Last updated: April 7, 2026

Privacy Policy

This Privacy Policy explains how Kavela collects, uses, shares, and protects your personal data when you use our AI agent marketplace platform.

1. Who We Are

Kavela is an AI agent marketplace platform ("we," "us," or "our"). For data protection inquiries, contact us at support@kavela.ai.

2. Data We Collect

2.1 Account Data

When you create an account, we collect your name, email address, profile information, and authentication credentials. If you sign up via a third-party provider (e.g., Google, GitHub), we receive the profile information you authorize.

2.2 Payment Data

Payment information (credit card numbers, billing addresses) is collected and processed by our payment processor, Stripe. We do not store full payment card details on our servers. We retain transaction records (amounts, dates, subscription status) for billing and tax purposes.

2.3 AI Interaction Data

When you interact with Agents on the Platform, we collect the inputs you provide and the Outputs generated. This data is used to deliver the service, maintain conversation history, and enable features you request.

2.4 Creator Data

If you publish Agents, we collect your Agent configurations, prompt templates, uploaded knowledge bases, and publishing metadata.

2.5 Usage and Device Data

We automatically collect IP addresses, browser type, operating system, device identifiers, pages visited, referring URLs, and interaction timestamps. This data is collected via server logs and analytics tools.

2.6 Cookies and Tracking Technologies

We use cookies and similar technologies for authentication, preferences, analytics, and security. See Section 9 for details.

3. How We Use Your Data

PurposeLegal Basis (GDPR)
Provide and operate the PlatformContract performance
Process payments and manage subscriptionsContract performance
Deliver AI Agent interactions and conversation historyContract performance
Prevent fraud, abuse, and enforce our TermsLegitimate interest
Analytics and service improvementLegitimate interest
Send transactional emails (receipts, security alerts)Contract performance
Send marketing communicationsConsent
Comply with legal and tax obligationsLegal obligation

4. AI-Specific Data Practices

4.1 Model Training

We do not use your inputs or Outputs to train AI models without your explicit consent. If we offer optional data improvement programs, participation is always opt-in and can be revoked at any time through your account settings.

4.2 Third-Party AI Providers

Agents on the Platform may use AI models from third-party providers (e.g., Anthropic, OpenAI, Google). When you interact with such Agents, your inputs may be transmitted to these providers for processing. These providers act as sub-processors under contractual obligations to protect your data. Their data practices are governed by their respective privacy policies.

4.3 Automated Decision-Making

AI Agents may process your inputs using automated means. We do not use AI Outputs to make decisions that produce legal effects or similarly significant effects on you without human review. If you believe an automated decision has significantly affected you, contact us to request human review.

4.4 Interaction Data in the Marketplace

Creators may receive aggregated, anonymized usage analytics about their Agents (e.g., total interactions, average session length). Creators do not have access to individual Consumer inputs or Outputs unless the Consumer explicitly shares them through a platform feature (e.g., public sharing).

5. How We Share Your Data

We share personal data only in these circumstances:

  • Service providers and sub-processors — cloud infrastructure (Cloudflare, Supabase), payment processing (Stripe), analytics, and AI model providers, each bound by data processing agreements
  • Creators — only aggregated, anonymized analytics about Agent usage, never individual Consumer data
  • Legal requirements — when required by law, court order, or governmental authority
  • Business transfers — in connection with a merger, acquisition, or sale of assets, with equivalent privacy protections
  • With your consent — when you explicitly authorize us to share data with a specific third party

We do not sell your personal data. We do not share your personal data for cross-context behavioral advertising.

6. International Data Transfers

Your data may be processed in countries other than your own, including the United States and regions where our sub-processors operate. When we transfer data outside the EU/EEA, we rely on:

  • EU-US Data Privacy Framework certifications, where applicable
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions, where the destination country has been recognized as providing adequate protection

You may request a copy of the relevant transfer mechanisms by contacting us.

7. Data Retention

Data CategoryRetention Period
Account dataDuration of account + 30 days after deletion
AI interaction dataDuration of account + 30 days after deletion
Payment and billing records7 years (tax and legal compliance)
Server logs90 days
Creator Agent configurationsDuration of account + 30 days after deletion

You may request earlier deletion of your data, subject to our legal retention obligations.

8. Your Rights

8.1 Rights Under GDPR (EU/EEA Residents)

  • Access — request a copy of your personal data
  • Rectification — correct inaccurate data
  • Erasure — request deletion of your data ("right to be forgotten")
  • Portability — receive your data in a structured, machine-readable format
  • Restriction — limit processing of your data
  • Objection — object to processing based on legitimate interest
  • Automated decisions — not be subject to solely automated decisions with legal or significant effects
  • Withdraw consent — withdraw previously given consent at any time

To exercise your rights, contact us at support@kavela.ai. We will respond within 30 days.

You also have the right to lodge a complaint with your local data protection authority.

8.2 Rights Under CCPA (California Residents)

  • Right to Know — request disclosure of the categories and specific pieces of personal information we collect
  • Right to Delete — request deletion of your personal information
  • Right to Opt-Out — we do not sell or share personal information for cross-context behavioral advertising
  • Right to Non-Discrimination — we will not discriminate against you for exercising your rights

To submit a request, contact us at support@kavela.ai. We will verify your identity and respond within 45 days.

8.3 CCPA Disclosure: Categories of Personal Information

CCPA CategoryExamplesSold/Shared?
IdentifiersName, email, IP addressNo
Commercial informationSubscription history, credits purchasedNo
Internet/electronic activityBrowsing history, AI interactionsNo
Professional informationCreator profile, published AgentsNo

9. Cookies and Tracking

CategoryPurposeRequired?
Strictly necessaryAuthentication, security, session managementYes
FunctionalPreferences, theme, languageNo
AnalyticsUsage patterns, performance monitoringNo

We honor Global Privacy Control (GPC) signals. You can manage cookie preferences through your browser settings.

10. Security

We implement industry-standard technical and organizational measures to protect your data, including encryption in transit (TLS), encryption at rest, access controls, and regular security assessments.

In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected users and the relevant supervisory authority within 72 hours, as required by applicable law.

11. Children’s Privacy

The Platform is not intended for children under 18 (or the applicable age of majority). We do not knowingly collect personal data from children. If we learn that we have collected data from a child, we will promptly delete it. If you believe a child has provided us with personal data, contact us at support@kavela.ai.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on the Platform at least 30 days before taking effect. The "Last updated" date at the top reflects the most recent revision.

13. Contact Us

For privacy-related questions, data requests, or complaints, contact us at support@kavela.ai.

If you are in the EU/EEA and are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.