Skip to content

Privacy

Privacy

Where heykiku stores your data, how long we keep it, why we’re allowed to process it, and the controls you have. Questions? Email [email protected].

Support access (impersonation)

To help us reproduce UI issues you report, the heykiku team can sign in to your workspace as you. We use this to look at the same screens you see — not to read documents you wouldn’t already show us.

Each impersonation session requires a written reason, is recorded in our audit log, and automatically expires after 60 minutes.

We rely on legitimate interest (GDPR Art. 6(1)(f)) as the legal basis for support access — the standard basis B2B SaaS tools use for support work, because providing support is necessary for us to deliver the service you signed up for. That’s also why the setting is on by default: legitimate interest doesn’t require an opt-in, it requires that you can say no.

And you can: you retain the right to object (GDPR Art. 21), and the toggle at Account → Privacy is how you exercise it. Switch support access off at any time — sign-in attempts are rejected from then on, and any impersonated session for your account is signed out the moment it tries to load the dashboard.

Marketing chat bubble

On parts of this site you’ll see a small chat bubble that lets you ask kiku, our AI assistant, about heykiku before you sign up. We log the conversation along with the page you were on, the referrer, and any UTM parameters in the URL. We do this so we can answer follow-up questions, improve the bot, and recognise your reply if you later choose to email us.

If you click email me a recap we send the transcript to [email protected] so we can reply to you. The reply is a manual one-to-one email — we do not enrol you in any marketing list.

Processors involved: Mistral (the model that generates kiku’s replies), Resend (delivers the email recap), Cloudflare Turnstile (bot protection on the first message), and PostHog EU (cookieless product analytics — your chat messages and your email address are never sent to PostHog).

Want a conversation deleted? Email [email protected] from the same address you used to chat with us. We’ll remove the matching rows.

Sub-processors and where your data lives

Your customer content — the knowledge base, documents, voice memos, and chat history — is hosted in the European Union. Authentication is first-party: sign-in runs on our own EU-hosted infrastructure, not a third-party identity provider.

The full list — every sub-processor, what it can see, and where it runs — lives on its own page so it can be dated and referenced from a DPA: heykiku.com/sub-processors.

In short: the content layer stays in the EU, while billing and email delivery records are US-routed — a common pattern we prefer to disclose plainly rather than round up to a claim like “everything in the EU.” All sub-processors operate under GDPR-compliant data-processing agreements.

How long we keep your data

Your data lives as long as your account does, and leaves when you do. We don’t warehouse things “just in case.”

WhatHow long
Your account (email, name, password hash)Until you delete your account — then removed immediately
Your workspace and everything in it (documents, folders, settings)Until you delete the workspace, plus a 7-day grace period in case you change your mind — then permanently erased, including the copies our AI provider indexed
Chat conversations and voice memosHidden immediately when you delete them; fully removed, including the AI provider’s copy, when your account or workspace is erased
Product analyticsDetermined by our analytics provider’s plan retention — cookieless, no names or emails
Sign-in sessionsExpire after 7 days of inactivity and are swept from our database automatically
Audit logs (who did what, from where)Retained for security purposes — if you delete your account, your name is removed from log entries right away, though IP addresses and device metadata on those entries are kept for incident investigation
Billing records and invoicesAs long as tax law requires — the one thing account deletion legally can’t erase
Pre-signup chats (the marketing bubble)Until you ask us to remove them

Two honest footnotes. First, database backups: when you delete something, it disappears from the live product immediately, but it takes up to 7 days to age out of our automated database backups. Second, account erasure removes your personal data from the live database, but a small amount of residual data stays for operational reasons — security audit entries (with IP metadata kept for incident investigation), questions your team asked (the workspace’s knowledge, not yours), your pseudonymous analytics identifier (an account id, never your name or email), and some operational records (verification tokens, lifecycle-email logs, unsubscribe preferences). We document these explicitly rather than claiming “everything” is gone when it isn’t.

Workspace deletion has one separate analytics step. It removes your workspace content from heykiku and the AI provider, but the automatic teardown does not currently remove the PostHog workspace group or events carrying the workspace’s tenant id. If you ask us to remove the full customer dataset, email [email protected] and we’ll handle that PostHog deletion by hand. PostHog’s response is asynchronous, so we only describe it as complete after we receive a provider receipt and verify the group and its tenant-tagged events are gone.

Want something gone faster? Email [email protected] and we’ll handle it ourselves.

Your rights

Want a copy of your data, or your account and its data removed? Email [email protected] from your account address and we’ll handle it — we reply to every request ourselves.

You also have the right to lodge a complaint with your local data-protection authority (GDPR Art. 77). If something feels wrong, we’d appreciate the chance to fix it first — but that right is yours either way.

See also: Terms of service · Sub-processors