Privacy Policy
Last updated: April 2026
1. Information We Collect
When you use Keravox, we collect information you provide directly:
- Account information (name, email, profile picture via Google OAuth)
- Connected platform credentials (YouTube, Patreon OAuth tokens stored in Google Cloud Secret Manager)
- Content you upload or we ingest (video transcripts, blog posts, course materials)
- Voice configuration and guardrail preferences
We also collect information automatically:
- Fan interaction data (messages, engagement scores, platform IDs)
- Usage metrics (AI responses generated, features used)
- Technical data (IP address, browser type, device information)
2. How We Use Your Information
- Generate AI responses grounded in your published content
- Manage fan profiles and engagement analytics
- Process billing and subscription management via Stripe
- Improve our AI models and platform features
- Send you product updates and support communications
3. Data Storage and Security
All data is stored on Google Cloud Platform (GCP) infrastructure:
- Firestore for operational data (profiles, conversations, fan records)
- AlloyDB with pgvector for RAG vector embeddings
- Redis (Memorystore) for caching and rate limiting
- Secret Manager for all OAuth tokens and API keys (never stored in databases or environment variables)
- All data stores run in a private VPC with no public internet access
4. GDPR Rights
If you are in the European Economic Area, you have the right to:
- Access — Request a copy of all data we hold about you or your fans (Article 15)
- Rectification — Correct inaccurate data
- Erasure — Request deletion of your data or fan data (Article 17)
- Portability — Export your data in a machine-readable format
Fan data export is available via POST /v1/creators/{creatorId}/fans/{fanId}/export. Bulk deletion is available through the CRM segment bulk actions.
5. Third-Party Services
- Stripe — Payment processing (PCI DSS compliant)
- Google Vertex AI / Anthropic — LLM inference for AI responses
- Platform APIs — YouTube, Patreon (data accessed only with your OAuth consent)
6. Data Retention
Conversation data is retained for the duration of your subscription. Fan profiles are retained until you delete them or close your account. Notifications expire after 90 days. Upon account cancellation, all data is deleted within 30 days.
7. Contact
For privacy inquiries: privacy@keravox.com
Keravox, Inc.