This Privacy Policy informs you, pursuant to Articles 13 and 14 of the General Data Protection Regulation (GDPR), about how we process personal data when you use Kepos (“the Service”). Kepos is an encrypted knowledge system (Software as a Service) with AI support, speech transcription, a web clipper and team features.
1. Controller
The controller responsible for processing within the meaning of the GDPR is:
Tiamat UG (haftungsbeschränkt)
An der Strusbek 12, 22926 Ahrensburg, Germany
Represented by Managing Director Ansgar Holtmann
Email: mail@tiamat-labs.com
Full details: see the Imprint.
2. Your rights
You have the following rights against us in relation to your personal data:
- Access (Article 15 GDPR) — information about the data we process about you.
- Rectification (Article 16 GDPR) — correction of inaccurate data.
- Erasure (Article 17 GDPR) — erasure of your data unless a statutory retention obligation prevents this. You can authorize the deletion of your account and its content yourself at any time in the account settings.
- Restriction of processing (Article 18 GDPR).
- Data portability (Article 20 GDPR) — you can export your content yourself at any time as a password-protected ZIP archive containing Markdown files.
- Objection (Article 21 GDPR) — to processing based on our legitimate interests.
Where processing is based on your consent, you may withdraw that consent at any time with effect for the future (Article 7(3) GDPR); this does not affect the lawfulness of processing carried out before withdrawal. Send requests concerning your rights to mail@tiamat-labs.com.
Irrespective of this, you have the right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR). The authority responsible for us is the Independent Centre for Privacy Protection Schleswig-Holstein (ULD), Holstenstraße 98, 24103 Kiel, telephone +49 431 988-1200, mail@datenschutzzentrum.de. You may also contact the supervisory authority at your habitual place of residence.
3. Processing activities in detail
For each purpose, the following sections describe which data we process, the legal basis, the recipients to whom the data may be disclosed, and how long we retain it.
3.1 Registration, sign-in and account management
Data: email address, password (stored exclusively as an Argon2id hash, never in plain text), display name, and two-factor authentication details (for example, passkey/TOTP metadata). Purpose: providing and securing your account. Legal basis: Article 6(1)(b) GDPR (performance of a contract) and Article 6(1)(f) GDPR (legitimate interest in account security). Retention period: for the duration of the contractual relationship; deletion after account closure in accordance with Section 5.
3.2 Contract, subscription and payment processing
Data: selected plan, billing cycle, payment status, billing information and VAT information. The payment details themselves (for example, card details) are processed exclusively by our payment service provider Stripe; we do not receive them. Purpose: processing the paid subscription, invoicing, and compliance with tax and commercial-law obligations. Legal basis: Article 6(1)(b) GDPR (performance of a contract) and Article 6(1)(c) GDPR (legal obligation). Recipient: Stripe (see Section 4). Retention period: invoices and accounting records are retained for the statutory retention periods (accounting records for 8 years under Section 147(3) AO / Section 257 HGB in the version applicable from 2025; commercial and business correspondence for 6 years).
3.3 Notes and content (encrypted storage)
Data: notes, sketches, tags, tasks and files created by you. Purpose: providing the knowledge system. Legal basis: Article 6(1)(b) GDPR. Your content is stored in encrypted form (see Section 6). Retention period: for the duration of the contractual relationship; deletion after account closure in accordance with Section 5.
3.4 AI features (assistance, “Dreaming”, linking)
Data: content that you actively submit to an AI feature or expressly release for processing by “Dreaming”. Purpose: summarization, processing, tagging, link suggestions and other AI-assisted features. Legal basis: Article 6(1)(b) GDPR where AI processing is a contractually owed part of the Service; for optional features activated separately, Article 6(1)(a) GDPR (consent), where applicable. Recipients: specialized AI service providers acting as processors (Anthropic, Voyage AI and, where applicable, OpenAI; see Section 4). They process content solely on our documented instructions in order to provide the Service.
No training using your content: Under our contracts, our AI service providers do not use content transmitted through the commercial application programming interface (API) to train their models. Retention by the providers is limited to what is necessary for processing (for example, Anthropic deletes API data after a short period).
3.5 Speech transcription
Data: audio content uploaded or recorded by you. Purpose: conversion into text (transcription). Legal basis: Article 6(1)(b) GDPR. Recipient: Deepgram as a processor (see Section 4). Audio is processed only for the purpose of transcription.
3.6 Web clipper
Data: web content and its metadata saved by you using the browser extension. Purpose: importing third-party content into your knowledge system. Legal basis: Article 6(1)(b) GDPR.
3.7 Team and multi-tenant features
Data: memberships, roles and content shared within an organization. If an organization administrator invites you, we process your email address at their request (collection from third parties, Article 14 GDPR). Purpose: collaboration in separate areas (Spaces). Legal basis: Article 6(1)(b) GDPR. Access is technically secured by tenant-level data separation (Row-Level Security).
3.8 Transactional emails
Data: email address and reason for the message (for example, confirmation, invoice or security-related notices). Purpose: sending contract-related and security-related emails. Legal basis: Article 6(1)(b) and (f) GDPR. Recipient: Resend as a processor (see Section 4). We do not send marketing newsletters without separate consent.
3.9 Server logs and operational security
Data: minimal technical logs, including the IP address, for preventing errors and misuse. Purpose: operational security, stability and protection against attacks. Legal basis: Article 6(1)(f) GDPR (legitimate interest in secure operation). Retention period: generally a few days and no longer than 90 days, followed by automatic deletion. We do not use third-party tracking or analytics tools.
3.10 Product communication, activation and usage-based outreach
Data: email address, language, and state signals derived from your use — in particular whether and when you connected and used an AI client through the application programming interface (MCP), whether you created your first notes/sketches, whether a “Dreaming” run occurred, your most recent activity (recency), and your contract/trial phase. Purpose: supporting you at the right time with setup and feature discovery (activation), alerting you to expiring trial periods or payment problems (conversion), and providing inactive accounts with a specific way to return (reactivation). Communication is primarily provided as a non-promotional notice in the signed-in product (in-app) and by email only at selected moments.
Transparency about profiling (Article 4(4), Article 13(2)(f) GDPR): We evaluate the signals listed above automatically to determine which notice is relevant to you. There is no automated decision producing legal effects or similarly significantly affecting you within the meaning of Article 22 GDPR — the signals determine only whether and which product communication you receive. We use no tracking pixels for counting opens/clicks and no advertising trackers for this purpose; the only basis is usage data generated in the ordinary operation of the Service.
Legal basis: For usage-based product communication, we rely on Article 6(1)(f) GDPR (legitimate interest in activating and retaining our users), together with a documented balancing-of-interests assessment. For promotional emails to persons who are not existing customers, we additionally obtain your consent (Article 6(1)(a) GDPR / Section 7(2) UWG) through an optional checkbox during registration that is unticked by default; we may send existing customers information about our own similar products on the basis of Section 7(3) UWG. Objection/withdrawal: You may object to promotional communication or withdraw your consent at any time (Article 21 GDPR) — via the unsubscribe link in every promotional email (one click), via the “Product tips by email” setting in your account settings (Notifications), or informally by emailing mail@tiamat-labs.com. Transactional and security-related emails (Section 3.8) remain unaffected. Retention period: the state signals are continuously recalculated from the current state of use; we retain your objection/withdrawal and evidence of any consent given for the duration of the contractual relationship in order to comply with our accountability obligation (Article 5(2) GDPR).
4. Recipients and processors (subprocessors)
To provide the Service, we engage carefully selected processors with whom we have concluded data processing agreements under Article 28 GDPR. The current processors are:
- Hetzner Online GmbH — server hosting and data storage in a data centre in Germany (EU). Article 28 GDPR.
- Cloudflare, Inc. — Domain Name System (DNS) resolution and transport encryption (TLS). USA.
- Anthropic PBC — AI processing (assistance, “Dreaming”). USA.
- Voyage AI (MongoDB, Inc.) — calculation of text embeddings for search and linking. USA.
- Deepgram, Inc. — speech transcription. USA.
- OpenAI, L.L.C. — optional AI/embedding processing where activated by you or your organization. USA.
- Stripe, Inc. / Stripe Payments Europe, Ltd. — payment processing, invoicing and tax calculation. USA/Ireland.
- Resend (Plus Five Five, Inc.) — sending transactional and — on the basis of consent or Section 7(3) UWG — promotional/activation emails (Sections 3.8 and 3.10). USA.
5. Retention periods and deletion
We retain account and content data for the duration of the contractual relationship. If you authorize your account for deletion, a 30-day transition period applies (see the Terms of Use), during which you may still export your data or cancel deletion. Your data is then permanently deleted. A temporary copy created before a risk-bearing maintenance operation is deleted after the next successful maintenance operation or when it is no longer required. This does not apply to data that we must continue to retain due to statutory retention obligations (for example, invoices; see Section 3.2); processing of this data is restricted until the retention period expires.
6. Data security and encryption
Your content is stored in encrypted form (AES-GCM with keys assigned per note, master keys derived from your password using Argon2id, and a BIP39 recovery phrase). Data is stored in a data centre in Germany. Before risk-bearing maintenance, temporary manual copies may be created with access restricted to the operator carrying out the maintenance.
Important transparency notice: Kepos is not a pure zero-knowledge system. For core features (for example, full-text search, embedding calculation and AI processing), the server must decrypt content on the server side; for this purpose, the server retains a protected copy of the required key material. We therefore have technical access to your decrypted content, but use it exclusively for the features you use and to operate the Service — not for any other purposes.
7. Transfers to third countries (USA)
Some recipients named in Section 4 are located in the USA. Where a recipient is certified under the EU-U.S. Data Privacy Framework (DPF), the transfer is based on the European Commission’s adequacy decision (Article 45 GDPR). In all other cases, we base the transfer on the European Commission’s Standard Contractual Clauses (Article 46(2)(c) GDPR), together with supplementary safeguards. We will provide you with a copy of the relevant safeguards on request at mail@tiamat-labs.com.
8. Automated decision-making and AI transparency
No decision based solely on automated processing that produces legal effects or similarly significantly affects you within the meaning of Article 22 GDPR takes place. Kepos’s AI features are assistive: suggestions, summaries and processing remain under your control. We identify AI interactions and AI-generated content as such in the product where required by law (transparency obligations under the EU AI Act).
9. Cookies
We use only cookies that are strictly necessary (functional) — for example, to maintain your session, filter settings and appearance (theme). These cookies are required for operation; consent is not required (Section 25(2) TDDDG). We do not use tracking or advertising cookies.
10. Changes to this Privacy Policy
We update this Privacy Policy when our processing or the legal situation changes. The version published on this page applies in each case; its date is shown at the top of the page.