← Kono'S

Privacy Policy

Effective 2026-07-15 · Kono'S is operated by 通用創新有限公司, Taiwan ("Kono'S", "we", "us")

Pre-launch transparency notice. This page describes the approved product architecture and the controls required before public production use. The dedicated Kono'S data project, final storage regions, KMS-backed credential vault, browser-profile deletion, export-bucket retention and international-transfer terms must be verified before launch. Legal counsel review of this policy, our EU lawful bases, processor contracts and retention schedule is a production gate. This policy is not a certification of automatic GDPR compliance.

1. Who controls your data

通用創新有限公司 determines why and how Kono'S processes product data. If you use a shared workspace for an organisation, that organisation may also determine how workspace content is used. Contact us at seanlin@generalrev.com for privacy questions or rights requests.

2. Data we process

Account & profileEmail address, authentication and security metadata, display name, locale, time zone, work profile, consent records and account preferences.
ContentTasks, notes, chat messages, memories, routines, calendar-feed configuration, files and images, public pages and their submissions, interface configuration, templates, notifications, approvals, reports and task history.
Shared workspacesWorkspace or group name, members, roles, invitations, agents, messages, activity, shared content and member-specific views. Content posted to a workspace is visible to its members. Owners and admins can administer it and request a workspace export; the owner can transfer or delete the workspace.
AI & integrationsPrompts, relevant context, tool requests and tool results sent to the model or integration needed for your request. Connected MCP servers, calendar feeds, Connector agents and websites you choose to visit receive data under their own terms.
Files & storageFile bytes, names, types, sizes, folders, thumbnails, upload state, storage object paths and quota counters.
Live BrowserVisited URLs, page text, screenshots and actions needed to operate the browser. A tenant-bound Chromium profile can retain cookies, local storage and third-party login sessions between browser runs.
Plan & paymentsPlan, credits, usage counters, checkout intent, subscription/order identifiers and webhook events. We do not receive full payment-card numbers from checkout.
OperationsPush tokens, device/browser information, IP-derived security and rate-limit signals, errors, timestamps and limited service logs used for delivery, reliability and abuse prevention.

We do not sell product content or use it to train our own models. We use it to provide the service, secure accounts, meter plans, investigate failures, comply with law and respond to requests. The final EU legal-basis mapping—contract, consent where requested, legitimate interests for security, and legal obligations for transaction records—requires counsel approval before EU production launch.

3. Shared workspaces need shared judgment

Workspace members can see shared messages and content. Depending on their role, owners or admins can manage membership, agents, approvals and exports. A member's contribution may remain in the shared workspace after that member leaves because it is part of the team's record. Do not place another person's personal or confidential data in a workspace unless you are authorised to do so. Contact us if a personal rights request involves content held in someone else's workspace.

4. AI providers and your own keys

The hosted service uses Google Vertex AI for Gemini models and may use provider models made available through Vertex AI, including Anthropic Claude or OpenAI-family models. Kono'S may also use Microsoft Azure OpenAI after that provider is enabled and the current in-app provider notice has been accepted. If you choose BYOK, Kono'S can call Anthropic or an OpenAI-compatible provider you configure. We send the prompt, relevant Kono'S context and tool results needed to answer or act; we do not intentionally send your entire account on every turn.

BYOK credentials must never be stored in browser-readable Firestore fields. The approved design sends the key over an authenticated request to a server-side envelope-encryption vault; the browser receives only masked configuration metadata, and the key is decrypted only for the selected provider call. Saving credentials must remain disabled or fail closed until the dedicated KMS key, service identity, access policy and legacy-key migration are verified. BYOK use is also governed by your provider's terms, privacy practices and retention settings.

Hosted-provider contracts, data-processing terms, model-retention settings and the promise that customer content is not used for provider training must be checked against the exact production model and account before it is offered publicly.

5. Live Browser profiles and third-party sites

When you sign in to a website in Live Browser, your password is submitted to that website through the browser; do not paste passwords into Kono'S chat. The website may set cookies or other browser storage. The production design stores each tenant's browser profile as an encrypted, authenticated, tenant-bound archive so logins can persist. Page content and screenshots may be shown in Live View and supplied to the active AI model to perform your request.

Persistent browser access must not be enabled for public production users until the isolated Machine boundary, encryption key, outbound-network policy and account-deletion purge for browser profiles are verified end to end. Deleting cookies at the third-party site or revoking a third-party session may also be necessary because that site's copy is outside Kono'S.

6. Service providers and other recipients

Google Cloud / Firebase

Authentication, Firestore, object storage, hosting, push delivery, compute and hosted AI. Google generally acts as a processor for Firebase customer data. Firebase privacy and security.

Cloudflare

Domain/network services and a performance/page-view beacon on marketing and legal pages. Cloudflare describes Web Analytics as cookie-free and says it does not collect or use visitors' personal data for that product. The beacon is not included in the authenticated Kono'S app shell. Web Analytics details.

AI provider selected for a turn

Google, Microsoft Azure, Anthropic, OpenAI or the OpenAI-compatible provider you configure receives the data needed for that request. Exact recipients depend on your model and BYOK settings.

Lemon Squeezy

Merchant of record for checkout, tax, invoices, refunds and subscription administration. Lemon Squeezy receives checkout and transaction data under its privacy policy.

Third-party sites, MCP servers, calendars and locally connected agents that you deliberately connect are independent recipients, not automatically our processors. Review their terms before connecting them.

7. Storage location and international transfers

We do not yet promise a single production data region. The dedicated Kono'S Firebase, storage and worker projects—and their final regions—must be selected and recorded before public launch. Google states that Firebase Authentication is operated from US data centres, while other Firebase services may use global infrastructure or a location selected for that service. See Firebase data storage and processing locations.

If EU/EEA, UK or other restricted data is transferred internationally, the applicable provider terms, adequacy position and safeguards such as standard contractual clauses must be reviewed and disclosed. No region or transfer-safeguard claim should be inferred until that launch review is complete.

8. Export

Settings can request a background export for your personal account. Workspace owners and admins can request one for a shared workspace. The worker builds a private ZIP containing the tenant root, the known product collections (including tasks, notes, messages, memories, routines, files, public-page data, notifications, approvals and task events), plus actual user-file objects stored under that scope. It removes credential fields, encrypted secret material, private calendar-feed links and other access tokens.

The ZIP does not include the credential vault, browser profile/cookies, Firebase Authentication security records, provider-side data, global billing/legal records or unrelated workspaces. A short-lived HTTPS download link is issued from a dedicated encrypted archive bucket. That bucket, its lifecycle rule, IAM policy and large-archive disk sizing must be verified before export is enabled in production. For a broader access or portability request, contact us rather than assuming the in-app ZIP is the complete legal response.

9. Deletion and retention

Account deletion is a resumable server job. It removes tenant subcollections and task history, stored files and upload requests, published-page registry entries, workspace-join requests, export archives and job records, and vaulted credentials before removing the tenant root. Shared workspaces you solely own must be explicitly confirmed for deletion; a shared workspace with other members must be transferred or separately deleted. The Firebase Authentication user is removed after the product-data purge succeeds.

Deletion is not an unconditional promise that every record disappears immediately:

Our concrete retention table for operational logs, export-job metadata, backups and legally retained transaction records requires counsel and accounting review before production launch. The EU right to erasure is not absolute—for example, data can sometimes be retained to comply with a legal obligation or for legal claims. See the European Commission's official explanation of erasure and its limitations.

10. Your choices and rights

Depending on where you live, you may have rights to be informed, access data, correct it, request erasure or restriction, object to certain processing, receive portable data, withdraw consent, and complain to a data-protection authority. The European Commission explains these rights in its information for individuals and explains the conditions for data portability.

Email seanlin@generalrev.com with the account email, the right you want to exercise and enough detail to locate the data. We may verify your identity before acting. Where the GDPR applies, requests generally require a response without undue delay and in principle within one month; if we cannot fulfil a request, we will explain the reason and available complaint routes. In-app export and deletion help exercise rights but do not, by themselves, establish compliance with every applicable privacy law.

11. Security, children and changes

Approved controls include encryption in transit and at rest, tenant-scoped rules, server-verified identity for privileged operations, least-privilege service accounts, secret redaction, short-lived download URLs and approval gates for sensitive actions. No system is perfectly secure; report a suspected privacy or security issue to the contact above.

Kono'S is not intended for children under 18 or below the minimum age required to consent to online services where they live. Contact us if you believe a child provided personal data.

We will update this page before production to replace launch conditions with the verified projects, regions, processors, transfer safeguards and retention periods. Later material changes will be posted here and, when appropriate, announced in the app or by email.

Last reviewed against the code architecture on 2026-07-18. Product behaviour and provider terms can change; the current policy posted here controls our notice.