Privacy Policy
Effective Date: August 1, 2026
1. Overview
Kioku ("we", "our", or "us") provides a personal activity memory and recall service. We believe your capture data, conversations, and screen history belong to you. This Privacy Policy describes how information is collected, used, disclosed, retained, and protected when you use the Kioku Mac app, web dashboard at kiokuu.com, or an AI-assistant integration such as the Kioku plugin for ChatGPT.
2. Information We Process
- Account information: When you sign in with Google, we verify your identity token and store your verified email address and Google account subject identifier. We also store account status and feature preferences.
- Capture content: While capture is running, Kioku uploads bounded microphone and system-audio snippets, screenshots, application and window titles, exact browser URLs and tab observations, timestamps, device and stream metadata, and integrity information. Kioku derives transcripts, OCR text, timestamped speaker turns, learned people and voice profiles, facts, episode summaries, action items, and related evidence. This material can include information about you or other people visible or audible in your environment.
- Voice profiles: Kioku automatically computes biometric voice embeddings and uses explicit spoken or on-screen name evidence plus conservative voice similarity to recognize speakers over time. Profiles, samples, names, learned facts, confidence, and source evidence are stored in your encrypted archive. Ambiguous evidence remains unassigned rather than inventing an identity.
- AI-assistant requests and responses: When you connect Kioku to ChatGPT or another supported assistant, the assistant can send a narrowly scoped search, time range, or timestamp on your behalf. Kioku may return relevant transcript excerpts, OCR text, application/window context, URLs, episode summaries, action items, archive counts, and capture timestamps. Before assistant-facing content leaves the enclave, an MCP-only safety boundary refuses searches aimed at payment-card data, health information, government identifiers, passwords, API keys, tokens, or authentication codes; replaces matching incidental content with a redaction marker; and removes URL query strings and fragments. This boundary does not rewrite or delete your private archive and does not change owner-authorized dashboard or REST access. Kioku does not persist the text of MCP search queries or a per-query MCP activity log.
- Optional webhook automations: If you add a webhook destination, Kioku stores its HTTPS endpoint and a signing secret in the encrypted control store. Content-free finalized-episode notifications are the default. If you separately choose full brief content, the event also contains the episode title, times, participants, overview, decisions, action items, links, and open questions.
- Access-request information: If you submit the website access-request form, the name and email address you provide are processed separately from your private capture archive.
3. How We Use Information
- Authenticate you and keep each account's archive separated.
- Capture, synchronize, index, search, summarize, and display your personal activity memory.
- Return only the evidence needed to answer a search or recall request you make through Kioku or a connected assistant.
- Automatically transcribe audio, understand screenshots, diarize speakers, and learn people and voice profiles for recall.
- Provide features you configure, such as signed webhook automations.
- Protect the service with account controls, short-lived access tokens, and in-memory rate limits.
Kioku does not sell your personal information, use your private archive for advertising, or train a Kioku model on your archive.
4. Where Information Is Processed and Who Receives It
- Your Mac or iPhone: The Apple app captures and encodes bounded media, attaches authoritative timestamps and available application, window, display, and browser context, durably spools unacknowledged events, and uploads them. It does not transcribe, OCR, diarize, identify speakers, or build a local search index. Apple permission dialogs and platform recording indicators still apply.
- Google Cloud: Capture events are accepted and processed by the open-source Kioku service in a GCP Confidential Space enclave. Persistent raw media is encrypted per user before it is stored in a private Cloud Storage bucket; the enclave prunes it after 30 days and the bucket has a 35-day lifecycle failsafe. Derived archive data, people, voice profiles, and evidence are stored per user in encrypted databases. Google Identity Services supports sign-in.
- Google Vertex AI: Bounded raw audio and screenshot pixels are sent from the enclave to Vertex Gemini for timestamped transcription, diarization, OCR, and screenshot understanding. Settled-episode transcripts, OCR, application and window provenance, exact URLs, browser-tab metadata, and derived textual context may also be sent for summaries and recall features. Google processes this material under its applicable enterprise data terms. Voice embeddings and persistent cross-meeting identity matching are computed separately by Kioku inside the enclave and are not delegated to Gemini.
- OpenAI or another assistant provider: When you intentionally connect Kioku and make a recall request, the requested evidence leaves Kioku over HTTPS and is processed by that assistant provider under its own terms and privacy policy. Kioku sends no archive content to an assistant until an authorized tool request is made.
- Your webhook destination: If you configure a webhook, Kioku sends signed events to the HTTPS destination you choose. That destination is outside the enclave and processes the event under its own terms. Deleting the webhook stops future deliveries and cancels pending ones, but Kioku cannot retract data the destination already accepted.
- Web3Forms: The marketing-site access-request form sends only the name and email address you enter to Web3Forms; it does not send capture content.
The enclave backend source code is open source and auditable at github.com/joerodriguez/kioku-enclave.
5. AI-Assistant Connections
Connecting Kioku to ChatGPT or another supported assistant uses OAuth authorization. The connection grants read-only access to search your own Kioku archive; it does not let the assistant start or stop capture, edit your archive, send email, or delete data. Access tokens are short-lived, and refresh authorization expires after 90 days unless renewed. You can disconnect Kioku in the assistant's connection settings, and deleting your Kioku cloud account invalidates its Kioku authorization.
Kioku's assistant tools must not be used to seek payment-card data, health information, government identifiers, passwords, API keys, access or refresh tokens, private keys, recovery secrets, or MFA and one-time authentication codes. Targeted transcript and screen searches are refused before archive retrieval. All successful assistant tool results pass through the same in-enclave restricted-data projection, including transcript text, OCR, links, surrounding context, chronological digests, episode summaries, action items, minute summaries, and final briefs. Matching content is replaced rather than returned; malformed URLs and oversized text fail closed.
Only connect Kioku to an assistant account you trust. Content returned to an assistant may remain in that provider's chat history according to the settings and retention rules of that service.
6. Data Retention and User Controls
- Raw cloud media: Encrypted audio and screenshot objects are scheduled for deletion after 30 days, with a 35-day storage lifecycle failsafe.
- Derived cloud archive: Transcripts, OCR text, metadata, summaries, learned people, voice profiles, facts, and source evidence remain until you delete your cloud account or the service is discontinued. Kioku does not use inactivity alone to silently delete your archive.
- OAuth authorization: Kioku access tokens expire after approximately 15 minutes. AI-assistant refresh authorization expires after 90 days or earlier if disconnected or the account is deleted.
- Export: You can download an archive of supported cloud-synced account data from Web Dashboard Settings. The dashboard identifies features not yet included in export before you enable them.
- Deletion: You can purge your cloud account from Settings. This removes capture metadata, raw-media objects, transcripts, OCR text, episode summaries, learned people, facts, identity evidence, voice profiles and samples, account preferences, stored OAuth grants, webhook endpoints, and webhook signing secrets from Kioku's serving systems. It does not retract content already transferred to ChatGPT, a webhook destination, or another provider.
- Controls: You can pause capture, disconnect an assistant, delete webhook destinations, export supported account data, or delete your account. Audio, screenshots, and automatic voice/person learning are part of the normal capture pipeline rather than separate Kioku opt-in features. Deleting a webhook cancels its pending deliveries.
7. Security
Kioku encrypts synced archive data per user and uses a hardware-attested confidential-computing boundary for authorized query processing. No system is perfectly secure, so please report suspected security or privacy issues promptly through our Support page.
8. Changes and Contact
We may update this policy as Kioku changes. We will update the effective date and provide additional notice when required. For privacy questions or requests, contact privacy@kiokuu.com. For product help, visit kiokuu.com/support.