Privacy policy
Effective July 19, 2026
Kogi (“Kogi”, “we”, “us”) operates kogi.chat — an embeddable AI concierge that businesses in travel and hospitality add to their own websites. This policy explains what we collect, why, and the choices you have. We've written it to be read, not skimmed past.
Kogi touches personal information in two distinct roles:
- If you hold a Kogi account (you run agents on your site), we decide how your account information is used — we're the “controller” of that data.
- If you chatted with a concierge on someone else's website, that business is the controller of your conversation. We process it on their behalf, under their instructions and this policy's safeguards. The site you were on is your first stop for questions about how your data is used — though we'll always help (see Your rights).
What we collect
From account holders
- Your email address and a password (stored only as a bcrypt hash — we can't read it).
- Workspace details: workspace names, teammate invitations (email address and role), and membership records.
- The content you add to run your agents: instructions, brand voice, knowledge documents, offer catalogs, guardrail text, and settings.
- Usage records: token consumption, estimated costs, and feature activity — used for your own dashboards and any applicable limits.
- Messages you send us (support, feedback).
From visitors chatting with an agent on a customer's site
- The messages you type to the concierge.
- A snapshot of the visible content of the page you're on, so the agent can answer questions about it and act on it (scroll, highlight, click). Snapshots come only from the pages where the site owner installed the widget.
- A randomly generated visitor identifier stored in your browser's local storage — scoped to the site you're visiting, so your conversation can continue as you move between its pages. It does not follow you across other websites.
- Details you choose to share in conversation — travel dates, party size, occasion, and similar trip context.
- Contact details (such as email or phone) only if you submit them through a consent form with an affirmative, unchecked-by-default checkbox. We store proof of that consent with the record.
- Feedback you give on answers (thumbs up/down).
- Interaction events: widget views and opens, suggested-action clicks, and conversion events the site owner has defined (for example, reaching a confirmation page), attributed to your chat session for the site owner's reporting.
- Your IP address, held transiently for rate limiting and abuse prevention — not used to build profiles.
How we use it
- To run the service: answer messages, perform on-page actions, keep conversations continuous across pages.
- To generate responses: conversation content and page snapshots are processed by our AI subprocessor, Anthropic (Claude models), via API to produce the agent's replies.
- To give the site owner their own reporting: transcripts, AI-written summaries, topics, sentiment, satisfaction, lead records, and conversion attribution for conversations that happened on their site.
- To send email you asked for: if you consented to receive an offer summary or a reminder, we send it (via our email subprocessor) with a way to pick up where you left off. Account holders receive operational email such as team invitations and, optionally, a weekly digest.
- To secure the service: rate limiting, origin allowlists, and abuse detection.
What we don't do
- We don't sell or rent personal information. To anyone.
- We don't run advertising networks or place third-party advertising cookies.
- We don't build cross-site behavioral profiles of visitors.
- The agent never collects payment card details — card fields are blocked at the software level, not just by policy.
- We don't use your conversations or content to train our own models.
Cookies and local storage
- Account holders: a session cookie (httpOnly) to keep you signed in, plus local-storage preferences for theme and layout. That's it.
- Visitors: the random visitor identifier described above, stored in local storage under the site you're visiting. No third-party advertising cookies, ever.
When we share
- With the site owner: conversations, leads, and events from their own site are theirs to see in their dashboard.
- With subprocessors that make the service work: Anthropic (AI responses), Resend (email delivery), and the cloud infrastructure that hosts our application and database. Each processes data only to provide their service to us.
- When the law requires it: in response to valid legal process, or to protect the rights, safety, or property of Kogi, our customers, or others.
- In a business transfer: if Kogi is acquired or merges, data may transfer with it — under this policy's commitments, and we'll notify account holders.
How long we keep things
- Account data: for as long as your account is active.
- Conversations, leads, and events: until the site owner deletes them or closes their account. (Chat sessions rotate after 30 minutes of inactivity, but transcripts remain available to the site owner.)
- Rate-limiting records: transient — minutes, not months.
Your rights
Depending on where you live (including under GDPR, UK GDPR, and CCPA/CPRA), you may have the right to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to not be discriminated against for exercising these rights.
- Account holders: email us at privacy@kogi.chat and we'll act on your request.
- Visitors: the business whose site you chatted on is the controller of your conversation — contacting them is usually fastest. If you contact us instead, we'll help directly or forward your request to them, and we support our customers in honoring these requests.
Security
Passwords are bcrypt-hashed, sessions use httpOnly cookies, traffic is encrypted in transit, each agent enforces an allowlist of origins it will answer from, and chat endpoints are rate limited. No system is perfectly secure, but if we learn of a breach affecting your data we'll notify you as the law requires.
Children
Kogi is not directed to children under 16, and we don't knowingly collect their information. If you believe a child has provided us personal information, contact us and we'll delete it.
International transfers
We operate from the United States, and data is processed there. Where the law requires safeguards for transfers (such as standard contractual clauses), we use them.
Changes to this policy
When we change this policy we'll update the date at the top; for material changes we'll notify account holders by email or in the dashboard before they take effect.
Contact
Questions, requests, or concerns: privacy@kogi.chat. For terms of service, see Terms.