As little about you as possible
Last updated July 19, 2026
K.ai is built to hold as little information about you as possible. This policy identifies what the app collects or transmits, how it obtains that data, every purpose for which it is used, who receives it, and how to withdraw permission or request deletion.
Your anonymous account
K.ai has no sign-up. The app creates a random 32 byte account key on your device. The app sends a one way verifier derived from that key, and K.ai stores only another hash of the verifier to authenticate future requests. The account destination derived from the verifier maintains credits and spending records. The raw account key is never sent to K.ai or an inference provider. If you deliberately enable account recovery, Apple synchronizes an end to end encrypted copy through your iCloud Keychain. Otherwise it remains local. Web sign in with Nostr creates a random session token; K.ai stores only its hash. We do not ask for or collect your name, email address, phone number, contacts, advertising identifier, or precise location, and we do not use analytics or advertising SDKs.
Data you choose to send
K.ai obtains content only when you type, speak, capture, select, share, or link it. Depending on the feature you choose, a request may contain:
- Your question and a limited number of recent messages needed for conversational context.
- An optional “about me” memory note stored on your device.
- Photos you capture or select, and instructions for generating or editing an image.
- Text extracted on-device from documents you select. The app offers on-device personal-information redaction before sending.
- Voice audio for transcription, the resulting transcript, and answer text for speech playback.
- A webpage address you share, or question-relevant excerpts and relative source labels returned from an External Brain on your linked Mac. Absolute folder locations, security bookmarks, the search index, and the knowledge graph stay on the Mac.
- Your question or a derived search query when web search or deep research is used.
Please do not send information you do not want processed. K.ai sends only the categories needed for the feature you invoke; selecting a photo, document, microphone, or linked Mac does not grant access to unrelated content.
Your permission
Before the iPhone, iPad, or Mac app sends any prompt, photo, document text, voice audio, search query, or linked excerpt for AI processing, it displays an in-app disclosure naming the recipients below and asks you to choose Allow AI processing or Not now. Declining blocks those requests. You may later allow or turn off sharing in Settings → Privacy → AI data sharing. Turning it off blocks all new AI, search, voice, photo, document, and linked-content requests.
Who receives request content
K.ai's server removes your account identifier before forwarding request content. The applicable processor receives content only to perform the feature you requested:
DeepInfra, Inc. Processes text answers, photo understanding, document questions, image generation and editing, and some speech requests. DeepInfra states that API inference input and output are not used for training and are generally held only in memory, subject to limited debugging, security, and model-provider exceptions. DeepInfra data privacy.
Google LLC, through DeepInfra A Google vision model may process a photo request. DeepInfra states that Google may log prompts and responses for a limited period to detect prohibited use. Google does not receive your K.ai account identifier.
Groq, Inc. May process voice audio for transcription or answer text for speech. K.ai's Groq organization has Zero Data Retention enabled, and the server disables Groq content processing unless that configuration is explicitly confirmed. Groq retains content-free service metadata but does not retain K.ai inference input or output under this setting. Groq data practices.
Cerebras Systems Inc. May process a question and limited recent context for a low-latency voice answer. Cerebras states that it does not retain inputs and outputs associated with its inference service and safeguards service data under its privacy policy. Cerebras privacy policy.
Exa Labs, Inc. May receive a search query or a webpage address when K.ai performs web research or extracts a page. K.ai disables Exa unless the server operator has explicitly confirmed the applicable business data protections. Exa never receives attached photos, document text, External Brain excerpts, recent chat history, or your K.ai account identifier. Exa privacy policy.
Brave Software, Inc. Receives a search query only when K.ai uses web search or deep research. Brave states that standard API query logs may be retained for up to 90 days for billing, troubleshooting, and abuse prevention and are not linked to an end user or device. Brave does not receive attachments, linked excerpts, recent chat history, or your K.ai account identifier. Brave Search API privacy.
WikEM.ai, operated by K.ai. Receives only an acute care question and answer language when K.ai selects its specialist medical route. It receives no K.ai account identifier and does not log or retain the question or answer.
Equal protection. K.ai uses these companies as service processors only to fulfill the request you chose. We confirm that each processor is required to safeguard the data it receives with the same or equal protection required by this policy and Apple's privacy requirements. We do not permit them to identify K.ai users, advertise to them, sell their content, or train a model on their content on K.ai's behalf.
K.ai Link network privacy
K.ai Link encrypts questions, evidence, and answers between paired devices. It uses the public Pear and HyperDHT network and may use a blind encrypted relay when a direct connection is unavailable. Network participants may observe endpoint and traffic metadata, but they receive no K.ai account credential, application key, question, excerpt, or answer plaintext. K.ai does not operate a Link signaling, routing, or relay server.
Storage and deletion
Your conversation history is stored only on your device and automatically deletes seven days after the last activity unless you save it. “Wash everything away” deletes local conversations and memory immediately. On Mac, Wash Local Data Away also removes attachment grants, Projects, External Brain grants and indexes, linked devices, K.ai Link keys, and Link audit history. It does not delete your source files or K.ai balance. K.ai's server handles questions, photos, document text, linked excerpts, and voice audio in transit and does not add them to a chat-history database. A generated answer, generated image, and source list may remain in an in-flight delivery record until acknowledged or expired, no longer than 48 hours.
K.ai does not write prompts, answers, media, credentials, or IP addresses to application or web access logs. Pseudonymous operational records for provider usage and model routing are linked to an account or request while retained. They contain service, lane, timing, token counts, cost, and status, but no question, answer, media, document, audio, credential, or IP content. They are normally deleted after 90 days. The configured period is bounded between 30 and 365 days. Financial ledger records are retained while needed to maintain the prepaid balance, prevent duplicate credits, process refunds, and meet legal obligations.
Third-party processor retention is described above. Revoking permission prevents new transfers but cannot undo processing already completed or records a processor must temporarily retain for security, billing, or legal compliance.
What we do keep
- Your pseudonymous account destination with its credit balance and credit and spending ledger, used for balance restoration, purchases, refunds, and fraud prevention. A modern key account cannot be authenticated with the destination alone.
- Service metrics without question, answer, photo, document, audio, credential, or IP content: processor and model tier, timing, token counts, cost, and request status. We use these to operate the service, calculate charges, diagnose failures, and improve routing.
- For the public Nostr service, public keys, public event identifiers, answer counts, zap totals, and financial zap records. Content-free answer telemetry follows the operational retention period. Counters and payment records remain as needed to enforce the public allowance and maintain financial records.
- For Android welcome credit, a one-way hash of the app-specific device identifier. It is retained only to prevent the same device from repeatedly claiming promotional credit.
Payments
App Store purchases are handled entirely by Apple. We never see your name or payment details. Google Play purchases are handled by Google; K.ai sends Google the purchase token and product identifier for verification and keeps the transaction reference in the financial ledger. Bitcoin Lightning payments reach us as a settled payment tied to a pseudonymous account destination, nothing more. The Apple welcome credit uses Apple's DeviceCheck. The app obtains a DeviceCheck token from Apple and sends it through K.ai to Apple only to set or read the one-time welcome-credit bit. K.ai does not store the token; Apple tells us only whether the device already claimed. Android uses Google Play Integrity to verify the app and device before applying the one-way welcome-credit marker described above.
Your choices and deletion requests
If you use a Nostr key with K.ai, its private half is generated and held on your device. We store only the public half as the name of your credit balance and cannot recover a lost private key. You can delete device content with “Wash everything away,” revoke AI sharing in Settings, or contact us to request deletion of the server-side anonymous account and ledger. Because there is no email account, we will ask for the public account destination and proof that you control it. Never send us your account key, private Nostr key, verifier, or session token.