Privacy Policy
Effective Date: March 18, 2026 · Last Updated: September 23, 2026
1. Introduction
Kaimoku Technologies, LLC (“Kaimoku,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Kuju Email service and our website at kaimoku.tech (collectively, the “Service”).
By using the Service, you consent to the data practices described in this policy. If you do not agree, please discontinue use of the Service.
2. Information We Collect
Account Information. When you create an account, we collect:
- Name and email address
- Password (stored in hashed form)
- Billing information and payment details (processed by our payment processor)
- Domain name(s) you register with the Service
Email and Communications Data. To provide the email service, we process:
- Email messages (content, headers, attachments) sent to and from your account
- Calendar events and contact records you create
- Folder structures and organizational preferences
Connected Account Data (Kuju Bridge). If you connect an external email account (Gmail, Outlook, or IMAP provider) through Kuju Bridge, we collect:
- OAuth 2.0 tokens (access and refresh tokens) issued by Google or Microsoft to authorize access to your account
- Email messages, metadata (sender, recipient, subject, date), and attachments from your connected account
- Folder and label structures from your connected provider
- Basic profile information (name, email address) used to identify your connected account
For IMAP connections, we collect the server credentials you provide (username and password). IMAP passwords are encrypted using AES-256 before storage and are never stored in plaintext.
Usage Data. We automatically collect:
- Log data (IP addresses, browser type, access times, pages viewed)
- Service usage metrics (storage used, messages sent/received, feature usage)
- Device information (operating system, client application)
Cookies and Similar Technologies. We use essential cookies for authentication and session management. We do not use third-party advertising or tracking cookies. See Section 8 for details.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Process and deliver email messages
- Authenticate your identity and secure your account
- Process payments and manage subscriptions
- Detect and prevent spam, phishing, malware, and abuse
- Provide customer support
- Send service-related communications (account notifications, security alerts, maintenance notices)
- Comply with legal obligations
- Analyze usage patterns to improve the Service (in aggregate, non-identifying form)
4. Connected Accounts (Kuju Bridge)
Kuju Bridge allows you to connect external email accounts (Gmail, Microsoft Outlook, or IMAP providers) to view and manage your email within the Kuju interface. This section describes how we handle data from connected accounts.
Authentication and Credentials.
- Gmail and Outlook connections use OAuth 2.0 — Kuju never sees or stores your Google or Microsoft password
- OAuth tokens are encrypted by the application (AES-256-GCM) before storage; the encrypted values are kept in our database and the key that decrypts them in a separate secrets store
- IMAP connections use credentials you provide, encrypted with AES-256 before storage
- You can revoke access at any time by disconnecting your account in Kuju or revoking permissions in your provider’s security settings
Data Handling Modes. Kuju Bridge supports two modes for handling email from connected accounts:
- Mirror mode: Email messages are copied from your provider and stored locally in Kuju. This enables full search, AI features, and offline access. Mirrored data is subject to the same encryption and retention policies as native Kuju email.
- Proxy mode: Email messages are fetched on demand from your provider and displayed in the Kuju interface without persistent local storage. Metadata (sender, subject, date) may be cached temporarily to enable folder listing and search.
How Connected Account Data Is Used.
- To display your email, folders, and labels within the Kuju interface
- To send email on your behalf through your connected provider (with your explicit action)
- To provide AI-powered features (such as message analysis you request) where they are enabled for your domain
- We do not use connected account data for advertising, market research, or any purpose unrelated to providing the Service
Deletion of Connected Account Data. When you disconnect an external account:
- OAuth tokens and stored credentials are deleted immediately
- In Mirror mode, locally stored copies of email are deleted within 30 days
- In Proxy mode, cached metadata is deleted immediately
- Deletion of data from your external provider is not affected — your original emails remain in Gmail, Outlook, or your IMAP server
5. AI and Automated Processing
Kuju Email uses AI models for spam and phishing detection, and for message analysis you request.
- Spam and phishing scanning runs on incoming mail as it is delivered. For each scanned message we send the sender (From), the subject, the results of the SPF, DKIM and DMARC checks, and up to the first 4,000 characters of the message text to Together.ai, a third-party provider that runs the model
- Mail you import from another provider is not scanned this way
- The scan is enabled per domain, and your domain administrator can turn it off for your domain; individual users cannot opt out on their own
- We do not use your email content to train AI models
For spam and phishing scanning, we send the AI provider only the fields listed above, and only to classify the message. Message analysis you request sends that message's headers and text for the analysis you asked for.
6. How We Share Your Information
We do not sell your personal information. We may share information in the following circumstances:
- Email Delivery. To deliver email, message data is transmitted to recipient mail servers as required by email protocols (SMTP).
- Service Providers. We use third-party service providers for payment processing, infrastructure hosting, and other operational needs. These providers are contractually obligated to protect your data and use it only to perform services on our behalf.
- Legal Requirements. We may disclose information if required by law, regulation, legal process, or governmental request.
- Safety and Enforcement. We may disclose information to protect the rights, property, or safety of Kaimoku, our users, or the public, and to enforce our Terms of Service and Acceptable Use Policy.
- Business Transfers. In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
7. Data Retention
We retain your account information and email data for as long as your account is active. Upon account termination or cancellation:
- Your account is suspended right away, and 30 days later its records — including your folders and message records — are deleted from our database
- That automatic deletion does not currently remove the stored content of your messages (bodies and attachments). If you ask us to delete your account before it runs, by contacting us, we delete that stored content as well
- Accounts that hold Business Mode compliance records are not deleted automatically
- Database backups containing your data are kept for 30 days
- Stored mail is also copied daily to an off-site backup. That backup currently only adds files: it does not remove mail you have deleted, so copies of deleted messages can remain in it
- We may retain limited information as required by law (e.g., billing records for tax purposes)
Usage logs and analytics data are retained in aggregate, non-identifying form and are not tied to individual accounts after deletion.
8. Data Security
We implement industry-standard security measures to protect your data, including:
- Encryption in transit (TLS) for webmail, IMAP, mail submission, and calendar and contacts sync. Mail exchanged with other mail servers is encrypted whenever the other server supports it
- Encryption at rest for stored mail and server boot disks, using our hosting provider's volume encryption with provider-managed keys
- Hashed and salted password storage
- OAuth tokens and IMAP credentials encrypted by the application (AES-256-GCM) before storage, with the key held in a separate secrets store
While we strive to protect your information, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
9. Cookies
We use only essential cookies required for the Service to function:
- Authentication cookies: To keep you logged in and verify your identity
- Session cookies: To maintain your session state
- Preference cookies: To remember your settings (theme, language)
We do not use cookies for advertising, analytics, or cross-site tracking. Because we only use essential cookies, no cookie consent banner is required under most privacy regulations; however, we disclose their use here for transparency.
10. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access. Request a copy of the personal information we hold about you.
- Correction. Request that we correct inaccurate or incomplete information.
- Deletion. Request deletion of your personal information, subject to legal retention requirements.
- Data Portability. Export your data using standard protocols (IMAP, CalDAV, CardDAV) or the API.
- Objection. Object to processing of your personal information in certain circumstances.
- Restriction. Request that we restrict processing of your personal information.
To exercise any of these rights, contact us at privacy@kaimoku.tech. We will respond within 30 days (or as required by applicable law).
11. International Data Transfers
The Service is operated from the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States or other jurisdictions where our service providers operate. By using the Service, you consent to such transfers. We take appropriate safeguards to ensure your data is protected in accordance with this Privacy Policy.
12. Children’s Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 18, we will take steps to delete that information promptly.
13. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to request deletion, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise your CCPA rights, contact us at privacy@kaimoku.tech.
14. European Privacy Rights (GDPR)
If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data on the following legal bases: (a) performance of a contract (to provide the Service); (b) legitimate interests (to improve the Service and ensure security); and (c) your consent (where applicable). You may withdraw consent at any time. You also have the right to lodge a complaint with your local data protection authority.
15. Google API Services User Data Policy
Kuju Bridge’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use data obtained through Google APIs to provide and improve the Kuju email client functionality that you have authorized
- We do not transfer Google user data to third parties, except as necessary to provide the Service, as required by law, or with your explicit consent
- We do not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising
- We do not use Google user data to train machine learning or artificial intelligence models that are unrelated to providing the Service to you
- We do not allow humans to read your Google user data unless: (a) you have given explicit consent; (b) it is necessary for security purposes (e.g., investigating abuse); (c) it is required by law; or (d) the data has been aggregated and anonymized for internal operations
16. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service at least 30 days before they take effect. The “Last Updated” date at the top of this page indicates when the policy was last revised.
17. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us at:
Kaimoku Technologies, LLC
Email: privacy@kaimoku.tech