Last updated 9 February 2026
Privacy Policy
This policy explains what Volaris Labs does with personal data when you use Kymo at kymo.volarishq.uk.
1. Controller
Volaris Labs, a Volaris Solutions Group company, is the data controller for personal data processed through Kymo. Contact: privacy@volarishq.uk.
2. What we collect
- Account data — email address, hashed password (or the identifier returned by Google or Discord if you sign in with them), display name and avatar URL where provided.
- API keys — a name, a short non-secret prefix, a SHA-256 hash of the key, and its creation, last-used and revocation timestamps. We never store the key itself.
- Playground content — conversations, messages, uploaded images and model parameters you choose to save, so your threads persist across sessions.
- Usage logs — model used, request source, token counts, latency, HTTP status and error text, plus the timestamp and the API key involved. This powers your usage dashboard, rate limiting and abuse prevention.
- Technical data — IP address and request metadata processed transiently by our hosting and security layers.
We do not use advertising cookies or third-party trackers. We use only the storage strictly necessary to keep you signed in and remember your theme preference.
3. Why we process it (legal bases)
- Contract — to create your account, run inference requests, persist your conversations, and show your usage.
- Legitimate interests — security, fraud and abuse prevention, rate limiting, debugging, and improving reliability.
- Legal obligation — responding to lawful requests and keeping required records.
- Consent — where we ask for it, for example optional product emails. You can withdraw consent at any time.
4. Prompts, outputs and model training
We do not use your prompts, uploads or outputs to train models, and we do not sell your data. Inference requests are forwarded to our compute provider, Groq, solely to produce your response. Only the content required to serve the request is transmitted; account identifiers are not sent.
5. Processors we use
- Supabase — authentication, database and hosting of your account data.
- Groq — inference compute for prompt and image processing.
- Google and Discord — only if you choose to sign in with those providers.
Each processor acts under a data-processing agreement. Where data is transferred outside the UK/EEA, we rely on adequacy decisions or standard contractual clauses with appropriate safeguards.
6. Retention
- Account and profile data — until you delete your account.
- Conversations and messages — until you delete them or delete your account.
- API key records — until deleted; revoked keys are retained for audit for up to 12 months.
- Usage logs — up to 24 months, then deleted or aggregated into anonymous statistics.
7. Security
Data is encrypted in transit with TLS and at rest by our infrastructure provider. Access is row-level restricted so each account can only read its own conversations, keys and usage. API keys are stored as SHA-256 hashes and displayed once. Administrative access is limited to personnel who need it.
8. Your rights
If you are in the UK or EEA you have the right to access, rectify, erase, restrict, or object to processing of your personal data, and the right to data portability. Email privacy@volarishq.uk and we will respond within one month. You may also complain to the UK Information Commissioner’s Office (ico.org.uk) or your local supervisory authority.
9. Children
Kymo is not intended for children under 16. If you believe a child has given us personal data, contact privacy@volarishq.uk and we will delete it.
10. Changes
We will post updates here and change the date above. Material changes will be notified to account holders by email or in-product notice. See also our Terms of Service.