Skip to main content
Owner-approved · professional review pending

PRIVACY NOTICE

What Kyntra processes, why, and your rights.

This notice explains how ATL4S.AI INC. handles personal data when you visit kyntra.ai, create an account, or use the Hub and Kyntra Code. It says only what the product actually does.

Status. This is the current operative version of this document — an owner-approved company document that applies to your use of Kyntra today. It has not been reviewed by licensed counsel; professional legal review is planned, and this page will record that review when it completes. Material changes are announced as described in the Terms of Service.

VERSION privacy-2026-09-01 · LAST REVISED · 1 SEPTEMBER 2026

1. Who is responsible

The controller for the processing described here is ATL4S.AI INC., a Delaware corporation, 254 Chapman Rd, Ste 208 #26251, Newark, DE 19702, USA — reachable at hello@atl4s.ai. Company details are on the Legal Notice page.

This notice covers Kyntra's own surfaces. Websites our customers build and publish with Kyntra are those customers' sites: for personal data processed there, the customer is the controller and we act as their processor under the Data Processing Addendum.

2. Data we process

  • Account data: email address, sign-in identifiers (Google or GitHub account ID, or a hashed one-time email code), session tokens, plan and account settings.
  • Project inputs you submit: a business or project name, your idea text or a public website URL, and the files and instructions you add while working.
  • Project data the service produces for you: generated artifacts, project files, activity and version history.
  • Public-web research data collected at your request about the business you connect — which can include personal data appearing in public sources, such as names of owners in registries or authors of public reviews (see Section 6).
  • Usage and billing data: feature usage, build-credit and allowance consumption, subscription state, and payment events. Payments run through Stripe; we never store full card numbers.
  • Signup attribution: a referral code and UTM parameters from the link you arrived on (first touch, kept client-side for up to 60 days, then attached to your account once).
  • Communications with us, and technical logs (IP address, user agent, timestamps, error and security events) needed to run and defend the service.

3. Why, and on what legal basis

  • To provide the service — creating your account, running onboarding, operating projects, generating output, hosting what you publish, metering allowances, billing (performance of a contract, GDPR Art. 6(1)(b), where the GDPR applies).
  • To keep the service secure and reliable — authentication, abuse and fraud prevention, incident response, logging (legitimate interests, Art. 6(1)(f)).
  • To operate research features on public sources at your request (legitimate interests, Art. 6(1)(f); Section 6 explains the rights of people appearing in those sources).
  • To meet legal obligations — tax, accounting, responding to lawful requests (Art. 6(1)(c)).
  • With your consent, where we ask for it — for example the optional model-training opt-in in Section 5 (Art. 6(1)(a)); consent is revocable at any time.

4. AI processing

Kyntra's features are powered by machine-learning models. Content you submit to AI features is processed by the AI infrastructure providers listed in the DPA's subprocessor register, solely to return the requested output.

We do not use your content to train foundation models, and we do not permit our model providers to use it to train theirs. The only exception is your separate, explicit, revocable opt-in recorded in the product — it is off by default.

5. Who receives data

We do not sell personal data and we run no third-party advertising or tracking on Kyntra surfaces. Data reaches three kinds of recipients: (a) service providers (subprocessors) that host and power Kyntra — hosting, database, payment, transactional email, sign-in and model inference providers, each listed with its role in the DPA's subprocessor register; (b) authorities, where the law requires it; and (c) a successor entity in a merger or acquisition, under this notice's protections.

6. People who appear in public sources we research

To provide our service to a business, we collect publicly available information about that business, which can include names of people associated with it — for example, owners named in public registries or authors of public reviews. We use this information only to operate that business's service, we do not collect from behind logins, and our collection respects robots directives.

If you are such a person and want your data corrected or deleted, contact hello@atl4s.ai. We answer within one month, correct or delete the data where the request is founded, and suppress its re-collection.

7. International transfers

We are a US company and our providers process data primarily in the United States. Where the GDPR or UK GDPR applies to a transfer, we rely on recognised safeguards with each provider — EU–US Data Privacy Framework certification or Standard Contractual Clauses, as recorded per provider in the subprocessor register. Completion of formal transfer documentation, and the assessment of an EU representative under GDPR Art. 27, are part of the pending counsel review flagged at the top of this page.

8. How long we keep data

  • Account and project data: for as long as your account exists. Deleting your account in the product removes your account and project data from live systems.
  • Operational backups and copies clear on a rolling basis after live deletion.
  • Billing records: kept as long as tax and accounting law requires.
  • Security and technical logs: kept for a limited period appropriate to security and reliability, then deleted or de-identified.
  • One-time sign-in codes: stored only as hashes and expire within minutes.

9. Your rights

Where the GDPR or similar law applies, you can ask for access, correction, deletion, restriction, portability, and you can object to processing based on legitimate interests. Where processing rests on consent, you can withdraw it at any time without affecting past processing. Write to hello@atl4s.ai — we answer within one month. You can also delete your account directly in the product, and you have the right to complain to your data-protection supervisory authority.

10. Automated decisions, cookies, children

  • We make no automated decisions about you that produce legal or similarly significant effects.
  • Kyntra uses first-party browser storage for sign-in and product function only — no third-party advertising cookies. Details: Cookie & Browser Storage Notice.
  • Kyntra is a business tool and is not directed to children; you must be at least 18 to hold an account.

11. Security and incidents

We protect data with measures described on the Security page and in the DPA — transport encryption, access controls, tenant isolation, versioned artifacts and fail-closed publish gates — and we operate an incident process. Where a personal-data breach triggers legal notification duties (including GDPR Art. 33 and 34), we notify the competent authority and affected people as the law requires.

12. Changes and contact

We update this notice when the product or the law changes; material changes are announced by email or in the product before they take effect, and each version carries its stamp above. Questions, requests and complaints: hello@atl4s.ai, or by mail to ATL4S.AI INC., 254 Chapman Rd, Ste 208 #26251, Newark, DE 19702, USA.