Privacy Policy

Last updated 30 September 2026.

Who we are

Kaiedo is a platform that builds and runs websites for small businesses, and connects those

businesses to one another. This policy covers https://kaiedo.com and the Kaiedo application. It does

not cover the websites Kaiedo generates for its customers — each of those carries its own policy,

written for that business.

Two different kinds of person appear below, and the difference matters throughout:

  • A subscriber — the operator of a business who has a Kaiedo account.
  • A customer of that business — somebody who filled in an enquiry form, made a booking or

left a review on a Kaiedo-built website. They gave their details to the business, not to us.

We hold them on that business's behalf.

What we hold

Kaiedo's database has 160 stores. Every one of them is classified in the codebase

for what it does to a person, and that classification is enforced automatically: a new store

cannot ship without one. 72 hold no personal data at all.

88 hold personal data or a reference to a person.

For a subscriber that means: the account and sign-in details, the businesses and websites

owned, settings and preferences, billing records, and the files uploaded while building a site.

For a customer of a business it means: what they typed into that business's form — typically

a name, an email address, a phone number, and whatever they wrote — plus bookings, notes the

business keeps about them, and reviews they chose to publish.

What we do not do

  • We do not sell personal data, and we do not share it for anybody else's advertising.
  • We do not use one business's customer list to market to those customers.
  • We do not move a business's customers into another business's records. When businesses connect

to one another through Kaiedo, what passes between them is a stated need and, where the

business chooses to send it, a reference — never a copy of somebody's contact details.

  • We do not read the content of a Google Drive, where one is connected at all, beyond the

specific files a person picks in Google's own picker.

Connecting Google

This is optional, and plenty of businesses never do it. A business with no Google Business

Profile — a startup that has not been listed yet, or one that simply chooses not to be — uses

Kaiedo in full without connecting anything, and nothing in this section applies to it. Kaiedo

does not require a Google account to build a site, take enquiries, run bookings, keep customer

records or collect reviews.

Where a subscriber does connect Google services to their Kaiedo account, Kaiedo requests only

these:

  • business.manage — To read the reviews, rating and opening hours on the business's own Google Business Profile, so they appear in Kaiedo beside the reviews collected through Kaiedo itself. Read-only.
  • webmasters.readonly — To read how the business's own pages performed in Google Search — which queries showed them, how often, and where they ranked — so Kaiedo can tell them whether a wording change made a difference. READ-ONLY: this scope cannot change a property, a sitemap or any setting, and Kaiedo never acts on their Search Console. Read-only.
  • drive.file — To read only the specific files a person chooses in Google's own file picker, so they can be used as source material for their website. Kaiedo never sees any other file in the drive. Read-only.

Access is granted by the subscriber and is limited to the scopes above. It can be withdrawn at any

time from their Google account, and it can be withdrawn inside Kaiedo: every connection carries a

Disconnect control on the same screen that made it — Reviews for a Google Business Profile, Assets

for Google Drive. Disconnecting deletes the stored credentials, so Kaiedo can no longer reach the

account. It does not delete what Kaiedo has already recorded, which is covered below.

Kaiedo's use of information received from Google APIs adheres to the

Google API Services User Data Policy,

including the Limited Use requirements.

Connecting other services

A subscriber may also connect a booking service (Calendly) or a store (Shopify). Kaiedo holds the

access those services issue, encrypted, in order to bring bookings and products into the business's

own workspace. These are optional in exactly the same way, each is disconnected from the screen that

connected it — Booking and Commerce — and disconnecting deletes the stored credentials the same way.

Erasure

A person can ask to be forgotten, and the request is honoured by machinery rather than by

somebody remembering to look.

Every store that holds personal data is declared with what an erasure does to it, and one of

three things is true of each: it is destroyed where the record exists only because of the

person; it is de-identified where the record has an ongoing purpose for the business — a

completed job, a booking that carries an outcome — so the person is removed and the business's

own history survives; or it is retained where a legal or record-keeping basis outranks the

request, in which case the erasure report says so plainly rather than passing over it.

Across the personal-data map, 42 stores are destroyed on erasure and

12 are de-identified. Files held outside the database are collected before the

rows that point at them are removed, so nothing is left orphaned.

Every place we hold personal data has a declared erasure behaviour, and a new one cannot

ship without one — that is checked when the code is built rather than left to somebody

remembering. What erasure does not mean is that every trace of you disappears.

37 of those places state a basis that outranks the request: a record we are

required to keep, or one whose removal would destroy a business's own history rather than yours.

The erasure report names each of them instead of passing over it.

To make a request, or to ask what we hold about you, write to hello@kaiedo.com. If you are a

customer of a business that uses Kaiedo, that business is the right first port of call — it is

their record — but we will act on a request sent directly to us.

Uploaded documents

When you upload a document while building a site, Kaiedo reads it and keeps short passages from

it. It also keeps any phone numbers and email addresses it finds. The file itself is deleted soon

after it is read.

What was kept is deleted after 12 months. It is also deleted if you ask us to erase your account.

Ask AI history

When you ask Ask AI a question inside a business, Kaiedo keeps the question and its answer for 30

days. They are encrypted when stored. After 30 days they are deleted automatically.

You can see your own questions. The owner of that business can see them too. Nobody outside that

business can see them. You can delete your own questions sooner, from Recent questions in Help.

Kaiedo's operational logs never keep a question or an answer. They keep only details such as

length and time.

AI features

Some Kaiedo features use AI to work with your business details. These include Ask AI, writing

and translating your site, and help with your emails and customer notes.

These features use OpenAI or Anthropic. Both work for Kaiedo under Kaiedo's own API agreements.

Kaiedo does not use any other AI company for these features.

When you use Ask AI, Kaiedo sends:

  • your question;
  • the Kaiedo help guide for the page you are on;
  • the business details that help answer it. These are only details you can already see in Kaiedo.

Under those agreements, neither company uses this information to train its models. To learn

more, see OpenAI's business data commitments and

Anthropic's commercial terms, or write to

hello@kaiedo.com.

Where data is held

Kaiedo runs on Vercel and stores data in Neon (PostgreSQL), Upstash and Vercel Blob. Billing is

handled by Stripe and accounts by Clerk; email is sent through Resend. Each processes data on

Kaiedo's instructions.

Changes

This policy is generated from Kaiedo's own code and is regenerated when what the platform does

changes. The date at the top is the date of the version you are reading.

Contact

hello@kaiedo.com