Kitestring

Kitestring Privacy Policy

Last updated: August 4, 2026

This policy covers the Kitestring desktop app for macOS, the Kitestring browser extension, and the Kitestring dashboard.

Overview

Kitestring is a workplace AI analytics and coaching tool deployed by organizations to their teams. It gives your organization’s leadership an aggregate picture of how AI is being adopted, and gives you, individually, private coaching that helps you get more out of the AI tools you already use.

Kitestring is provided to you by your organization. Your organization is the controller of the data Kitestring produces; Kitestring operates as its processor.

This policy explains what Kitestring captures, what happens to it, who can see it, and how long it is kept. The short version:

What Kitestring captures, and from where

The Kitestring desktop agent (macOS) reads your conversations with supported AI apps using the operating system’s accessibility interface. It is restricted to a fixed allowlist of AI applications and AI websites: the Claude desktop app, and claude.ai (including Claude’s design tool) and chatgpt.com in Chrome. It cannot and does not read any other application, window, website, or browser tab.

The Kitestring browser extension processes your interactions with supported web-based AI tools: ChatGPT, Claude, Gemini, Perplexity, Mistral, DeepSeek, Grok, and the Gemini assistant inside Google Workspace (Google Docs, Sheets, Slides, and Drive). In Google Workspace, the extension processes only the request you type to the Gemini assistant (for example, “help me write a summary”). It does not read the contents of your documents, spreadsheets, presentations, or files, and it does not access Gmail at all. The extension runs only on the supported AI sites; it does not read your activity on other websites.

From those surfaces, Kitestring receives:

Who can see your prompt text

You. Your prompts power your personal coaching view, which can quote your own asks back to you with concrete suggestions. That view is yours alone.

Not your organization. The product does not show your prompt content to your organization’s administrators, managers, or leadership. What your organization sees is aggregated: work-type and subject categories, adoption and usage trends, active-time and cost totals. Requests your organization makes about your data as its controller (see “Your choices and rights”) are handled through Kitestring as processor, not through any content view in the product.

Kitestring personnel, only exceptionally. Kitestring staff do not access prompt content in the ordinary course of operating the service. Access happens only where strictly necessary: support you have asked for, investigation of a security incident, or a legal obligation.

Automated processing. Your prompt text is processed by Kitestring’s systems to classify it and to generate your coaching. Parts of this processing use AI model providers (for example Anthropic) as subprocessors, under terms that prohibit them from training models on your data.

How your prompt text is protected

Kitestring is currently undergoing SOC 1 and SOC 2 examinations.

What Kitestring does not do

How the information is used

The signals Kitestring derives are used for two things: to give your organization’s leadership visibility into AI adoption, usage patterns, and spend at an aggregate level, and to power a private coaching experience that helps you improve how you work with AI, grounded in your own real usage. People administering Kitestring for your organization see patterns, classifications, and totals, not the content of what you typed.

Permissions

Desktop agent (macOS): the agent asks for the system Accessibility permission. This is what allows it to read the on-screen text of the allowlisted AI apps and sites listed above, and it is used for nothing else. The agent also uses network access to send the captured signals to Kitestring, and local storage to queue signals while you are offline so none are lost.

Browser extension: access to the supported AI tool sites (so it can process your interactions with those tools and no others); network access to Kitestring’s servers; local storage for your sign-in token and the offline queue; and script injection solely to re-activate capture in already-open AI tabs after the extension updates.

Data sharing

Kitestring shares the processed signals (classifications, counts, totals) with your organization, which deployed it. Kitestring does not sell your information or share it with third parties for their own purposes. Service providers acting on Kitestring’s behalf under contract (cloud hosting and AI model providers) process data as subprocessors, bound to the commitments in this policy, or where disclosure is required by law.

Data retention

Your choices and rights

Kitestring is deployed by your organization, which decides whether and how it is used; your use may be governed by your organization’s workplace and monitoring policies. Because your organization is the controller of this data:

Contact

Questions about this policy can be directed to help@getkitestring.com.

Changes

We may update this policy. Material changes will be reflected by the “Last updated” date above.