Privacy Policy
Last updated: 7 August 2026
This policy explains what personal data Kyte processes, why, who we share it with, and the choices and rights you have.
Kyte is a business tool, so we handle data in two distinct capacities: data about our own customers, which we control, and data about our customers’ contacts, which we process on their behalf. Section 1 explains the difference and who to contact in each case — it is the most important part of this policy.
1. Our two roles: controller and processor
Understanding which role we play is the key to this policy, because it determines who decides what happens to your data and who you should contact about it.
We are the controller of account data
When you sign up for Kyte, we decide how to handle the data about you as our customer — your name, email address, password credentials, workspace membership and billing contact details. For this data we are the data controller, and you can exercise your rights directly with us.
We are a processor for workspace data
When you use Kyte to communicate with your own customers and contacts, the data about those people — their names, phone numbers, email addresses, channel handles, message content, CRM records and call recordings — is data we process on behalf of the workspace owner. The workspace owner is the data controller for it. They decide what to collect, why, how long to keep it, and who may see it. We act only on their documented instructions.
This matters practically: if you are a contact of a business that uses Kyte and you want your data accessed, corrected or deleted, contact that business directly — they control it. If they ask us to act, we will assist them. You may still contact us at privacy@flowtracker.io and we will route your request to the right workspace where we can identify it.
2. Data we process
Account data (we are controller)
- Identity and contact details: name, email address, profile information.
- Authentication data: hashed passwords, session tokens, and identifiers from third-party sign-in providers where you use them.
- Workspace data: which workspaces you belong to, your role and permissions within them.
- Billing data: billing contact details, plan and subscription status, invoice and payment references. Card numbers are handled by Stripe and never stored by us.
- Usage and technical data: log data, IP address, device and browser information, feature usage, and error diagnostics.
Workspace data (the workspace owner is controller)
- Contact identities: names, phone numbers, email addresses, and channel handles or IDs for WhatsApp, Telegram, Instagram, Messenger and other connected channels.
- Message content and attachments exchanged across connected channels and live chat.
- CRM records: leads, pipeline stages, notes, tags and custom properties.
- Tracked-link data: click events, coarse location derived from IP address, and device and browser characteristics.
- Payment references, where a workspace connects a payments integration.
- Call recordings and transcripts, where the workspace enables voice features. The workspace owner is responsible for providing any notice and obtaining any consent that recording requires in the relevant jurisdiction.
3. How we use data and our legal bases
Where the GDPR or similar laws apply, we rely on the following legal bases for account data that we control:
- Performance of a contract — to create and administer your account, provide the Service, process payments, and provide support.
- Legitimate interests — to secure the Service, prevent fraud and abuse, monitor errors and reliability, understand aggregate product usage, and communicate about material service changes. We balance these against your rights and interests.
- Consent — for optional marketing communications and any non-essential cookies. You may withdraw consent at any time.
- Legal obligation — to meet accounting, tax and other statutory requirements, and to respond to lawful requests.
For workspace data, the legal basis is determined by the workspace owner as controller. We process it under their instructions and under our data processing terms with them.
We do not sell personal data, and we do not use the content of workspace conversations to train generally-available AI models.
4. Subprocessors
We use the third-party providers below to deliver the Service. Each is bound by contractual confidentiality and data protection obligations, and may process data only to provide their service to us. Which subprocessors apply to a given workspace depends on the features and integrations that workspace enables — for example, telephony providers are involved only where voice features are turned on.
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Railway | Application hosting and infrastructure | All data processed by the Service |
| MongoDB, Redis, RabbitMQ (hosted on Railway) | Primary database, caching and message queuing | Account data, workspace data, message content |
| ClickHouse | Analytics and reporting storage | Event, click and aggregated usage data |
| Supabase | File and media storage | Attachments and uploaded files |
| Stripe | Payment processing and subscription billing | Billing contact details, payment references |
| Anthropic | AI model processing for AI agents and assistance | Content submitted to AI features |
| OpenAI | AI model processing for AI agents and assistance | Content submitted to AI features |
| ElevenLabs | Voice synthesis and transcription | Call audio and transcripts, where voice features are enabled |
| Resend | Transactional and outbound email delivery | Recipient email addresses and message content |
| Sentry | Error monitoring and diagnostics | Technical error data, which may include identifiers |
| Meta, Telegram, Google | Messaging channel and authentication integrations | Channel identifiers and message content for connected channels |
| Twilio, Plivo | Telephony and SMS delivery | Phone numbers, call metadata, message content |
We may update this list as the Service evolves. Material changes to subprocessors that affect workspace data will be notified to workspace owners in accordance with our data processing terms.
5. International transfers
Our subprocessors operate globally, so personal data may be transferred to and processed in countries other than the one where it was collected, including the United States. Those countries may not provide the same level of data protection as your home jurisdiction.
Where we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on appropriate safeguards — principally the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with supplementary technical and organisational measures such as encryption in transit and at rest. Where a recipient is covered by an adequacy decision or a certified transfer framework, we may rely on that instead.
6. Data retention
- Account data is retained for as long as your account is active. After you close your account we delete or anonymise it, except where we must keep records to meet legal, tax or accounting obligations, or to resolve disputes and enforce our agreements.
- Workspace data is retained according to the workspace owner’s configuration and instructions. They can delete records at any time, and they decide their own retention periods.
- On termination of a workspace, we delete or anonymise its data after a short grace period that allows for accidental deletion and final export, unless a longer period is required by law.
- Backups and logs may persist for a limited additional period before being overwritten on their normal cycle.
- Aggregated and anonymised data that can no longer identify anyone may be retained indefinitely for analytics and service improvement.
7. Security
We maintain technical and organisational measures appropriate to the risk, including:
- encryption of data in transit (TLS) and at rest;
- hashed password storage and scoped, expiring authentication tokens;
- multi-tenant isolation, so every request is scoped to the workspace it belongs to;
- role-based access control within workspaces, and least-privilege internal access to production systems;
- encrypted storage of third-party integration credentials;
- error monitoring, audit logging, and regular dependency patching.
No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the relevant supervisory authority where required by law and within the applicable deadlines.
8. Your rights and how to exercise them
Depending on where you live, you may have the right to access your personal data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent. Where we rely on legitimate interests, you may object at any time. You also have the right to lodge a complaint with your local data protection supervisory authority.
For account data
Contact us at privacy@flowtracker.io. We will respond within the period required by applicable law — generally one month under the GDPR — and may need to verify your identity first. Many settings can also be changed directly in your account.
For workspace data
If your data is held in a workspace operated by a business you interacted with, that business is the controller and you should direct your request to them. As their processor, we are not permitted to grant access to or delete their data on our own initiative. If you contact us, we will forward your request to the relevant workspace owner where we can identify it, and assist them in responding.
We will not discriminate against you for exercising any of these rights.
9. Children
The Service is a business tool and is not directed to children. You must be at least 16 years old to create an account. We do not knowingly collect personal data from children under 16 as a controller. If you believe a child has provided us with personal data, contact privacy@flowtracker.io and we will delete it. Where a workspace owner collects data from minors through the Service, they are responsible for having the necessary legal basis and parental consent.
11. Changes to this policy
We may update this Privacy Policy as the Service and the law evolve. The “Last updated” date at the top of this page always reflects the current version. If we make a material change, we will provide reasonable notice before it takes effect — for example by email or an in-product notice.
12. Contact us
For privacy questions or to exercise your rights, contact privacy@flowtracker.io. For general support, contact support@flowtracker.io.
Your use of the Service is also governed by our Terms of Service.