Vulnerabilities
Email [email protected] with reproduction details. Please give us reasonable time to remediate before public disclosure.
Kahvor connects to the most personal data most people have — their email. This page explains how that access works, how data is protected, and what controls you keep. We only claim what is actually built.
Formal documents: Security statement · Privacy Policy · Data Processing Addendum · Subprocessors
Your data
Kahvor reads the mail, calendar, and contact data of accounts you connect — because that is where the replies, decisions, commitments, and (for Delivery) orders live. It stores synchronized account records, your preferences, and the memory you can see and edit; it does not store your provider passwords.
Disconnecting an account removes its synchronized data under the documented retention rules, and deleting your Kahvor account removes your data the same way.
Gmail, Outlook, and Yahoo connect through each provider’s OAuth flow — Kahvor never sees those passwords. iCloud connects with an app-specific password you create and can revoke in your Apple account.
Connections request the scopes needed for the features you use, and you can disconnect an account at any time. Google-scope specifics are documented in Google API Data Use.
Data moves over encrypted connections (TLS) between your device, Kahvor, and providers. Stored provider credentials are encrypted server-side with AES-GCM and are decrypted only inside the backend to perform the actions you request; they are never sent to a client.
Kahvor does not claim end-to-end encryption or zero-knowledge storage, and does not currently hold certifications such as SOC 2 — we would rather tell you that than imply otherwise.
Every request is validated against your session, and mail data is ownership-scoped: an account’s records are reachable only by the signed-in user who connected it. Workspace data is separated by explicit membership and roles.
Connected-account data is processed to provide the features you use. Disconnecting an account or deleting your Kahvor account removes the associated data under the retention rules in the Privacy Policy.
AI processing
AI tasks receive the context they need — the thread you asked about, not your whole mailbox. The services Kahvor routes to are listed on the Subprocessors page, and the rules are in the AI Policy.
Kahvor does not take consequential action without your approval or an automation you explicitly configured. Sending, delegation, account changes, and destructive actions require explicit confirmation; rules and scheduled sends run only as you configured them. Prepared work is exactly that — prepared, then waiting.
Email protection
Remote images — and the tracking pixels that ride along with them — are blocked until you choose to load them. Rich email is sanitized and rendered in an isolated document.
Block a sender, quiet a repetitive one, unsubscribe in one click, and report phishing so suspicious senders are treated with more caution. Secure-mail signals (such as S/MIME markers) are recognized and displayed conservatively — Halo does not decrypt secure mail or manage private keys, and does not claim to.
Workspaces
Shared Spaces use explicit membership, roles, and collaboration settings. Personal context never enters a workspace unless you share it, and team memory requires source-backed review before it can shape shared replies.
Teams plans include member roles and collaboration controls; Business plans add centralized administration, organization policies, and audit history.
Reporting
Security reports go to a monitored address and are handled with priority. If we determine an incident affects user data, we investigate, mitigate, and notify affected users or workspace administrators as required by law or agreement.
Report to [email protected]Email [email protected] with reproduction details. Please give us reasonable time to remediate before public disclosure.
Use Report phishing on the message itself — it protects you and improves sender caution for everyone.
Questions about data handling go to [email protected], or start with the Privacy Policy.
Every claim on this page is grounded in what the product actually does today. When capabilities grow, this page grows with them.