What we collect
Three buckets. Things you tell us, things our servers see, and things we get back from the AI assistants when we run a check.
What you give us. When you run a free check, you type your business name, the city you're in, and your email. If you sign up for a paid plan, we also collect your name, a password (stored as a one-way hash, never in plain text), and your billing details. Billing details are handled by Stripe; we never see or store your full card number.
What our servers see. Standard web server logs: your IP address, browser and device type (user-agent), the pages you visit on kodo-ai.com, and timestamps. We also use cookies to keep you signed in and, optionally, to measure how the site is used. More on cookies further down.
What the AI assistants say about you. When we run a check, we ask ChatGPT, Gemini, Claude, Grok, Perplexity, and the Apple/Siri stack the kinds of questions a real customer asks. The answers come back as text, and we store them so we can build your report and show you how things change over time. This is data about you, not from you, but we treat it the same way.
Why we collect it
- To run your check and send your report. Your business name and city are the inputs. Your email is the delivery address.
- To keep your account working. If you subscribe, we need a way to sign you in, remember your settings, and re-run your monthly checks.
- To bill you correctly. Stripe handles the actual payment. We keep just enough on our side (a customer ID, the plan you're on, the dates) to know what you've paid for.
- To prevent fraud and abuse. Server logs help us spot bots, scrapers, and people abusing the free check.
- To make the product better. We look at aggregate usage (which pages get visited, where people drop off) to fix what's broken. We don't profile individuals.
Who we share it with
Only the third parties we need to run the service. We don't sell your data to anyone. We don't share it with data brokers or advertising networks.
- Stripe handles billing for paid plans. They see your card details, your name, and your billing address.
- Clerk handles sign-in for paid accounts. They see your email and the hashed password.
- Resend sends transactional email (your report, billing receipts, account notices). They see your email and the contents of the message.
- Vercel hosts the site and our servers. Their infrastructure sees the same things any web host does: IP addresses, requests, response times.
- AI assistant providers (OpenAI, Anthropic, Google, xAI, Perplexity, Apple) receive the questions we send when we run your check. We send the business name and city, plus a generic prompt. We do not send them your email or account details.
If we ever get acquired or merge with another company, your data would move with the company. We'd email you first, and you could ask us to delete your data before the transfer.
How long we keep it
- Free-check submissions. Kept indefinitely so we can show you a history if you come back, unless you ask us to delete them. Email [email protected] and we'll remove your record, usually within a few business days.
- Paid accounts. Kept while your subscription is active, plus 90 days after cancellation in case you want to come back. After that we delete account data, except for billing records we're required to keep for tax purposes (typically seven years).
- Server logs. About 30 days. After that they roll off automatically.
- Email records. Resend keeps a delivery log for 90 days. We keep our own copy of the message contents for the life of your account.
Your rights
If you live in the European Union, the United Kingdom, or California, you have specific rights over your personal data. Everyone else gets the same rights from us anyway. The list:
- Access. Ask us what we have on you. We'll send you a copy.
- Correction. Tell us if something we have is wrong, and we'll fix it.
- Deletion. Ask us to delete your data. We will, except where we're legally required to keep something (like billing records).
- Portability. Ask us for a copy of your data in a common format (we use JSON), and we'll send it.
- Opt-out of sale. We don't sell your data, so there's nothing to opt out of. The right exists in California law, so we list it.
To use any of these rights, email [email protected] from the address we have on file for you. We'll respond without unreasonable delay, usually within 30 days.
Children
Kodo is built for adults running a small business. It is not for children under 16. We don't knowingly collect data about anyone under 16. If you think a child has signed up or that we somehow have a child's data, email [email protected] and we'll delete it.
Cookies
We use two kinds of cookies. Strictly-necessary cookies keep you signed in and remember your preferences (like language). These are on by default because the site can't work without them.
Analytics cookies help us see which pages get used and where people get stuck. These are optional. You can decline them when you arrive at the site, or change your mind later from the cookie banner at the bottom of any page. We don't use advertising cookies and we don't track you across other sites.
International transfers
Kodo is a US company. Your data is processed in the United States. If you're in the European Union, the United Kingdom, or another region with data-transfer rules, your data may move to the US to be processed. For EU and UK data, we use the European Commission's Standard Contractual Clauses (the standard legal tool for this kind of transfer) with our vendors.
Changes to this policy
We'll update this page when we change anything material. The new version replaces this one, with a fresh date at the bottom. If the change is significant (a new vendor, a different retention rule), we'll email active subscribers ahead of time. Small wording fixes won't get an email, but they'll always show up here first.
Contact
Questions about this policy, or about anything we have on you: email [email protected]. A real person reads that inbox. For postal mail, our registered office is in Delaware, USA (write to us at the email above and we'll give you the current street address).
Last updated: 28 May 2026. Kodo is a small team. This policy is written in plain English so it's clear. It is not legal advice.
Does Kodo sell my data?
No. We don't sell your data to anyone, ever. We don't share it with advertising networks or data brokers. The only third parties we share with are the vendors we need to run the service (Stripe for billing, Clerk for sign-in, Resend for email, Vercel for hosting, and the AI assistant providers we query during your check).
How do I get my data deleted?
Email [email protected] from the address we have on file. We'll delete your account and your check history, usually within a few business days. We keep billing records longer because tax law requires it, but those aren't used for anything else.
What does Kodo send to ChatGPT and the other AI assistants?
When we run your check, we send the assistant generic questions a customer would ask (like "best barber in Pilsen"), plus your business name and city for matching. We don't send your email, your account details, or any billing info to the AI assistants.
Where is my data stored?
In the United States. Our hosting (Vercel) and most of our vendors run in US data centers. If you're in the EU or UK, your data is transferred to the US under Standard Contractual Clauses, the standard legal tool for that kind of transfer.
Do you use tracking cookies or pixels?
Only what's strictly necessary to keep you signed in and remember your language. Analytics cookies are optional and you can decline them from the cookie banner. We don't use ad pixels, retargeting cookies, or any cross-site tracking.