Legal
Privacy Policy
Last updated: June 29, 2026
1. Who we are
Kenzo AI (“Kenzo AI,” “we,” “us,” or “our”) is an IT asset management platform that helps teams track physical and digital assets, employees, and maintenance records. This Privacy Policy explains how we collect, use, share, and protect your information when you use our platform at k3nzoai.com.
2. What information we collect
We collect only what is necessary to provide the service.
Account information (collected at signup)
- Full name — stored in your user profile
- Email address — used for login, confirmations, and password resets
- Password — hashed by Supabase Auth; we never store or see your plaintext password
Platform data (entered by you)
The following data is stored only if you choose to enter it:
- Asset records — tags, names, categories, statuses, serial numbers, purchase and warranty dates, prices, and notes
- Employee records — names, email addresses, departments, and job titles (for asset assignment purposes)
- Location records — names, buildings, and room numbers
- Maintenance logs — descriptions, dates, technician names, and costs
Automatically collected technical data
Our hosting infrastructure (Supabase and Vercel) may automatically log standard server data including IP addresses, request timestamps, HTTP methods, and browser user agents. Kenzo AI does not run any separate analytics, tracking, or behavioral monitoring software.
Cookies
We use a small number of functional cookies. See our Cookie Policy for details.
3. How we use your information
- To create and manage your account
- To deliver the asset management features you use
- To send transactional emails — account confirmation, password reset (sent by Supabase)
- To power the AI assistant when you actively send a message (see Section 5)
- To respond to requests you send to our contact address
We do not send marketing emails, newsletters, or promotional communications. We do not use your data for advertising or profiling.
4. How we share your information
We do not sell, rent, or trade your data. We share data only with the third-party service providers listed below, who act as data processors under our direction.
Service providers
Supabase
Hosts our database and authentication infrastructure. All account data and platform data is stored on Supabase. Supabase uses Amazon Web Services (AWS) for underlying infrastructure. Subject to the Supabase Privacy Policy.
Anthropic
Provides the Claude AI model that powers our AI assistant. Your chat messages and the results of database queries about your assets are sent to Anthropic when you use the AI chat feature. See Section 5 for full detail. Subject to the Anthropic Privacy Policy.
Vercel
Hosts and serves the Kenzo AI web application. Standard server request logs (IP, timestamp, path) may be retained by Vercel per their policies. Subject to the Vercel Privacy Policy.
We do not share your data with any advertising networks, data brokers, or analytics services.
5. AI features and Anthropic
When you type a message in the AI chat panel and press send, the following is transmitted to Anthropic's API:
- The message you typed
- Recent prior messages in the saved conversation you are continuing (for context)
- Results of database queries against your asset data — for example, if the AI queries “assets assigned to Jane Smith,” those asset records are included in the API request
When you continue a saved conversation, your current message and recent prior messages from that conversation are included in the request to Anthropic so the assistant can maintain context.
No data is sent to Anthropic unless you actively send a message. The AI assistant does not proactively monitor or analyze your data in the background.
The AI assistant is read-only. It cannot create, modify, or delete any assets, employees, locations, or records in your account.
Kenzo AI stores your chat messages and assistant responses in its database as saved conversation history. Saved conversations are scoped to your signed-in user and organization and are not shown to other members of your organization.
Anthropic may process and retain API inputs and outputs per their own usage policies. We recommend reviewing the Anthropic Privacy Policy and their Usage Policy for details on how they handle API data. You can limit your exposure by not including sensitive personal information in AI queries.
See our full AI Usage Policy for more detail.
6. Data retention
You may request deletion of your account and associated data at any time by contacting us at privacy@k3nzoai.com. We will process deletion requests within 30 days.
7. Your rights
You can access and update your account information at any time from the Settings page inside the platform. You can update your name and email, change your password, and export your asset data as CSV from the Assets page.
To request deletion of your account or a copy of your data, contact us at privacy@k3nzoai.com.
8. Data security
We implement the following technical safeguards:
- All data is transmitted over HTTPS / TLS
- Passwords are hashed using industry-standard algorithms by Supabase Auth
- Session cookies are HttpOnly — they cannot be accessed by client-side JavaScript
- Authentication is verified server-side before any data access
- Input validation is enforced on all forms and API endpoints
No method of transmission or storage is 100% secure. We cannot guarantee absolute security. See our Security page for more detail.
9. Children
10. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page. Continued use of the service after changes constitutes acceptance.
11. Contact us
Questions about this Privacy Policy or requests related to your data:
Email: privacy@k3nzoai.com
Address:
Or use our Contact page.