Skip to main content

Data handling FAQ

Where is my data stored?

Workspace data is in Google Cloud SQL for PostgreSQL in us-central1; uploaded files are in Google Cloud Storage, US multi-region; the application runs in Google Cloud us-central1. Everything is hosted in Google Cloud in the United States. Provider inference endpoints are not region-pinned.

Is anything trained on my content?

No. Model providers are used on API tiers that do not train on API content, and Kumkuat trains no models of its own. Standard provider API retention applies; a zero-data-retention addendum is not in place today.

What happens to a document I test once?

A quick reaction test on pasted or uploaded text extracts the text for that request only. Neither the document nor the reactions are stored. Narrative tests, chat attachments and library uploads are stored with their outputs, because you will want to come back to them.

Who at Kumkuat can see my workspace?

Workspace members you invite, and Kumkuat operators for support and incident response. Access by operators is logged.

How do I delete data?

Delete a document, persona, chat or report from the app and it is removed from the workspace. Ask your Kumkuat contact to delete a whole workspace, including its files and backups, on the timeline agreed in your contract.

Which third parties are involved?

Sub-processorPurposeWhat it receives
Google CloudHosting, database (Cloud SQL), storage, secretsEverything in the platform
Firebase Authentication (Google)Sign-inEmail address, password hash
Google Gemini, OpenAI, AnthropicModel inferencePrompts: persona profile, retrieved excerpts, your submitted text
Bright Data, FirecrawlPublic-content retrievalHandles and URLs to fetch only
Financial data feedsPress releases and transcriptsCompany tickers only
Slack (if installed)Delivery and slash commandsDigest text and the messages you send the app
Transactional email providerInvitations, digests, scheduled reportsRecipient address and the message

Does a persona chat question go to a public model?

Yes. The question is sent to the configured provider over the API, with web-search grounding on by default so the model may search the web for context. It is not used for training, and grounding can be turned off per workspace. See Data flow.

Can I use my own model keys?

Yes. A workspace admin can add an OpenAI, Google Gemini or Anthropic key under Workspace settings → Models & provider keys. Once a key is saved, every call this workspace makes to that provider runs on your key and is billed to your account: chat, reactions, surveys, narrative tests, alert digests, and the background work such as document tagging, signal extraction and embeddings. Providers you have not added a key for keep running on Kumkuat-managed accounts. Keys are masked after saving and can be removed at any time. See Models and providers.

Do you offer single sign-on?

Not at the moment. Sign-in is email and password. Tell your Kumkuat contact if SAML or Google SSO is a requirement.

Can outputs be published automatically?

No. Reports, drafts and reactions are saved to the workspace. They leave only when a user exports them or creates a share link, which that user can revoke. Alert digests go only to the channels your admin configured.

What about compliance attestations?

Ask your Kumkuat contact for the current position on third-party attestations before completing a questionnaire; these pages describe controls, not certifications.