Kip
Kip Privacy Policy
Effective date: October 1, 2026
Publisher: Kippenhuck Industries Inc., trading as Kipnetic, 30 Hartland Avenue, Paradise, NL A1L 0V3, Canada
Contact: support@kipnetic.com (Privacy Officer: Garreth Kippenhuck)
1. Who we are and what this policy covers
Kip is an email and calendar client made by Kippenhuck Industries Inc., which does business as Kipnetic ("Kipnetic", "we", "us"). This policy explains what information Kip handles, why, who else touches it, how long it is kept, and what you can do about it. It covers:
- Kip for desktop, the application you install on your computer.
- Kip on the web, the hosted version at
https://kip.kipnetic.com. - Kip agent access, the optional feature that lets an AI assistant you choose (for example Claude or ChatGPT) read or act on your mail through Kip.
- Our website,
https://www.kipnetic.com.
We follow Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). Where the EU or UK General Data Protection Regulation (GDPR) applies to you, section 12 describes the additional rights you have.
2. The short version
- Kip reads your mailbox, calendar and contacts only to show them to you and to run features you use. We do not sell your data, we do not use it for advertising, and we do not use it to train AI models.
- On desktop, your mail is stored on your own computer. Kipnetic does not receive a copy.
- On the web, your mail is stored on our servers in the United States, in a database that belongs to your account alone and is never shared with another customer.
- AI features send the specific mail content a feature needs to an AI model through our AI provider, OpenRouter, and only to model providers that do not keep or train on it. Section 6 explains exactly what is sent. You can turn AI off entirely.
- Your use and our transfer of information received from Google APIs follows Google's Limited Use requirements (section 7).
- You can remove a mailbox at any time, and you can export or delete your whole Kip account from Settings.
3. How Kip runs, and why it matters for your data
Kip comes in two forms, and where your data lives depends on which one you use.
Desktop. Kip connects directly from your computer to Google or Microsoft. Mail, calendar and contact data is stored in a database file on your computer (on macOS, under ~/Library/Application Support/Solenix Mail/; the folder keeps Kip's former name so that existing installations keep their data). The credential that lets Kip stay connected (an OAuth refresh token) is encrypted with your operating system's secure storage (on macOS, the Keychain). Kipnetic's servers are not in that path.
Web. Kip runs on our servers so you can use it from a browser or phone. Your account has its own database and its own storage folder, and your mail is processed by a worker that serves only your account; no database is shared between customers. The server keeps a working copy of your mailbox so the web app can search it, sort it and notify you, in the same way the desktop app does on your computer. Your OAuth refresh tokens and other credentials are encrypted with AES-256-GCM under a key that is unique to your account, and that key is itself encrypted under a master key kept only in our hosting provider's secret store. A small number of accounts created before launch run on a dedicated server of their own, with the same protections.
4. What we collect
4.1 Your Kip account
To create and sign in to a Kip account on the web we use your email address. You can sign in with a single-use link sent to that address, with Google or Microsoft, or with a passkey:
- Google or Microsoft sign-in gives us your name, email address and a stable account identifier, using the
openid,emailandprofilepermissions (andUser.Readfor Microsoft). - A passkey gives us its public key only. The private key never leaves your device.
- Sign-in links are stored only as a one-way hash and expire after 15 minutes.
We use this information only to recognise you and keep you signed in.
4.2 Data from the mailboxes you connect
When you connect a mailbox, you grant Kip permissions on the provider's own consent screen. Kip uses each permission for the purposes listed here and nothing else.
Google accounts
| Permission | What Kip does with it |
|---|---|
gmail.modify | Reads your messages and threads to display, search and summarise them; archives, marks read or unread, labels, moves to trash; creates and sends drafts and messages you write or approve. It cannot permanently delete mail. |
calendar.events | Reads and edits events on your calendars, including creating events, adding Google Meet links and responding to invitations. |
calendar.readonly | Reads your list of calendars and your free/busy availability. |
contacts.other.readonly | Reads the "Other contacts" Google keeps for people you have emailed, to show their profile photos next to their messages. |
contacts.readonly | Reads your saved contacts' photos, for the same purpose. |
openid, email, profile | Identifies which Google account you connected. |
Microsoft accounts (Outlook.com and Microsoft 365)
| Permission | What Kip does with it |
|---|---|
Mail.ReadWrite | Reads, organises, drafts and moves your mail. |
Mail.Send | Sends messages you write or approve. |
Calendars.ReadWrite | Reads and edits your calendar events, including Teams meeting links and invitation responses. |
Contacts.Read | Reads your contacts' photos to show next to their messages. |
User.Read, openid, profile, email | Identifies the connected account. |
offline_access | Keeps Kip connected without asking you to sign in again. |
From these permissions Kip stores: message metadata (sender, recipients, subject, date, labels or folders, a short preview), message bodies, attachment metadata, calendar events, contact names, addresses and photos, and a full-text search index built from that content.
4.3 Things you create in Kip
Settings, tags, rules, signatures, snoozes, scheduled sends, recipient groups, blocked senders, your profile details (name, role, and any context you give the assistant), assistant conversations, and the "memories" the assistant keeps (section 6.4).
4.4 People who are not Kip users
Email by nature contains information about other people: the people who write to you and the people you write to. Kip processes that information only as part of showing and managing your mail. If you use Polls to find a meeting time, Kip stores each invitee's name, email address and answers, and shows invitees a voting page.
4.5 Devices and notifications
If you turn on notifications in Kip on the web, your browser gives us a push subscription (an endpoint address and encryption keys). We store it to deliver notifications and delete it when it stops working or you remove the device in Settings > Notifications.
4.6 Billing
Payments are processed by Stripe, which acts as the merchant of record (the seller of record for your purchase) through Stripe Managed Payments. Stripe collects your payment details directly, and Stripe's own privacy policy applies to them. From Stripe we receive and keep your email address, Stripe's customer and subscription identifiers, your plan, your subscription status, the end of the current billing period, whether you have cancelled, and the date a payment first failed. We never see or store your card number.
4.7 Waitlist
If you join the waitlist for the Gmail beta, we keep your email address, the mail provider you prefer and when you joined, so we can invite you.
4.8 Support and communication
If you email us, we keep the conversation to answer you and to improve Kip. We also send you service email: sign-in links, billing notices and invitations you asked for.
4.9 Technical information, error reports and usage events
Our servers record operational logs (timestamps, request paths, error messages and counts such as how many messages a sync processed). These logs describe what the system did, not what your mail says. Kip also records, for each AI request, the feature used, the model, token counts, cost, timing and whether it succeeded, but not the prompt or the answer.
Kip uses PostHog (PostHog US Cloud) for error reports and a short, fixed list of usage events. They are sent only while Share anonymous usage and error reports is on, in Settings > Privacy. It is on by default, and you can turn it off at any time.
- An error report contains the type of error, its message with email addresses, quoted names, file names, web addresses, tokens, identifiers and numbers removed, the place in Kip's own code where it happened, the app version, and either a random identifier for your installation or a one-way hash of your account identifier.
- Usage events are only these: you signed in, you completed a setup step, you connected a Gmail or Microsoft mailbox, you used an AI feature (and which one), you started a checkout, and you started a subscription (and which plan).
Error reports and events never contain your messages, subjects, email addresses, contact names, attachments or file names. Kip does not record your screen, your clicks or your keystrokes. Kip tells PostHog not to build a profile of you and not to look up your location from your IP address. Two kinds of report are sent regardless of the switch, because they describe our service rather than your use of Kip: checkout and subscription events, and failures of Kip's own servers. Neither contains mail or account details.
Our website. www.kipnetic.com does not use advertising cookies. It includes PostHog analytics, which is switched off by default and records no visits unless you agree to analytics; your choice is remembered in your browser. If you send us a message, take the AI readiness scorecard or sign up for updates on the website, what you submit (such as your name, email address and answers) is stored in PostHog so we can reply and follow up.
5. How we use information
We use information to:
- Provide Kip: show, search, organise and send your mail; show and edit your calendar; notify you.
- Run the features you choose, including AI features (section 6).
- Keep Kip secure, prevent abuse, and diagnose problems.
- Bill you and provide support.
- Meet legal obligations.
We do not use mailbox, calendar or contact data for advertising, we do not sell it, and we do not use it to train or improve general AI or machine learning models.
6. AI features
6.1 What happens
Kip's AI features include the Brief (a daily overview), thread and inbox summaries, triage (finding what needs a reply), reply and compose drafts, the Assistant and "ask your inbox", event creation from an image, proofreading, and voice dictation. When you use one, Kip sends the content that feature needs to an AI model and shows you the result. For example, a thread summary sends that thread; the Assistant sends your question plus the messages and events it retrieved to answer it; dictation sends the audio you recorded.
While AI is turned on, some AI processing starts without a separate click:
- Opening a thread generates a short summary of it, shown at the top of the reader.
- The Brief can prepare itself when you open Kip.
- Memory reads finished assistant conversations and the other sources you allow, in the background (section 6.4).
6.2 Who processes it
AI requests go to OpenRouter, Inc. (United States), which routes each request to the company that runs the chosen model. At the time of writing Kip uses these models:
| Model | Used for |
|---|---|
z-ai/glm-5.3-flash | Most features: Brief, summaries, triage, Assistant, memory |
google/gemini-2.5-flash-lite | Reply and compose drafts |
google/gemini-2.5-flash | Proofreading and voice dictation |
openai/text-embedding-3-small (served by Microsoft Azure) | Search by meaning, only if it is switched on (section 6.6) |
We update this table when the models change.
6.3 No retention and no training
On every AI request, Kip tells OpenRouter to use only model providers that do not store your content or use it for training. A request that no such provider can serve fails rather than going anywhere else.
On Kip on the web, AI requests use a key that Kipnetic issues for your account from our own OpenRouter account, which is also set to use only zero data retention endpoints (the provider does not keep your prompts or outputs after answering). OpenRouter documents both controls at https://openrouter.ai/docs/guides/features/zdr.
On Kip for desktop, AI features use the OpenRouter key you enter in Settings. The no-storage, no-training instruction above is still sent on every request; whether only zero data retention endpoints are used also depends on the settings of your own OpenRouter account.
6.4 Memory
The Assistant can remember durable facts (for example "prefers morning meetings") so it does not need to be told twice. Memories are extracted by the AI model from these sources:
| Source | Default for new users |
|---|---|
| Your conversations with the Assistant | On |
| Actions you take in Kip | On |
| Mail you send | On |
| Mail you receive | Off, and Kip asks you once, at first sign-in, whether to turn it on |
Extraction runs in the background, for example after a conversation has been idle for 20 minutes. Memories are stored in your Kip database (on your computer for desktop, in your account's database for web). You can view and delete memories, and switch memory or any of its sources on or off, in Settings > Memory; you can also switch memory off during onboarding.
6.5 Your choice
AI features are optional. Mail, search and calendar work without them. You can turn off all AI processing in Settings > AI or during onboarding; while it is off, Kip sends nothing to AI providers, including the automatic summaries, the Brief and memory.
Each Kip on the web subscription includes a monthly AI allowance. If it runs out, AI features pause until the next month; everything else keeps working.
6.6 Search by meaning
Kip can find an email by what it is about as well as by the words in it, so that "what did my accountant say about taxes" finds a message that only says "T2 filing". This is switched off unless we turn it on for your Kip, and we will tell you before we do. When it is on, Kip sends each cached email's subject, sender name and the first 2,000 characters of its text to OpenRouter once, and receives back a list of numbers (an "embedding") that it stores in your Kip database. Your questions to the Assistant are turned into the same kind of numbers when you ask them. The embedding model is openai/text-embedding-3-small, which OpenRouter routes only to a zero data retention endpoint (at the time of writing, Microsoft Azure); Kip asks for zero data retention and no data collection on every one of these requests, and a request fails rather than go anywhere else. The stored numbers are deleted with the email they came from, and with your account.
7. Google user data and the Limited Use requirements
Kip's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, for data obtained through Gmail, Google Calendar and Google People (Contacts) APIs:
- We use it only to provide or improve user-facing features that are visible in Kip: reading, searching, organising and sending mail, managing your calendar, showing contact photos, and the AI features described in section 6.
- We transfer it to others only as needed to provide those features (our hosting provider for the web version, and our AI provider when you use an AI feature), to an AI assistant you connect through Kip agent access, for security purposes, to comply with law, or as part of a merger or acquisition with your prior consent.
- No human at Kipnetic reads it unless you give us permission for a specific message (for example when you ask for support), it is necessary for security (such as investigating abuse), it is required by law, or the data has been aggregated and anonymised for internal operations.
- We never use or transfer it to serve advertising, including retargeting or personalised or interest-based ads, never sell it, never transfer it to data brokers or information resellers, and never use it to determine credit-worthiness or for lending.
- We do not use it to develop, improve or train generalised or non-personalised AI or machine learning models.
8. Agent access (optional)
If you turn on agent access, you can let an AI assistant of your choosing connect to Kip and read or act on your mail. You decide which assistant, whether it can only read or also make changes, and you can revoke it at any time in Settings > Agent access. Grants expire after 90 days. Anything that sends mail or reaches another person stops for your approval first. When an assistant has access, it receives the mail it asks for, and that assistant's own provider handles it under its own privacy policy, not this one.
9. Who else processes your information (subprocessors)
| Company | Role | Data | Location |
|---|---|---|---|
| Railway Corporation | Hosts Kip on the web: application servers, storage, and backups | Everything stored for your web account | United States (US West) |
| OpenRouter, Inc. | AI request routing | Content sent by AI features you use (section 6) | United States |
| Model providers reached through OpenRouter (currently Z.ai and Google) | Run the AI model | Same, without retention or training | Where the provider's endpoint runs, which can be outside your country |
| Microsoft Corporation (Azure OpenAI Service, reached through OpenRouter) | Compute embeddings for search by meaning, only if it is switched on (section 6.6) | Subject, sender name and the first 2,000 characters of each cached email, and your Assistant questions, under zero data retention | Where OpenRouter's zero data retention endpoint for the model runs |
| Google LLC | Gmail, Calendar and People APIs; Cloud Pub/Sub for new-mail signals; Firebase Cloud Messaging for Android and Chrome notifications; Google Workspace for our support mailbox | Your Google data (you already store it with Google); new-mail signals contain only your address and a change marker; notification payloads are end-to-end encrypted; your emails to support | United States and worldwide |
| Microsoft Corporation | Microsoft Graph; change notifications | Your Microsoft data (already stored with Microsoft); change notifications carry identifiers, not content | Worldwide |
| Apple Inc. and Mozilla | Deliver web push notifications to Safari/iOS and Firefox | Encrypted payload containing a sender and subject line, which they cannot read | Worldwide |
| Stripe, Inc. (merchant of record) | Payments, tax, invoicing, fraud prevention | Billing details | United States and worldwide |
| Resend | Sends service email: sign-in links, billing notices, invitations | Your email address and the content of those messages | United States |
| PostHog, Inc. | Product analytics and error reporting | Error reports and usage events, only while Share anonymous usage and error reports is on (on by default; Settings > Privacy); checkout, subscription and server-failure reports without mail or account details (section 4.9) | United States (PostHog US Cloud) |
| Gravatar (Automattic Inc.) | Sender photos, only if you turn this on in Settings > Sender identity | A one-way hash of a sender's email address | United States |
To show logos for senders, Kip requests the sender's own website icon and checks the sender domain's BIMI DNS record. Those requests reveal the domain name only, never your address or the message, and Kip does not use third-party icon services.
Remote images in email are blocked until you choose to show them, so senders cannot track when you open their message.
10. Where your information is stored and cross-border transfers
Desktop data stays on your computer. Kip on the web is hosted in the United States. AI requests are processed in the United States or where the model provider's endpoint runs. This means information may be accessible to courts, law enforcement and national security authorities of those countries under their laws. We rely on contracts with our subprocessors to protect it.
11. How long we keep it
| Data | How long |
|---|---|
| Cached mail, calendar and contacts | Until you remove the mailbox from Kip or delete your Kip account |
| Assistant conversations | The 200 most recent conversations; older ones are deleted automatically |
| AI request records (feature, model, tokens, cost, timing; no content) | 90 days |
| Sender logos and photos | Refreshed every 30 days; deleted with the mailbox |
| Sign-in links | 15 minutes, single use |
| Web sessions | 30 days from your last visit, then you sign in again |
| Account export downloads | 15 minutes, or until downloaded once |
| Agent upload tickets | 30 minutes |
| Agent access grants | 90 days unless you revoke sooner |
| Push subscriptions | Until the device stops accepting notifications or you remove it |
| Copies of a web account kept on our server for recovery | The three most recent nightly copies; deleted with the account |
| Our hosting provider's backups of the storage volume | Up to about 3 months (daily copies for 6 days, weekly for 27 days, monthly for 89 days), then deleted |
| A lapsed subscription's account | Deleted 60 days after it becomes read-only (Terms of Service, section 5) |
| Billing records | As long as tax law requires (in Canada, generally six years) |
12. Your rights and choices
Everyone. You may ask us to give you access to the personal information we hold about you, correct it, or delete it, and you may withdraw consent. We will answer within 30 days. Email support@kipnetic.com from the address on your account.
Removing a mailbox. In Settings > Accounts, you can remove a mailbox. Kip stops syncing it, deletes its cached mail, calendar and contact data, and deletes its stored credential. For a Google account, Kip also revokes its access at Google. Microsoft offers no way for an app to revoke its own access, so for a Microsoft account you can also remove Kip at https://account.live.com/consent/Manage (personal accounts) or https://myapps.microsoft.com (work or school accounts). You can review Google access at https://myaccount.google.com/permissions.
Export and deletion of your whole Kip account (web). In Settings > Account you can download an export of your Kip data at any time, including while your account is read-only. You can also delete your account there: after you confirm by typing your email address and signing in again, Kip cancels your subscription, revokes Kip's access to your Google mailboxes, and permanently deletes your account's database, storage folder and recovery copies from our server straight away. Copies inside our hosting provider's volume backups are deleted when those backups expire (section 11), and the credentials inside them can no longer be decrypted because the key that protected them is destroyed at deletion. We keep the record that your account existed, its email address and its Stripe identifiers for our accounting. If your account is one of the few on a dedicated server (section 3), email support@kipnetic.com for an export or deletion and we will complete it within 30 days.
Desktop. Uninstalling Kip does not delete its data folder. Delete the folder listed in section 3 to remove everything.
EU and UK residents (GDPR). Our legal bases are: performance of our contract with you (providing Kip), your consent (optional features such as AI memory, Gravatar and agent access, which you can withdraw at any time), and our legitimate interests (security, error reports and service improvement that do not override your rights). You also have the rights to data portability, to restrict or object to processing, and to complain to your local data protection authority. Kipnetic is established in Canada, which the European Commission recognises as providing adequate protection for commercial organisations subject to PIPEDA. We have not appointed a representative in the EU or the UK.
Canada. If you are not satisfied with our answer, you can contact the Office of the Privacy Commissioner of Canada at https://www.priv.gc.ca.
13. Security
- All connections to Google, Microsoft, OpenRouter and Kip on the web use TLS.
- Credentials are encrypted at rest: by your operating system's keychain on desktop, and with AES-256-GCM under a per-account key on the web.
- Each web account has its own database, and its credentials can be decrypted only by the worker that serves that account.
- Our hosting provider encrypts its storage at rest at the disk level. Kip does not add a further layer of encryption to cached mail.
- Web sessions use
HttpOnly,Secure,SameSitecookies stored on our side only as a one-way hash, and the web app sends a strict Content Security Policy and HSTS. - Incoming email HTML is sanitised through an allowlist before display, and remote content is blocked by default.
- Access to production systems is limited to Kipnetic's founder and protected by multi-factor authentication.
If we learn of a breach of security safeguards involving your personal information that creates a real risk of significant harm, we will notify you and the Privacy Commissioner of Canada as PIPEDA requires.
14. Children
Kip is not directed to children, and you must be at least 16 to use it.
15. Changes to this policy
We will post changes here and update the effective date. If a change materially affects how we use information we already hold, we will tell you by email or in Kip before it takes effect.
16. Contact
Kippenhuck Industries Inc. (Kipnetic)
Attn: Privacy Officer, Garreth Kippenhuck
30 Hartland Avenue
Paradise, NL A1L 0V3
Canada
support@kipnetic.com