Kitestring

Kitestring Privacy Policy

Last updated: September 5, 2026

This policy covers the Kitestring desktop app for macOS and the Kitestring dashboard.

Overview

Kitestring is a workplace AI analytics and coaching tool deployed by organizations to their teams. It gives your organization’s leadership an aggregate picture of how AI is being adopted, and gives you, individually, private coaching that helps you get more out of the AI tools you already use.

Kitestring is provided to you by your organization. Your organization is the controller of the data Kitestring produces; Kitestring operates as its processor.

This policy explains what Kitestring captures, what happens to it, who can see it, and how long it is kept. The short version:

What Kitestring captures, and from where

The Kitestring desktop agent (macOS) reads your conversations with supported AI apps using the operating system’s accessibility interface. It is restricted to a fixed allowlist of AI applications and AI websites: the Claude desktop app, the ChatGPT desktop app, and claude.ai (including Claude’s design tool) and chatgpt.com in Chrome and Safari, gemini.google.com, www.perplexity.ai and chat.deepseek.com in Chrome, and the Gemini side panel inside Google Docs and Google Sheets in Chrome (only the panel’s own conversation is read; the document or spreadsheet itself, its outline, cells and any screen-reader text are never read). It cannot and does not read any other application, window, website, or browser tab. The one narrow exception is material you paste into a supported AI tool, described under “Permissions” below.

Earlier versions of Kitestring included a browser extension. It has been retired and is no longer distributed; the desktop agent is the only capture surface.

From the desktop agent, Kitestring receives:

Who can see your prompt text

You. Your prompts power your personal coaching view, which can quote your own asks back to you with concrete suggestions. That view is yours alone.

Not your organization. The product does not show your prompt content to your organization’s administrators, managers, or leadership. What your organization sees is aggregated: work-type and subject categories, adoption and usage trends, active-time and cost totals. Requests your organization makes about your data as its controller (see “Your choices and rights”) are handled through Kitestring as processor, not through any content view in the product.

Kitestring personnel, only exceptionally. Kitestring staff do not access prompt content in the ordinary course of operating the service. Access happens only where strictly necessary: support you have asked for, investigation of a security incident, or a legal obligation. Any such access is recorded, and that record is available to your organization’s administrators.

Automated processing. Your prompt text is processed by Kitestring’s systems to classify it and to generate your coaching. Parts of this processing use AI model providers (for example Anthropic) as subprocessors, under terms that prohibit them from training models on your data.

How your prompt text is protected

Kitestring is currently undergoing SOC 1 and SOC 2 examinations.

What Kitestring does not do

How the information is used

The signals Kitestring derives are used for two things: to give your organization’s leadership visibility into AI adoption, usage patterns, and spend at an aggregate level, and to power a private coaching experience that helps you improve how you work with AI, grounded in your own real usage. People administering Kitestring for your organization see patterns, classifications, and totals, not the content of what you typed.

Website and product analytics

Kitestring uses Google Analytics on its website and in the dashboard to understand how people find the product, install it, and get to their first coaching card. This is product measurement, not tracking of what you do inside AI tools. It is entirely separate from the capture described above, and none of the material Kitestring captures from AI tools is ever sent to Google.

What is measured: pages viewed, and a small set of named actions such as starting a download, creating an account, receiving a first coaching card, and starting or completing a subscription. Google sets an identifier in your browser to recognize a returning visit. Dashboard pages that identify a person in their address are reported in a generic form (for example /people/[id]) so that no per-person identifier reaches Google.

Some of these measurements are sent by Kitestring’s servers rather than by your browser, including installing the desktop app, granting the Accessibility permission, capture starting for the first time, and app updates. The desktop app never contacts Google. So that one person’s journey reads as one journey rather than several disconnected ones, Kitestring passes the browser’s Google identifier to the desktop app when you sign in, and includes a random account identifier with these measurements. That identifier is generated by Kitestring and is not your name, your email address, or anything derived from them.

Kitestring also uses the Meta Pixel on its public website (www.getkitestring.com) to measure whether its advertising on Meta platforms leads to downloads and subscriptions. The pixel runs only on the website, never in the dashboard or the desktop app. It reports pages viewed on the website and a small set of website actions: starting a download, requesting a download link by email, and opening the demo booking form. Meta sets an identifier in your browser and, if you arrived from a Meta ad, records that you did.

To measure the same journey end to end, Kitestring’s servers report four later milestones to Meta: creating an account, receiving a first coaching card, starting a checkout, and completing a subscription (with its price). These reports carry the same Meta browser identifier, plus the internet address and browser type of the session that started the checkout, and nothing else: no email address, no name, no account identifier, and nothing about how you use AI. Meta may use this to measure and improve the delivery of Kitestring’s ads, as described in Meta’s data policy. Nothing captured from your AI tools is ever sent to Meta.

Kitestring also uses OpenAI’s ChatGPT Ads measurement pixel on its public website, for the same purpose: to measure whether its advertising in ChatGPT leads to downloads. It runs only on the website, never in the dashboard or the desktop app, and reports the same things as the Meta Pixel: pages viewed on the website, starting a download, requesting a download link by email, and opening the demo booking form. OpenAI sets an identifier in your browser and, if you arrived from a ChatGPT ad, records that you did. Nothing is reported from Kitestring’s servers to OpenAI’s ads service, and nothing captured from your AI tools is ever sent to it.

Never included in analytics: your prompt text, AI responses, conversation or project names, file names, your email address, or your organization’s name. Google Analytics measurements are sent with personalized advertising disabled and are not used for advertising. The Meta Pixel and the ChatGPT Ads pixel are used only to measure Kitestring’s own advertising. Analytics data is not sold. Browser settings that block cookies or analytics scripts prevent this collection, and Kitestring works normally without it.

Permissions

Desktop agent (macOS): the agent asks for the system Accessibility permission. This is what allows it to read the on-screen text of the allowlisted AI apps and sites listed above, and it is used for nothing else. The agent also uses network access to send the captured signals to Kitestring, and local storage to queue signals while you are offline so none are lost.

Some AI tools display a long paste as a collapsed attachment whose full text is not readable on screen. To capture that pasted material as part of your prompt, the agent may also read the contents of your clipboard, and on recent versions of macOS it relies on the system clipboard (pasteboard) permission to do so. This read is narrow by design: it happens only at the moment a paste into a supported AI tool is on screen, the clipboard text is used only when it verifiably matches that paste, and anything that does not match is discarded immediately. The agent does not otherwise monitor, read, or store your clipboard.

Data sharing

Kitestring shares the processed signals (classifications, counts, totals) with your organization, which deployed it. Kitestring does not sell your information or share it with third parties for their own purposes. Service providers acting on Kitestring’s behalf under contract (cloud hosting, AI model providers, email delivery, and the analytics provider described above) process data as subprocessors, bound to the commitments in this policy, or where disclosure is required by law.

Data retention

Your choices and rights

Kitestring is deployed by your organization, which decides whether and how it is used; your use may be governed by your organization’s workplace and monitoring policies. Because your organization is the controller of this data:

Contact

Questions about this policy can be directed to help@getkitestring.com.

Changes

We may update this policy. Material changes will be reflected by the “Last updated” date above.