Privacy Policy
Last updated: August 22, 2026
1. Who we are
KatieFlow (“Katie,” “we,” “us”) is a work operating system that helps you organise tasks, preserve context across AI tools, and keep work moving. This policy explains what data we collect, why, and your rights regarding that data.
2. Data we collect
We collect the minimum data needed to provide and improve the service:
Account information. When you sign up we receive your name and email address via our authentication provider (Clerk). We do not store passwords directly.
Work content. Tasks, AI Contexts, descriptions, links, and file attachments you create within Katie. This data is stored in our database (Supabase) and file storage.
Uploaded files. Documents you attach to tasks (PDFs, Word docs, spreadsheets, presentations, images, etc.) are stored in Supabase Storage.
Usage data. Basic analytics such as page views, feature usage, and error logs to help us improve the product. We do not use third-party advertising trackers.
3. How we use your data
Your data is used to provide core product functionality: storing and displaying your tasks, generating AI summaries of uploaded documents, connecting context across your work, and operating Katie’s Chief of Staff features. We also use aggregated, anonymised usage data to improve the product.
4. AI processing and third-party services
To provide AI-powered features (document summarisation, task evaluation, context generation), we send relevant content to OpenAI’s API. Important details about this:
No model training.Data sent to the OpenAI API is not used to train their models. OpenAI’s API data usage policy confirms that API inputs and outputs are not used for training purposes.
Limited retention. OpenAI retains API data for up to 30 days for abuse and misuse monitoring, then deletes it. We send only the minimum content necessary for each AI operation.
Future direction. We are actively working toward self-hosted AI models to eliminate third-party data processing entirely.
We also use the following service providers to operate Katie:
Clerk — authentication and identity management.
Supabase — database and file storage (hosted on AWS infrastructure).
Netlify — application hosting and delivery.
4a. Google user data (Gmail & Drive)
If you connect a Google account, Katie requests two OAuth scopes: gmail.readonly (read your messages; Katie never changes or deletes anything in your mailbox) and drive.file (create and access only files Katie itself creates in your Drive). Katie uses Gmail data for exactly two features you invoke:
- Star capture — messages you star are read (sender, subject, snippet) to create a task linking back to the thread. The star stays until you clear it.
- Billing extraction — messages from recognised billing senders are read to record the provider, amount, and currency of invoices on your own dashboard.
For billing extraction, the text of a billing email may be processed by OpenAI’s API to extract the invoice fields. OpenAI processes this data as a service provider and does not use API data to train its models. No other Google user data is transferred to third parties.
Katie’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: Google user data is only used to provide the user-facing features described above; it is never sold, never used for advertising, never used to train generalised AI or machine-learning models, and is not read by humans except with your explicit consent, where required for security, or to comply with law. Access tokens are held by Clerk, our authentication provider; Katie never stores your Google password or refresh tokens. You can revoke access at any time from Settings → Accounts or at myaccount.google.com/connections.
5. Data storage and security
Your data is stored on servers within the United States and European Union via our infrastructure providers. We use encryption in transit (TLS) and at rest where supported by our providers. Access to production systems is restricted to authorised personnel only.
6. Data retention
We retain your data for as long as your account is active. If you delete your account, we will delete your personal data and work content within 30 days, except where we are required to retain it by law. Uploaded files are deleted from storage when removed from tasks or when your account is deleted.
7. Your rights
Depending on your location, you may have the following rights:
Access. Request a copy of the personal data we hold about you.
Correction. Ask us to correct inaccurate data.
Deletion. Request deletion of your data and account.
Portability. Request an export of your data in a structured format.
Opt-out. Opt out of non-essential data processing at any time.
To exercise any of these rights, contact us at hello@katieaios.com. We will respond within 30 days.
8. Cookies
Katie uses essential cookies required for authentication and session management. We do not use advertising or tracking cookies. No cookie consent banner is required as we only use strictly necessary cookies.
9. Children’s privacy
Katie is not intended for use by anyone under the age of 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
10. Changes to this policy
We may update this privacy policy from time to time. If we make material changes, we will notify you via email or a prominent notice within the product. Your continued use of Katie after changes take effect constitutes acceptance of the updated policy.
11. Contact
Questions or concerns about this policy? Reach us at hello@katieaios.com.