Privacy Policy (United States and Other Regions)
Effective date: 01 March 2026 Last updated: 01 March 2026
For the EU/EEA, UK, Switzerland Version of this policy please refer to the following link.
This Privacy Policy explains how Kahuna Labs UG (“we”, “us”, “our”) collects, uses, stores, and shares personal data when you use our website, applications, and services (collectively, the “Services”).
We are committed to respecting your privacy and protecting the information we collect from or about you.
1. Scope of this Privacy Policy
This Privacy Policy applies to personal data we collect when you use our Services as an individual user.
This Privacy Policy does not apply to data we process solely on behalf of business customers under separate agreements (for example, API or enterprise services subject to a separate contract).
If you are located in the EEA, UK, or Switzerland, a separate regional privacy policy may apply. If you are in the Republic of Korea, a Korea addendum/policy may apply.
2. Personal Data We Collect
We collect personal data relating to you (“Personal Data”) as follows:
A. Personal Data You Provide
- Account Information: name, email address, username, password, account settings, and profile information you choose to add.
- User Content: prompts, uploads (including files/images/audio/video, if supported), and generated outputs/results associated with your use of the Services.
- Communication Information: information you provide when contacting support, sending feedback, or communicating with us.
- Other Information You Provide: survey responses, event participation details, and identity/age verification information where required.
B. Payment and Transaction Information (via Stripe)
If you purchase a subscription or paid features, payment processing is handled by Stripe (or another payment processor we designate).
We do not store full payment card numbers on our own systems. Stripe processes card/payment details and may provide us with transaction-related information such as:
- payment status
- transaction identifiers
- billing name/address
- partial payment method details (e.g., last four digits)
- subscription/invoice status
We use this information for billing, invoicing, fraud prevention, support, and accounting.
C. Personal Data We Receive from Your Use of the Services
- Log Data: IP address, browser type/settings, timestamps, request metadata, and interactions with the Services.
- Usage Data: features used, actions taken, session/activity data, and performance/error diagnostics.
- Device Information: operating system, browser, device identifiers, device type.
- Location Information: general location inferred from IP address (for security, fraud prevention, and service functionality), and more precise location only if you choose to provide it and the feature requires it.
- Cookies and Similar Technologies: see Section 8.
D. Information from Other Sources
We may receive information from:
- security and fraud prevention partners
- analytics/marketing providers
- publicly available sources (including internet content), including for improving and developing our models/services, where permitted by law
3. How We Use Personal Data
We use Personal Data for the following purposes:
- Provide, operate, and maintain the Services
- create/manage accounts
- process prompts and return outputs
- store prompts/results so they remain available to you later (e.g., history/retrieval)
- Improve and develop the Services
- improve functionality, reliability, and safety
- conduct analytics and research
- develop new features
- potentially use content (prompts/outputs) to improve our services/models, subject to your settings and applicable law
- Personalize your experience
- tailor features and responses
- provide more relevant experiences (where applicable)
- Communicate with you
- support responses
- service notices and updates
- product announcements and marketing communications (subject to applicable law and your choices)
- Process payments and manage subscriptions
- billing, invoicing, refunds, charge dispute handling, and compliance
- Security, fraud prevention, and policy enforcement
- detect misuse, abuse, unauthorized access, and suspicious activity
- enforce our terms and policies
- Legal compliance and protection
- comply with law and legal process
- protect rights, safety, and property of users, us, and third parties
We may also aggregate or de-identify Personal Data and use it for analytics, service improvement, and research. We will not attempt to re-identify de-identified data unless required or permitted by law.
4. Disclosure of Personal Data
We may disclose Personal Data in the following circumstances:
A. Vendors and Service Providers
We share Personal Data with vendors and service providers that help us operate the Services, such as:
- hosting/cloud infrastructure providers
- customer support tools
- analytics and monitoring providers
- email/communication providers
- security/fraud prevention services
- payment processors (including Stripe)
- AI/LLM infrastructure or model providers (if applicable)
They process data on our behalf under contractual restrictions.
B. Business Transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or transition of service, Personal Data may be disclosed as part of that process and transferred to a successor entity, subject to applicable law.
C. Legal and Safety Reasons
We may disclose Personal Data to government authorities, regulators, or other third parties if necessary to:
- comply with applicable law or legal process
- enforce our terms or policies
- detect/prevent fraud, abuse, or security issues
- protect rights, property, safety, or legal interests
D. Affiliates
We may share Personal Data with affiliated companies under common ownership/control, consistent with this Privacy Policy.
E. Other Users / Third Parties You Interact With
If the Services include sharing features, content you choose to share may be visible to others or provided to third-party services you choose to use. Their privacy practices govern their handling of that data.
5. Retention
We retain Personal Data only as long as necessary for the purposes described in this Privacy Policy, including to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements.
Examples:
- Account data: retained while your account is active and for a reasonable period after closure
- Prompts/outputs: retained to provide account history/retrieval features unless deleted by you, subject to legal/security retention needs
- Payment and transaction data: retained as required for accounting, tax, fraud prevention, and regulatory compliance
- Logs/security data: retained for operational and security purposes for a limited period
- Deletion request records: retained to document compliance and prevent abuse
We may retain certain data longer where legally required or necessary to establish, exercise, or defend legal claims.
6. Data Controls
Depending on the features we offer, you may be able to:
- access account settings and manage profile information
- export your data
- delete chats/content or your account
- control whether your content may be used to improve our services/models
- manage cookie preferences (where applicable)
- unsubscribe from marketing emails
Feature availability may vary by product and region.
7. Your Rights
Depending on where you live, you may have statutory rights regarding your Personal Data, which may include the right to:
- access your Personal Data
- correct inaccurate Personal Data
- delete Personal Data
- restrict certain processing
- data portability
- withdraw consent (where processing is based on consent)
- appeal a decision regarding a privacy request (where required by law)
- be free from unlawful discrimination/retaliation for exercising privacy rights
To exercise your rights, contact us at privacy@kahuna-labs.de or use available in-product controls.
We may need to verify your identity before processing certain requests.
8. Cookies and Similar Technologies
We use cookies and similar technologies to:
- operate and secure the Services
- remember preferences
- support authentication
- analyze usage and improve performance
- measure communications or feature effectiveness
Where required by law, we provide cookie choices/consent controls. You can also manage cookies through your browser settings.
9. Additional U.S. State Privacy Disclosures (if applicable)
Some U.S. state privacy laws require additional disclosures.
Categories of Personal Data We May Collect
Depending on your use of the Services, we may collect:
- identifiers (name, email, IP address, account identifiers)
- commercial information (subscription and transaction history)
- internet/network activity information (usage, logs, device/browser interactions)
- geolocation data (general location inferred from IP; precise location only if you provide it)
- communications and support messages
- user content (prompts, uploads, generated outputs)
- other information you provide (surveys, verification information)
Sources, Purposes, Disclosures, and Retention
We describe:
- data categories and sources in Section 2
- purposes of use in Section 3
- disclosures in Section 4
- retention practices in Section 5
U.S. State Rights (where applicable)
Depending on your state, you may have rights to:
- know/access
- delete
- correct
- obtain a portable copy
- appeal a denied request
- non-discrimination/non-retaliation
“Sale,” “Sharing,” and Targeted Advertising (Important — choose one version)
Option A (if true for your service): We do not sell Personal Data or share Personal Data for cross-context behavioral advertising, and we do not process Personal Data for targeted advertising as defined by applicable U.S. state privacy laws.
Option B (if not true / uncertain): We may engage in activities that could be considered “sale,” “sharing,” or “targeted advertising” under some U.S. state privacy laws. If so, we will provide required notices and opt-out rights.
Authorized Agents and Verification (U.S.)
Where required by law, you may submit requests through an authorized agent. We may require identity verification and proof of authorization before fulfilling certain requests.
10. AI Output Accuracy Notice
Our Services may generate outputs using machine learning models. Outputs may be inaccurate, incomplete, or not appropriate for your specific use case.
You should evaluate outputs before relying on them, especially for important decisions.
If you believe generated output contains inaccurate personal information about you and you want to request review, correction, or removal (where applicable), contact us at privacy@kahuna-labs.de.
11. International Processing and Transfers
We may process and store Personal Data in the United States and other countries where we or our service providers operate.
Data protection laws vary by jurisdiction. We take reasonable steps to protect Personal Data and use legally recognized transfer mechanisms where required by applicable law.
12. Children
Our Services are not directed to children under 13 (or a higher age where required by applicable law), and we do not knowingly collect Personal Data from children under that age.
If you believe a child has provided Personal Data to us, contact us and we will investigate and take appropriate action.
13. Security
We implement reasonable technical, administrative, and organizational safeguards designed to protect Personal Data from unauthorized access, loss, misuse, alteration, or disclosure.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will post the updated version and revise the Effective Date above. If required by law, we will provide additional notice.
15. Data Controller / Company Information
If you are located outside the EEA/UK/Switzerland and use the Services, the controller is typically:
Kahuna Labs UG (haftungsbeshränkt) Pauline Str. 23/25 74076 Heilbronn (DE)
(If you operate separate entities by region, list them here.)
16. Contact Us
If you have questions or concerns about this Privacy Policy or our privacy practices, contact us at:
Kahuna Labs UG
Pauline Str. 23/25 74076 Heilbronn (DE)