Security, stated plainly.

Kahvor connects to the most personal data most people have — their email. This page explains how that access works, how data is protected, and what controls you keep. We only claim what is actually built.

Formal documents: Security statement · Privacy Policy · Data Processing Addendum · Subprocessors

Your data

How accounts connect and stay protected.

What Kahvor reads, and why

Kahvor reads the mail, calendar, and contact data of accounts you connect — because that is where the replies, decisions, commitments, and (for Delivery) orders live. It stores synchronized account records, your preferences, and the memory you can see and edit; it does not store your provider passwords.

Disconnecting an account removes its synchronized data under the documented retention rules, and deleting your Kahvor account removes your data the same way.

Account connections

Gmail, Outlook, and Yahoo connect through each provider’s OAuth flow — Kahvor never sees those passwords. iCloud connects with an app-specific password you create and can revoke in your Apple account.

Connections request the scopes needed for the features you use, and you can disconnect an account at any time. Google-scope specifics are documented in Google API Data Use.

Encryption

Data moves over encrypted connections (TLS) between your device, Kahvor, and providers. Stored provider credentials are encrypted server-side with AES-GCM and are decrypted only inside the backend to perform the actions you request; they are never sent to a client.

Kahvor does not claim end-to-end encryption or zero-knowledge storage, and does not currently hold certifications such as SOC 2 — we would rather tell you that than imply otherwise.

Isolation

Every request is validated against your session, and mail data is ownership-scoped: an account’s records are reachable only by the signed-in user who connected it. Workspace data is separated by explicit membership and roles.

Data retention and deletion

Connected-account data is processed to provide the features you use. Disconnecting an account or deleting your Kahvor account removes the associated data under the retention rules in the Privacy Policy.

AI processing

Intelligence with permissions, not free rein.

Scoped context

AI tasks receive the context they need — the thread you asked about, not your whole mailbox. The services Kahvor routes to are listed on the Subprocessors page, and the rules are in the AI Policy.

Approval-first actions

Kahvor does not take consequential action without your approval or an automation you explicitly configured. Sending, delegation, account changes, and destructive actions require explicit confirmation; rules and scheduled sends run only as you configured them. Prepared work is exactly that — prepared, then waiting.

How Kahvor intelligence works →

Email protection

Defenses built into Halo.

Remote-image privacy

Remote images — and the tracking pixels that ride along with them — are blocked until you choose to load them. Rich email is sanitized and rendered in an isolated document.

Sender controls

Block a sender, quiet a repetitive one, unsubscribe in one click, and report phishing so suspicious senders are treated with more caution. Secure-mail signals (such as S/MIME markers) are recognized and displayed conservatively — Halo does not decrypt secure mail or manage private keys, and does not claim to.

Workspaces

Team security without personal exposure.

Workspace boundaries

Shared Spaces use explicit membership, roles, and collaboration settings. Personal context never enters a workspace unless you share it, and team memory requires source-backed review before it can shape shared replies.

Administration

Teams plans include member roles and collaboration controls; Business plans add centralized administration, organization policies, and audit history.

Reporting

Found something? Tell us directly.

Security reports go to a monitored address and are handled with priority. If we determine an incident affects user data, we investigate, mitigate, and notify affected users or workspace administrators as required by law or agreement.

Report to [email protected]
01

Vulnerabilities

Email [email protected] with reproduction details. Please give us reasonable time to remediate before public disclosure.

02

Suspicious email in Halo

Use Report phishing on the message itself — it protects you and improves sender caution for everyone.

Trust is a feature we ship.

Every claim on this page is grounded in what the product actually does today. When capabilities grow, this page grows with them.