Kapso Privacy Policy
Last updated: August 29, 2026
Effective date: September 1, 2026
This Privacy Policy explains how Kapso, Inc. (“Kapso,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information when you visit our websites, create an account, communicate with us, or use our applications, APIs, tools, messaging infrastructure, AI features, and related services (collectively, the “Services”).
Kapso, Inc. is a Delaware corporation with an address at 251 Little Falls Drive, Wilmington, Delaware 19808, United States. Questions and privacy requests may be sent to legal@kap.so.
1. When this Policy applies
This Policy applies when Kapso determines why and how personal information is processed, such as for account administration, billing, product analytics, marketing, security, and support.
Customers also submit messages, contacts, media, prompts, files, and other information to the Services for processing on their behalf (“Customer Content”). For personal information contained in Customer Content, the customer generally determines the purposes of processing and acts as controller or business, while Kapso acts as processor or service provider. That processing is governed by the customer’s agreement with Kapso and the Kapso Data Processing Addendum. If you are an end user of a Kapso customer, you should direct requests about Customer Content to that customer first.
This Policy does not govern independent products or services operated by Meta, WhatsApp, Stripe, AI providers, or other third parties, even when they connect with Kapso.
2. Information we collect
Information you provide
We may collect:
- Account and profile information: name, email address, organization, role, authentication information, preferences, and account settings.
- Billing information: plan, subscription, invoices, transaction history, balances, usage, tax information, and limited payment-method information. Payment-card details are generally collected and stored by Stripe rather than Kapso.
- Communications: support requests, survey responses, feedback, emails, calls, and other communications with us.
- Customer Content: messages, contacts, media, templates, prompts, files, transcripts, recordings, configurations, webhooks, tool inputs and outputs, and related metadata that you choose to process through the Services.
- Integration information: identifiers, credentials, tokens, permissions, account metadata, and configuration information needed to connect services such as Meta and WhatsApp.
- Phone-number information: telephone numbers you connect, numbers provisioned through Kapso, verification and registration data, call or messaging metadata, and number activity.
Information collected automatically
When you use the Services, we may collect:
- IP address, device type, browser, operating system, language, approximate location, and identifiers;
- pages and features viewed, clicks, navigation, timestamps, referrers, and interaction events;
- API calls, webhook activity, usage volume, errors, performance data, logs, and security events;
- subscription and feature usage, including messaging, AI, transcription, and telephony consumption; and
- session replay or similar interaction recordings designed to help us understand product use and diagnose issues. We configure these tools to reduce capture of sensitive fields, but you should not enter secrets or Restricted Data into fields not intended for them.
Information from third parties
We may receive information from:
- account and authentication providers;
- Meta, WhatsApp, Stripe, telephony providers, AI providers, and other integrations you enable;
- customers, partners, resellers, and other users who invite or manage you;
- analytics, advertising, and security providers; and
- public sources where permitted by law.
3. How we use information
We use personal information to:
- provide, configure, maintain, and improve the Services;
- create and administer accounts, organizations, projects, permissions, and integrations;
- process transactions, subscriptions, credits, usage, overages, and taxes;
- transmit messages, media, prompts, files, calls, webhooks, and other requested operations;
- provide support and communicate about service, billing, security, and policy updates;
- monitor performance, understand product use, troubleshoot, and develop features;
- protect accounts and systems, prevent fraud and abuse, enforce our Terms, and investigate incidents;
- comply with law and respond to valid legal requests;
- market Kapso, measure campaigns, and personalize communications where permitted; and
- carry out corporate transactions such as a financing, reorganization, acquisition, or sale.
We may aggregate or de-identify information and use it for analytics, research, benchmarking, security, and product improvement. We do not attempt to re-identify data that we maintain as de-identified.
4. AI and model improvement
When you use an AI, transcription, speech, or automated feature, we process the inputs, context, files, outputs, and related metadata needed to provide that feature. Depending on the feature and your configuration, this information may be sent to one or more AI or infrastructure providers identified in our Subprocessor List.
Our use of Customer Content to develop, test, train, and improve Kapso features and models depends on the Project’s plan and model-improvement preference. For Projects on the Free plan, this use is enabled by default, but a Project owner or admin may disable it through an available account control or by contacting legal@kap.so. For Projects without an active plan and for Projects on paid plans other than Enterprise, this use is disabled by default and occurs only if a Project owner or admin enables it. We will not use Enterprise Project Customer Content for generalized model or product improvement unless separately agreed in writing.
Enabling or disabling this preference applies prospectively. It does not prevent processing needed to provide a requested feature, maintain security, investigate abuse, comply with law, or produce aggregated or de-identified analytics.
We seek to use business or API arrangements that restrict third-party providers from using submitted data to train their general models where commercially available. Provider behavior can depend on the model, route, account, and feature selected by the customer. Customers should review available settings and should not submit Restricted Data to AI features without written approval.
5. Legal bases for processing
Where laws such as the GDPR require a legal basis, we process personal information based on one or more of the following:
- Contract: to provide the Services and take requested steps before entering into a contract.
- Legitimate interests: to secure, operate, analyze, and improve the Services; communicate with users; prevent abuse; and run our business, where those interests are not overridden by individual rights.
- Consent: where we ask for consent, including for certain cookies, marketing, or optional uses. Consent may be withdrawn at any time.
- Legal obligations: to maintain records, respond to lawful requests, and comply with applicable law.
- Protection of rights: to establish, exercise, or defend legal claims and protect people, systems, and property.
When we process Customer Content as a processor, the customer is responsible for identifying the appropriate legal basis and giving us lawful instructions.
6. How we disclose information
We may disclose personal information to:
- Affiliates: including Kapso SpA in Chile, which supports engineering, operations, and customer service.
- Service providers and subprocessors: providers of hosting, databases, storage, monitoring, analytics, communications, billing, AI, transcription, telephony, security, and related functions. Our current Customer Content subprocessors are listed in the Kapso Subprocessor List.
- Third-party platforms and integrations: including Meta and WhatsApp, when you request or configure the connection. Those parties may act as independent controllers for some processing.
- Your organization and authorized users: administrators and other people with permissions in your account may access account activity and Customer Content.
- Professional advisers: lawyers, auditors, accountants, insurers, and consultants subject to appropriate duties.
- Authorities and affected parties: when reasonably necessary to comply with law, legal process, or valid requests; enforce agreements; or protect rights, safety, and systems.
- Transaction participants: actual or potential investors, lenders, buyers, sellers, and advisers in a financing, merger, acquisition, reorganization, bankruptcy, or sale, subject to appropriate safeguards.
- Others at your direction or with your consent.
We do not sell personal information for money. We use analytics and advertising technologies, including PostHog and X, to understand use and measure or promote Kapso. Under some U.S. state laws, certain advertising-cookie disclosures may be considered a “sale,” “sharing,” or targeted advertising even when no money is exchanged. Where required, you may opt out using the privacy or cookie controls we make available or by contacting us.
7. Cookies, analytics, replay, and advertising
We and our providers use cookies, pixels, local storage, SDKs, and similar technologies to:
- keep you signed in and remember settings;
- secure the Services and prevent abuse;
- understand performance and product usage;
- replay selected interactions to troubleshoot and improve user experience; and
- measure and improve advertising campaigns.
Some technologies are necessary for the Services. Others are used based on consent or another lawful basis where permitted. Browser controls may block some technologies, but blocking necessary technologies can affect functionality. Where required, we provide a cookie or privacy preference control and honor applicable opt-out signals.
8. International data transfers
Kapso is based in the United States, works with an affiliated team in Chile, and uses providers that operate in the United States and other countries. Personal information may therefore be processed outside the country where it was collected.
Where required, we use recognized transfer mechanisms and safeguards, such as adequacy decisions, the European Commission’s Standard Contractual Clauses, and the UK transfer addendum. The Kapso Data Processing Addendum provides additional terms for Customer Content.
9. Retention
We retain personal information for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, comply with law, resolve disputes, secure systems, and enforce agreements. Retention depends on the type of information and how it is used.
For example:
- account, project, message, contact, and integration data may remain while an account or relevant project is active;
- operational logs, webhook events, execution records, and telemetry may be kept for shorter periods ranging from days to months;
- billing, tax, fraud-prevention, security, audit, and legal records may be retained longer;
- information in backups is deleted through normal backup rotation; and
- when an account or project is deleted, we generally delete or anonymize Customer Content from active systems within a commercially reasonable period, typically 30 to 90 days, subject to technical limitations, backup cycles, legal obligations, security needs, and any contrary customer instruction or agreement.
Customers may access much of their information through the dashboard and APIs and may request deletion through available endpoints, project settings, or support. Certain financial, security, or audit records may remain after project deletion where required or reasonably necessary.
10. Security
We use technical and organizational measures designed to protect personal information, including access controls, authentication safeguards, encryption supported by our infrastructure providers, monitoring, change-management practices, incident response, backups, and vendor oversight. No system is completely secure, and we cannot guarantee absolute security.
You are responsible for protecting your credentials and systems, configuring the Services appropriately, limiting permissions, and notifying us promptly of suspected compromise.
11. Your choices and rights
Depending on where you live, you may have rights to:
- access or obtain a copy of personal information;
- correct inaccurate information;
- delete information;
- object to or restrict certain processing;
- withdraw consent;
- receive portable data;
- opt out of targeted advertising, sale, or sharing as defined by applicable law;
- manage the available model-improvement preference described above; and
- appeal a decision on a privacy request.
You can manage much of your account and Customer Content through the dashboard and APIs. You may also submit a request to legal@kap.so. We may verify your identity and authority before acting. Authorized agents may submit requests where permitted by law.
If your information appears in Customer Content controlled by a Kapso customer, contact that customer first. We will assist the customer as required by our Data Processing Addendum.
EEA, UK, and Swiss residents may complain to their local data-protection authority. We encourage you to contact us first so we can try to resolve the concern.
We will not discriminate against you for exercising applicable privacy rights.
12. Children
The Services are not directed to children under 16, and we do not knowingly collect personal information directly from children under 16. Customers must not submit personal data of children under 16 without Kapso’s prior written approval and a lawful basis. If you believe a child has provided information in violation of this Policy, contact us.
13. Marketing communications
You may unsubscribe from promotional emails using the link in the message or by contacting us. We may still send transactional, billing, security, and service communications necessary to administer your account.
14. Business customers and downstream users
Customers that use Kapso to provide products or services to their own customers are responsible for giving those individuals appropriate privacy notices, obtaining required permissions, and configuring the Services consistently with those notices. Kapso may process requests received from downstream users by directing them to the relevant customer.
15. Changes to this Policy
We may update this Policy as our Services and practices change. If a change is material, we will provide reasonable notice through the Services, by email, or by another appropriate method. The “Last updated” date shows when this version was revised.
16. Contact us
Kapso, Inc.
251 Little Falls Drive
Wilmington, Delaware 19808
United States
legal@kap.so