Kilby Privacy Policy
Effective date: July 3, 2026
Kilby is an AI agent. Kilby operates on a prepaid credit model — you purchase credits through the app to use the agentic features. This page explains, in plain English, what Kilby stores, how Kilby uses that information, and how you can delete your data.
What Kilby Collects
- Your account details from Firebase Authentication, such as email address, display name, and user ID.
- Your chats, saved threads, profile information, and app settings.
- Your agent configurations.
- Your credit balance and usage records, because Kilby operates on a prepaid credit model.
- Files, file metadata, extracted text, and OCR output only when you upload files or import selected files into Kilby.
- Photos and images only when you choose to upload them or import selected images from Google Photos.
- Microphone input only when you actively use voice features.
- Location only when you ask for location-based help, such as weather.
- Google connection data only if you choose to connect Google services.
- Slack connection data only if you choose to connect Slack.
- Brokerage connection tokens only if you choose to connect a brokerage account.
What Kilby Uses That Information For
- To sign you in and keep your session active.
- To save your chats, settings, and profile between sessions.
- To generate agent responses and voice output.
- To run optional features you request, such as Google integrations, Slack, uploads, weather, and brokerage connections.
Credits and Billing
Kilby operates on a prepaid credit model. You purchase credits through the Settings panel, and those credits are consumed as you use the service. Kilby calls Anthropic's API on your behalf using credits — you are not required to provide your own API key.
Credit balance and usage records are stored in your Kilby account. Kilby does not store full payment card details; payment processing is handled by Stripe and is subject to Stripe's own privacy policy.
Connected Google Services Data
If you choose to connect Google services, Kilby can interact with the Google services and scopes you authorize to perform actions on your behalf. Google data is used only to provide user-facing Kilby features you request. Kilby's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Kilby does not sell Google user data or use it for advertising, unauthorized model training, credit-worthiness decisions, or lending purposes.
Google Drive
Kilby uses the Google Drive File scope with Google Drive Picker. In this flow, Kilby can access only the Drive files you explicitly select for Kilby. Kilby does not request permission to view or download all files in your Google Drive and does not scan your Drive.
Selected Drive file content and metadata are used only to fulfill your request, such as importing, summarizing, or analyzing the selected file. When you import a selected Drive file, Kilby may store the file, file metadata, extracted text, OCR output, and processing artifacts in your Kilby workspace so the file can be attached to the current chat and reused for follow-up work. If selected Drive content becomes part of a saved Kilby chat or workspace file, it is retained and deleted under the same rules as other saved chat and workspace data.
Google Calendar
Kilby can create, read, and manage calendar events in response to your instructions. When you ask to "schedule a meeting" or "book an event," the agent verifies your availability and inserts the details directly into your Google Calendar so you don't have to update it manually.
Google Contacts
Kilby retrieves contact details, such as names and email addresses, when you ask to find a person or schedule a meeting. This allows the agent to correctly identify recipients for your invites and communications. Kilby does not maintain a standalone contacts database. If contact details become part of a saved chat, they are retained and deleted under the same rules as other saved chat data.
Google Photos
Kilby provides a secure way for you to import specific images from your Google Photos library for analysis or reference. Using the secure Google-provided photo picker, Kilby only accesses the exact images you explicitly select; it has no unauthorized access to your broader photo library. Selected images are attached to the request you make in Kilby and may be processed by Kilby and its AI service providers to fulfill that request.
Brokerage Connections
Kilby is not a broker-dealer, investment adviser, securities exchange, custodian, or clearing firm. Kilby does not open brokerage accounts, hold customer funds or securities, clear or settle transactions, or provide brokerage services.
If brokerage features are enabled and you choose to connect a brokerage account through a supported third-party brokerage platform, Kilby stores an OAuth access token in Google Cloud Firestore to maintain your connection. This token is encrypted at rest and is used solely to communicate with the brokerage platform you authorize.
When you use brokerage-related features, Kilby may relay or submit user-authorized order instructions you provide and retrieve account data such as positions, balances, and order status from the connected third-party brokerage platform. This data is processed to fulfill your request. If brokerage data becomes part of a saved Kilby chat, it is retained and deleted under the same rules as other saved chat data; otherwise, Kilby does not maintain a separate brokerage account-data store beyond what is necessary to maintain the connection and provide the requested feature.
Brokerage services, account custody, order acceptance or rejection, order execution, clearing, settlement, and related regulated financial services are provided by the third-party brokerage platform, not by Kilby. You can disconnect your brokerage account at any time through Settings, which revokes the stored token.
Who Kilby Shares Data With
Kilby does not sell personal information. Kilby shares data only with service providers needed to run the app, such as:
- Firebase Authentication for sign-in.
- Google Cloud and Firebase services for app data and infrastructure.
- Anthropic and Google AI services for agentic and voice features.
- Stripe for payment processing if you purchase Kilby credits.
- Google APIs if you choose to connect Google services.
- Slack APIs if you choose to connect Slack.
- Weather and geocoding providers when you ask for location-based help.
- Supported third-party brokerage platforms if you choose to connect a brokerage account.
Data Protection Mechanisms for Sensitive Data
Kilby employs strict security measures to protect your sensitive information, including connected Google services data and account details:
- Encryption in Transit: All data transmitted between your device, Kilby's servers, and third-party APIs is encrypted using industry-standard TLS/SSL (HTTPS) protocols.
- Encryption at Rest: Sensitive data stored on our infrastructure, including connected-service tokens and user settings, is encrypted at rest using Google Cloud and Firebase's built-in AES-256 encryption mechanisms.
- Access Controls: Access to infrastructure and databases is strictly limited to authorized personnel with a legitimate business need, enforced via secure authentication and role-based access controls.
- Limited Processing: Data retrieved from Google APIs (like Drive, Calendar, Contacts, and Photos) is processed to fulfill your prompt and is not used for advertising, sale, unauthorized model training, credit-worthiness decisions, or lending purposes. Google content is retained only when it becomes part of saved chat data, workspace files, connected-service tokens, or other records described in this policy.
How Long Data Is Kept
Kilby keeps account data, chats, settings, workspace files, and connected-service tokens until you delete your account or the data is otherwise removed by the publisher.
Credit balance, usage records, and payment processor records may be retained as needed for billing, accounting, fraud prevention, dispute handling, and legal compliance.
How To Delete Your Data
You can delete your Kilby account in the app under Settings using Delete Account. That removes saved chats, profile data, settings, connected Google and Slack tokens, and Kilby workspace files associated with your Kilby account. Disconnecting Google, Slack, or brokerage connections revokes the stored connection tokens but does not automatically remove saved chats or workspace files already created from content you selected or submitted.
You can also review the complete web deletion instructions and initiate self-service account deletion at Kilby Account and Data Deletion.
Children
Kilby is not intended for children under 13.
Contact
For privacy questions or support requests, contact: support@agentkilby.com