Last updated: August 19, 2026

Privacy Policy

KikuAI values privacy and keeps data collection to the minimum required to run public product previews, respond to requests, and protect the site from abuse.

Product-specific policy: FitKiku Privacy PolicyHourleaf Privacy PolicyДоставай! Privacy PolicyKiku Captions Privacy Policy

1. Minimal Data Collection

We collect only the minimum data required for the product flow you use:

  • Preview request details you submit, such as name, email, video title, language pair, and notes
  • Automation or integration requests you submit, such as email address, workflow note, and source page
  • Rights confirmation for submitted preview requests
  • Operational metadata such as timestamps, requested product, and request IDs
  • IP address for abuse prevention and rate limiting
  • Email address, hashed one-time codes, and hashed session tokens when you use email account access
  • API key ownership records; full PATAS and Automatic Subtitles API keys are shown once and are not stored
  • Payment references for paid product flows, such as Paddle customer and transaction IDs, shared credit grants, and credit usage
  • Automatic Subtitles preview, entitlement, signed job, artifact expiry, account-owned API job status, duration, credit, and abuse-prevention records
  • Privacy-limited blog events containing only article slug, content lane, source, outcome, and timestamp

2. No Third-Party Tracking

We do not use third-party advertising trackers or advertising analytics. We may use essential cookies or an essential HttpOnly session cookie when required for account security. Simple public tools do not require an account before showing their initial result. Blog events do not contain email, free text, IP address, browser fingerprint, or the destination URL. Standard infrastructure logs remain covered separately below.

3. Payment Processing

Kiku Credits purchases from the account, PATAS, and Automatic Subtitles may be processed by Paddle.com as Merchant of Record. Payment details are handled by Paddle, not by KikuAI. KikuAI retrieves the verified payer email to create or link the account that owns the credits, and stores the Paddle transaction reference, shared credit grant, and credit usage records. Automatic Subtitles also stores an anonymous client hash and temporary job entitlement so the paid browser can unlock the same uploaded preview without signing in first.

4. Transactional Email

One-time sign-in codes may be delivered through Brevo. KikuAI sends only the recipient email, the transactional message, and delivery metadata required to send the code. Codes expire and are stored by KikuAI only as hashes.

5. Blog Newsletter

The blog subscription form posts the email address directly to Buttondown. Buttondown sends the double opt-in confirmation and stores the subscriber record under its service terms. KikuAI does not receive or store the address submitted through this form; KikuAI reads only the aggregate confirmed subscriber count.

6. Product Data Processing

Product previews may process the information you submit so we can review the request and respond. We do not use submitted product data to train AI models.

PATAS hosted audits do not persist raw customer rows. The stored report uses sanitized pattern evidence, usage counters, input hashes, and audit metadata. If a deeper integration launches, its data handling rules will be described on the relevant product or docs page.

Automatic Subtitles uploads the source video to KikuAI's Hetzner worker. The worker sends extracted speech audio and any optional Protected Words through KikuAI's private OmniRoute to Groq Whisper for transcription. Protected Words are used only as bounded spelling guidance. Selected Russian transcript segments that lack punctuation are sent through the same private route to Groq Qwen for punctuation-only restoration. Before payment, the worker may create a watermarked video excerpt and return up to ten sample captions to the submitting browser. The source video, Protected Words, extracted audio, preview, timed SRT, and rendered MP4 are deleted automatically within 24 hours. KikuAI does not use this media or transcript to train AI models. Product analytics exclude filenames, media, transcript text, Protected Words, capability tokens, checkout URLs, and output bytes.

Automatic Subtitles API keys are stored only as hashes with a visible prefix and tail. The account history stores the job identifier, status, measured duration, quoted and spent credits, and timestamps; it does not store the filename, media, transcript text, Protected Words, signed job ticket, or output bytes. API media uses the same private worker and 24-hour deletion window as the browser product.

7. Server Logs

Our web server logs standard technical information (IP address, browser type, access time, requested URL) for operational stability and security monitoring. Logs are retained for a limited period and are not shared with third parties.

8. Data Security

We apply standard security practices including rate limiting, request throttling, abuse detection, and encrypted communications. While we strive for secure operation, no system can guarantee absolute security.

9. Your Rights

You have the right to:

  • Access your personal data
  • Request correction or deletion of your data
  • Export your data
  • Request deletion of stored contact or workflow requests

10. Policy Updates

We may update this Privacy Policy periodically. Continued use of the website signifies acceptance of any updated version.

11. Contact