Legal

Privacy Policy

This policy describes the information Kona currently handles, why it is used, and the controls and limitations that apply.

Updated

Last updated: August 22, 2026

Support

Questions about this document can be sent to support@konabusiness.ai.

Last updated: August 22, 2026

1. SCOPE AND OPERATOR

This Privacy Policy applies to the Kona Business AI website and web application (the "Service"). In this policy, "Kona," "we," and "us" refer to the Service operator identified below. The operator's data-protection role can depend on the processing context and applicable law. This page describes current product behavior; it is not a security certification or a representation that every privacy law applies to every user.

Service operator
Not supplied
Service address
Not supplied
Privacy and legal contact
Not supplied. Operational product support remains available at support@konabusiness.ai.

2. INFORMATION WE HANDLE

  • Account information: when you use Google sign-in, Kona receives account details made available by Google, such as your name, email address, profile image, provider identifier, and authentication tokens. Kona does not receive your Google password.
  • Content and workspace information: prompts, responses, conversations, uploaded files, extracted file content, projects, assistants, planning sessions, sources, assumptions, formulas, scenarios, generated artifacts, exports, tasks, feedback, and workspace settings you choose to create.
  • Connected-service information: credentials, authorization grants, configuration, and data returned by a supported connector when you choose to connect it. Kona currently describes supported connector access as read-only unless a capability page explicitly states otherwise.
  • Technical information: IP address, user agent, request timing, error and security logs, rate-limit state, service diagnostics, and other data needed to operate and protect the Service.
  • Page measurement and analytics preference: Kona uses cookieless Vercel Web Analytics for aggregate page-view measurement. A first-party local-storage value records whether you also allowed optional Google Analytics and coarse events such as sign-in started or Workspace opened. These measurements are designed not to include prompts, file names, user IDs, email addresses, or workspace content.

Kona is currently offered without a paid subscription. The current product does not require payment-card details. If paid access is introduced, this policy and the purchase flow must describe the payment data and processor before collection begins.

3. HOW WE USE INFORMATION

  • Authenticate users and protect private product routes.
  • Generate requested answers, research, plans, scenarios, files, and other work products.
  • Store and restore conversations, workspace state, artifacts, and settings.
  • Operate connectors and other user-selected integrations.
  • Detect abuse, enforce limits, investigate failures, and improve reliability and security.
  • Respond to support, privacy, correction, and feedback requests.
  • Measure aggregate page visits and, when optional analytics is allowed, coarse product activation.

4. AI MODEL PROCESSING

To provide an AI feature, Kona sends the input needed for that request to the model provider configured for the feature. Depending on deployment configuration, providers may include Google, OpenAI, Microsoft Azure, or Anthropic. Inputs can include prompt text, conversation context, extracted file content, connected context, and tool results. Kona's application does not contain a pipeline that trains a Kona model on customer content. How an upstream provider retains or uses data is governed by that provider's applicable service configuration and terms; Kona does not make a broader provider-training promise on this page.

5. SERVICE PROVIDERS AND DISCLOSURE

Kona may disclose information to:

  • Hosting, authentication, storage, model-processing, email, analytics, and security providers used to run the Service.
  • A connected service when you initiate and authorize that connection.
  • Authorities or other parties when reasonably necessary to comply with law, protect users, or defend legal rights.
  • A successor involved in a merger, financing, reorganization, or sale, subject to appropriate confidentiality obligations.

Kona does not sell personal information or use workspace content for cross-context behavioral advertising. The Trust Center describes current product-control boundaries. A formal, self-service subprocessor schedule and Data Processing Addendum are not currently represented as available.

6. ANALYTICS, COOKIES, AND LOCAL STORAGE

Essential cookies and browser storage support authentication, security, preferences, and prompt handoff. Kona uses Vercel Web Analytics for cookieless, aggregate page-view measurement; it does not receive prompts, account IDs, or workspace content from Kona. Google Analytics and Kona's enumerated activation events load or send only after you select "Allow optional analytics" in the product. Selecting "Essential only" prevents those optional services. You can reset the preference by clearing this site's browser storage. Kona does not currently provide a separate account-level analytics-preference page.

7. RETENTION AND DELETION

Retention is feature-specific. Some short-lived operational data expires automatically, while account content and workspace records can remain until you delete the applicable item or ask Kona to handle a verified deletion request. A single self-service account action does not yet guarantee deletion or export of every data type across conversations, planning, connectors, code projects, tasks, memory, artifacts, and identity systems. Contact support@konabusiness.ai for a verified account-wide request. Legal, security, fraud-prevention, or backup obligations may require limited continued retention.

8. SECURITY

Kona uses server-side authentication and resource-ownership checks on protected routes. Connector credential payloads use AES-256-GCM when the required encryption configuration is present, and connector credential storage is blocked without that configuration. Hosting and infrastructure providers supply additional transport and storage protections. No method is perfectly secure. Enterprise SSO, SCIM, an independently audited control report, and a published penetration-testing program are not currently represented as available.

9. INTERNATIONAL USE

Kona and its providers may process information in the United States and other locations where they operate. Those locations may have different data-protection rules. Kona does not claim on this page that a particular transfer mechanism or regional hosting arrangement applies to every user. Contact us before using Kona where your organization requires a specific data location, transfer agreement, or procurement commitment.

10. YOUR CHOICES AND RIGHTS

Depending on where you live, applicable law may give you rights to access, correct, delete, restrict, object to, or receive a copy of personal information. Email support@konabusiness.aiwith the account email and the request. We may need to verify account control before acting. You may also disconnect integrations, remove individual content where the product provides a delete control, or decline optional analytics.

11. CHILDREN

The Service is intended for adults and business users, not children. Do not use Kona or submit personal information if you cannot legally agree to the Terms of Service in your jurisdiction.

12. CHANGES AND CONTACT

We may update this policy as the Service changes. The date at the top identifies the latest published version. Material changes will be presented through a reasonable product or website notice before they apply when required. Questions, requests, or complaints can be sent to support@konabusiness.ai.