Kitestring Privacy Policy
Last updated: August 4, 2026
This policy covers the Kitestring desktop app for macOS, the Kitestring browser extension, and the Kitestring dashboard.
Overview
Kitestring is a workplace AI analytics and coaching tool deployed by organizations to their teams. It gives your organization’s leadership an aggregate picture of how AI is being adopted, and gives you, individually, private coaching that helps you get more out of the AI tools you already use.
Kitestring is provided to you by your organization. Your organization is the controller of the data Kitestring produces; Kitestring operates as its processor.
This policy explains what Kitestring captures, what happens to it, who can see it, and how long it is kept. The short version:
- Kitestring captures the text of the prompts you write to supported AI tools, along with usage metadata. It does not capture the AI’s responses, only their length.
- Your prompt text exists to power your own coaching. In the product, it is visible only to you. Your organization sees aggregated analytics: categories, trends, usage and cost totals. It does not see what you typed.
- Prompt text is encrypted in transit and at rest, is never used to train models, and is deleted within 90 days.
What Kitestring captures, and from where
The Kitestring desktop agent (macOS) reads your conversations with supported AI apps using the operating system’s accessibility interface. It is restricted to a fixed allowlist of AI applications and AI websites: the Claude desktop app, and claude.ai (including Claude’s design tool) and chatgpt.com in Chrome. It cannot and does not read any other application, window, website, or browser tab.
The Kitestring browser extension processes your interactions with supported web-based AI tools: ChatGPT, Claude, Gemini, Perplexity, Mistral, DeepSeek, Grok, and the Gemini assistant inside Google Workspace (Google Docs, Sheets, Slides, and Drive). In Google Workspace, the extension processes only the request you type to the Gemini assistant (for example, “help me write a summary”). It does not read the contents of your documents, spreadsheets, presentations, or files, and it does not access Gmail at all. The extension runs only on the supported AI sites; it does not read your activity on other websites.
From those surfaces, Kitestring receives:
- The text of your prompts, as you wrote them. This is the material your personal coaching is built from: it is what lets Kitestring show you how to improve a specific ask rather than offer generic tips.
- Usage metadata: which AI tool and model was used, conversation identifiers, timestamps, measured active time in supported tools, and whether a conversation used features like projects or produced an artifact.
- A character count of each AI response. The content of responses is never transmitted.
- Classification labels derived from your prompts: the type of work (for example writing, research, analysis) and its subject area.
- Your work identity: you sign in with your work account, and Kitestring receives your work email address to associate usage with your account within your organization. Your password is handled by your identity provider (for example Google) and is never sent to or stored by Kitestring.
Who can see your prompt text
You. Your prompts power your personal coaching view, which can quote your own asks back to you with concrete suggestions. That view is yours alone.
Not your organization. The product does not show your prompt content to your organization’s administrators, managers, or leadership. What your organization sees is aggregated: work-type and subject categories, adoption and usage trends, active-time and cost totals. Requests your organization makes about your data as its controller (see “Your choices and rights”) are handled through Kitestring as processor, not through any content view in the product.
Kitestring personnel, only exceptionally. Kitestring staff do not access prompt content in the ordinary course of operating the service. Access happens only where strictly necessary: support you have asked for, investigation of a security incident, or a legal obligation.
Automated processing. Your prompt text is processed by Kitestring’s systems to classify it and to generate your coaching. Parts of this processing use AI model providers (for example Anthropic) as subprocessors, under terms that prohibit them from training models on your data.
How your prompt text is protected
- Encrypted in transit (TLS) between your device and Kitestring, and between Kitestring and its subprocessors.
- Encrypted at rest (AES-256) in Kitestring’s production data store.
- Access-controlled: tenant isolation separates each customer’s data, and the individual-only visibility described above is enforced server-side, not just hidden in the interface.
- Never used for training. Kitestring does not train models on your data, and its AI subprocessors are contractually prohibited from doing so.
- Deleted on schedule: see “Data retention” below.
Kitestring is currently undergoing SOC 1 and SOC 2 examinations.
What Kitestring does not do
- It does not record your AI responses beyond their length.
- It does not show your prompt content to your employer; your organization sees aggregated analytics only.
- It does not read any application or website outside the supported AI tools listed above, and in Google Workspace it does not read your documents, files, or email.
- It does not train models on your data, and does not permit its subprocessors to.
- It does not sell your data.
- It does not use your data for advertising.
How the information is used
The signals Kitestring derives are used for two things: to give your organization’s leadership visibility into AI adoption, usage patterns, and spend at an aggregate level, and to power a private coaching experience that helps you improve how you work with AI, grounded in your own real usage. People administering Kitestring for your organization see patterns, classifications, and totals, not the content of what you typed.
Permissions
Desktop agent (macOS): the agent asks for the system Accessibility permission. This is what allows it to read the on-screen text of the allowlisted AI apps and sites listed above, and it is used for nothing else. The agent also uses network access to send the captured signals to Kitestring, and local storage to queue signals while you are offline so none are lost.
Browser extension: access to the supported AI tool sites (so it can process your interactions with those tools and no others); network access to Kitestring’s servers; local storage for your sign-in token and the offline queue; and script injection solely to re-activate capture in already-open AI tabs after the extension updates.
Data sharing
Kitestring shares the processed signals (classifications, counts, totals) with your organization, which deployed it. Kitestring does not sell your information or share it with third parties for their own purposes. Service providers acting on Kitestring’s behalf under contract (cloud hosting and AI model providers) process data as subprocessors, bound to the commitments in this policy, or where disclosure is required by law.
Data retention
- Prompt text is retained for up to 90 days and then deleted. Short excerpts of your own prompts quoted in your personal coaching view are retained as part of your coaching history for as long as your account is active, and are visible only to you.
- Usage signals and classifications (counts, work-type and subject labels, token and cost estimates, response character counts, which AI tool was used, measured active time, and your organizational user identity) are retained for the duration of your organization’s subscription so dashboards and coaching can show trends over time, and are deleted or returned within 90 days after the subscription ends. Your organization may configure a shorter window.
- Coaching guidance generated for you (the advice itself, not your prompt text) is retained while your account is active so your coach does not repeat itself.
- Aggregated or anonymized statistics that cannot be linked to an individual may be retained beyond these periods.
Your choices and rights
Kitestring is deployed by your organization, which decides whether and how it is used; your use may be governed by your organization’s workplace and monitoring policies. Because your organization is the controller of this data:
- Questions and requests about what is collected, how it is used, or to access or delete information associated with you should be directed to your organization first. Kitestring supports your organization in responding to these requests as its processor.
- Seeing your own data: you can view your own usage, classifications, and coaching in the Kitestring dashboard at any time.
- Legal rights: depending on your location you may have rights over your personal data (such as to access, correct, or delete it). Where these apply, they are exercised through your organization as controller, and Kitestring assists as required by law.
Contact
Questions about this policy can be directed to help@getkitestring.com.
Changes
We may update this policy. Material changes will be reflected by the “Last updated” date above.