01 / Privacy
Privacy Policy.
Last updated · April 27, 2026
1. Introduction
Kimpton AI (“Kimpton,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our portfolio-aware market intelligence platform and related services.
By using Kimpton, you agree to the collection and use of information in accordance with this policy.
2. Information we collect
2.1 Account information
When you create an account, we collect your email address, name, and authentication credentials. If you sign up through a third-party service (such as Google), we receive basic profile information from that service.
2.2 Portfolio data
If you choose to connect your brokerage accounts, we access read-only portfolio data including holdings, positions, and account balances. We use secure, encrypted connections (via Plaid or similar providers) and never store your brokerage login credentials.
2.3 Usage data
We automatically collect information about how you interact with our platform, including queries submitted, features used, pages visited, and session duration. This helps us improve our services.
2.4 Device information
We collect device identifiers, browser type, operating system, IP address, and similar technical information for security and analytics purposes.
3. How we use your information
- To provide personalized market insights based on your portfolio holdings
- To process and respond to your research queries
- To improve platform features and service reliability (customer portfolio data, queries, and analysis results are not used to train AI models — see our Security page for details)
- To communicate with you about updates, security alerts, and support
- To detect, prevent, and address fraud and security issues
- To comply with legal obligations
4. Data sharing and disclosure
We do not sell your personal information. We may share data with:
- Service providers (sub-processors): Third parties that help us operate our platform (hosting, authentication, analytics, AI inference, observability). A current list of sub-processors is provided in our Data Processing Agreement and is available on request. We provide notice of material changes to our sub-processor roster.
- Brokerage connectors: Secure aggregation services like Plaid to access your portfolio data with your explicit consent
- Legal requirements: When required by law, subpoena, or to protect our rights and safety
- Business transfers: In connection with a merger, acquisition, or sale of assets
We require all sub-processors to maintain data protection obligations substantially similar to those described in this policy and our Data Processing Agreement.
5. Data security
We implement industry-standard security measures to protect your data:
- All data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Read-only access to brokerage accounts — we cannot move or trade your assets
- Periodic access reviews for production systems
- SOC 2 Type II audit in review; enterprise-grade controls in place
- Multi-factor authentication available for all accounts
6. Data retention
We retain your data for as long as your account is active or as needed to provide services. You may request deletion of your account and associated data at any time by contacting us at info@kimpton.ai. Portfolio connection data is deleted immediately upon disconnection; account data is deleted within 30 days of account closure.
7. Your rights
Depending on your jurisdiction, you may have the right to:
- Access and receive a copy of your personal data
- Rectify inaccurate personal data
- Request deletion of your personal data
- Object to or restrict processing of your data
- Data portability
- Withdraw consent at any time
To exercise these rights, please contact us at info@kimpton.ai. We will respond to verified requests within 30 days.
8. Cookies and tracking
We use essential cookies for authentication and session management. We also use analytics cookies provided by the following services to understand how you use our platform:
- PostHog — product analytics (page views, feature usage, error tracking)
- Customer.io — user engagement and communication analytics
You can opt out of analytics cookies at any time using the consent banner on our site or by visiting the Your Privacy Choices section below. See our Cookie Preferences for full details.
8a. Your privacy choices
We do not sell your personal information. Under the California Consumer Privacy Act (CCPA), you have the right to:
- Know what personal information we collect and how it is used
- Request deletion of your personal information
- Opt out of the sale or sharing of your personal information
- Not be discriminated against for exercising your privacy rights
To opt out of analytics tracking, click “Required only” on the cookie consent banner, or contact us at info@kimpton.ai.
We also respect the Global Privacy Control (GPC) signal. If your browser sends a GPC signal, we treat it as a request to opt out of analytics tracking.
8b. European Economic Area (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) applies to your use of Kimpton. We process your data under the following legal bases:
- Consent— for analytics and non-essential cookies. We do not track you until you click “Accept all” on the consent banner.
- Contractual necessity — to provide the Kimpton service you signed up for (account management, portfolio data, AI queries).
- Legitimate interest — for security, fraud prevention, and service reliability.
Under GDPR, you have the right to:
- Access your personal data and receive a copy
- Rectify inaccurate or incomplete data
- Request erasure of your data (“right to be forgotten”)
- Restrict or object to processing
- Data portability (receive your data in a structured format)
- Withdraw consent at any time without affecting prior processing
- Lodge a complaint with your local data protection authority
To exercise any of these rights, contact us at info@kimpton.ai. We will respond within 30 days.
9. Children’s privacy
Kimpton is not intended for individuals under the age of 18. We do not knowingly collect personal information from children.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the “Last updated” date. Continued use of Kimpton after changes constitutes acceptance of the revised policy.
11. Contact us
If you have questions about this Privacy Policy or our data practices, please contact us at info@kimpton.ai. For security inquiries, contact security@kimpton.ai.
Enterprise customers may request a signed Data Processing Agreement by contacting info@kimpton.ai.