Legal
Privacy Policy
Effective September 30, 2026
Overview
This Privacy Policy describes how Krazimo Inc. (Krazimo, we, us or our) handles personal information in connection with Krazimo Studio, including our hosted workspace, APIs and mobile application (the Services).
We act as a controller for information used to manage accounts, billing, support and the security of our Services. When an organization uses Studio to process personal information in its agents, workflows or knowledge base, that organization determines the purposes of processing and we act on its instructions as a processor or service provider. The organization's agreement with us and any applicable Data Processing Addendum govern that processing.
If you use a workspace supplied by your employer or another organization, its administrators manage your access and may access workspace content and activity. Contact that organization about its use of your information. Independently operated deployments and third-party services have their own privacy practices. The corporate website at krazimo.com is covered by its separate Privacy Policy.
Personal Information We Collect
Account and contact information: your name, email address, account identifier, organization, workspace memberships, permissions, authentication information and information you provide when contacting support. We also receive account and access information from your workspace administrator or identity provider.
Customer Data: information submitted to or generated through your workspace, including messages, prompts, inputs and outputs, images and files you upload, knowledge-base documents, agent and workflow configurations, run history, evaluations, feedback and review decisions. Customer Data may include personal information about you or others, depending on what the organization submits. Please provide only information necessary for your intended use.
Usage and technical information: requests and activity associated with accounts, workspaces, sessions and runs; model and token usage; cost, timing and error information; and technical information such as IP addresses and browser or device information recorded by our infrastructure. These records support service operation, troubleshooting, security and usage billing.
Billing information: customer and subscription identifiers, plan and transaction information, billing contacts and payment status. Stripe processes payment details in its checkout and billing portal; Studio does not receive your full payment-card number.
Mobile access: the app stores a session credential on your device to keep you signed in and stores preferences such as appearance. Images you select for an agent are uploaded to Studio. We do not need access to your contacts, microphone or precise location to provide the mobile app's current features.
How We Use Personal Information
We use personal information to authenticate users; provide and administer workspaces; run agents and workflows; store and display conversations, run history and results; process subscriptions and usage; respond to support requests; investigate errors; prevent unauthorized access and abuse; and comply with legal obligations.
Where applicable data protection law requires a legal basis, we rely on performance of a contract for providing an individual's account and requested Services, legitimate interests for business account administration, support and protecting our Services, compliance with legal obligations, and consent where required. Where we act as a processor, the Customer is responsible for identifying a lawful basis and providing notices to the individuals whose information it submits.
AI Services and Model Providers
Agents and workflows send the information needed for a model request to the configured model service. This may include instructions, conversation history, inputs, selected images and retrieved knowledge-base content. A request may involve multiple model calls, including guardrails, memory and evaluations. A declined answer does not necessarily mean that no model provider received the input.
Krazimo does not use Customer Data to train foundation or fine-tuned models unless the Customer explicitly agrees in writing. Model inference is distinct from training. Our managed inference uses Amazon Bedrock and OpenRouter according to the configured route. OpenRouter requests are configured to require endpoints with no provider data collection and zero data retention. Those settings do not delete the conversations, run history or other records stored by Studio itself.
If a Customer supplies its own provider credentials or connects an external service, the Customer's agreement with that provider also applies. The Customer should review its provider's processing locations and data-handling terms before submitting personal information. We do not represent that every external service connected by a Customer has identical retention practices.
How Long We Retain Personal Information
We retain personal information for as long as needed to provide the Services, follow Customer instructions, maintain security, resolve disputes and meet legal or accounting obligations. The period depends on the type of information, the workspace's configuration, the applicable agreement and whether an account or workflow remains active.
We generally keep captured model-request records used for debugging for seven days, unless a different period is configured. Conversations, uploaded content, run history and billing records have separate retention periods based on their purpose and the applicable agreement. Files attached to conversations may remain with those conversations. Removing a source document does not automatically remove excerpts already included in conversation or run records.
To request access, export, correction or deletion, contact your workspace administrator or support@krazimo.com. We may need to verify your identity and, for organization-controlled content, obtain instructions from the Customer. We may retain information where legally required or needed for legitimate security and dispute-resolution purposes. Backup copies may remain until replaced through the applicable backup cycle. We will explain any applicable limits when responding to a request.
How We Protect Personal Information
We use technical and organizational measures designed to protect personal information, including authentication, workspace access controls, encrypted connections and restricted infrastructure access. No system or transmission method can be guaranteed completely secure. Customers are responsible for managing their users, permissions, credentials and connected services.
International Data Transfers
Krazimo and its providers may process information in the United States, Australia and other countries where they operate. A workspace's hosting region does not by itself determine where every model provider or connected service processes information. Where applicable law requires safeguards for an international transfer, the applicable agreement and required transfer mechanism govern. Contact us for information about the arrangements applicable to your workspace before submitting data subject to location restrictions.
Your Rights and Choices
Depending on your location and applicable law, you may have rights to access, correct, delete or obtain a copy of your personal information; restrict or object to processing; withdraw consent where processing relies on consent; and appeal a decision about your request. Withdrawal does not affect processing already carried out lawfully. You may also lodge a complaint with your local data protection authority.
Send requests to support@krazimo.com. An authorized agent may submit a request where permitted by law, subject to verification. We will not discriminate against you for exercising applicable privacy rights. Where we process information for an organization, we will direct the request to that organization or assist it as required by our agreement and applicable law. You can also revoke optional device permissions in your device settings.
Children
Studio is a business service and is not directed to children. If you believe a child has provided personal information without appropriate authorization, contact support@krazimo.com so we can investigate and take appropriate action.
Changes to This Policy and Contact
We may update this Privacy Policy to reflect changes to the Services or applicable requirements. We will update the effective date and provide additional notice where required. For privacy questions or requests, contact support@krazimo.com.