1. Who We Are & Scope of This Policy
Controller for the website: KazmaAI / Mubder Alfaris, Kuwait. Contact: privacy@kazma.ai (postal address available upon written request).
This policy covers two distinct contexts — please read the one that applies to you:
- (A) The kazma.ai website (informational site, docs, product pages). We are the data controller.
- (B) The Kazma self-hosted software (MIT-licensed; you deploy it on your own server, Docker, or VPS via
kazma serve). Your data stays on infrastructure you control. When you self-host, you (the operator/deployer) are the data controller for personal data processed by your instance. We do not receive, see, or process your instance's Gmail, Drive, chat, memory, or vault contents. This policy describes how the software handles data locally so you can meet your own disclosure duties.
Kazma does not operate a multi-tenant public SaaS by default. If we ever offer hosted SaaS in the future, we will update this policy and offer a Data Processing Addendum (DPA).
2. Summary of Key Commitments
- We do not sell, rent, or share personal data with data brokers or advertisers.
- We do not use your Gmail / Google Drive content to train generalized AI models.
- Google User Data use is limited to the purposes disclosed here and to Google's Limited Use requirements (see §5).
- Self-hosted data (memory databases, vault, snapshots, backups) remains on your host unless you configure external providers (LLM APIs, Telegram/Discord/Slack/X, backups).
- AI outputs are machine-generated and may be inaccurate — human review is required (see the AI Disclaimer).
3. Data We Process — Website (A)
| Category | Examples | Purpose & Legal Basis |
|---|---|---|
| Technical / logs | IP address, user-agent, pages visited, error logs (Cloudflare / hosting logs) | Security, abuse prevention, site operation. GDPR Art. 6(1)(f) legitimate interests; Kuwait E-Transactions Law security duties. |
| Contact data | Email you send to our contact/privacy inboxes; GitHub/X/Telegram handle if you contact us there | Responding to enquiries. Art. 6(1)(b)/(f). |
| Preferences | Language (EN/AR), theme | Remember settings (local client storage only). Consent / legitimate interests. |
We do not use advertising cookies or cross-site trackers on kazma.ai. If analytics are added, this section and a cookie banner will be updated (see §12).
4. Data Processed by Self-Hosted Kazma (B) — Stays With You
Depending on features you enable, your instance may locally process:
| Category | Examples | Where It Lives |
|---|---|---|
| Connected-account data | Gmail messages, Drive files/metadata (only scopes you authorize); Telegram/Discord/Slack messages; scheduled X posts and drafts; calendar events | Your host (SQLite/Postgres, local files). Transmitted only to the provider APIs you configured, to execute your requested task. |
| Agent memory | Bi-temporal belief graph, episodes, embeddings (memory_state.db), snapshots, task ledger, research outputs | Your host. Optional scheduled backups (restic local/offsite) only if you configure them. |
| Secrets | API keys, tokens in the vault (AES-256-GCM, requires KAZMA_VAULT_KEY) | Your host, encrypted at rest. Never sent to us. |
| LLM prompts / completions | Prompts, tool calls, file contents you ask the agent to act on | Sent to the LLM provider you select (OpenAI-compatible, Anthropic, Gemini, Azure, Bedrock, Ollama/LM Studio). Governed by that provider's terms. |
| Voice / images / documents | Voice notes (transcribed via your configured provider), speech synthesis, uploaded images/PDFs and processed documents | Your host + transcription/TTS provider you select. |
We (the Kazma project) have no access to the above when you self-host. Telemetry is off by default; there is no phone-home of prompts, mailbox content, or secrets.
5. Google User Data — Detailed Disclosure (OAuth Verification / Limited Use)
This section satisfies the Google API Services User Data Policy, the Google Workspace User Data & Developer Policy, and OAuth verification requirements. Only enable the scopes you need (least privilege). See also the Google integration page for a plain-language description of the integration.
5.1 Scopes We May Request (as configured by operator)
| Scope family | Typical scopes | Approved use case |
|---|---|---|
| Gmail (Restricted) | gmail.readonly, gmail.send, gmail.modify / gmail.compose (only if operator enables) | Email clients; automatic backup; productivity (summaries, categorization, reporting). No bulk-spam sending. |
| Drive (Restricted/Sensitive) | drive.readonly, drive.file, drive.metadata.readonly (prefer narrowest) | Local sync / automatic backup; productivity apps handling files via UI; reporting on sharing. |
| Calendar / People (as enabled) | calendar / calendar.readonly, contacts.readonly | Scheduling and contact resolution for requested automations. |
| OpenID / profile | openid, email, profile | Sign-in / account identification where enabled. |
5.2 How We Use Google Data
- Only to fulfil your requested actions: e.g. back up specified mailbox/Drive folders; list/read/send/categorize mail you authorize; generate summaries or reports you request.
- No secondary uses. We do not use Google data for advertising, credit scoring, or training generalized AI/ML models.
- Human access: Google data is processed automatically by your self-hosted instance. Humans (other than you/your authorized users) do not access it. The only exceptions are the four Limited Use allowances: (a) with your affirmative consent for a specific message/feature; (b) for security/abuse investigation; (c) legal compliance; (d) internal operations limited to aggregated, anonymized data per Google's Limited Use §4(d).
- No transfer except as you direct: e.g. forwarding a message via Telegram/Discord/Slack channels you connect, or storing a backup where you configure. No sale or rental to third parties.
- Retention & deletion: retained only as long as needed for the workflow you configured (or as your retention policy states). Revoking OAuth in your Google Account stops future access; you may delete local copies from your instance (mailbox backups, knowledge corpora, memory beliefs) at any time. Deletion requests are honored promptly.
Security assessment: if your deployment stores or transmits Restricted-scope data on servers, Google may require a third-party security assessment (CASA/annual reassessment). The operator is responsible for completing verification for their own OAuth client.
6. LLM & Third-Party Providers (Operator-Selected)
Kazma is provider-agnostic. When you configure a provider, relevant prompts/files are sent to that provider under their terms. Examples: OpenAI, Anthropic, Google (Gemini), Azure OpenAI, AWS Bedrock, Groq, Ollama (local), Telegram/Discord/Slack/X APIs, optional malware scanning, and the websites your agent browses. Review each provider's privacy/DPA before enabling. Prefer EU-region endpoints or local models (Ollama) for heightened confidentiality.
Prompt-fencing note: Kazma wraps recalled/untrusted content in <kazma:data untrusted> fences to reduce prompt-injection authority. This is a mitigation, not a guarantee — always review high-stakes actions via HITL approval cards.
7. Legal Bases (EEA/UK) & Consent (Kuwait/MENA)
- EEA/UK GDPR: consent (Art. 6(1)(a)) for OAuth connections and optional features; contract (b) for requested services; legal obligation (c); legitimate interests (f) for site security and abuse prevention, balanced against your rights.
- Kuwait: Electronic Transactions Law No. 20/2014 requires consent/purpose specification for access/disclosure of personal data in electronic records, plus accuracy and safeguards (Arts. 32–36). Consent may be express or inferred from affirmative action indicating approval. Cybercrime Law No. 63/2015 criminalizes unauthorized access/disclosure.
- US state laws (e.g. California CCPA/CPRA): we do not sell/share personal information; see §10 for rights.
8. Retention
Website logs: 90 days, then aggregated/deleted. Contact emails: duration of correspondence + 24 months. Self-hosted data: controlled by operator retention settings; encrypted backups per operator schedule; delete on request/uninstall (note: restic snapshots retain per retention policy until pruned — document your prune schedule).
9. Security Measures
- Triple-wired Human-In-The-Loop (HITL) fail-closed gates; YOLO mode hard-blocked in production unless explicitly overridden; danger tools (shell execution, file writes, vault retrieval/deletion, outbound sends) require approval.
- HMAC-SHA256 skill checksum verification; RBAC roles (viewer/operator/admin); optional OIDC; AES-256-GCM secret vault; WAL-safe SQLite copies / validated Postgres dumps + JSONL exports.
- Transport security (TLS), least-privilege scopes, per-tenant isolation options, audit logs.
- No security is perfect. Operators must set strong
KAZMA_SECRETandKAZMA_VAULT_KEY, keep the default127.0.0.1binding, setKAZMA_PRODUCTION=1+KAZMA_TRUSTED_PROXIESbehind proxies, and patch promptly (see SECURITY.md).
10. Your Rights
EEA/UK (GDPR)
Access, rectification, erasure, restriction, portability, objection, withdraw consent, lodge a complaint with your supervisory authority. Contact privacy@kazma.ai; we respond within one month.
California / US states
Right to know, delete, correct, opt out of sale/sharing (we do not sell), limit sensitive processing, non-discrimination. Authorized agents honored with verification.
Kuwait / MENA
Under E-Transactions Law Arts. 33/36 you may request access/record, modification, or deletion of your personal data in our electronic records via yourself or a legal representative. UAE PDPL / Saudi PDPL rights apply to residents of those states for website data; self-host operators should honor equivalent requests for instance data.
To exercise rights for a self-hosted instance you do not operate, contact that operator directly.
11. International Transfers
Website hosting/CDN may process logs outside Kuwait. Where GDPR applies we use appropriate safeguards (adequacy, SCCs, transfer impact assessment). Self-host operators choose their hosting/LLM regions and are responsible for transfer compliance (e.g. CITRA Cloud Framework approvals; note that DPPR breach-notification duties apply to CITRA licensees).
12. Cookies & Similar Technologies
kazma.ai currently uses only strictly-necessary storage (theme/language) and does not set advertising/tracking cookies. If analytics are added, we will show a consent banner and list cookies here with purpose, duration, and opt-out.
13. Children
Kazma is not directed to children under 13 (or the higher minimum age in your jurisdiction, e.g. 16 under the GDPR default). Do not connect a child's Google account. Guardian consent is required where applicable.
14. Automated Decision-Making & AI Transparency (EU AI Act Art. 50)
- Kazma agents interact conversationally and generate synthetic content. Deployers must inform exposed persons they are interacting with AI no later than first interaction, in a clear, accessible manner.
- AI-generated outputs should be labelled as such where required (machine-readable marking per Art. 50(2) for systems placed on the market from 2 Aug 2026; grace to 2 Dec 2026 for earlier systems). Do not present agent outputs as solely human-authored where the law requires disclosure (including California SB-942 AI-detection disclosure duties where applicable).
- No emotion-recognition, biometric categorization, social scoring, or other prohibited practices (Art. 5) are built in — and they are prohibited via the Acceptable Use Policy.
- Human oversight stays mandatory: HITL approval for consequential actions; the operator remains responsible for verifying outputs before legal, medical, financial, or safety-critical reliance.
15. Breach Notification
For website breaches we notify affected users and authorities as required (GDPR 72h to the authority; Kuwait Cybercrime/CITRA duties where applicable — CITRA licensees: 24h to CITRA + users). Self-host operators are independently responsible for breach response for their instances (see the Disaster Recovery docs in the repository).
16. Changes
We will post updates here with a new "Last updated" date and, for material changes (especially Google-data use), provide prominent notice and renewed consent where required. Review periodically.
17. Contact & Complaints
Privacy questions / rights requests: privacy@kazma.ai. Security issues: admin@kazma.ai (see SECURITY.md). Kuwait: CITRA (telecom matters) / Cybercrime Department, Ministry of Interior. EU: your national DPA. We aim to acknowledge within 48 hours (best effort).
Related: Terms of Use · AI Disclaimer · Acceptable Use Policy · MIT License