Privacy Policy

Last updated: 7 August 2026

This policy explains what personal data Kyte processes, why, who we share it with, and the choices and rights you have.

Kyte is a business tool, so we handle data in two distinct capacities: data about our own customers, which we control, and data about our customers’ contacts, which we process on their behalf. Section 1 explains the difference and who to contact in each case — it is the most important part of this policy.

1. Our two roles: controller and processor

Understanding which role we play is the key to this policy, because it determines who decides what happens to your data and who you should contact about it.

We are the controller of account data

When you sign up for Kyte, we decide how to handle the data about you as our customer — your name, email address, password credentials, workspace membership and billing contact details. For this data we are the data controller, and you can exercise your rights directly with us.

We are a processor for workspace data

When you use Kyte to communicate with your own customers and contacts, the data about those people — their names, phone numbers, email addresses, channel handles, message content, CRM records and call recordings — is data we process on behalf of the workspace owner. The workspace owner is the data controller for it. They decide what to collect, why, how long to keep it, and who may see it. We act only on their documented instructions.

This matters practically: if you are a contact of a business that uses Kyte and you want your data accessed, corrected or deleted, contact that business directly — they control it. If they ask us to act, we will assist them. You may still contact us at privacy@flowtracker.io and we will route your request to the right workspace where we can identify it.

2. Data we process

Account data (we are controller)

  • Identity and contact details: name, email address, profile information.
  • Authentication data: hashed passwords, session tokens, and identifiers from third-party sign-in providers where you use them.
  • Workspace data: which workspaces you belong to, your role and permissions within them.
  • Billing data: billing contact details, plan and subscription status, invoice and payment references. Card numbers are handled by Stripe and never stored by us.
  • Usage and technical data: log data, IP address, device and browser information, feature usage, and error diagnostics.

Workspace data (the workspace owner is controller)

  • Contact identities: names, phone numbers, email addresses, and channel handles or IDs for WhatsApp, Telegram, Instagram, Messenger and other connected channels.
  • Message content and attachments exchanged across connected channels and live chat.
  • CRM records: leads, pipeline stages, notes, tags and custom properties.
  • Tracked-link data: click events, coarse location derived from IP address, and device and browser characteristics.
  • Payment references, where a workspace connects a payments integration.
  • Call recordings and transcripts, where the workspace enables voice features. The workspace owner is responsible for providing any notice and obtaining any consent that recording requires in the relevant jurisdiction.

3. How we use data and our legal bases

Where the GDPR or similar laws apply, we rely on the following legal bases for account data that we control:

  • Performance of a contract — to create and administer your account, provide the Service, process payments, and provide support.
  • Legitimate interests — to secure the Service, prevent fraud and abuse, monitor errors and reliability, understand aggregate product usage, and communicate about material service changes. We balance these against your rights and interests.
  • Consent — for optional marketing communications and any non-essential cookies. You may withdraw consent at any time.
  • Legal obligation — to meet accounting, tax and other statutory requirements, and to respond to lawful requests.

For workspace data, the legal basis is determined by the workspace owner as controller. We process it under their instructions and under our data processing terms with them.

We do not sell personal data, and we do not use the content of workspace conversations to train generally-available AI models.

4. Subprocessors

We use the third-party providers below to deliver the Service. Each is bound by contractual confidentiality and data protection obligations, and may process data only to provide their service to us. Which subprocessors apply to a given workspace depends on the features and integrations that workspace enables — for example, telephony providers are involved only where voice features are turned on.

SubprocessorPurposeData involved
RailwayApplication hosting and infrastructureAll data processed by the Service
MongoDB, Redis, RabbitMQ (hosted on Railway)Primary database, caching and message queuingAccount data, workspace data, message content
ClickHouseAnalytics and reporting storageEvent, click and aggregated usage data
SupabaseFile and media storageAttachments and uploaded files
StripePayment processing and subscription billingBilling contact details, payment references
AnthropicAI model processing for AI agents and assistanceContent submitted to AI features
OpenAIAI model processing for AI agents and assistanceContent submitted to AI features
ElevenLabsVoice synthesis and transcriptionCall audio and transcripts, where voice features are enabled
ResendTransactional and outbound email deliveryRecipient email addresses and message content
SentryError monitoring and diagnosticsTechnical error data, which may include identifiers
Meta, Telegram, GoogleMessaging channel and authentication integrationsChannel identifiers and message content for connected channels
Twilio, PlivoTelephony and SMS deliveryPhone numbers, call metadata, message content

We may update this list as the Service evolves. Material changes to subprocessors that affect workspace data will be notified to workspace owners in accordance with our data processing terms.

5. International transfers

Our subprocessors operate globally, so personal data may be transferred to and processed in countries other than the one where it was collected, including the United States. Those countries may not provide the same level of data protection as your home jurisdiction.

Where we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on appropriate safeguards — principally the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with supplementary technical and organisational measures such as encryption in transit and at rest. Where a recipient is covered by an adequacy decision or a certified transfer framework, we may rely on that instead.

6. Data retention

  • Account data is retained for as long as your account is active. After you close your account we delete or anonymise it, except where we must keep records to meet legal, tax or accounting obligations, or to resolve disputes and enforce our agreements.
  • Workspace data is retained according to the workspace owner’s configuration and instructions. They can delete records at any time, and they decide their own retention periods.
  • On termination of a workspace, we delete or anonymise its data after a short grace period that allows for accidental deletion and final export, unless a longer period is required by law.
  • Backups and logs may persist for a limited additional period before being overwritten on their normal cycle.
  • Aggregated and anonymised data that can no longer identify anyone may be retained indefinitely for analytics and service improvement.

7. Security

We maintain technical and organisational measures appropriate to the risk, including:

  • encryption of data in transit (TLS) and at rest;
  • hashed password storage and scoped, expiring authentication tokens;
  • multi-tenant isolation, so every request is scoped to the workspace it belongs to;
  • role-based access control within workspaces, and least-privilege internal access to production systems;
  • encrypted storage of third-party integration credentials;
  • error monitoring, audit logging, and regular dependency patching.

No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the relevant supervisory authority where required by law and within the applicable deadlines.

8. Your rights and how to exercise them

Depending on where you live, you may have the right to access your personal data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent. Where we rely on legitimate interests, you may object at any time. You also have the right to lodge a complaint with your local data protection supervisory authority.

For account data

Contact us at privacy@flowtracker.io. We will respond within the period required by applicable law — generally one month under the GDPR — and may need to verify your identity first. Many settings can also be changed directly in your account.

For workspace data

If your data is held in a workspace operated by a business you interacted with, that business is the controller and you should direct your request to them. As their processor, we are not permitted to grant access to or delete their data on our own initiative. If you contact us, we will forward your request to the relevant workspace owner where we can identify it, and assist them in responding.

We will not discriminate against you for exercising any of these rights.

9. Children

The Service is a business tool and is not directed to children. You must be at least 16 years old to create an account. We do not knowingly collect personal data from children under 16 as a controller. If you believe a child has provided us with personal data, contact privacy@flowtracker.io and we will delete it. Where a workspace owner collects data from minors through the Service, they are responsible for having the necessary legal basis and parental consent.

10. Cookies and similar technologies

We use a small number of cookies and browser storage entries to keep you signed in and remember your preferences. We do not use third-party advertising cookies. Full details are in our Cookie Policy.

11. Changes to this policy

We may update this Privacy Policy as the Service and the law evolve. The “Last updated” date at the top of this page always reflects the current version. If we make a material change, we will provide reasonable notice before it takes effect — for example by email or an in-product notice.

12. Contact us

For privacy questions or to exercise your rights, contact privacy@flowtracker.io. For general support, contact support@flowtracker.io.

Your use of the Service is also governed by our Terms of Service.