Privacy Policy
Last updated: September 26, 2026
Who we are
Kith Rabbit ("Kith", "we", "us") is a messenger with a personal AI companion, operated by Haah, Inc. We are the data controller for personal information processed through kithrabbit.com, api.kithrabbit.com, and the Kith Rabbit apps. For privacy questions, contact privacy@haah.ing.
What we collect
Account data. When you sign in with Apple or Google we receive your name, email address, and a stable account identifier. We never see your password. If you claim an @username, it becomes your public handle on Kith.
Your conversations. Messages you exchange with your Kith and with other people — including photos and short videos you attach — are stored so the product can work. Messages you send to other Kith users are delivered into their account too: like any messenger, the recipient keeps their copy. Deleting one of your messages removes its content for everyone in the chat, leaving a "deleted" marker.
Your knowledge graph. The people, companies, places, projects, interests, and books your Kith learns about — with notes, quotes, and the connections between them — are stored in a database that belongs to your account alone. Your graph is private to you; other users never see it.
Your profile and network. Your profile (name, bio, location, profile picture, what you're interested in, what you can help with) is shown to other users according to the visibility level you choose: public, connections-only, or anonymous (handle only). Mutual connections and reputation — endorse/caution keywords other users attach to your handle from their own experience — are part of the shared network and visible to other users.
Activity status. While your app is connected we keep the time of your most recent connection, and people who can see your profile may see an "active now" indicator for a few minutes around it. This is a single timestamp, not a history of when you were online, and it resets whenever our servers restart. An anonymous account shows no activity status.
Device signals. Your device timezone (so reminders fire at the right hour). If you grant location access, your current locality is used to inform replies while the app is open — we do not build a movement history. If you grant calendar access, your calendar is read on your device; when a reply needs it, a summary of the requested date range passes through our server to the AI and is not retained outside that conversation. The app also records first-time-use marks for a few gestures (e.g. "has ever used drag-to-connect") so it can stop offering tips — this is not behavioral analytics.
Push notifications. If you enable notifications, we store a delivery token for your device. The notification itself carries only identifiers — never message text or names; your device fetches the content from our servers when it displays the alert, so the push transport (Google Firebase Cloud Messaging on Android, Apple Push Notification service on iOS when available) never sees what was said.
Technical data. We keep short-lived server logs (timestamps, IP address, endpoint) for security, abuse prevention, and debugging. We use no advertising trackers and no third-party analytics.
How the AI works with your data
Your Kith's replies are generated by a large language model. To generate a reply, the relevant conversation excerpt, your profile, and related pieces of your knowledge graph are sent to an AI provider for processing.
Zero data retention. Every provider we send your content to is held to a zero-data-retention arrangement: they process what a reply needs, return the answer, and do not keep a copy. Nobody in this list may train on your content, and neither do we.
- Baseten — our primary provider, reached directly. Baseten runs the open-weight GLM model on its own infrastructure in the United States and serves replies, photo and video descriptions, the scanned pages and pictures in PDFs you attach (a PDF's own text is read on our server, and only pages that need it are shown to the model), and the smaller internal steps such as summarizing conversations and web-search results or drafting a first bio for a new graph entry. Baseten does not store model inputs or outputs.
- OpenRouter — the fallback, used when Baseten is unavailable and for the few things it does not serve. Every OpenRouter request carries a zero-retention flag and is restricted to a named list of vetted endpoints: BaseTen, Z.AI, CoreWeave and DeepInfra. Z.AI operates from China; the others from the United States.
- Voyage AI — turns short excerpts of your conversations and graph entries into numeric embeddings, so your Kith can recall relevant past context. Voyage receives the text it embeds and returns numbers; the embeddings are stored only in your own store.
- Apple on-device intelligence — an optional engine that generates replies entirely on your device. Nothing leaves your device when it is selected.
These providers process the content to produce the response you asked for. We do not sell your data, we do not use it for advertising, and we do not use your content to train models of our own.
When your Kith looks things up
- Serper — when your Kith searches the web on your behalf, the search query is sent there, not your conversation (SerpAPI stands in as a backup).
- Firecrawl — when your Kith opens a page to read it in full, the address of that page is sent there. Firecrawl fetches the page and returns its text.
- AgentMail — runs the mailbox your Kith has of its own, so it can send and receive email you ask it to.
- X API — when your Kith looks up a person's X account or their recent posts, that account's handle is sent to X, which returns their public profile and posts. Nothing from your conversation is sent.
Email we send you
- Resend — delivers the emails Kith sends you: the daily summary of conversations waiting for you (who wrote, a line of what they said, and a link back) and notices about your account. The email passes through Resend on its way to your inbox. One click in any summary stops them.
Recording a conversation
On iPhone, iPad and Mac your Kith can record a conversation you are part of. It announces itself to the room before it starts. The audio is transcribed on your device and the audio never leaves it; the transcript and the summary drawn from it are stored in your own store like any other conversation.
Contacts you bring with you
You can give your Kith address books to consult: your phone's contacts, your Google contacts, and a connections file you export from LinkedIn. These are kept as a private reference pool in your own store — they are not published, not shared with other users, and nobody is contacted because they are in it. You choose which of these people are put on your map. Settings lists every source you have connected, what it holds, and when it last synced, and you can disconnect any of them.
If you ask your Kith to tell you when someone you know joins Kith, it compares irreversible fingerprints of contact details rather than the details themselves. Someone who has chosen to stay hidden is never matched to anybody.
Payments
Kith has paid plans. A subscription bought on an iPhone, iPad or Mac is billed by Apple, and one bought on Android by Google Play; we receive confirmation that a plan is active and never see your card. A subscription bought on the web is processed by Stripe, which collects your payment details directly and handles them as the payment processor; we receive the subscription status and the last four digits of the card, not the card itself.
Google user data (Limited Use)
Kith's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We use Google sign-in data (name, email, account identifier) only to create and authenticate your account.
Separately, and only if you connect your Google account in Settings, you may grant Kith access to any of the following. Each is its own permission, asked for on Google's own screen, and each can be withdrawn by disconnecting the account:
- Google Contacts (read-only) — joins the private reference pool described above, so a name you mention is a person your Kith already recognises.
- Google Calendar (read and write) — your Kith can tell you who is in a meeting and what to know walking in, and can create an event and send invitations when you ask it to.
- Gmail (read and send) — your Kith can tell you in one line what in your inbox matters, and send or reply from your address when you ask. It never acts on what it finds without your word. This is an alpha feature, open to a limited group of testers.
We do not use Google user data to train AI models, to serve ads, or for any purpose unrelated to the feature you turned it on for, and we do not sell or transfer it to third parties except as necessary to operate the service or as required by law. Google user data is never transferred to a human for reading except with your consent, for security purposes, or as required by law.
Where your data lives
Each account's content is kept in its own isolated, encrypted store on servers we rent from Hetzner Online GmbH in Singapore. Hetzner is a German company, subject to EU data protection law. It provides the machines and the network; your store is encrypted at rest on them.
The providers listed above operate from other regions — mostly the United States (Baseten, Voyage, Serper, SerpAPI, Firecrawl, AgentMail, Resend, X, Stripe), and China in the case of Z.AI, which sits in the fallback pool. The AI and search providers receive only what a given request needs and do not keep it. Stripe, AgentMail and Resend keep what their job requires: Stripe the payment records for a web subscription, AgentMail the mailbox your Kith sends and receives from, and Resend a record of the emails it delivered.
Security
Encrypted in transit. All traffic between the apps and our servers uses TLS.
Encrypted at rest. Everything we store for you is encrypted on disk: your conversations, knowledge graph, and profile live in a database encrypted under a key unique to your account, and every photo and video is stored as an encrypted file. The encryption keys are kept separately from the data they protect, so a copy of the stored files alone — a backup, a disk — is unreadable.
What this does and doesn't mean. Messages are not end-to-end encrypted: the server must read them to deliver them and to let your Kith help you with them — that's the product. Encryption at rest protects your data as stored files; it does not change who can process it (you, your recipients, and the AI providers above, per this policy). We do not read your content except when needed to debug a problem you report, to investigate abuse, or as required by law.
Retention and deletion
Your content is kept for as long as your account is active. You can delete individual messages and any entry in your knowledge graph from the app at any time. To delete your account and everything in it, open Settings → Delete account in the app — your store and account data are erased immediately and you're signed out; there's no form to fill out and no waiting period. If you can't reach the button because you've lost access to your device or sign-in, email privacy@haah.ing from your sign-in address and we'll delete it for you. Copies of messages you already delivered to other users remain in their accounts, as in any messenger, and a minimal set of safety and moderation records may be retained where required (see our account-deletion page for the full list of what is kept and why).
Lawful basis (EEA/UK)
Where GDPR applies, we process your data to perform our contract with you (running Kith), with your consent for optional features you switch on (location, calendar, trace sharing — each withdrawable in settings), for our legitimate interests in securing and improving the service, and to meet legal obligations.
Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or object to our processing of your personal data, and to withdraw consent. EEA and UK users can lodge a complaint with their local data protection authority; California residents have the rights provided by the CCPA/CPRA, and we do not sell or share personal information for cross-context behavioral advertising. To exercise any of these rights, email privacy@haah.ing.
Children
Kith is not intended for anyone under 16. We do not knowingly collect personal data from children under 16; if you believe a child has provided us personal data, contact us and we will delete it.
Changes to this policy
We may update this policy as the product evolves. Material changes will be posted on this page with an updated date, and flagged in the app when they matter.
Contact
Haah, Inc. — privacy@haah.ing
2261 Market Street STE 16236, San Francisco, CA 94114, United States