Trust centre
How Kemble handles your data, what we can see, and what we have not finished.
Data we hold
Account details, the organizations you belong to, the messages and files you send, and operational records: audit rows, sign-in sessions with the IP address and browser they came from, and usage counters for the limits your plan enforces.
K Buddy conversations are kept until the person who had them deletes them. The record of what K Buddy read on somebody’s behalf holds ids, not content, and is deleted after 90 days.
Call transcripts are text — who said what, and when. The audio they were made from is processed in memory and never stored. They follow the organization’s message retention, as recordings do.
Kemble does not use your content to train AI models. When somebody uses K Buddy, what it reads goes to the AI provider, and what the provider may do with a request is governed by its own terms.
All of it — what is collected, why, and for how long — is in the privacy policy
Who can see it
Within your organization, visibility follows the permission model: private channels are visible to their members, and the check runs inside the query rather than filtering results afterwards.
Kemble staff do not read customer message content as a matter of routine. There is no cross-tenant content moderation surface, and the platform console deliberately does not have one — building it would need a reason-and-log discipline that has not been designed yet.
Encryption
In transit, HTTPS. Passwords are hashed with Argon2 and are not recoverable; two-factor secrets and payment-provider credentials are stored encrypted.
Calls in direct messages and private channels can be end-to-end encrypted. It is opt-in, per call, and covers audio, video and screen share: each browser encrypts with a key for that call alone, and the media server relays what it cannot decode. Recording, captions and AI notes are refused while it is on, because each would need to hear the call. The key is issued by Kemble’s server to the people in the call, so it protects the call from the media path, not from Kemble.
Run on our own server
Voice and video go through a media server Kemble operates itself, with its own relay for networks that block a direct route; no outside company carries your calls. Captions and transcripts are made on the same server, so call audio never leaves it. Email is sent from our own mail server, and search runs on our own database.
One exception to know about: if the media server is unavailable, calls of eight people or fewer connect browsers to each other directly, and the people in the call can then see each other’s IP addresses.
Sub-processors
Kemble uses a small number of third parties, each only for the feature it serves: Backblaze for file storage; Baseten, with LLM Gateway as a fallback, for K Buddy; Klipy for GIF search, which your browser contacts directly; Google for signing in with Google or a phone number, for push notifications, and for YouTube videos in Watch together; and Paddle, PayTabs or PayPal for payments, once switched on.
What each one receives, and when: the sub-processor list in the privacy policy
Reporting a vulnerability
Email security@kemble.io. We will acknowledge within two working days. Please give us a reasonable window to fix an issue before disclosing it, and we will credit you unless you would rather we did not.