K Kraitos
Home About Us Demo FAQ
Privacy Policy

Privacy Policy

LAST UPDATED: JULY 2, 2026

Kraitos ("we," "our," or "us") is committed to protecting privacy and handling personal data transparently. This Privacy Policy explains how we collect, use, store, share, and protect information when you visit kraitos.app, visit emploai.kraitos.app, join a waitlist, sign in, receive beta builds, use the EmploAI desktop runtime, connect to the cloud backend at api.kraitos.app, or use related AI agent, diagnostic, release, and fleet-management features.

1. Who Controls Your Data

Kraitos is the controller of personal data collected through the Kraitos and EmploAI websites, official desktop builds, account systems, waitlist, cloud backend, and support workflows, unless a separate written agreement says otherwise. Privacy and data-rights requests can be sent to security@kraitos.app. Legal notices can be sent to legal@kraitos.app. If we appoint a statutory data protection officer or Israeli privacy protection officer, we will publish that contact here.

2. Scope

This policy applies to the Kraitos website, EmploAI website, Windows desktop app, cloud APIs, beta distribution hub, account services, fleet-management features, diagnostics, support workflows, and official release controls. Legacy mobile, pairing, or Telegram records, if any exist from earlier testing, are also handled under this policy as legacy account data.

3. Notice When You Provide Information

Unless a form says otherwise, providing personal information is voluntary. If you do not provide information required for a feature, we may not be able to provide that feature, approve beta access, authenticate your account, send access links, or respond to support requests. We request information for the purposes described in this policy, and we disclose it only to the recipient categories listed here or when required by law.

4. Information We Collect

Depending on which Kraitos or EmploAI features you use, we may collect or process the following categories of information:

  • Account and contact data: Email address, account identifiers, display name, beta waitlist status, approval status, assigned build bundle, and support messages you send us.
  • Authentication and device data: Login tokens, session tokens, generated device IDs, desktop names, token expiration metadata, revocation status, and legacy pairing records if they exist.
  • Desktop app data: Desktop runtime configuration, installation and update status, operating system information, provider settings, local runtime logs, workspace metadata, command history, chat messages, task results, cloud connection status where enabled, and Yggdrasil or mesh connection status for fleet features.
  • User content and AI task data: Prompts, commands, chat messages, uploaded files, selected images, generated outputs, workspace files, screenshots, tool results, and other content you intentionally provide to the agent runtime or ask the agent to process.
  • Screen, file, and audio data: The desktop app may process screen captures, local files, and microphone/audio input when you enable features that require them. Future features that require new device permissions will use platform permission prompts where applicable.
  • Cloud backend data: API requests, IP address, user agent, timestamps, logs, rate-limit data, workspace recovery/sync metadata, remote-control session events, queued commands, status reports, grants, locks, audit events, and error diagnostics.
  • Third-party connection data: If you connect Google, Meta/Facebook, AI model providers, or other integrations, we may process the account identifiers, tokens, scopes, profile/contact information, messages, files, or API responses you authorize those services to provide. Legacy Telegram records, if any exist from earlier testing, are treated as integration data.
  • Website and waitlist data: Email address, Turnstile anti-spam token results, local storage flags for waitlist state, browser type, IP address, page requests, and beta access link metadata.

5. Phone and Mobile Connections

The current Kraitos/EmploAI testing channel does not include a phone companion, mobile pairing flow, or Telegram command surface. If legacy mobile or phone-connection records exist from earlier testing, they are treated as account data and can be deleted through the process below.

6. Why We Use Information

We use information to:

  • Operate accounts, beta approvals, build distribution, and access links.
  • Send transactional emails such as account verification codes, login notices, beta approvals, access links, and support messages.
  • Authenticate account, desktop, cloud, and fleet-management sessions.
  • Send commands, chat messages, files, screenshots, and task results between the desktop app, Yggdrasil or mesh-connected worker machines, cloud backend where enabled, fleet surfaces, and enabled integrations.
  • Run AI agent workflows, generate responses, execute user-approved actions, and return task outputs.
  • Maintain cloud backend reliability, security, abuse prevention, rate limits, diagnostics, audit trails, and support workflows.
  • Improve app quality, fix bugs, verify build compatibility, and develop fleet-management features.
  • Comply with legal obligations and platform requirements.

7. Legal Bases Where Required

Where a law such as the GDPR, UK GDPR, or another privacy law requires a legal basis, we rely on one or more of the following: your consent, performance of a contract or pre-contract request, our legitimate interests in operating and securing the service, compliance with legal obligations, and protection of rights, safety, and security. You may withdraw consent where processing is based on consent, but withdrawal does not affect earlier lawful processing.

8. Local Processing and Cloud Processing

EmploAI is designed around a desktop owner runtime, with Kraitos providing hosted account and backend services where needed. Many actions, files, credentials, screen captures, and provider API keys may stay on your desktop depending on your configuration. When you enable cloud, workspace recovery, account sync, AI provider, fleet-management, or integration features, relevant data may be transmitted through the Kraitos cloud backend, across a Yggdrasil or peer mesh for machine-to-machine fleet features, or to the third-party services you selected so those features can work.

You should not send sensitive files, credentials, financial information, health information, or confidential third-party data to the agent unless you have the right to do so and understand which enabled services will process it.

9. Cookies, Local Storage, and Similar Technologies

We may use cookies, local storage, session storage, and similar technologies to keep you signed in, remember consent and waitlist state, protect forms from abuse, store approval tokens for gated downloads, measure basic site operation, and improve reliability. We do not use advertising cookies for cross-site behavioral advertising. You can control cookies through your browser, but blocking storage may prevent sign-in, waitlist state, or beta access links from working correctly.

10. Sharing and Disclosure

We do not sell your personal data. We share information only as needed to operate, secure, or improve Kraitos, or when you direct us to connect with another service. Recipients may include:

  • Hosting, backend, and storage providers: Used to host the website, APIs, beta access database, logs, and cloud workspace features.
  • Netlify and Netlify Blobs: Used for the public website, waitlist, approval status, and beta access metadata.
  • Cloudflare: Used for Turnstile bot challenge validations and related anti-abuse protections.
  • Resend: Used to deliver transactional emails such as verification codes, login notices, beta approval messages, access links, and support emails.
  • Google: Used for OAuth/sign-in features when enabled and platform services you choose to use.
  • AI model and speech providers: OpenAI, Anthropic, Google/Gemini, xAI, DeepSeek, OpenRouter, or other providers you configure may receive prompts, chat history, images, files, screenshots, audio transcripts, tool outputs, and related context needed to fulfill your requests.
  • Integration providers: Meta/Facebook, Google Workspace, and other connected services may receive or return data according to the integrations you enable and their own policies. Legacy Telegram records, if any exist, are handled as retained integration data.
  • Legal and safety recipients: We may disclose information if required by law, to protect rights and safety, investigate abuse, or enforce our terms.

11. AI Providers and Automated Processing

When you connect or select an AI provider, prompts, files, images, screenshots, audio transcripts, tool outputs, and related context may be sent to that provider so it can return model output. AI output can be inaccurate or incomplete, and you are responsible for reviewing results before relying on them. We do not use fully automated decisions to approve or deny legal rights; beta access and account gating may use automated checks but can be reviewed by the EmploAI owner or Kraitos support contact.

12. International Transfers

We may process and store information in Israel, the United States, the European Economic Area, or other countries where our providers operate. Where required, we use appropriate safeguards for international transfers, such as contractual restrictions, processor obligations, technical safeguards, and applicable legal exceptions. If EEA-origin data is stored in Israeli databases, we aim to handle it consistently with applicable Israeli rules for EEA-transferred data.

13. Retention

We retain personal data only as long as needed for the purposes described in this policy, including account operation, beta access, security, debugging, legal compliance, and abuse prevention. Waitlist and beta access records are kept while your account or approval is active. Cloud backend logs, fleet events, legacy pairing records if any, and diagnostics may be kept for a limited period for security and troubleshooting. Local desktop data remains on your machine unless you enable features that transmit or sync it. We may keep limited records where needed for legal, security, fraud-prevention, backup, or dispute purposes.

14. Security

We use administrative, technical, and organizational safeguards including HTTPS, HTTP Strict Transport Security (HSTS), Content Security Policy (CSP), cryptographic token validation, token expiration, secure local storage where available, access controls, peer-mesh isolation where enabled, rate limiting, abuse monitoring, least-privilege practices, and vendor review where appropriate. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

15. Your Choices and Rights

You can choose whether to join the waitlist, install the desktop app, connect third-party accounts, upload files/images, enable cloud or fleet features, or provide AI provider API keys. Depending on your location, you may have rights to access, inspect, correct, delete, export, restrict, or object to processing of your personal data. Israeli users may request inspection of personal data kept about them and correction of information that is incorrect, incomplete, unclear, or outdated. You may also object to direct marketing or request removal from direct-mailing lists where applicable.

To exercise rights, contact security@kraitos.app. We may need to verify your identity before acting on a request. You may also contact the Israeli Privacy Protection Authority or another competent regulator if you believe your privacy rights were violated.

16. Data Deletion

You may request deletion of your waitlist, beta access, desktop app, cloud backend, fleet, mesh peer records, legacy pairing, or integration-related personal data by contacting us at security@kraitos.app, or by following the account deletion instructions at kraitos.app/delete-account. Include the email address, account identifier, or device identifier associated with your Kraitos access so we can locate the relevant records. Deleting cloud records may not delete files or settings stored locally on your own desktop or other machines in your mesh; you can remove those by uninstalling the app or deleting local app data.

17. United States Privacy Notice

We do not sell personal information or share it for cross-context behavioral advertising. If a U.S. state privacy law applies to you, you may have rights to know, access, correct, delete, obtain a copy of, or opt out of certain processing of personal information. We will not discriminate against you for exercising privacy rights.

18. Children

Kraitos and EmploAI are not directed to children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has provided personal data to us, contact us so we can delete it.

19. Changes to This Policy

We may update this Privacy Policy as Kraitos evolves. The "Last Updated" date above shows when the policy was last revised. Material changes will be reflected on this page and, when appropriate, in app or account notices.

20. Contact Us

If you have questions or comments about this Privacy Policy, please contact us at:

security@kraitos.app

Legal notices: legal@kraitos.app

© 2026 Kraitos. All rights reserved.

kraitos.app Privacy Policy Delete Account Terms of Service License Agreement Accessibility / נגישות GitHub