Legal · SeKondBrain
Part 01 · Privacy

Privacy
Policy.

How SeKondBrain collects, uses, shares and protects personal data across the Website, Kora, Kanvas, KIT, Kemory, SeKondBrain for Business and the Community Edition.

Version 2.5 Effective 5 August 2026

1. Who we are and what this Policy covers

1.1 SeKondBrain AI Labs Limited (“SeKondBrain”, “we”, “us”, “our”) is a private limited company incorporated in England and Wales (Company No. 16806279) with its registered office at 2 Peel Court, 24 St. Cuthberts Way, Darlington, England DL1 1GB. We operate a cognitive memory and knowledge infrastructure platform for individuals, teams and AI agents.

1.2 This Privacy Policy explains how we collect, use, share and protect personal data in connection with:

  • our website at sekondbrain.ai and related sites (the “Website”);
  • Kora (conversational assistant, including Kora Voice) and Kanvas (structured notebook and knowledge workspace, including the Kora for Chrome extension);
  • KIT (Knowledge Intelligent Toolkit) — SeKondBrain for Product Developers, including its MCP tool interface for connected coding agents;
  • Kemory — our permissioned memory platform for AI agents, including AI conversation capture, namespaces, artefacts and the Kemory CLI and dashboard;
  • SeKondBrain for Business (KompanyBrain) — our company-level intelligence product deployed for business customers; and
  • the Community Edition and any trial, beta or early-access features,

together, the “Services”.

1.2A By using the Services you acknowledge the practices described in this Policy. This acknowledgment does not itself constitute consent; where we rely on consent as a legal basis, we obtain it separately as described below.

1.3 We process personal data in accordance with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (“PECR”). Where we serve users in the European Economic Area, the EU GDPR applies equivalently.

2. Our role: controller or processor

2.1 Our role under data protection law depends on how you use the Services.

2.2 We act as controller for: (a) account, profile, billing and subscription data; (b) usage, device, log and analytics data; (c) communications with us, including support; (d) marketing data; and (e) content you provide to the Services as an individual user of Kora, Kanvas, KIT (individual plans), Kemory (personal namespaces) or the Community Edition.

2.3 We act as processor on behalf of the relevant business customer for content processed within SeKondBrain for Business (KompanyBrain) deployments and within organisation-managed KIT Team or Kemory workspaces. This includes client artefacts a business ingests into KompanyBrain — emails, files, meeting records, decisions and communications — which may contain personal data relating to that business’s own clients and contacts. In those cases the business is the controller, our processing is governed by the Data Processing Agreement forming part of our Business Terms, and questions or rights requests concerning that data should be directed to the relevant business in the first instance.

2.4 If you use the Services through an organisation, your organisation’s administrators may be able to access, manage, restrict or delete content within your organisation workspace, and your organisation’s own policies apply alongside this Policy.

2.5 Self-hosted Kemory. If you run a self-hosted Kemory instance (including Community Edition deployments) and synchronise content to it, your data flows to your own server, not ours: you (or your organisation) are the controller for data held on that instance, and we act only as the provider of the software.

3. Personal data we collect

3.1 Information you provide

  • Account and profile data: name, email address, password (stored hashed), organisation, team, role, job title, profile photo and settings.
  • User Content: text, files, documents, notes, pages, comments, product manifests and artefacts, images, audio and video you upload to or create within the Services.
  • Memory Data: memories, namespaces, concepts, knowledge-graph entities, provenance records and artefacts stored in Kemory or synchronised through our cognition layer at your direction.
  • Derived memory data: records Kemory automatically derives from synchronised content so that recall works — extracted memories (short facts and preferences), compressed summaries of related memories and of each namespace, and numeric search representations (embeddings). Derived records are part of your data and are covered by the same access controls, retention and deletion rules as the content they came from.
  • Captured AI Conversations: where you enable capture (for example via the Kora for Chrome extension), full conversations you conduct with third-party AI services (such as ChatGPT, Claude or Gemini) and associated artefacts, which we store, classify and map to namespaces on your instruction, including files and images exchanged in those conversations (captured subject to a per-file size cap). Capture is user-initiated and can be disabled at any time.
  • Prompt enrichment drafts: where you enable cross-AI recall, in-progress draft text you compose on an enabled AI platform may be sent to your connected Kemory as a search query to surface your own relevant memories. Draft text is used only to search, is not stored as a conversation or memory by this feature, and is sent nowhere other than your connected Kemory. You can turn this off in Settings.
  • Voice data: where you use Kora Voice, audio input, transcripts and speaker metadata generated during your session.
  • Payment data: purchases are processed by Paddle, our merchant of record, which collects billing name, address, VAT details and payment method as the seller of record and acts as an independent controller of that data under its own privacy policy; we receive transaction confirmations and subscription status, and we do not store full card numbers.
  • Communications: messages, feedback and attachments you send us.

3.2 Information we collect automatically

  • Usage and log data: feature-usage events (names, counts, durations, error types), actions taken, pages and artefacts viewed or edited, timestamps, IP address, referral pages and error diagnostics. Telemetry events never include the content of your conversations or memories. Server-side access and error logs and audit trails describe actions, not content.
  • Device data: browser type and version, operating system, device identifiers and language settings.
  • Audit records: security-relevant events (for example access grants, memory reads and writes, sharing and export actions) recorded in tamper-evident audit logs to protect your account and satisfy our security commitments.
  • Cookies and similar technologies: as described in our Cookie Policy and section 12 below.

3.3 Information from third parties

  • Connected services: if you connect a third-party service to the Services (for example an email, calendar, storage or messaging integration, or a connector you configure through our connector framework), we receive the data you authorise that service to share, subject to its permissions model.
  • Authentication providers: if you sign in via a third-party identity provider, we receive your name, email address and authentication tokens.

4. How we use personal data

4.1 We use personal data to:

  • provide the Services: create and manage accounts; store, index and retrieve your content; extract concepts and build knowledge graphs; generate responses, artefacts, summaries and visual assets; maintain provenance links between outputs and their sources; and synchronise memory across the agents and surfaces you authorise;
  • operate AI features: send relevant content to large language model providers and our own models to generate responses and structured artefacts, as described in section 5;
  • secure the Services: authenticate users, enforce permissions (including our default-deny authorisation model), maintain audit logs, and detect and prevent fraud, abuse and security incidents;
  • improve the Services: analyse usage in aggregate, diagnose faults, and develop and test features;
  • communicate with you: service notices, security alerts, support responses and, with your consent or as otherwise permitted by law, marketing communications;
  • bill and administer: process payments, manage subscriptions and entitlements, and keep accounting records; and
  • comply with law: meet legal, regulatory and tax obligations, and establish, exercise or defend legal claims.

5. AI processing and model providers

5.1 The Services use artificial intelligence, including third-party large language models, to process your content and generate outputs. When you use an AI feature, relevant portions of your content and context are transmitted to the model provider for the sole purpose of generating your requested output.

5.2 We do not use your User Content, Memory Data or Captured AI Conversations to train our models. Content sent to our inference providers is transmitted solely to generate your requested output. Our current sub-processors, including the categories of inference providers we use, are listed at docs.sekondbrain.ai/subprocessors.

5.3 Where we offer optional programmes under which content may be used to improve our models or Services, participation is opt-in (or, for existing features, subject to a clearly signposted opt-out), and you may change your choice at any time in your settings.

5.4 AI outputs are generated content. We ground outputs in retrieval and provenance and audit them for quality, but outputs may nonetheless be inaccurate or incomplete, and you should not rely on them without verification. Outputs do not constitute professional advice.

5.5 We do not make decisions based solely on automated processing that produce legal or similarly significant effects concerning you.

6. Legal bases

6.1 We rely on the following legal bases under Article 6 UK GDPR:

  • Contract: to provide the Services you have signed up for, including account management, content processing, AI features and billing.
  • Legitimate interests: to secure and improve the Services, prevent abuse, maintain audit records, conduct analytics, and market our services to business contacts — in each case balanced against your rights and interests.
  • Consent: for non-essential cookies, electronic marketing to individuals, optional data-use programmes and any other processing where we ask for it. You may withdraw consent at any time.
  • Legal obligation: to comply with applicable law, including tax, accounting and lawful requests from authorities.

6.2 We do not intentionally collect special category data. If your content happens to include such data, we process it only as necessary to provide the Services at your direction, and where we act as processor the controller is responsible for ensuring an appropriate condition applies.

7. How we share personal data

7.1 We do not sell personal data. We share it only:

  • with sub-processors and service providers who support the Services — including cloud infrastructure (Google Cloud), large language model and speech providers, storage, email delivery and analytics — under contracts that restrict their use of the data to providing services to us. A current sub-processor list is maintained at docs.sekondbrain.ai/subprocessors. Payment providers have a dual role: Paddle and Stripe process billing and subscription data on our instructions as sub-processors, and Paddle, as merchant of record, is additionally the seller of record for your transaction and an independent controller of that transaction data under its own privacy policy.
  • with third-party AI services and agents you connect or authorise: if you capture conversations from, move context to, or expose artefacts to a third-party AI service or MCP-compatible agent (for example a coding agent you connect to KIT), that third party receives the data you direct us to share and processes it under its own terms and privacy policy. We are not responsible for third-party services you choose to connect.
  • within your organisation, where you use an organisation workspace, in accordance with its permission settings;
  • with recipients of content you share, where you create share links, invite collaborators or export content;
  • with our group companies, including SeKondBrain AI Labs FZCO (UAE), our billing affiliate, for invoicing, collection and account administration, under intra-group data protection arrangements;
  • in a business transfer, in connection with a merger, acquisition, financing or sale of assets, subject to confidentiality; and
  • where required by law, to comply with legal process, enforce our agreements, or protect the rights, safety and security of SeKondBrain, our users or the public.

8. International transfers

8.1 We host the Services on Google Cloud infrastructure in Switzerland (for customers in the rest of the world) and India (for customers in India). Business customers select their deployment region at organisation creation.

8.1A Separately from hosting, billing and account administration data is processed by our group affiliate SeKondBrain AI Labs FZCO in the United Arab Emirates (section 7.1). No User Content, Memory Data or Captured AI Conversations are transferred to that affiliate.

8.2 Transfers to Switzerland are covered by UK adequacy regulations. The United Arab Emirates is not covered by a UK adequacy decision: that transfer is made under an intra-group data transfer agreement incorporating the UK International Data Transfer Agreement, supported by a transfer risk assessment. Transfers to India, to the UAE, and any other transfer to a country without UK adequacy (including processing by inference providers in other jurisdictions), are made under the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, with supplementary measures where appropriate. You may request details of the safeguards applicable to a specific transfer at privacy@sekondbrain.ai.

9. Retention

9.1 We retain personal data for as long as your account is active and as needed to provide the Services, and thereafter only as necessary to comply with legal obligations, resolve disputes and enforce agreements.

9.2 If you delete your account, we initiate deletion of your content across all data stores (including relational, vector, graph and object storage and Kemory memories) subject to a 30-day grace period during which you may reverse the deletion, after which deletion is permanent. Residual copies may persist in encrypted backups for up to [90] days before being overwritten.

9.3 Standard retention periods: account data — life of the account plus 30 days after a deletion request; content and memories (including derived memory data) — until you delete them or your account; product telemetry — 12 months, then deleted or irreversibly aggregated; server access and error logs — 90 days; audit logs, billing and other records we must keep by law — the applicable statutory periods. Records may be kept longer where required by law.

9.4 Where we act as processor, we retain and delete data as instructed by the controller under the applicable Data Processing Agreement.

10. Security

10.1 We implement appropriate technical and organisational measures, including encryption in transit (TLS) and at rest, role-based and default-deny access controls, per-install device-scoped API keys revocable per device, tenant isolation (with single-tenant data deployments for KompanyBrain customers), hash-chained tamper-evident audit logging, secrets management and regular security review. Sign-in uses OAuth 2.0 with PKCE on our own pages; passwords are never transmitted through or stored by our browser extension. No system is perfectly secure, and you are responsible for keeping your credentials confidential.

10.2 Optional content encryption at rest. You may opt in to content encryption at rest for your hosted Kemory. Your conversation and memory content is encrypted with AES-256-GCM envelope encryption using data-encryption keys unique to your account, wrapped by a root key held in a cloud key-management service. Enabling encryption is permanent for your account. Encrypted content is decrypted only transiently, in memory, to serve your requests and the background organisation described in section 5. When your account is deleted, your keys are destroyed, rendering any residual encrypted content permanently unreadable.

10.3 Personal data breaches. Where a breach is notifiable, we will notify the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours of becoming aware of it (Article 33 UK GDPR), and where the breach is likely to result in a high risk to your rights and freedoms we will notify you directly without undue delay (Article 34). Where we act as processor, we notify the controller as set out in the applicable Data Processing Agreement.

11. Your rights

11.1 Subject to conditions in law, you have the right to: access your personal data; rectify inaccurate data; erase your data; restrict or object to processing; data portability; withdraw consent; and not be subject to solely automated decisions with legal or similarly significant effects.

11.2 You can exercise access and portability directly through the “Download my data” function, which exports your conversations, manifests, pages, comments, memories and associated graph data in a machine-readable format, and you can delete your account in settings.

11.3 For anything else, contact us at privacy@sekondbrain.ai (alias: privacy@s9n.ai). We respond within one month (extendable by two further months for complex requests, in which case we will tell you). If your request concerns data we process on behalf of a business (section 2.3), we will refer it to that business and assist them as required.

11.4 You may complain at any time to the Information Commissioner’s Office (ico.org.uk). We would appreciate the chance to address your concerns first.

12. Cookies

12.1 We use strictly necessary cookies to operate the Services and, with your consent, analytics and preference cookies. Details, durations and controls are set out in our Cookie Policy. You can withdraw consent through the cookie banner or your browser settings.

13. Children

13.1 The Services are not intended for anyone under 18 and we do not knowingly collect data from them. If you believe a child has provided us personal data, contact us and we will delete it.

14. Changes and contact

14.1 We may update this Policy from time to time. Material changes will be notified through the Services or by email before they take effect. The version date appears at the top of this Policy.

14.2 Data controller: SeKondBrain AI Labs Limited, 2 Peel Court, 24 St. Cuthberts Way, Darlington, England DL1 1GB. ICO registration: applied for; registration number will be added here once issued. Privacy contact: privacy@sekondbrain.ai (alias: privacy@s9n.ai). We have not appointed a statutory Data Protection Officer.