This Privacy Policy (the “Policy”) describes how Kondense (“Kondense”, “we”, “us”, or “our”) collects, uses, discloses, retains, and protects personal information when you visit our marketing site, create or access an account, or otherwise use the Kondense platform (the “Service”). It also describes the choices and rights you have with respect to that information.
Kondense is a business-to-business platform. When you use the Service as part of an organization’s workspace, that organization (the “Customer”) is the “controller” of the personal information you contribute or that is generated about your use, and Kondense acts as the “processor” on the Customer’s behalf. If you have questions about how the Customer uses your information, please contact that Customer directly.
1. Information we collect
a. Information you give us
- Account details — name, email address, password credentials (stored only as a salted hash by our identity provider), profile photo, and any optional fields you complete (job title, timezone, communication preferences).
- Workspace content — courses, lessons, videos, quizzes, tasks, comments, checklists, notes, announcements, policies, uploaded files, and any other content you or your teammates create or upload into a workspace.
- Billing and organization details when applicable — company name, billing address, tax identifier, and payment method information (payment cards themselves are tokenized by our payment processor; we never see the raw card number).
- Support communications — messages, screenshots, and diagnostic data you send when contacting support.
b. Information we collect automatically
- Log and device data — IP address, browser type and version, operating system, device identifiers, referring URLs, request timestamps, HTTP response codes.
- Usage data — pages viewed, features accessed, time spent on a page, links clicked, search queries typed inside the app, video playback events (buffered, played, paused, completed), quiz submissions, and lesson-progress markers.
- Cookies and similar technologies — strictly necessary cookies for session management (keeping you signed in), preference cookies (theme, sidebar state), and, if enabled, a minimal set of analytics cookies. See Section 6 below.
c. Information from third parties
We may receive information about you from services that integrate with the Service (for example, a Discord webhook posting a completion celebration, or an OAuth sign-in). We only receive the fields those services expose to us as part of the integration you or your Customer configured.
2. How we use information
- To provide, operate, secure, and maintain the Service.
- To authenticate you and enforce access controls (workspace membership, role permissions, module grants).
- To send you transactional messages: password resets, sign-in notifications, receipts, security alerts, and Service-critical announcements.
- To send you product updates, tips, or educational material you have opted into. You can opt out at any time from your account settings or via the unsubscribe link in any such email; transactional messages are not opt-out.
- To detect, prevent, and respond to fraud, abuse, and security incidents.
- To measure and improve the Service — for example, aggregating usage data to understand which features are useful. Where possible we do this on aggregated or de-identified data.
- To comply with legal obligations and to defend legal claims.
3. Legal bases (EEA / UK visitors)
If you are in the European Economic Area, the United Kingdom, or Switzerland, our legal bases for processing your personal information are:
- Contract — to provide the Service you or your Customer signed up for.
- Legitimate interests — to secure the Service, prevent abuse, understand product usage, and communicate with you about the Service, provided those interests are not overridden by your rights.
- Consent — for marketing emails you have opted into, and for any analytics cookies that require consent under local law. You can withdraw consent at any time.
- Legal obligation — where processing is required by applicable law (tax, accounting, responding to a lawful request from an authority).
4. Sharing and disclosure
We do not sell personal information. We share it only in these situations:
- Within your workspace — content you create in a workspace is visible to other members of that workspace according to their permissions. Workspace administrators can see all content in the workspace, including membership, activity logs, and audit trails.
- Sub-processors — vetted vendors who process personal information on our behalf under contractual terms that require them to protect it (Section 5).
- Corporate transactions — if Kondense is involved in a merger, acquisition, financing, reorganization, bankruptcy, or asset sale, personal information may be transferred as part of that transaction; we will notify you before your information becomes subject to a different privacy policy.
- Legal and safety — to comply with a valid legal request, to enforce our terms, to protect the rights, property, or safety of Kondense, our users, or the public, or in connection with a criminal investigation.
- With your direction — when you connect a third-party integration or explicitly authorize a share.
5. Sub-processors
We use the following categories of sub-processors to run the Service. Each is bound by written data-protection terms that limit their use of personal information to what is necessary to deliver their service.
- Supabase — authentication, primary database, and file storage. Data hosted in the Supabase region we have selected for our tenant.
- Vercel — application hosting, edge routing, and content delivery.
- Mux — video ingest, hosting, transcoding, and playback for course lessons.
- Resend — transactional email delivery (sign-in links, receipts, in-app notification emails).
- Anthropic — LLM inference for optional AI-assisted features. Content sent to Anthropic is not used to train their models.
An up-to-date list is available on request. We will notify Customers of material changes to sub-processors with at least 30 days’ notice so they can object.
6. Cookies and analytics
We use a small number of cookies:
- Strictly necessary — session cookies from our identity provider that keep you signed in. Without them the Service cannot function. These do not require consent under most laws.
- Preference — remember your UI settings such as theme, sidebar collapse state, and language. First-party only.
- Analytics — if enabled, we collect aggregated, pseudonymised event data to understand feature usage. Where the law requires consent (e.g. EEA / UK) we ask before setting these.
Most browsers let you control cookies through their settings. Blocking strictly-necessary cookies will prevent you from signing in.
7. Data retention
We keep personal information only as long as we need it for the purpose we collected it for or as required by law.
- Account data — retained while your account is active. When you close your account we delete or anonymize it within 90 days, subject to the exceptions below.
- Workspace content— controlled by the Customer’s retention decisions. Deleted content is purged from our production databases within 30 days; encrypted backups roll off within 90 days.
- Log data — retained for up to 12 months for security, debugging, and abuse prevention.
- Financial records — retained as required by applicable tax and accounting laws (typically 7 years).
8. Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct information that is inaccurate or incomplete.
- Delete your account and associated personal information.
- Export your data in a machine-readable format.
- Object to or restrict certain processing.
- Withdraw a previously-given consent.
- Lodge a complaint with a data-protection authority (in the EEA / UK / Switzerland).
You can exercise most rights directly from your account settings. For anything the app doesn’t expose, email us at the address in Section 13; we will respond within 30 days.
If you are a resident of California, you may have additional rights under the CCPA / CPRA (right to know, right to delete, right to correct, right to opt out of “sale” or “sharing” of personal information, and right to limit use of sensitive personal information). We do not sell or share personal information as defined by the CCPA / CPRA.
9. Security
We take reasonable, industry-standard measures to protect personal information: TLS everywhere in transit, encryption at rest for databases and file storage, principle-of-least-privilege access controls for staff, mandatory two-factor authentication for privileged accounts, audit logging, quarterly reviews of production access, and periodic third-party security assessments. No system is ever perfectly secure; if you become aware of a vulnerability please report it responsibly to the address in Section 13.
10. International transfers
Kondense is operated from the United States. When we transfer personal information from the EEA, UK, or Switzerland to a country that has not been recognized as providing an adequate level of protection, we rely on Standard Contractual Clauses (or equivalent transfer mechanisms) with our sub-processors.
11. Children
The Service is not intended for children under 13 (or the age of digital consent in your country). We do not knowingly collect personal information from children. If we learn that we have collected such information without a parent’s consent we will delete it. Contact us if you believe a child has provided us with personal information.
12. Changes to this Policy
We may update this Policy from time to time. Material changes will be announced in-app and, for account holders, by email at least 14 days before they take effect. The “Effective” date at the top of the page reflects when the current version took effect. Previous versions are available on request.
13. Contact
Questions, requests, or complaints? Email hello@kondense.ai. If you are a Customer, your Data Processing Addendum lists a specific privacy contact — use that address for DPA-scoped requests.
