you connect, the permissions you grant, and the features you request or enable. A connection does not mean every category or every item in your account is always read.
- Gmail: messages and threads, message bodies, attachments, labels, drafts, and send-as aliases, for requested email search and summaries, drafting and sending messages, and authorized labeling and email management.
- Google Calendar: calendar lists, events and attendees, availability (free/busy), settings, and sharing permissions, for calendar queries, scheduling or changing events, and authorized calendar and sharing management.
- Google Drive: file contents and metadata, folders, and permissions, for searching and reading files, uploading, creating or modifying files, and sharing management you request.
- Google Docs: document contents, structure, and formatting, for reading, creating, and editing documents.
- Google Sheets: cell contents and formulas, worksheet structure, and formatting, for reading, creating, and editing spreadsheets.
Features such as stored email activity and Email Understanding can retain retrieved email content and derived information to support the feature you enable. Email Understanding can analyze sent-mail and thread history to help draft replies in your context; this is not limited to the single message in your current request. Sections 5, 6, and 8 explain AI processing, sharing, and deletion boundaries.
3. How We Collect Information
We collect information through the following means:
- Directly from you: when you create an account, configure your profile, send messages, upload files, set preferences, or connect third-party services.
- Automatically: through your use of the Service, including device information, session data, and usage analytics.
- From authentication providers: account information is synchronized from our authentication provider, Clerk, based on your sign-up or SSO login.
- From third-party integrations: when you authorize connections to external services, we receive authentication credentials and identifiers from those services via OAuth or API key exchange. Our native Google integrations use Google OAuth and call Google APIs directly. Composio supports some other integrations; it is not the intermediary for these native Google connections.
- From AI model providers: responses generated by AI agents in your workspace are received from third-party AI model providers (see Section 5).
4. How We Use Information
| Purpose | Legal Basis (GDPR) |
|---|---|
| Providing the Service: creating and managing your account, enabling workspace collaboration, processing messages, storing files, and facilitating AI agent interactions | Performance of contract |
| AI Processing: sending user content to third-party AI model providers to generate agent responses, summaries, and automated actions within workspaces | Performance of contract; Legitimate interest |
| Authentication and Security: verifying your identity, managing sessions, preventing unauthorized access, and detecting abuse | Performance of contract; Legitimate interest |
| Third-Party Integrations: connecting your workspace to external services you authorize, executing workflows, and synchronizing data | Performance of contract; Consent |
| Push Notifications: delivering real-time notifications about workspace activity to your devices | Consent; Performance of contract |
| Voice Communications: facilitating voice meetings and calls within workspaces | Performance of contract |
| Analytics and Improvement: understanding how the Service is used, diagnosing technical issues, and improving features and performance | Legitimate interest |
| Error Reporting and Debugging: collecting and analyzing error data to identify and resolve technical issues | Legitimate interest |
| Compliance: meeting legal obligations, responding to lawful requests, and enforcing our terms of service | Legal obligation; Legitimate interest |
| Communications: sending you service-related communications (e.g., security alerts, policy changes) | Performance of contract; Legitimate interest |
| SMS Verification: sending a one-time code by text message to a phone number you have provided, to confirm you control that number | Consent |
We do not sell your personal information for money, and we do not use the content of your workspace for advertising. On our marketing website (kylon.io) we use advertising tools from Google and Meta to measure and improve our ads, and in the United States RB2B to identify business visitors. Section 10 lists each tool and how to turn it off. Some US state laws may treat this as “selling” or “sharing” personal information; you can opt out at any time (Section 9.2). We do not use mobile phone numbers, SMS opt-in data, or messaging consent for marketing or promotional messaging.
4.1 Google API Limited Use
Use and transfer of information received from Google APIs is subject to the Google API Services User Data Policy, including its Limited Use requirements, and the Google Workspace API User Data and Developer Policy. These restrictions apply to the original Google data and information derived from it, including summaries, extracted content, and aggregated or de-identified information.
Google user data is limited to providing or improving the user-facing features you authorize and that are described in this policy. It must not be sold, used for advertising or targeted marketing, or repurposed for unrelated uses. The Google-specific restrictions in this policy govern notwithstanding the general purposes or legal bases described elsewhere in this policy.
5. AI Processing Disclosure
5.1 How AI Agents Work in Kylon
Kylon’s core functionality includes AI agents that operate as workspace members. These agents can read messages, generate responses, process files, execute workflows, and interact with connected services — all within the permissions and context of your workspace.
5.2 Data Sent to AI Model Providers
To enable AI agent functionality, user-generated content — including messages, file contents, table data, and related workspace context — is transmitted to third-party AI model providers listed on our Subprocessors page. The specific provider used may vary depending on the task, model routing configuration, and availability.
When you request or enable an Agent feature that works with Google data, relevant email messages or attachments, calendar events, Drive files, documents, spreadsheet contents, and information derived from them may be included in the task context sent to the AI service executing that task. The purpose is to carry out the requested search, summary, draft, edit, scheduling, or other authorized function, not to send your entire Google account to every provider on the list.
Kylon supports AI services including Anthropic, OpenAI, Google (Gemini / Vertex AI), and Cerebras, as well as model-routing services such as OpenRouter. The selected model and route determine the recipients; a routing service may also pass task context to the model provider. The Subprocessors page identifies services used by Kylon, not a promise that every service receives every task.
An Agent brought by a workspace member may run in that member’s local or separately hosted environment. Context delivered to that Agent can be processed in that environment and sent to its configured AI services. Its operator and service configuration therefore matter in addition to Kylon’s subprocessor list. Granting an Agent access can enable its future tasks to use that connection until access is removed.
5.3 What AI Providers Do with Your Data
Provider terms, account settings, and the selected processing route determine input and output retention. The following restrictions govern processing of Google user data by Pure Reason and its recipients:
- We do not use Google Workspace API data, including derived information, to develop, improve, or train general-purpose or non-personalized AI or machine-learning models. We do not permit AI service providers, routing services, or Agent operators receiving that data for a Kylon task to use it for those purposes. Task-specific context and personalized responses are not permission to train a general-purpose model.
- Kylon uses encrypted HTTPS/TLS connections to Google APIs and its AI service APIs. An Agent’s local storage and separately configured services have their own controls, which must be reviewed before enabling Google-data processing there.
- Providers may temporarily retain input and output data for abuse monitoring and safety purposes, in accordance with their policies. Depending on the API route and settings, response records and cached task context may also be retained for service operation. We do not represent that storage is disabled on every route; any retention of Google data must remain limited to permitted purposes and the same Google-data restrictions.
- Google data may be sent to a provider or Agent environment only under terms and settings consistent with these restrictions and the authorized feature. This policy is not a zero-retention guarantee for Kylon, AI providers, or Agent operators.
5.4 Your Control Over AI Processing
Workspace administrators can configure which rooms and workflows involve AI agent interactions. If you have questions about AI processing in your workspace, please contact your workspace administrator or reach out to us at the contact information provided in Section 15.
Before Google data is shared for AI processing, the product flow must disclose the relevant data, recipients, purpose, and sharing and obtain your informed, affirmative consent where required. This must be an in-product disclosure before authorization or the relevant processing, not merely a link to this policy, acceptance of general terms, or continued use of Kylon.
6. Information Sharing and Sub-processors
We share personal information only as described in this policy. We do not sell personal information.
6.1 Sub-processors
We use a number of third-party service providers (“sub-processors”) to operate the Service. A current, maintained list of our sub-processors — including their function — is available at: kylon.io/subprocessors. We update that page whenever our sub-processors change; we do not separately notify workspace administrators by email.
6.2 Other Disclosures
We may also share personal information:
- With your workspace administrator and members: content you contribute to a workspace is visible to other members of that workspace, subject to workspace and room access controls.
- As directed by you: when you connect third-party services or authorize specific data sharing.
- With analytics and advertising providers on our marketing website: PostHog, Google, Meta and, in the United States, RB2B and its identity partners receive the information described in Section 10, subject to your choices there.
- For legal compliance: to comply with applicable law, regulation, legal process, or governmental request.
- To protect rights and safety: to enforce our agreements, protect the rights, privacy, safety, or property of Pure Reason, our users, or the public.
- In business transfers: in connection with a merger, acquisition, reorganization, or sale of assets, in which case personal information may be transferred to the successor entity. Transfer of Google user data in a merger, acquisition, or sale of assets requires your explicit prior consent, and remains subject to the Google-specific restrictions below.
6.3 Mobile Phone Numbers, SMS Opt-In Data, and Messaging Consent
We do not sell, rent, or share mobile phone numbers, SMS opt-in data, or messaging consent with third parties or affiliates for marketing or promotional purposes. This information is disclosed to our messaging service providers only as needed to deliver and support phone verification, or where disclosure is required to comply with law. It is never shared with third parties for their own marketing purposes.
6.4 Google Data Access and Sharing Boundaries
A Google authorization grants access to the connection; it does not make your Google account public to the workspace. Connection access grants and task authorization control which members and Agents may use it. Content you choose to bring into a Room, file, App, or other workspace resource is then subject to that resource’s access controls. People who can use an Agent with a persistent connection grant may ask it to access data through that connection. Review both the connection grants and the Agent’s audience before sharing access.
For an Agent running outside Kylon’s managed environment, the operator may receive the task context even if they are not a member of the Room. Room permissions alone do not prevent access by that runtime or its configured AI services. The required disclosure and consent must cover this processing boundary.
Transfers of Google user data are limited to those necessary for the authorized user-facing feature with appropriate consent, for necessary security purposes, to comply with applicable law, or for a qualifying business transfer with your explicit prior consent. Recipients remain subject to the same Google data-use restrictions. General legal, safety, or business-transfer language elsewhere in this policy does not authorize unrestricted use or disclosure.
Human reading of Google user data is limited to Google-policy permitted circumstances: your affirmative agreement to view specific data (for example, to help resolve a support request), necessary security investigations such as abuse investigation, or applicable legal obligations. Routine human review of private Google content for unrelated purposes is not permitted.
7. Data Storage and Security
7.1 Where We Store Data
Your data is stored primarily on Google Cloud Platform infrastructure in the United States. Specific storage mechanisms include:
- PostgreSQL database (with pgvector extension) hosted on GCP for structured data (accounts, messages, tables, metadata)
- Google Cloud Storage (GCS) for uploaded files
- Redis for caching and ephemeral data
7.2 Security Measures
We implement technical and organizational measures designed to protect your personal information, including:
- Encryption at rest and in transit: data is encrypted in transit using TLS. Sensitive credentials (OAuth tokens, API keys) are encrypted at rest using pgcrypto.
- Authentication and access control: Clerk-based authentication with session management, API key authentication with rotation support, and role-based access control scoped to workspaces and rooms.
- Session management: device tracking, session expiration, and session revocation capabilities.
- Network security: CORS restrictions and API gateway protections.
- Secrets management: production secrets are managed through Doppler and GCP Secret Manager, with separation from application code.
- Monitoring: error reporting and logging infrastructure for incident detection.
While we take reasonable measures to protect your information, no method of transmission or storage is completely secure. We cannot guarantee absolute security.
7.3 SOC 2 Type II in Progress
Pure Reason's SOC 2 Type II is in progress to demonstrate our commitment to security, availability, and confidentiality.
8. Data Retention
We retain your personal information for as long as your account is active or as needed for the authorized purposes described in this policy, subject to your deletion rights and applicable law. Different categories are handled separately:
- Account data: retained for the duration of your account and handled through account-deletion procedures when you request deletion.
- Content data (messages, files, table data): retained for the duration of the workspace in which the content resides. Workspace administrators may delete content within the Service, subject to their permissions. Copies incorporated into other workspace resources need to be considered separately.
- Session and device data: session records are retained as needed for authentication, session management, and security.
- Usage and analytics data: retained in forms used for service analytics. Google user data and its derivatives remain subject to Section 4.1, including when aggregated or de-identified.
- Logs and backups: diagnostic records and backup copies have separate retention and deletion processes. Removing active content does not mean all logs or backups are immediately erased.
- Connection credentials: OAuth tokens and API keys are removed from the active connection record when an authorized user disconnects the connection. This is separate from deletion of retrieved content and backup copies.
We may retain certain information as required by applicable law or for necessary security investigations. Any exception for Google user data must also satisfy the Google-specific restrictions in this policy; it is not permission for indefinite or unrelated use.
This policy does not promise immediate erasure from every system, a uniform retention period across providers, or zero retention.
8.1 Disconnecting Google and Requesting Deletion
- Disconnect in Kylon: remove the relevant connection through its connection controls, using an account authorized to manage it. This removes the active connection and its credentials. Kylon attempts to revoke the Google token and clean up connection-specific stored content; those remote and storage cleanup steps are best-effort, not a guarantee that every copy is erased at the moment of disconnect.
- Revoke at Google: in your Google Account third-party connections, select the relevant Kylon connection and remove its access to your Google Account. This stops further access under that authorization; it does not delete data already stored in Kylon.
- Previously imported content and derived information: emails, files, events, spreadsheet content, summaries, drafts, or other results copied into workspace resources may remain after disconnect or revocation. Use the relevant resource’s deletion controls where available, or request deletion from us. Deleting a Kylon copy is distinct from deleting the original in your Google account.
- Deletion requests: email privacy@kylon.io to request deletion of Google data and its derivatives, identifying the connected account and relevant workspace. Do not send passwords or tokens. Our engineering and technical team handles these requests. To verify your identity and authority, we may contact an email address already associated with your Kylon account or the relevant connected account and ask you to reply with a temporary verification code and confirm the account, workspace, and data covered by your request. We do not rely solely on the sender address of the initial email. Logs, backups, and copies held by task recipients require separate handling; legally required records and necessary security records remain subject to the narrow exceptions above.
9. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
9.1 Rights Under the EU/EEA General Data Protection Regulation (GDPR)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the right to:
- Access: request a copy of the personal data we hold about you.
- Rectification: request correction of inaccurate or incomplete personal data.
- Erasure (“right to be forgotten”): request deletion of your personal data, subject to legal exceptions.
- Restriction: request that we restrict processing of your personal data in certain circumstances.
- Data portability: receive your personal data in a structured, commonly used, machine-readable format.
- Object: object to processing based on legitimate interests, including profiling.
- Withdraw consent: withdraw consent at any time where processing is based on consent.
- Lodge a complaint: file a complaint with your local data protection authority.
To exercise these rights, contact us at the address provided in Section 15. We will respond within 30 days (or as required by applicable law).
Data Protection Officer: Quinn — privacy@kylon.io
9.2 Rights Under the California Consumer Privacy Act (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know: request disclosure of the categories and specific pieces of personal information we have collected about you.
- Delete: request deletion of your personal information, subject to legal exceptions.
- Correct: request correction of inaccurate personal information.
- Opt out of sale/sharing: the advertising and visitor-identification tools on our marketing website (Section 10) may count as “selling” or “sharing” personal information for cross-context behavioral advertising. Use Privacy choices at the bottom of any kylon.io page to turn advertising off, or turn on Global Privacy Control in your browser, which we honor as an opt-out: we stop personalized ads and remarketing, keep ad measurement only under Google’s restricted data processing and Meta’s Limited Data Use, and do not load RB2B. RB2B also offers its own opt-out at app.retention.com/optout.
- Non-discrimination: we will not discriminate against you for exercising your privacy rights.
| CCPA Category | Examples |
|---|---|
| Identifiers | Name, email address, device identifiers, account ID |
| Internet or electronic network activity | Usage data, error logs, session information |
| Professional or employment-related information | Workspace membership, role within workspaces |
| Geolocation data | Timezone setting (approximate location only) |
| Audio, electronic, or visual information | Voice call audio, uploaded files |
| Inferences | AI-generated content based on workspace data |
To submit a CCPA request, contact us at the address provided in Section 15. We will verify your identity before processing your request.
9.3 Rights Under Singapore’s Personal Data Protection Act (PDPA)
If you are located in Singapore, you have the right to:
- Access: request access to your personal data held by us and information about how it has been used or disclosed in the past year.
- Correction: request correction of any error or omission in your personal data.
- Withdrawal of consent: withdraw your consent for collection, use, or disclosure of your personal data (subject to legal and contractual restrictions).
- Data portability: request a copy of your data in a commonly used machine-readable format (where applicable under the PDPA’s data portability provisions).
To exercise these rights, contact our Data Protection Officer at the address provided in Section 15.
9.4 How to Exercise Your Rights
You may exercise your rights by contacting us using the information in Section 15. We may need to verify your identity before fulfilling your request. We will respond within the timeframe required by applicable law.
11. Children’s Privacy
The Service is not intended for use by individuals under the age of 16 (or under 13 in the United States). We do not knowingly collect personal information from children under these ages.
If we become aware that we have collected personal information from a child under the applicable age threshold, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at the address provided in Section 15.
12. International Data Transfers
Your personal information may be transferred to, stored in, and processed in countries other than your country of residence, including the United States, where our primary infrastructure is located. Our Data Processing Agreement, available at kylon.io/dpa, sets out the safeguards that apply to such transfers, including the EU Standard Contractual Clauses where applicable.
By using the Service, you acknowledge that your information may be transferred to and processed in jurisdictions with different data protection laws than your own.
13. Data Processing Agreement
Where Pure Reason processes Personal Data as a processor on behalf of a Customer, our Data Processing Agreement, available at kylon.io/dpa, sets out our processing terms — including our roles, sub-processor arrangements, and the EU Standard Contractual Clauses that apply to international transfers — and is incorporated by reference into our agreement with that Customer.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make material changes, we will:
- Update the “Last Updated” date at the top of this policy.
- Notify workspace administrators via email and in-app notification.
- Disclose material changes to Google-data uses or sharing before implementing them and obtain explicit consent before the new processing where required by Google policy or applicable law.
We encourage you to review this Privacy Policy periodically. Continued use is not consent to a new Google-data purpose, a new recipient or sharing arrangement that requires consent, or additional Google permissions. Any required consent must be obtained separately before the affected processing begins.
15. Contact Information
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about our data practices, please contact us at:
Pure Reason Inc.
privacy@kylon.io
For GDPR inquiries: Quinn — privacy@kylon.io
For CCPA requests: privacy@kylon.io
16. Supplemental Notices
16.1 For Workspace Administrators
As a workspace administrator, you may have additional responsibilities under applicable data protection laws regarding the personal data of members in your workspace. You act as a data controller (or equivalent) for content data created within your workspace, and Pure Reason acts as a data processor on your behalf. Our Data Processing Agreement is available at kylon.io/dpa.
16.2 For AI Agent Developers
If you develop or configure AI agents within Kylon, you are responsible for ensuring that the agents you deploy comply with applicable data protection laws and do not process personal data beyond the scope authorized by your workspace’s data governance policies.
© 2026 Pure Reason Inc. All rights reserved.