Legal

Privacy Policy

sauble.ai is a product of Kinara Systems Inc.  ·  Version 0.1  ·  Effective July 20th, 2026

This Privacy Policy explains how Kinara Systems Inc. (“Kinara,” “we,” or “us”) collects, uses, and shares personal data about the individuals who use the sauble.ai platform, the Playground, and related services (the “Service”). It covers personal data about users of the Service. Your use of the Service is also governed by our Terms of Service.

The data, credentials, and systems you connect to the Service (“Customer Data”) are governed by the Terms of Service and any applicable Data Processing Addendum, not by this policy. The third parties that process data on our behalf are listed on our Sub-processors page.

1. Information we collect

Account information you provide at signup: your name, work email address, company, and role.

Authentication data used to sign you in. Sign-in uses a passwordless magic-link / one-time-code flow operated through our authentication provider; we do not store passwords.

Usage and analytics data about how you interact with the Service — for example sign-in events, the pages and tabs you view, and the features you use — together with basic device and browser information and an approximate location derived from your IP address.

Session and analysis data. When you use the Service, we store your sessions so you can revisit your work and so we can operate, secure, and improve the Service. A session can include the questions and queries you run, the data the Service retrieves from the tools and sources you connect while it works, and the analyses, root-cause explanations, and recommendations the Service generates.

Knowledge you provide. Documents and knowledge-base content you upload to your workspace are stored so the Service can use them to ground its retrieval, analysis, and recommendations for you and your team.

Workspace context. Analytics events are associated with your user and organization/workspace using pseudonymous keys, so usage can be analyzed per user and workspace without exposing the underlying identifiers, name, or email to our analytics provider.

Cookies and local storage used to keep you signed in and to operate analytics (see “Cookies, tracking, and Global Privacy Control”).

Most of this information comes from you or from your use of the Service. Some may come from other sources — for example, a colleague or workspace administrator who invites you to a shared workspace, and the systems your organization connects to the Service.

Some of the data above — session content, data retrieved from the tools you connect, and documents you upload — is or contains Customer Data. Where it includes personal data, we handle it as described in this policy; the systems you connect and the data drawn from them are also governed by the Terms of Service and any Data Processing Addendum, which cover the personal data Kinara processes on your behalf.

2. How we use information

To provide, operate, secure, and support the Service, including authenticating you and maintaining your account and workspace.

To generate analyses, root-cause explanations, and recommendations using AI models (see “AI and automated processing”).

To understand how the Service is used and to improve its reliability, usability, and features.

To communicate with you about your account, security, and material changes to the Service or our policies, and to comply with legal obligations and enforce our agreements.

3. AI and automated processing

The Service uses AI models, including models operated by the third-party AI providers listed on our Sub-processors page, to generate analyses and recommendations. Inputs may include Customer Data and data read from your connected systems.

We do not use your data to train foundation models, and we configure these providers, where their applicable terms allow, not to train on inputs or outputs. Provider-specific terms are identified on the Sub-processors page.

AI outputs are decision-support only. We do not use the Service to make decisions about you that produce legal or similarly significant effects without human involvement, and you are responsible for reviewing outputs before acting on them.

4. Service providers and sub-processors

We share personal data with vendors that process it on our behalf, under contract and bound by appropriate confidentiality and data-protection obligations, only to provide the Service — including our authentication + database provider, product-analytics provider, transactional-email provider, hosting/compute providers, and AI providers.

The current list of sub-processors, with the purpose and processing region of each, is maintained on our Sub-processors page. We do not sell or “share” personal data (as defined by California law) and we do not use it for third-party advertising.

5. Where your data is processed; international transfers

Kinara is based in Ontario, Canada. Your personal data is processed in Canada, the United States, and the European Union depending on the function: account and application data are hosted in the United States; product analytics is processed in the European Union; AI processing occurs in the United States.

Because data is processed outside your own country, it may be subject to the laws of, and accessible to courts, law-enforcement, and authorities in, those jurisdictions. Where we transfer personal data internationally, we rely on appropriate safeguards required by applicable law, including the European Commission’s Standard Contractual Clauses and, for transfers from the United Kingdom, the UK International Data Transfer Addendum.

6. Legal bases for processing (EEA/UK)

Where the GDPR or UK GDPR applies, we process personal data on the basis of: performance of our contract with you (to provide the Service); our legitimate interests (to secure and improve the Service and understand product usage), balanced against your rights; compliance with legal obligations; and your consent where required, which you may withdraw at any time.

7. Your privacy rights

Subject to applicable law, you may request access to, correction of, deletion of, or a copy of your personal data, and may object to or ask us to restrict certain processing. Where we rely on consent, you may withdraw it at any time without affecting prior processing.

Under Canada’s PIPEDA, you may request access to and correction of your personal data and may address concerns to our privacy contact; if unresolved, you may complain to the Office of the Privacy Commissioner of Canada. In the EEA/UK you may also complain to your local supervisory authority.

To exercise any of these rights, contact our privacy contact (below). We will verify your request and respond within the timeframes required by applicable law, and we will not discriminate against you for exercising your rights.

8. California privacy (CCPA/CPRA)

In the past 12 months we have collected these categories of personal information: identifiers (name, email); commercial or professional information (company, role); internet or network activity (pseudonymous usage analytics, device and browser information); approximate geolocation (derived from IP address); and other information you choose to submit or upload, including the contents of queries, sessions, and documents, which may contain personal information. We collect it for the business purposes described in “How we use information” and disclose it only to the sub-processors described above.

We do not sell or share personal information and have not done so in the past 12 months. California residents may request to know, delete, or correct their personal information, and to opt out of any sale/share — which is not applicable here. You may use an authorized agent. Because we do not sell or share personal information, there is no sale or share for a Global Privacy Control signal to opt out of; you can still opt out of product analytics using the control on this page.

9. Cookies, tracking, and Global Privacy Control

We use strictly necessary cookies and local storage to keep you signed in and operate the Service, and first-party analytics identifiers to measure product usage. We do not use advertising cookies or cross-site tracking.

You can opt out of analytics at any time using the control on this page; your choice is stored on your device. We do not currently detect browser Do Not Track or Global Privacy Control (GPC) signals automatically, so please use the on-page control to opt out.

10. Data retention

We retain personal data only for as long as needed for the purposes described in this policy, then delete or de-identify it. Retention periods vary by category:

Account information — for as long as your account is active and for a limited period afterward to meet legal, tax, and security obligations [retention period to be finalized].

Session and analysis data and uploaded knowledge — for as long as your workspace retains them or until you or your organization delete them, subject to backup cycles [retention period to be finalized].

Product-analytics data — retained for a limited period according to our analytics configuration [retention period to be finalized].

We may retain information longer where required by law or to establish, exercise, or defend legal claims.

11. Security

We maintain reasonable administrative, technical, and organizational measures designed to protect personal data, including keeping raw identifiers out of our analytics provider. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

If a breach of security safeguards creates a real risk of significant harm, we will notify affected individuals and the Office of the Privacy Commissioner of Canada as required by PIPEDA, and any other authorities where applicable law requires.

12. Children's privacy

The Service is a business product intended for use by adults in a work context. It is not directed to children under 16, and we do not knowingly collect personal data from anyone under 16. If we learn that we have collected such data, we will delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. We will communicate material changes by reasonable means and update the “Effective” date above. Where a change materially reduces your privacy protections and applicable law requires your consent, we will obtain it before the change applies to you.

14. Contact and privacy contact

Kinara Systems Inc. is the controller of the personal data described in this policy. For personal data contained in Customer Data that we process on your organization’s behalf, we act as a processor and your organization is the controller; those requests should be directed to your organization.

Direct privacy questions and rights requests to our privacy contact via the contact page; a dedicated privacy contact email and postal address will be published here before launch. If we are required to appoint a representative in the EEA or the UK under Article 27 of the GDPR, we will identify them here.

Your analytics choice

We use pseudonymous product analytics to understand how the Service is used. You can opt out at any time; your choice is remembered on this device.

Product analytics is not currently active in this environment.

Contact

Questions or privacy requests may be directed to Kinara Systems Inc. via our contact page. A dedicated privacy contact will be published here before launch.