Privacy Policy
Last updated 9 August 2026.
Who this policy is for
This policy explains how Kea AI collects, uses, stores and shares personal information when you visit this website, use the demo, book a call, or ask us to set up Kea AI for your business. We are based in New Zealand and handle personal information in line with the Privacy Act 2020.
What we collect
If you book a call or request setup: your business name, industry, plan interest, your name, email, and optionally a phone number, website, preferred languages and notes about what you want Kea AI to handle. We collect this so we can contact you, prepare a relevant demo or setup, provide support, and keep a record of your request.
If you pay through Airwallex: payment is handled by Airwallex on its hosted checkout page. We receive a signed payment notification containing limited details such as the Airwallex checkout session, customer email, amount and currency so we can match your payment to your setup request and keep accounting records.
If you use the demo chatbot: whatever you type is sent to the AI model Kea selects to generate a response. The available engines include third-party providers (Anthropic, OpenAI, DeepSeek, Mistral or Gemini). The Qwen3 option is different: it is an open-weight model running on a server Kea controls, so those messages go to us rather than to an outside AI company. It is privately hosted, not on your own device - your message still leaves your browser either way. We also keep a copy of demo conversations so we can see what people actually ask and improve the assistant - see "How long we keep it" below. See "Third parties" for what this means for a message you type into the demo.
If you use the demo's booking or voice features: an email address you provide for a demo calendar invite is used only to send that invite (or, while email sending isn't fully enabled yet, is not used at all). Browser voice input and spoken replies are not sent to our servers by us; your browser, device or operating system may process speech features under its own settings and policies.
If you use the demo's photo-based quote feature: the photo is processed by a Kea-controlled vision model to generate a ballpark estimate, then discarded - we don't save it, and it isn't used for anything beyond that one response.
If you use a live chatbot's appointment or callback request form: the name, phone number or email address, preferred date/time or callback window, and notes you enter are emailed to that business so it can respond. Submitting a preferred time does not confirm an appointment or guarantee an exact callback time. The structured form sends those details to the business by email; it does not ask an AI model to interpret them.
If we set up Kea AI for your business: we read the website address you gave us and collect the text of your public pages - services, prices, hours, contact details, FAQs - so your assistant can answer using your real information instead of guessing. We send that text to an AI model to pull out a structured summary, which a person then checks and corrects before your assistant goes live. If your website can't be read automatically, we build the same summary from what you tell us instead. We only read pages that are publicly visible; we do not log in to anything or submit forms.
If you use the Kea AI client portal: we use the account email already attached to your service to send a single-use sign-in link. To protect the account and limit sign-in abuse, we record the login/session time, IP address and browser user-agent, along with an audit of portal settings changes. Login and session secrets are stored only as one-way hashes. The settings themselves include the greeting, visual palette, avatar, colour mode and launcher choices you save for your assistant.
If you publish a live business update in the client portal: we send the update to Anthropic for an automated security check that looks only for attempts to manipulate the assistant. If Anthropic is unavailable, we use OpenAI for the same check. We do not publish the update if neither check is available. This check does not assess whether your business information is true, legal or suitable. We retain a content hash, account email, check outcome and time for 90 days to enforce the update limit and diagnose the service; rejected update text is not retained in that record.
If you use a customer's live Kea chatbot: your message and that customer's approved business profile are sent to the AI model configured by Kea to make the reply. Kea keeps the message and reply for up to 30 days so it can provide that business with its promised chat log and weekly service report. Follow-up messages from the same browser tab are grouped under a random conversation reference; Kea does not add your IP address, browser identity or an account identifier to the transcript. The report is sent only to the email recipient configured for that business. Engage and Complete reports may send the bounded transcript to an AI model again to identify unsure answers and prepare escalation notes. If you report an answer as wrong, confusing or inappropriate, we attach only that reason to the existing reply; we do not add a contact identity or free-text comment, and it is deleted with the same chat-log copy. Do not send passwords, payment-card details, health records or other sensitive information through chat.
We keep a content-free operational record of a live-chat request: which customer assistant handled it, the time, model provider, input and output character counts, response status and response time. We do not put the message, reply, IP address, browser identity or conversation reference in that operational record. It exists to enforce service limits and diagnose reliability.
How we use your information
We use personal information to respond to enquiries, prepare and deliver demos, set up or support your Kea AI service, send service-related messages, improve the product, and meet legal or security obligations. If you opt in to marketing, we may send practical product or marketing tips; you can unsubscribe or ask us to stop at any time.
Third parties
Your setup details, lead records and payment confirmation records are stored on a New Zealand server. Demo chat messages are sent to whichever AI model Kea selects so it can generate a reply. Routing to Anthropic, OpenAI, DeepSeek, Mistral or Gemini sends your message to that company. Routing to Qwen3 sends it instead to a privately hosted model on Kea-controlled infrastructure, so no outside AI company receives it. Production chat replies may also send the relevant prompt and business knowledge to the AI model configured for that account, which may include trusted providers outside New Zealand. A bounded live-chat transcript may also be processed to prepare a client's weekly summary and escalation notes. Each provider processes that information under its own privacy policy and terms - we don't control how they handle it beyond the request itself. Don't type real personal or business-sensitive information into the public demo chatbot; it's a demonstration, not your production system.
When we set up your assistant, the text of your public web pages is sent to the AI model we use for that extraction, under that provider's own privacy policy and terms, and is held briefly on Kea-controlled infrastructure while your assistant is being built (see "How long we keep it"). Photo-based quote requests are processed by a Kea-controlled vision model and are not stored after processing. We may also use Airwallex for payments, Google Analytics for site usage measurement, plus hosting, email and operational service providers to run this site, store setup requests, and send notifications. Some providers may process information outside New Zealand. Where that happens, we use providers we understand to be reputable and appropriate for the service being provided.
How long we keep it
Your website content, when we set up your assistant: the page text we collect is deleted 30 days after your assistant's knowledge has been reviewed. We keep it that long only to check the summary is right and to fix it if something reads wrongly soon after going live. After that we retain the page addresses, timestamps and the approved facts your assistant actually uses - not a copy of your website. The same 30-day limit applies wherever that text was held while your assistant was being built. You can ask us to delete it sooner, or to correct any fact your assistant uses, at any time: [email protected].
Signup and setup information is kept for as long as reasonably needed to follow up, provide the service, or until you ask us to delete it. Payment confirmation records are kept only as long as needed for accounting, dispute handling and legal obligations. Demo conversations are kept so we can understand what visitors ask for and make the assistant better at answering it. We store the message you typed, the reply, and technical details such as which industry and AI model were selected, how long the reply took, and any error. We do not store your IP address or any account identifier alongside it, so these records are not linked to you personally. The log is capped and the oldest entries are discarded automatically. Because the demo is public, please don't type real personal or business-sensitive information into it - if you have already and want it removed, email [email protected] and we'll delete it.
If you cancel: your assistant stops answering straight away. Everything we hold to run it - the pages we read from your website, the reviewed facts and prices your assistant used, its conversation records, and the contact details on your signup - is deleted 30 days after you cancel. The 30 days exist so the decision can be reversed and so we can still answer a question about your account in the weeks right after it ends. You do not have to wait: email [email protected] and we will delete it immediately. This includes the copy held on the Kea-controlled machine that reads websites. Two things are kept afterwards and nothing else: your payment records, which accounting and tax law require us to hold, and a dated note that the deletion happened, recording your business name and how many records were destroyed - it does not contain your email address.
Content-free live-chat operational records are deleted after 90 days. Live-chat message and reply content is not stored in those operational records. Kea's separate production chat-log copy is deleted after 30 days. A report or chat-log attachment already delivered to the customer's configured mailbox is then under that customer's own email retention settings.
If a business turns on voice for its assistant and you tap the microphone: your browser records the audio and sends it to your browser's own vendor (Google for Chrome, Apple for Safari) to turn into text. That transcription is done by the browser, not by Kea, and is covered by that vendor's privacy policy. Kea receives only the resulting text, exactly as if you had typed it. The button is not shown in browsers without speech recognition, and using it is always optional - typing does the same thing.
Expired client and operator login-token records are deleted 1 day after expiry, and expired portal/session records are deleted 30 days after expiry. Portal security audit entries - the sign-in and settings-change record described above - are deleted 90 days after they are recorded, or sooner with the rest of your data if you cancel or ask for deletion.
A business that adds the optional Social Auto-Sync add-on authorises us to read its own public Instagram page on a schedule and use new posts to keep its assistant's knowledge current. The post captions and images we read for this are deleted 90 days after they are read, or sooner with the rest of that business's data if it cancels or asks for deletion.
Security
We take reasonable steps to protect personal information against loss, unauthorised access, misuse and disclosure. No internet service is completely risk-free, so please do not submit sensitive information through the public demo.
What we don't do
We don't sell your information. We don't use demo chat or photo uploads to build a public customer database. We only share information where needed to run the site, provide the demo or service, communicate with you, or comply with the law.
Cookies and tracking
This site can use Google Analytics 4 to understand how visitors find and use the site - which pages get viewed, roughly where visitors come from, and which devices they use - but only if you say yes to the cookie banner shown on your first visit. Nothing loads and no cookie is set until you click Accept; if you click Decline, or simply close the banner without choosing, Google Analytics never runs. You can change your choice at any time with the "Cookie settings" link in the footer of every page. If you do accept, it sets cookies in your browser and sends usage data to Google, who process it under their own privacy policy. This is aggregate traffic measurement: we use it to see what's working on the site, not to identify you personally.
The client portal also sets a strictly necessary, secure session cookie after you use a sign-in link. It is used only to keep you signed in and protect changes to your own assistant; it is not an advertising or analytics cookie, and - being necessary for a service you asked for - it is not gated by the consent banner.
If you did accept and want to withdraw later, the footer link above also covers it - or you can opt out with Google's browser opt-out add-on, by blocking cookies for this site in your browser settings, or by using your browser's Do Not Track or tracking-protection features. The site works normally either way - nothing here depends on analytics being allowed.
We don't use advertising or remarketing cookies, and we don't sell analytics data.
Your rights
Under the Privacy Act 2020 (New Zealand), you can ask what information we hold about you and ask us to correct or delete it. Contact us at [email protected] to do so.
If you are not happy with how we handle a privacy request, you can also contact the Office of the Privacy Commissioner at privacy.org.nz.
Changes
If this policy changes in a way that matters, we'll update the date at the top of this page.