Legal

Privacy policy

Kogi (“Kogi”, “we”, “us”) operates kogi.chat — an embeddable AI concierge that businesses in travel and hospitality add to their own websites. This policy explains what we collect, why, and the choices you have. We've written it to be read, not skimmed past.

Kogi touches personal information in two distinct roles:

What we collect

From account holders

From visitors chatting with an agent on a customer's site

How we use it

What we don't do

Cookies and local storage

When we share

How long we keep things

Your rights

Depending on where you live (including under GDPR, UK GDPR, and CCPA/CPRA), you may have the right to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to not be discriminated against for exercising these rights.

Security

Passwords are bcrypt-hashed, sessions use httpOnly cookies, traffic is encrypted in transit, each agent enforces an allowlist of origins it will answer from, and chat endpoints are rate limited. No system is perfectly secure, but if we learn of a breach affecting your data we'll notify you as the law requires.

Children

Kogi is not directed to children under 16, and we don't knowingly collect their information. If you believe a child has provided us personal information, contact us and we'll delete it.

International transfers

We operate from the United States, and data is processed there. Where the law requires safeguards for transfers (such as standard contractual clauses), we use them.

Changes to this policy

When we change this policy we'll update the date at the top; for material changes we'll notify account holders by email or in the dashboard before they take effect.

Contact

Questions, requests, or concerns: privacy@kogi.chat. For terms of service, see Terms.