Keiki

Privacy policy · Updated August 18, 2026

Privacy Policy

What Keiki collects, why we collect it, and the controls you have: for the people who run agents and the people who talk to them.

Our approach

Keiki is infrastructure for conversations that belong to you: your knowledge, your customers, your channels. We collect what is needed to run agents on your behalf, keep them secure, and bill for the Service: and nothing we can operate without.

We do not sell personal information, and we do not use your data or your conversations to train foundation models.

Who this covers

For account and platform data, we are the controller. For the conversations your agents have with your customers, you are the controller and we act as your processor: you decide what an agent knows, says, and does, and we process that data on your instructions.

Account information

When you create an account or an organization we collect your name, email address, password credentials, organization details, role, and: for paid plans: billing contact and payment information processed by our payment provider. We do not store full card numbers.

Agent and knowledge data

We store the material you give an agent: knowledge sources, prompts and voice, tool and plugin configuration, evaluation cases, and the settings that define how much autonomy the agent has and which actions need approval.

Conversation data

When an agent runs, we process the conversation and the context around it: messages exchanged on the connected channel, the contact identifier that channel supplies (such as a phone number, email address, or chat handle), the tools the agent called and what they returned, model requests and responses, and the outcome of the turn.

This is what makes conversations reviewable: you can read what happened, see the steps behind an answer, and correct an agent that got it wrong.

Connected services

You choose which services to connect, and we process only what those integrations need:

  • messaging and email providers, to send and receive on your channels
  • model providers, to generate agent responses: using your own provider key where you supply one
  • tools and APIs you wire into an agent, which receive the data the agent sends them
  • payments and analytics providers, for billing and product measurement

We share personal information with these providers only as needed to deliver the feature you enabled, under contracts that limit what they may do with it. You can disconnect an integration at any time.

Usage and diagnostics

We collect product analytics and technical logs: pages and features used, requests, errors, performance, IP address, and device or browser information: to keep the Service reliable, secure, and understandable. We use first-party cookies and similar storage for sessions and preferences, not for advertising.

How we use data

We use the data described above to provide and operate the Service, run and improve your agents at your direction, keep accounts and conversations secure, prevent abuse, meter and bill usage, provide support, and comply with legal obligations.

We do not use your knowledge or conversation data for advertising, and we do not disclose it to anyone other than the providers above except with your instruction or where the law requires it.

Access controls and audit trail

Access to an organization’s data is scoped to its members and their roles, and to the API keys you issue. Agents run inside the boundaries you set: the autonomy level you choose, the tools you enable, and the approvals you require for sensitive actions.

Actions taken by an agent or by a member are recorded so you can inspect what happened, who or what did it, and when.

Security

We encrypt data in transit, store credentials and provider keys encrypted, restrict internal access to those who need it to run the Service, and log administrative access. Sandboxes that execute agent code are isolated per organization.

No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you without undue delay. We can share our current security documentation on request at nizzy@orchid.ai.

Retention and deletion

We keep account data for as long as your account exists, and conversation and agent data until you delete it or your account is closed. Deleting content removes it from the product and from our backups in the ordinary backup cycle.

We keep what we must for legal, accounting, and abuse-prevention purposes, and aggregated data that no longer identifies anyone.

International transfers

We and our providers may process data in countries other than yours, including the United States. Where required, we rely on appropriate transfer safeguards, such as the European Commission’s standard contractual clauses.

Your rights

Depending on where you live, you may have the right to access, correct, export, restrict, or delete your personal information, to object to certain processing, and to withdraw consent. You can do much of this yourself in the product: reading and exporting your data, disconnecting integrations, and deleting agents, knowledge, conversations, or your account.

To make a request, or to complain about how we handle your data, write to nizzy@orchid.ai. If you are a customer of a business that runs an agent on Keiki, contact that business first: we act on their instructions and will pass your request to them.

Children

The Service is not intended for children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, write to nizzy@orchid.ai and we will delete it.

Changes to this policy

We will update this policy as the Service changes and post the new version here with a fresh date. When a change is material we will give notice in the product or by email before it takes effect.

Contact

Privacy questions and requests: nizzy@orchid.ai.

Keiki is a product of Zero Email, Inc., a Delaware corporation.