LEGAL
Privacy Policy
1. Who we are
KitchenAgent.ai ("we", "us", "our") provides an AI-powered kitchen design tool. We are the data controller for the personal data described in this policy.
2. Data we collect
- Account data — email address, name (if provided via Google sign-in or showroom signup).
- Payment data — processed by Stripe. We do not store card numbers. We retain Stripe customer and subscription IDs.
- Design data — kitchen design preferences, uploaded room photos, AI-generated images, and specifications.
- Usage data — page views, feature usage, session recordings (via PostHog). IP addresses are anonymised.
- Communication data — emails sent to you (magic links, specifications, marketing) and any replies.
3. How we use your data
- To provide the kitchen design service and deliver specifications.
- To authenticate your account and manage subscriptions.
- To process payments via Stripe.
- To send transactional emails (login links, specs, receipts).
- To improve our product through anonymised analytics.
- To connect you with kitchen suppliers (only with your explicit request).
4. Legal basis
We process your data under the following bases (UK GDPR):
- Contract — to provide the service you signed up for.
- Legitimate interest — to improve our service and prevent abuse.
- Consent — for optional marketing communications.
5. Third-party services
- Google Gemini — processes uploaded photos and design prompts to generate kitchen images. Photos are sent to Google's API and are subject to Google's data policies.
- Stripe — handles payment processing. See Stripe's privacy policy.
- Resend — delivers transactional emails.
- PostHog — anonymised product analytics and session recording.
- Upstash — encrypted data storage (Redis).
- Vercel — application hosting.
6. Data retention
- Account data is retained while your account is active and for 12 months after deletion.
- Design images and specifications are retained for 12 months.
- Payment records are retained as required by UK tax law (6 years).
- Analytics data is retained for 12 months.
7. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data ("right to be forgotten").
- Object to processing based on legitimate interest.
- Data portability — receive your data in a structured format.
To exercise any of these rights, email hello@kitchenagent.ai.
8. Cookies
We use a single session cookie (ka_session) for authentication. It is HTTP-only and expires after 30 days. We do not use advertising or tracking cookies.
9. Contact
For privacy queries, contact us at hello@kitchenagent.ai.
Last updated: April 2026