This Privacy Policy (hereinafter referred to as "the Policy") sets out how we collect, use, store, share, and protect your (the User’s) personal information and data when you utilize the services of the Kisto AI Chat Application (hereinafter referred to as "Kisto" or "the Application"). By downloading, installing, logging into, or using any feature of the Application, you confirm that you have read, understood, and agreed to all provisions of this Policy, and consent to the processing of your data by us in accordance with the terms outlined herein.
We only collect data that is essential for providing services, enhancing user experience, and ensuring the smooth operation of the Application. The collected data is primarily categorized into the following two types:
When you use specific features of the Application, you may choose to provide relevant data, including but not limited to:
• Chat content: Text, images, audio, or other forms of content that you input during AI chat interactions, as well as the response content generated by the AI (utilized to maintain the continuity of chat services and improve the accuracy of AI responses).
• Feedback and contact information: When submitting suggestions, filing complaints, or getting in touch with customer support, you may provide details such as your name, contact methods, and the content of your feedback (used to address your requests and provide you with a response).
When you use the Application, we will automatically collect data related to your usage behavior and device through technical tools, which includes:
• Device information: Details such as device model, operating system version, device identifier (e.g., Universally Unique Identifier/UUID), IP address, Wi-Fi MAC address, and network connection type (employed to enable the Application to adapt to different devices, ensure service compatibility, and block malicious device access).
• Usage behavior data: Information such as login and logout times, the frequency of using various features (e.g., AI chat, content saving), the duration of each chat session, and error logs generated during usage (applied to analyze user needs, enhance service performance, and resolve technical issues).
We will only use your data for the following legitimate purposes, and will not use it for any purposes unrelated to service provision without your explicit consent:
1. Provision and maintenance of basic services: To ensure the normal operation of the AI chat function, and to store chat records (with your permission) for your future reference and review.
2. Improvement of user experience: To analyze your usage habits (such as common chat topics and preferred features) so as to provide personalized service recommendations (e.g., refining the response style of the AI) and enhance the interface design and operational efficiency of the Application.
3. Ensuring service security: To utilize device information and usage behavior data to detect and prevent illegal or malicious activities (such as virus attacks and data tampering), thereby protecting the security of your data.
4. Compliance with legal obligations: To respond to valid requests from government departments, regulatory authorities, or judicial institutions (e.g., providing relevant data in accordance with court orders) and fulfill legal responsibilities.
5. Research, development, and service updates: To use anonymized and desensitized usage data (which does not contain any personally identifiable information) for optimizing AI algorithm models, testing new features, and evaluating the effectiveness of services.
• Storage period: We will retain your data only for the period necessary to achieve the objectives specified in this Policy. For example, chat records will cease to be stored in accordance with your settings (either temporary storage for the current session or long-term storage with your consent) or when the Application terminates the relevant services. Once the storage period expires or the service is terminated, your data will be securely deleted or anonymized (rendering it unidentifiable).
• Storage location: Your data will be stored on secure servers managed by us or authorized third-party service providers (e.g., cloud service providers). We will ensure that these servers comply with data protection laws and regulations, and implement strict security measures to prevent data leakage.
We attach great importance to data security and have adopted the following measures to protect your data:
• Technical measures: We use encryption technologies (such as SSL/TLS encryption for data transmission and AES encryption for data storage), establish access control systems (including multi-factor authentication and role-based permission management), and conduct regular security updates and vulnerability scans to prevent cyberattacks.
• Management measures: We maintain a dedicated data security team, provide regular data protection training for employees, and sign confidentiality agreements with employees and third-party service providers to clarify their obligations regarding data protection.
It should be noted that no method of data transmission or storage is 100% secure. In the event of a data security incident caused by factors beyond our reasonable control (e.g., force majeure, cyberattacks by third parties), we will promptly notify you in accordance with relevant laws and regulations, explain the situation, and take necessary corrective actions.
We will never sell, rent, or transfer your personal information to any third party for profit-making purposes. Without your consent, we will not share your data with third parties, except in the following circumstances:
1. Authorized third-party service providers: We may engage third-party service providers to offer technical support (e.g., cloud storage, server maintenance). These third parties are only allowed to access the data necessary for performing their duties, must comply with this Policy and relevant laws and regulations, and are prohibited from using the data for other purposes.
2. Legal requirements: We may share your data with government departments, regulatory authorities, or judicial institutions in accordance with laws, regulations, or legal procedures (e.g., responding to subpoenas or court orders).
3. Protection of legitimate rights and interests: We may share relevant data to protect the legitimate rights and interests of Kisto, its users, or the public (e.g., preventing fraud, resolving disputes, and stopping acts that violate this Policy or relevant laws).
4. Business transfers: In the event of a merger, acquisition, asset transfer, or other business restructuring involving Kisto, your data may be transferred to the new entity. We will notify you of such a transfer in advance (e.g., via an in-Application announcement or email) and ensure that the new entity complies with this Policy.
In accordance with relevant laws and regulations, you are entitled to the following rights regarding your data, and we will provide convenient channels for you to exercise these rights:
1. Right of access: You may view stored chat records and usage behavior data through the relevant features of the Application. If you need a copy of your data, you may contact customer support to submit a request.
2. Right of deletion: You may delete chat records at any time through the chat interface of the Application. For the deletion of other data, please contact customer support—we will verify your identity and process your request in accordance with the provisions of the "Data Storage" section of this Policy.
3. Right to withdraw consent: You may withdraw your consent to data collection and use at any time (e.g., turning off the chat record storage function). The withdrawal of consent will not affect the validity of data processing that has already been completed based on your prior consent.
4. Right to object: If you believe that we are misusing your data, you may contact us to raise an objection, and we will review your objection and provide a response.
If you encounter difficulties in exercising the above rights or have questions about them, please contact customer support (see Section 7 for contact details)—we will assist you in resolving the issue within a reasonable period of time.
We may update this Policy in light of changes to laws and regulations, technological developments, or adjustments to the Application’s services. The updated version of the Policy will be posted in the Application (e.g., in the "Settings - Privacy Policy" section) and will take effect on the date of publication. For major updates, we will notify you through prominent means (e.g., an in-Application pop-up window, email, or SMS) to remind you to review the updated content.
Your continued use of the Application after the Policy is updated will be deemed as your acceptance of the revised Policy. If you do not agree to the updated Policy, you must immediately cease using the Application. We recommend that you review this Policy on a regular basis to stay informed of the latest information regarding data protection.
If you have any questions, suggestions, or complaints regarding this Policy or data processing matters, please contact us via the following channel:
Email: app_kisto@outlook.com
We will process your inquiry or complaint within 15 working days of receipt, verify your identity if necessary, and provide you with a clear response.