Privacy Policy

Last updated: 17 June 2026

This Privacy Policy explains how Kyosho collects, uses, shares, and protects personal data when you use the Kyosho desktop application, website, and related services (the “Service”). We act as the data controller for the personal data described here.

Who we are

Kyosho is operated by Abhishek Singla, Brauhausstraße 9, 13086 Berlin, Germany (VAT ID DE449964422). For any privacy questions or to exercise your rights, contact support@kyosho.ai.

What data we collect

  • Account data — your name, email address, and profile picture, provided through Google sign-in when you create an account.
  • CRM data (read-only) — if you connect HubSpot (or another CRM), we read your deals, companies, contacts, owners, and related activity to show your pipeline in Kyosho. We request read-only access and never write back to your CRM.
  • Calendar data — if you connect Google Calendar, we read your upcoming events, their titles, join links, and attendees to detect meetings and match them to deals.
  • Meeting transcripts — when you record a call, Kyosho captures audio on your device and converts it to a text transcript. The audio itself is never uploaded or stored by Kyosho — only the resulting transcript and the notes and follow-ups generated from it are saved.
  • Derived content — summaries, coaching signals, suggested tasks, deal intelligence, and search embeddings that we generate from your transcripts, notes, and CRM/calendar data.
  • Enrichment data (about external meeting participants) — the people you meet are typically external third parties, such as prospects and customers, who are not Kyosho users. When such an external participant on one of your meetings cannot be identified from your connected CRM, we may look up publicly available professional information about them (such as their name, job title, and company) from a business-data provider, so we can tell you who is on the call. We never enrich your own teammates, and we do this only for external business contacts you are already meeting with and who are not already known from your CRM.
  • Billing data — when you subscribe, payments are processed by our payment provider Stripe. We do not receive or store your full card details. We store your subscription status, plan, and a Stripe customer/subscription identifier.
  • Usage and device data — basic technical information needed to operate and secure the Service (e.g. app version, error logs).

How and why we use your data

We process personal data to provide and improve the Service — syncing your CRM and calendar, transcribing and analysing your meetings, generating summaries, coaching, and follow-up tasks, managing your subscription, and supporting you. Our legal bases under the GDPR are:

  • Performance of a contract (Art. 6(1)(b)) — to deliver the features you sign up for.
  • Legitimate interests (Art. 6(1)(f)) — to secure, maintain, and improve the Service, to communicate with you about it, and to enrich professional information about external participants in your meetings (third parties such as the prospects and customers you meet, in a business-to-business sales context) where they cannot be identified from your CRM. Those external individuals are the data subjects of this processing and may exercise their rights, including objection, by contacting us; workspace administrators can also disable enrichment.
  • Consent (Art. 6(1)(a)) — where you choose to connect optional integrations (CRM, calendar) or enable recording. You can withdraw consent at any time by disconnecting the integration or stopping recording.

We do not sell your personal data, and we do not use your meeting content or CRM data to train third-party AI models.

Optional: cross-team benchmarks

If a workspace administrator turns on cross-team benchmarks (off by default, in Settings), Kyosho contributes that workspace’s aggregated, anonymized deal signals — statistical win/loss patterns only — to power comparative benchmarks. We never include deal names, company or contact identities, transcripts, or any other identifying content, and aggregates are gated so no individual workspace can be singled out. An administrator can withdraw at any time in Settings, which stops further contribution.

Service providers (sub-processors)

We share data with the following providers only as needed to run the Service. Some are located outside the European Economic Area; where that is the case, transfers are protected by appropriate safeguards such as the EU Standard Contractual Clauses.

  • Supabase — database, authentication, and backend hosting.
  • Vercel — hosting of our website and checkout page.
  • Recall.ai — the desktop recording SDK and media processing used to produce transcripts.
  • Deepgram — speech-to-text transcription.
  • Anthropic (Claude) — AI processing for summaries, coaching, and follow-ups.
  • Voyage AI — text embeddings that power semantic search over your account.
  • Parallel — business-data enrichment: when an external meeting participant (such as a prospect or customer) cannot be identified from your CRM, we send their business email address or company domain to look up professional information (such as name, job title, and company) so we can give you context on who is on the call. We send only those business identifiers — never your meeting content or transcripts, and never your own teammates' details.
  • Stripe — payment processing and billing.
  • Google and HubSpot — only when you choose to connect them, to read your calendar and CRM.

Data retention

We keep your data for as long as your account is active and as needed to provide the Service. You can delete your meetings, notes, and account at any time; when you delete your account we remove your personal data, except where we must retain limited records to comply with legal obligations (for example, billing records). Captured audio is never retained.

Security

Data is encrypted in transit and at rest, access is restricted on a need-to-know basis, and each customer’s data is isolated using row-level security so you only ever see your own organisation’s data. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your information.

Your rights

If you are in the EEA, you have the right to access, correct, delete, restrict, or object to the processing of your personal data, and to data portability. To exercise any of these, email support@kyosho.ai. You also have the right to lodge a complaint with your local data protection authority; in Germany this is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).

Cookies

Our website and checkout page use only the cookies strictly necessary to operate them (for example, to keep you signed in and to run secure checkout). The Kyosho desktop app does not use advertising or tracking cookies.

Children

The Service is intended for business use and is not directed to anyone under 18. We do not knowingly collect data from children.

Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you in the app or by email.

Contact

Questions about this policy or your data? Email support@kyosho.ai.