Privacy policy
What Kemble collects, why, where it goes, how long we keep it, and what you can do about it. Written from the code that does it, including the parts that are less flattering.
Effective
Who we are
Kemble is one product with two surfaces: Kemble Work, for companies, and Kemble Circle, for communities. This policy covers both, the app at kemble.io/app, and this website.
Questions, requests and complaints about your data go to privacy@kemble.io. Security vulnerabilities go to security@kemble.io instead.
If you use Kemble through an organization — your employer’s workspace, a community you joined — its administrators decide several things on this page: how long messages are kept, whether K Buddy, GIFs and activities are on, and who can see which channels. Where that is so, we say so. If your question is about how your organization uses Kemble, ask its administrators too; we will help them answer it.
What we collect and why
Your account
- Your name, username and email address, and a phone number if you sign in with one. To identify you and let people find you.
- Your password, stored only as an Argon2 hash. It cannot be recovered, by you or by us.
- Two-factor authentication: the secret is stored encrypted, recovery codes only as hashes. Passkeys: the public key and the name of the device, never anything that could sign in as you.
- What you choose to add to your profile: picture, banner, bio, pronouns, title, status. Your language and time zone, so times and notifications arrive when you expect them.
- How to say your name, if you add it: a spelling, and a recording of up to five seconds made in your browser. Both are shown on your profile card in every workspace and community you belong to, and the recording is deleted from storage when you remove it or replace it.
- In a Kemble Work workspace, your answers to the profile fields it asks everyone — a team, a start date, a manager. An admin can fill in the fields marked admins-only. Everybody in that workspace can see them on your card.
- In Kemble Circle, a community’s tag, if you choose to wear one: its letters and badge are shown beside your name wherever you appear in Kemble Circle — including to people outside that community — which says you belong to it. Only people your profile setting lets see your profile see it, and you can take it off at any time.
- Your display and accessibility choices — reduced motion, text size, colour, how stickers and emoji move — saved to your account so they follow you to every device you sign in on, and kept on each device so pages open the way you set them.
- If you sign in with Google or a phone number, Google confirms who you are and tells us your name, email address, phone number and the address of your profile picture. We store the ones your account does not already have.
What you put into Kemble
Messages, threads, reactions, files, canvases, polls, tasks, drafts and everything else you create, and the organizations, spaces, channels and roles you belong to. Stored so they can be read back, searched and shared with the people you shared them with. When you send a GIF, the message keeps the GIF and the words you searched for to find it. While you have a canvas open, the others in it see your name and where you are typing; that is not stored.
When you post a link, our server fetches that page (as KembleBot) to show a preview, and stores the title, description and picture address. The people reading the message then load the preview picture straight from that website. You can send a message without previews.
A message an app or an incoming webhook posts can carry a card with pictures; the people reading it load those pictures straight from the address the app gave, as they do a link preview’s.
Workflows your workspace builds, and what happens when they run: the answers you give a workflow’s form are kept with it, and each run keeps a record of the steps it took and what they made — messages it posted, items it added, the values it passed along. The people who manage the workflow can read both, and download the answers. A workflow acts with the permissions of the person who published it, checked again at every step.
What the product records as you use it
- Sign-in sessions: the IP address and browser each one was started from, and when. So you can see where you are signed in and end any of it, and so we can investigate misuse. We also record the IP address that asks for an email sign-in code.
- Push notifications, if you turn them on: the device’s push token and browser.
- Presence: whether you are online, and when you were last seen. Choosing “invisible” shows you as offline to everyone and hides when you were last seen.
- Working hours: in a Kemble Work workspace, your colleagues see your local time and, from the notification schedule you set, the hours you receive notifications and whether a message sent now would reach you — or that you have do not disturb on. Kemble Circle communities are never shown this.
- Read position: how far you have read in each channel. Other members of a channel can see it, and there is no setting to hide it yet.
- An audit trail of consequential actions — who did what, to what, and when — which your organization’s administrators can read. It is append-only.
- Usage counts for the limits your plan enforces, including how many AI tokens your organization has used. Counts, not content.
- Request and error logs on our own server, which include IP addresses, so we can fix faults and stop abuse.
Payments
Card details are always typed into the payment provider’s own page, never into Kemble’s. We keep the provider’s ids for the subscription and invoices, amounts, status and receipt links, and each notification the provider sends us about a payment, exactly as it was sent. Depending on the provider, those notifications include the buyer’s email address and details of the card used.
This website
The contact form sends what you type — name, email, organization, topic and message — to the right team’s inbox as an email. It is not stored in the product’s database. To stop the form being abused, your IP address and email are counted for an hour.
What we do not do
- We do not sell your data, and we do not show advertising.
- We do not use your content to train AI models. What the AI providers may do with a request is set by their own terms, linked in the table below.
- There is no analytics or tracking script in the website or the app.
What K Buddy sees, and when
K Buddy is Kemble’s AI assistant. It runs only when somebody asks it something or uses one of the features listed below. It reads what it is allowed to read for that person, and sends what it read to the AI provider to produce an answer.
When you ask it something
The provider receives your question, the earlier turns of that conversation, and your display name, organization, channel name and local time. Not your account id and not your email address.
- What is on your screen. If your organization has screen context on, the app tells our server which messages, thread, canvas or file you have open — as ids — and the server reads them with your permissions. You can take an item out of a question before you send it.
- Pictures you can see. If pictures are on, images you can see may go to the provider as images, up to six a question unless your organization sets fewer.
- Its own lookups. If tools are on, K Buddy can search and read further — again only what you can read. Anything that would change something is offered to you as a proposal and happens only if you click it.
- In a channel, an @K Buddy answer draws only on that conversation, because the answer is posted where others read it.
When it runs without a question
Some features use K Buddy as part of what they do, and each sends the provider the content it works on:
- In Circle, the catch-up of topics since you left, when you open a channel with unread messages, and the Today catch-up card.
- Routines and daily recaps that you set up yourself, on the schedule you chose.
- Workflow steps an administrator has configured to use K Buddy.
- Translate, explain and summarise, when you press them.
- Write with K Buddy in a canvas, when you ask it to: your request, the canvas as you can read it, and any words you selected. Nothing goes into the canvas until you choose Insert.
- AI notes on a call, when somebody in the call starts them or the channel has automatic AI notes on. Never in an encrypted call, and never in a call with guests.
- Trivia questions a game’s host asks K Buddy to write, drawn only from channels everyone in the community can read. You can opt out of being quoted.
What we keep
- Your K Buddy conversations — your questions, its answers, the ids of what was on screen, and what it searched for — until you delete the conversation, or your account or organization is deleted.
- A record of each read K Buddy made on your behalf, holding ids only, for 90 days, so administrators can see what it looked at.
- Token counts for your organization’s allowance.
- Translations are cached in memory for 7 days and catch-up topics for 15 minutes, so a second request does not go to the provider again.
Everything above stops when your organization turns K Buddy off. Administrators can also limit it to some spaces or channels, turn screen context, pictures and tools off separately, cap pictures, set a monthly allowance, and decide which roles may use it.
The providers are Baseten, and LLM Gateway as a fallback. What they keep, and for how long, is set by their policies: who else handles your data
GIF search (Klipy)
GIFs come from Klipy, and your browser talks to Klipy directly — Klipy’s terms require that. So Klipy receives your IP address and what you search for, with your language, country and your organization’s content filter. To tell your searches apart from other people’s it also receives an anonymous id: a keyed one-way hash of your Kemble account, which reveals neither your account nor your email and is the same in every organization you belong to.
A GIF posted in a message is loaded from Klipy’s servers by everyone who sees it, so Klipy receives their IP address too. Klipy uses what it receives under its own privacy policy, which includes measuring advertising. Kemble’s key has advertising turned off, and Kemble drops anything Klipy marks as an advert before it is shown.
Your favourite GIFs are stored by Kemble, as each GIF’s id and title only. The Caption This game uses Klipy the same way.
An organization’s administrators can turn GIFs off entirely and choose how strict the content filter is. With GIFs off, GIFs already posted are not loaded until somebody chooses to show one.
Klipy’s own terms apply to what it receives: Klipy privacy policy
Watch together (YouTube)
Watch together plays videos in a call. Videos somebody uploads are served from Kemble’s storage. YouTube videos play in YouTube’s own embedded player, using YouTube’s privacy-enhanced (no-cookie) domain for the video.
Nothing is loaded from YouTube until a YouTube video is added. From then on, everybody who has Watch together open loads YouTube’s player, so Google receives their IP address, what their browser sends, and which video is playing, and treats it under Google’s privacy policy. Kemble’s server also asks YouTube for each added video’s title, which sends nothing about you.
Kemble keeps the queue — each video’s id and title, and who added it — while the session runs, and a list of what was played afterwards. Administrators can choose which activities members may start in each space.
By using YouTube videos in Watch together you are also using YouTube, under YouTube’s Terms of Service
and Google handles what it receives under Google’s privacy policy
Calls, captions, transcripts and recordings
Where calls go
Voice and video run through a media server Kemble operates on its own server, with a relay on the same server for networks that block a direct route. No outside company carries your calls. If the media server is unavailable, calls of eight people or fewer fall back to connecting browsers directly to each other; while they do, the people in the call can see each other’s IP addresses, as they can in any peer-to-peer call.
End-to-end encryption
Calls in direct messages and private channels can be end-to-end encrypted. It is off until it is turned on for the call, and once on it stays on until the call ends. Every browser then encrypts its audio, video and screen share with a key for that call alone, so the media server relays what it cannot decode. Recording, captions and AI notes are refused in an encrypted call, because each would need to hear it.
Captions and transcripts
Captions run on Kemble’s own server, using whisper.cpp. The audio is turned into text in memory and never stored, and never leaves the server. What is kept is the text: who said it and when. Everyone in the call is told before transcription starts, including people who join later. Afterwards, a transcript can be read only by people who were in the call and can still read the channel. Audio and video clips you upload are transcribed the same way, on our server.
AI notes are different: they send the transcript text to the AI provider, as described under K Buddy. Administrators can turn automatic AI notes on or off per channel.
Recordings
A call can be recorded as audio only, by somebody with permission to record — owners and administrators, unless your organization grants it more widely. The recording is made in that person’s browser and stored in Kemble’s file storage. Everyone in the call is told a recording is running, including people who join later.
Who else handles your data
These companies receive personal data when you use the feature each one serves. Each uses what it receives under its own policy, which is linked; we do not repeat or promise terms we cannot see.
| Company | What for | What it receives | When | Its policy |
|---|---|---|---|---|
| Baseten | K Buddy’s model (DeepSeek-V4.1-Flash), and every other AI feature | The request: your question, the earlier turns of that conversation, what K Buddy was allowed to read to answer it, pictures when pictures are on, and your display name, organization, channel name and local time. Not your account id or email address. | Only when somebody uses K Buddy or an AI feature (see “What K Buddy sees”) | Privacy policy |
| LLM Gateway | The fallback for K Buddy when Baseten does not answer | The same request, as text only — never pictures. It passes the request to the model provider it is set up to use. | Only when the first provider fails | Privacy policy |
| Klipy | GIF search, and the GIF game Caption This | Straight from your browser: your IP address, what you search for, your language and country, the organization’s content filter, and an anonymous id made from your account by a keyed one-way hash — never the account id or your email. | When you open the GIF picker, search, or send a GIF, and when a GIF is shown | Privacy policy |
| Google — YouTube | Playing YouTube videos in Watch together | Your IP address and what your browser sends when it loads YouTube’s player, and which video it plays. | Only when a YouTube video is added to Watch together and you have it open | Privacy policy |
| Google — Firebase Authentication | Signing in with Google, or with a phone number | Your Google sign-in or your phone number, and what Google’s sign-in and reCAPTCHA check collect. It tells us your name, email address, phone number and profile picture address. | Only if you choose one of those two ways to sign in | Privacy policy |
| Google — Firebase Cloud Messaging | Push notifications | Your device’s push token, and each notification: who mentioned you and where, and the first 140 characters of the message — or, for a list item assigned to you or due today, who assigned it and the first 140 characters of its name. | Only if you turn on notifications on a device | Privacy policy |
| Backblaze | Storage for uploaded files, pictures, recordings and videos (B2, EU Central region) | The files themselves. When you download a file, play a recording or watch an uploaded video, your browser fetches it from Backblaze directly, so Backblaze sees your IP address. | Whenever something is uploaded or opened | Privacy policy |
| Paddle | Payments | The buyer’s email address and what is being bought. Card details are typed into Paddle’s own page, never into Kemble. | Only when somebody pays through Paddle, once it is switched on | Privacy policy |
| PayTabs | Payments | The buyer’s email address, the amount, and a description that includes the organization’s name. Card details are typed into PayTabs’ own page, never into Kemble. | Only when somebody pays through PayTabs, once it is switched on | Privacy policy |
| PayPal | Payments | The buyer’s email address and what is being bought. Payment details are entered on PayPal’s own page, never into Kemble. | Only when somebody pays through PayPal, once it is switched on | Privacy policy |
Payments go through whichever of Paddle, PayTabs and PayPal is switched on and chosen at checkout; a provider that is not switched on receives nothing. Stripe is built but not in use; it will be added to this table before it is.
Your browser also fetches a few things directly from Google: the push notification code from gstatic.com, if you turn notifications on, and the animated emoji shown for an emoji-only message, from fonts.gstatic.com, unless you prefer reduced motion. Google receives your IP address when it does.
Your organization may send data elsewhere itself: to a webhook address it configured (which receives message text and the author’s name, or — from a workflow’s webhook step — the values that step sends, which can include answers given to the workflow’s form), to its own single sign-on provider, or to an app it installed. When you press an app’s button, fill in its form or run one of its commands, that app is told your account id, where you did it and what you chose or typed — and, for a command you run on a message, that message’s words. Those are its choices, under its policies.
Run on our own server — not third parties
| What | How |
|---|---|
| Voice and video | LiveKit, the media server that carries calls, rooms and stages |
| Connection relay | coturn, which relays call traffic for people whose network blocks a direct route |
| Captions and transcripts | whisper.cpp, which turns call audio into text |
| Our own mail server, mail.kemble.io, with no relay in between | |
| Database and search | Your messages, and the full-text index search reads — no outside search service |
| Link previews | The server that fetches a page to preview a link posted in a message |
Cookies and browser storage
Kemble sets no cookies, on this website or in the app, and loads no analytics or advertising trackers. A third party you load through a feature — YouTube’s player, Google sign-in — may set its own, under its policy.
The app keeps what it needs in your browser’s local storage: the sign-in token for each account you use there, with that account’s name, email and picture; unsent drafts and messages waiting to send; your recent searches, emoji and switcher history; and interface settings such as theme, sidebar and panel sizes. It stays on that device. Signing out ends the session and removes the token, but drafts and recent searches stay in that browser until you clear its site data.
This website stores nothing about you. It caches its own pages in your browser so they open offline.
Channels shared with another organization
In Kemble Work, an organization can share a channel with another organization. The people from both can then read everything in that channel, including what was said before it was shared, and see each other’s names, pictures, and which organization each of them comes from.
- The channel belongs to the organization that shared it. Messages and files anybody writes there — people from the other organization included — are stored by that organization, under its retention and legal holds, and its apps, webhooks and workflows can read them.
- While a channel is connected, a legal hold at the other organization also keeps the edit history of what is deleted there, and stops the owning organization’s retention sweep deleting that channel. A connected channel cannot be deleted until it is disconnected.
- Either organization can disconnect at any time. The other organization’s people then lose access to the channel. Nothing they wrote is deleted; it stays with the organization that owns the channel, and the other organization keeps no copy.
- The invitation is sent to an administrator’s email address. The address, who sent it, which organization accepted it, and every change to the connection are recorded in both organizations’ audit trails.
- K Buddy reads a shared channel for somebody only as that person, and only through their own organization’s K Buddy.
How long we keep it
- Messages, files and what you create: until they are deleted. Deleting a message also deletes its edit history.
- Canvases: the last 100 versions of each canvas, so it can be put back as it was. While an organization has a legal hold, no version is removed and no comment on a canvas can be deleted.
- Organization retention: an organization can set messages to be deleted after between 1 and 3,650 days. The sweep deletes them permanently, with the call transcripts and recordings in that organization. If it sets nothing, nothing is deleted on a schedule.
- Legal hold: while an organization has a legal hold, the retention sweep deletes nothing in it, a deleted message’s edit history is kept, files cannot be deleted, and list items and the values in a list’s fields cannot be deleted (an item can be marked dropped instead).
- K Buddy conversations: until you delete them, or your account or organization is deleted. The record of what K Buddy read on your behalf: ids only, 90 days.
- Whiteboards: deleted 30 days after the session ends.
- Sign-in session records, with their IP address and browser: deleted 90 days after the session expires or is ended. A session lasts at most 30 days.
- Audit trail and payment records: not deleted on a schedule.
- Data exports: the file is deleted 7 days after it is made. The record that it was made, by whom and of what, stays in the audit log.
- Name recordings and profile field answers: until you remove them, the workspace removes the field, or your account is deleted.
- Workflow runs and the answers given to workflow forms: until the workflow is deleted, which a legal hold stops. A form nobody answers stops waiting after 7 days.
- Email sign-in codes, with the IP address that asked for them, and password-reset and email-change links: deleted a day after they expire or are used.
- Push devices: until you remove them or your account is deleted.
- Backups of the database: 14 days, on Kemble’s own server.
- Logs from the media server and the speech-to-text service: 14 days.
- Contact form enquiries: in the inbox they were sent to.
Your choices and rights
What your organization’s administrators control
- K Buddy: on or off; which spaces and channels it may read; screen context, pictures and tools, each on or off; how many pictures a question may carry; a monthly allowance; and which roles may use it.
- GIFs: on or off, and how strict the content filter is.
- Activities: which ones members may start in each space, and how many people may watch together.
- Automatic AI notes, per channel, and who may record calls.
- Message retention, and legal holds.
- Whether members may edit their messages (always, never, or for a set time after sending), delete their own, and whether apps may delete theirs.
- A secrets detector, which refuses messages that look like they contain an access key, token or private key. The message is never stored, and the alert it can post names only the kind of key, never the key.
- Data exports, in Kemble Work. Owners and admins can export the messages in public channels as a file. On the Enterprise plan an owner can also export private channels and direct messages, but only after switching on full exports — which emails every member first — and each such export is emailed to every owner and recorded in the audit log. Everybody in the workspace is listed in an export by name; email addresses are included only when the person exporting may already see them.
- Which channels are shared with other organizations, whether those organizations’ people may post in them, and disconnecting them.
- Workflows: who may build and publish them, turning each one off, and deleting it with its runs and the answers given to its forms.
What you control yourself
- Your profile, status, and whether you appear online (“invisible”).
- Notifications, per device, space, channel and thread, and quiet hours.
- Your sign-in sessions and push devices: see them all, end any of them.
- Your K Buddy conversations and routines: delete them. Leave an item out of a question.
- Whether trivia may quote you, per community.
- Blocking people, and removing apps you authorized.
- Encryption for a call in a direct message or private channel.
Access, correction, export and deletion
You can see and correct most of your account in your settings. There is not yet a button to download everything we hold about you or to delete your account. Until there is, email privacy@kemble.io from the address on your account and we will do it by hand: send you a copy of your data, correct it, or delete your account. If you are in an organization, some of what you wrote belongs to its record too, and we will tell you what its retention and legal holds mean for your request.
Depending on where you live, the law may give you further rights — to object to or restrict how we use your data, or to complain to your data-protection authority. Email us first and we will try to put it right.
Children
Kemble is not meant for anybody under 13. We do not ask for your date of birth, so we cannot check; if you know of an account belonging to a child under 13, email privacy@kemble.io and we will delete it.
A channel can be marked 18+. It then asks each reader to confirm they are 18 or older before it shows them anything, and keeps their answer and when they gave it — never a date of birth. Its messages are also kept out of notification previews.
Changes to this policy
When what this page says changes, the date at the top changes with it. If a change sends your data somewhere it did not go before, the page changes before the data does.
For how Kemble is built to keep your data safe, see the trust centre