Kievit
Terms of ServicePrivacy PolicyEULA

Privacy Policy

Version 2026-09-24 · effective 2026-09-24

This policy explains what personal data Kievit processes, why, and your rights. Sagoskatt Holdings is the controller for this processing (contact details at the end). The short version: message text is never stored, only what’s needed to show your tasks; finished tasks and message details are deleted after 6 months; you can download or delete everything yourself at any time.

1. What we process

  • Account: your name, email address, time zone, the public key of your passkey (we never see the private key), and a hashed session token in a cookie.
  • Connected accounts: the address or workspace, server settings, and the app password or sign-in token you provide — stored encrypted.
  • Message details: for messages that are checked, the sender, recipients, subject, date and thread references (for Slack: channel, sender and timestamps; for calendar events: title, time, place, organiser, attendees and your answer to the invitation).
  • Message text: read when a new message is analysed and when you open it (for events: the description). It is kept at most 15 minutes in an encrypted cache and never stored otherwise.
  • Conversations with the AI about a task (“Ask AI”): your questions and the answers, stored encrypted until you clear them or the task is deleted. Each question sends the task and the text of its linked messages to the AI; an attachment is only sent when you tick it, for that question, and is never stored.
  • Tasks: the tasks you create or confirm, the AI’s title and summary, notes, due dates, reminders and history.
  • Beta sign-ups: if you use “Join the beta”, your email address and what you told us you run, until we’ve invited you (and deleted when you ask).
  • Statistics: daily counts of what Kievit did for you (messages checked, newsletters and automated mail filtered, scams flagged, tasks made and done, AI use). Only numbers, never content. They are kept after the details are deleted, so you can see your totals over time, and when you delete your account they are merged into anonymous totals that can’t be traced back to you.
  • Preferences and devices: notification settings, ignore rules, and push subscriptions for the devices where you turned on notifications.
  • Usage and payments: AI usage per analysed message (tokens, model, cost), your credit balance and top-ups, and your Stripe customer reference. Card details are handled by Stripe only.
  • Technical data: IP address and request information processed by our hosting provider to deliver and protect the Service.

2. Why, and on what basis

  • To provide the Service you asked for — syncing, analysing messages, showing tasks, posting your Slack replies, reminders and notifications (performance of our agreement, Art. 6(1)(b) GDPR).
  • To keep the Service secure and prevent abuse (our legitimate interest, Art. 6(1)(f)).
  • To bill Kievit AI credit and keep bookkeeping records (legal obligation, Art. 6(1)(c)).

We don’t sell your data, don’t use it for advertising, and don’t use trackers or analytics cookies. We don’t use your messages to train AI models, and our AI provider doesn’t either under its commercial terms. AI suggestions never take effect without your confirmation.

3. Who processes data for us

  • Cloudflare — hosting, database, cache and the mail gateway (processor).
  • Anthropic — AI analysis of new messages and answers in Ask AI. With Kievit AI this runs under our account (processor); with your own API key, under your agreement with Anthropic.
  • Stripe — payments for credit. Stripe is an independent controller for the payment data it collects.
  • Push services of Apple, Google, Mozilla or Microsoft deliver notifications to your devices; the content is end-to-end encrypted.
  • Your mail, Slack and calendar providers — we access the accounts you connect, as you authorised.
  • Coworkers you share an area with — they see that area’s tasks (with their board columns, labels, checklists and comments) and can open the emails, Slack messages and events linked to them. Tasks outside shared areas, and your other messages, stay yours.
  • AI assistants you connect (for example Claude or ChatGPT, through “AI Assistants” in Settings) — they receive the tasks, messages and calendar events they look up for you (mail and calendars only if you allow it) and handle them under their own terms, as independent controllers. You approve each one and can disconnect it any time.

Some of these providers process data outside the European Economic Area, in particular in the United States. Such transfers are covered by the EU–US Data Privacy Framework or the European Commission’s standard contractual clauses.

4. Google user data

This section describes what Kievit does with data it receives from Google when you connect a Google account (“Sign in with Google” for Gmail, or for Google Calendar).

  • What we access. Your Google account’s email address (to know which account you connected). With Gmail (permission “Read your email”, gmail.readonly): the messages in your Inbox and Sent mail — sender, recipients, subject, date, thread references, read/unread state, the message text and attachments. With Google Calendar (calendar.readonly): your events and invitations. Access is read-only: Kievit can’t send, change, move or delete email or events.
  • How we use it. Only to provide Kievit’s features to you: finding the emails and invitations that need you and suggesting them as tasks, setting aside newsletters, automated mail and likely scams, showing a message when you open it, and closing a task when a reply you sent appears in your Sent mail. Nothing else: no advertising, no profiling, no selling.
  • How we share it. The text of new messages (and of attachments, only when you choose to share one) is sent to our AI provider, Anthropic, to analyse it, under terms that don’t allow it to be used for training. Our hosting provider Cloudflare stores and processes it for us. Coworkers you share an area with can open the messages linked to its tasks, and AI assistants you connect can look up mail only if you allow it. We don’t transfer Google user data to anyone else, except to comply with the law.
  • How we store and protect it. Message text and attachments are never stored: they are read live and kept at most 15 minutes in an encrypted cache. We store message details (sender, recipients, subject, date, thread references), the tasks made from them, and your sign-in token, which is encrypted with a key per user. Data is stored in the EU and all connections use TLS.
  • How long we keep it, and deleting it. Message details are deleted 6 months after the message was sent (unless a task you keep refers to it). Disconnecting the account in Settings stops all access and deletes its sign-in token; deleting your Kievit account deletes everything and revokes our access at Google. You can also remove Kievit’s access at any time at myaccount.google.com/permissions.
  • People. No human reads your Google user data unless you ask us to (for support), it’s needed for security or to investigate abuse, or the law requires it.
  • AI. We don’t use Google user data to develop, improve or train generalized AI or machine-learning models.

Kievit’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Microsoft and Slack accounts are handled the same way.

5. How long we keep data

  • Message text: at most 15 minutes, encrypted.
  • Finished (done or dismissed) tasks: 6 months after they were finished. Message details: 6 months after the message was sent, unless a task you keep still refers to it. Task history, AI usage logs, expired sessions and unused devices: 6 months.
  • Open tasks, connected accounts, rules and settings: until you delete them or your account.
  • Payment records: 7 years, as Dutch tax law requires (kept by Stripe and in our bookkeeping).
  • When you delete your account, everything else is deleted immediately, including the encryption key for your data, and our access to connected Slack and Google accounts is revoked.
  • On your own devices: the app keeps a copy of your tasks, accounts and settings so it works offline (never message text or conversations), and changes you make offline until they’re sent. Signing out removes it.

6. Security

Sign-in uses passkeys, so there are no passwords to steal. Credentials and cached message text are encrypted with a key per user; all connections use TLS. Access is invite-only.

7. Your rights

You can access, correct, export (Profile → Download my data) and delete (Profile → Delete my account) your data yourself. You also have the right to restrict or object to processing and to data portability. For anything else, write to legal@sagoskatt.nl; we reply within a month. You can also complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or the authority where you live.

8. Cookies and local storage

Kievit uses one strictly necessary cookie to keep you signed in. Your device also stores a few preferences (such as the last list you opened) and the app’s offline files. There are no tracking cookies, so there is no cookie banner.

9. Changes

We’ll update this policy when the Service changes. For material changes we ask you to review the new version when you next open Kievit.

10. Contact

Sagoskatt Holdings
Achteromstraat 2a, 1381AV Weesp
The Netherlands
Email: legal@sagoskatt.nl
Chamber of Commerce (KvK): 81265611