KydeKYDE

Privacy Policy

Last updated 30 August 2026

Kyde connects to the marketing platforms you already use, reads your performance data, and proposes actions you approve. That only works if you trust us with access. This page explains exactly what we collect, why, who else touches it, and how to get it back or delete it.

1. Who we are

Kyde is operated by Kyde Digital Pvt Ltd, 2nd Floor, Ofis Square, The Iconic Corenthum, Plot No. A41, Sector 62, Noida 201301, India. For any privacy question, or to exercise the rights in section 8, write to alerts@kyde.in.

2. What we collect

Account data. Your name, email address and a hashed password. If you sign in with Google, we receive your email address, name and profile picture from your Google account — nothing else.

Connected platform data. When you connect a data source, we store the access and refresh tokens and pull the metrics you asked us to analyse:

  • Google Search Console — impressions, clicks, positions and queries for the properties you select
  • Google Analytics 4 — sessions, conversions and channel data for the properties you select
  • Meta Ads, LinkedIn Ads — campaign spend, impressions and conversion metrics
  • HubSpot — contact and deal records; Shopify — orders, products and customers

Usage data. Actions you take in the product, agent runs, approvals and rejections, and standard server logs (IP address, browser, timestamps) kept for security and debugging.

Billing data. Plan, invoices and subscription status. Card and UPI details are handled entirely by Razorpay and Stripe — we never see or store them.

3. How we use it

  • To run the product: build your dashboards, score your performance, detect anomalies and generate reports
  • To propose and execute actions you explicitly approve
  • To send the alerts and scheduled reports you configure
  • To bill you, support you, and secure the service against abuse

We do not sell your data, share it with data brokers, or use it for advertising.

4. Google user data — Limited Use

Kyde's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, data obtained from Google Search Console and Google Analytics:

  • is used only to provide and improve the features you can see in your own workspace — reports, scores, alerts and recommendations
  • is never used for advertising of any kind
  • is never sold or transferred to data brokers or information resellers
  • is never used to train generalised or foundation AI models, ours or anyone else’s
  • is never read by a human at Kyde, except where you explicitly ask us to for support, where required by law, or where necessary to investigate a security incident or abuse

We request read-only scopes only (webmasters.readonly, analytics.readonly). Kyde cannot modify or delete anything in your Google account. You can revoke our access at any time from your Google account permissions, or by disconnecting the source inside Kyde.

5. AI processing

Kyde is built on large language models. To answer a question, run an agent or draft a recommendation, we send the relevant slice of your workspace data to our AI providers (Anthropic, OpenAI, Perplexity and Google) as part of that request.

These providers process it solely to return the result for that request. Under our agreements with them, your data is not used to train their models. We do not build models on your data either. Where the request involves Google user data, the Limited Use commitments in section 4 apply to that processing as well.

6. Who else processes your data

We use a small set of subprocessors, each for a single purpose:

  • Supabase — primary database, hosted in Seoul (ap-northeast-2)
  • Upstash — queue and cache for scheduled jobs
  • Hostinger — application hosting
  • Anthropic, OpenAI, Perplexity, Google — AI model inference (section 5)
  • Razorpay and Stripe — payments
  • Our email provider — transactional alerts and reports

Your data is stored in India and Singapore/Seoul region infrastructure. Because some subprocessors operate globally, data may be processed outside India under appropriate contractual safeguards.

7. Security

Connector access tokens are encrypted at rest with AES-256-GCM. Passwords are hashed, never stored in plain text. All traffic runs over TLS. Access to production systems is limited to personnel who need it.

No system is perfectly secure. If a breach affects your data, we will notify you and the relevant authorities as required under the DPDP Act and GDPR.

8. Your rights

You can exercise all of these yourself, from inside the product:

  • Export — Account Settings → Export my data returns everything we hold about you as JSON
  • Delete — Account Settings → Delete account permanently removes your workspaces, connections, prompts, alerts, reports, agent runs, actions, notifications and profile
  • Disconnect — remove any connected platform at any time; its tokens are deleted immediately
  • Correct — update your profile details at any time

Deletion is immediate and irreversible. We retain billing records where tax law requires it. If you would rather we act on your behalf, email alerts@kyde.in and we will respond within 30 days.

9. Retention

We keep your data for as long as your account is active. After you cancel, your data stays exportable for 90 days and is then deleted. Delete your account instead if you want it gone straight away.

10. Children

Kyde is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.

11. Changes

If we change this policy materially — new subprocessor categories, new uses of your data — we will email account holders before it takes effect. The date at the top always reflects the current version.

Questions? alerts@kyde.in · Sign in to Kyde