DATA PROCESSING
How your data is processed.
A plain-language summary of how kynikOS collects, stores, and processes your personal data — where it lives, who else touches it, and for how long.
Last updated: July 2026
This page is a plain-language summary, not a signed DPA. For a signed data processing agreement, contact [email protected].
Data controller
The data controller is Kynikos OÜ, Järvevana tee 9, Kesklinna linnaosa, 11314 Tallinn, Estonia (registry code 17330279). We are responsible for deciding how and why your personal data is processed. For any data-related enquiries contact [email protected].
Where your data is hosted
Your data is stored in Europe — the primary database is hosted in Switzerland, which the European Commission recognises as providing an adequate level of data protection. Application services run on cloud hosting, and observability runs on our own self-hosted infrastructure. Data is encrypted in transit (TLS 1.2+) and at rest. Beyond that, your conversations and the payloads of the tasks the assistant runs are additionally encrypted at rest with keys held outside the database provider, so their contents are not readable by the hosting provider alone. Health data receives an additional layer of encryption at rest.
Identity and sign-in
Identity is handled through Telegram. We store your Telegram user ID and the profile name you choose to share. kynikOS does not use, store, or ask for passwords.
What data we process
- Account data — your Telegram identity, the profile details you provide (such as display name and time zone), and any contact details you add.
- Calendar & scheduling data — events from connected calendars, appointments created on your behalf, and your scheduling preferences.
- Conversations — messages you exchange with kynikOS, including instructions, preferences, goals, and the personal context you declare.
- Health signals — activity, sleep, heart rate, recovery, body composition, and related metrics from connected wearables (currently Garmin, Withings, and WHOOP). Health data is only collected when you explicitly connect a device and is governed by stricter rules described in our Privacy Policy (Section 3). Raw wearable metrics never reach an external AI provider — only coarse derived bands do.
- Bookings & actions — records of actions taken on your behalf (reservations, calls, emails) including outcome logs and, for phone calls, transcripts (raw call audio is not retained once transcribed).
Why we process it
We process your data only to execute your instructions. kynikOS acts as an agent on your behalf — it does not process your data for advertising, does not sell or rent it to third parties, and does not use it to profile you for any purpose other than improving the service it provides to you personally.
How long we keep it
Your chat and message history is kept until you delete it, because it is the assistant's working memory — it is what lets kynikOS remember your preferences and context. When you delete something, it is removed from our live systems immediately and clears from encrypted backups as they roll off, within approximately 30 days. Voice call transcripts are retained like your other messages, while raw call audio is not retained once transcribed. Health data from a disconnected source is deleted within 30 days of disconnection. To request a full export or deletion, email [email protected]; a self-serve flow is not yet available, so requests are handled by our team and honoured promptly.
Sub-processors
We use a small number of third-party services to operate kynikOS. Each is bound by a data processing agreement and may only process data as we instruct. A given processor only receives data when you use the relevant feature — for example, Duffel only receives passenger details when you ask kynikOS to book travel, and Garmin, Withings, or WHOOP are only involved once you connect them. Where a processor is located outside Europe, transfers rely on Standard Contractual Clauses (SCCs).
| Processor | Purpose | Data | Location |
|---|---|---|---|
| Anthropic | AI model that powers the assistant | Message text, calendar event titles, personal context you declare, and coarse derived (non-numeric) health bands — never raw wearable metrics. API traffic is not used to train models. | United States (SCCs) |
| Supabase | Database hosting | All stored data. Sensitive columns — including conversations and task payloads — are encrypted at rest with keys held outside the database provider. | Switzerland (EU-adequate) |
| Railway | Application hosting | Data in transit while the assistant runs your requests. | Cloud hosting |
| Deepgram | Voice-note transcription | Voice audio and the resulting transcript. | United States (SCCs) |
| Twilio | Outbound phone calls on your behalf | Phone numbers and call content. | United States (SCCs) |
| LiveKit | Real-time voice transport | Voice audio during a live call. | Cloud hosting |
| Resend | Sending email on your behalf | Email addresses and message content. | United States (SCCs) |
| Browserbase | Browser automation to complete online bookings | Booking details such as name, party size, and times. | United States (SCCs) |
| Duffel | Flight and hotel booking | Passenger name, date of birth, and contact details, shared only to complete a booking you request. | United Kingdom |
| Stripe | Payments and billing | Billing identifiers. Card data is handled by Stripe under PCI-DSS; kynikOS does not store card numbers. | EU / United States |
| Google (Places) | Place and business search | Search query text. | United States (SCCs) |
| Garmin / Withings / WHOOP | Wearable integrations you connect | Health data flows in from your device; training plans can flow back out to Garmin. Only active when you connect the account. | United States / EU |
| Open-Meteo | Weather for scheduling | Approximate coordinates. | European Union |
| Sentry | Error and reliability monitoring | Technical error data. Message content is not sent to Sentry. | European Union (EU ingest) |
Your GDPR rights
Under the GDPR you have the right to:
- Access — request a copy of all personal data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — request deletion of your data.
- Portability — receive your data in a structured, machine-readable format.
- Restriction — ask us to limit how we process your data.
- Objection — object to processing carried out on the basis of legitimate interest.
To exercise any of these rights, contact [email protected]. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or with the supervisory authority in your country of residence.