Intelligence you can see, question, and correct.

Kahvor’s intelligence layer is one system shared by every Kahvor product. This page explains, in plain language, how it assists, which AI services it uses, what it remembers, and where the hard limits are.

The formal version of these commitments lives in the AI Policy. This page is the readable one.

The shape of it

Contextual help, not a chatbot bolted on.

Kahvor’s assistance shows up inside your work: a summary next to the thread it summarizes, a prepared reply grounded in the conversation, a package explanation grounded in carrier events. It reasons from your real context and shows its sources.

The trust model

Observe. Prepare. You approve.

Everything Kahvor's intelligence does fits a three-step shape — and only the last step changes anything.

Kahvor observes permitted context

Only the accounts you connected, with the scopes you granted. Reading mail lets Halo find replies, decisions, commitments, and — for Delivery — orders and tracking numbers.

Kahvor prepares an explanation or action

A summary, a drafted reply, a package-risk explanation — each labeled as prepared work, with the sources it came from visible.

You review and approve what executes

Kahvor does not take consequential action without your approval or an automation you explicitly configured. Prepared work is inert until you act, or until an automation you set up — a rule, a scheduled send — runs exactly as configured.

Model routing

The right service for each task.

Kahvor is provider-neutral by design. Different tasks suit different models, and no single vendor should own your context.

Which providers Kahvor uses

Kahvor routes AI tasks across configured services from OpenAI, Anthropic, Google, Perplexity, in a failover order maintained on Kahvor’s servers. If one service is unavailable, another handles the task.

Kahvor does not make claims about what these providers do beyond the contracts that govern them — the current list is documented on the Subprocessors page.

Only necessary context

A task is sent with the context it needs — the thread you asked about, not your whole mailbox. Sensitive actions follow stricter permissions, and diagnostics never include message bodies, recipients, or credentials.

You keep visibility and control

Assistance is labeled as assistance. Prepared work shows what it used and what will happen next, and Kahvor’s recommendations are reviewable — you can correct the system rather than being corrected by it.

Recommendations are not verdicts

Kahvor treats model output as a draft of judgment, not a replacement for it. Anything consequential — sending, deleting, changing accounts — waits for your explicit approval or runs only through an automation you configured yourself.

Hard boundaries

What Kahvor’s intelligence will not do.

These are product rules, enforced in the backend — not aspirations.

01

No unapproved sends

Drafts never send themselves — external sends require your review. Scheduled sends and rules run only when you explicitly set them up, exactly as configured.

02

No silent destructive actions

Bulk delete, external forwarding, and account changes remain human-initiated with clear confirmation.

03

No blurred boundaries

Private memory stays private. Team memory requires source-backed review before it can shape workspace replies.

04

No invented certainty

Summaries and package explanations cite what they are grounded in. When the data is thin, Kahvor says so.

Memory

Memory you can open like a drawer.

Kahvor’s usefulness compounds because it remembers. That only works if you can see and control what it remembers.

What does Kahvor remember?

Context that helps prepare your work: who you correspond with, commitments and decisions inside threads, and preferences you set. Memory is visible in the product — you can see each item and where it came from.

How is memory created?

From the accounts you connect and the way you use Kahvor. Memory entries show their source, and personal context stays personal unless you explicitly share it with a workspace.

Can I review, edit, or delete memory?

Yes. Memory is designed to be inspectable: you can review what Kahvor remembers, correct it, and remove entries. Deleting a memory removes it from future assistance.

What is the difference between personal and workspace memory?

Personal memory belongs to you and never leaks into shared contexts. Workspace memory is explicitly shared and used only inside that workspace, with team-safe boundaries.

Data retention follows the Privacy Policy: connected-account data is processed to provide the features you use, and disconnecting an account or deleting your Kahvor account removes it under the documented retention rules.

See it work on your own inbox.

The clearest explanation of Kahvor’s intelligence is watching it prepare your first morning.