AI Auto Support logoKefuAgents
  • Features
  • Workflow
  • Pricing
  • FAQ
  • Contact
Sign up
AI Auto Support logoKefuAgents

Paste one link. Your AI support agent starts today.

Product
  • Features
  • Pricing
  • FAQ
Resources
  • Documentation
Company
  • About
  • Contact
Legal
  • Cookie Policy
  • Privacy Policy
  • Terms of Service
  • Refund Policy
© 2026 KefuAgents. All Rights Reserved.

Privacy Policy

How we handle your account data, your customers' email and chat data, and the data flows involved in AI processing

2026/08/04

Last updated: 4 August 2026

Introduction

KefuAgents (kefuagents.com) is an AI customer-service product for cross-border ecommerce merchants. The service is operated by an individual developer (in this policy, "we", "us", "KefuAgents"). You can reach us at support@kefuagents.com.

We process two distinct categories of data: your account data (the merchant's own registration, billing and usage information) and your customers' email and chat data (the content of the support mailbox and storefront live chat you authorize us to take over). This policy covers both.

Roles. For your account data we act as the data controller. For your customers' email and chat data we act as your processor: you decide what mailbox to connect, what the AI is allowed to do and what gets sent. By using the service you confirm that you are authorized to let us process the mail in your support mailbox and the conversations in your storefront chat widget, and that you have fulfilled your own privacy-notice obligations toward your end customers under the laws of your region and target markets (for example the GDPR, UK GDPR, and US state privacy laws).

1. Your account data

We collect:

  • Registration information: email, name, login credentials (passwords are stored hashed), and linked OAuth accounts (Google, GitHub) if you sign in that way.
  • Subscription and billing records: plan, subscription status, invoice and transaction references, AI credit balance and consumption history. We do not collect, see or store your card number. Card details are entered directly with our payment processor (see section 5).
  • Usage data: feature usage and operation logs (reviews, sends, settings changes) used for security auditing, billing accuracy and product improvement.
  • Technical data: IP address, request metadata and timestamps, processed for security and abuse prevention (see section 4.4).

2. Your customers' email and chat data (core terms)

Once you connect a support mailbox or install the storefront chat widget, we process the following data belonging to your customers:

  • Raw emails (body, subject, addresses, headers) and chat messages;
  • Support context extracted from them (order numbers, issue categories, knowledge candidates), including a Chinese translation of the message so that you can review it in Chinese;
  • Image attachments your customers send, and, when you connect a commerce platform such as Shopify, order information fetched on demand (order number, payment and fulfilment status, order total, line-item titles and quantities, carrier and tracking number).

How processing works, and its boundaries:

  1. AI processing. Email and chat content is sent to third-party large-model APIs for classification, summarization, reply drafting and quality evaluation. As of the date of this policy those providers are Google (Gemini) and DeepSeek, selected per operation type. We transmit only the text and images needed for the task.
  2. No training on your data. We do not use your data or your customers' data to train our own models. We use Google's paid Gemini tier specifically because it excludes prompts and outputs from model training and human review; our DeepSeek usage is on the same commercial no-training basis. We never route customer-service content through free consumer AI tiers.
  3. Platform-operated AI only. All inference runs through provider accounts we operate. We do not offer, and you cannot configure, your own AI API key. Merchants who want to use their own AI do so through the Agent Gateway (MCP), where their own agent performs the reasoning and we only receive the tool calls it makes.
  4. Mailbox credentials. Your IMAP/SMTP passwords are encrypted at rest with AES-256-GCM and decrypted only to synchronize mail and send replies. The same encryption protects your Shopify access token and any messaging-platform app secrets (Feishu, DingTalk, WeCom) you configure.
  5. Shadow mode. In shadow testing we only read mail to produce benchmark reports. We never change the state of any message in your mailbox and never send anything to your customers.
  6. Non-support mail. Messages classified as not customer service keep only a classification record used to improve detection; the messages themselves stay untouched in your mailbox.
  7. Attachments. Image attachments are stored in object storage (see section 5) so the AI and your reviewers can see them. Video attachments are not stored; we retain only metadata and flag the message for human review.

3. The storefront chat widget

If you install our chat widget on your own store, it collects data about your visitors, and you — not us — are responsible for telling them so in your own privacy notice and obtaining any consent your jurisdiction requires.

The widget:

  • Generates a random visitor ID in the browser and stores it in localStorage (not a cookie), so a returning visitor can resume their most recent open conversation, by default within 24 hours. The ID is per-browser and per-store; it is not shared across devices and is not used for advertising.
  • Stores the conversation messages, an optional email address only if the visitor types one, the intent and risk classification of the conversation, any image the visitor uploads, and your store domain.
  • Does not read cookies, browsing history, page URLs, referrers, screen characteristics or user-agent fingerprints, and sets no cookies of its own.

4. Storage, retention and deletion

4.1 Where data is stored

Data is stored in a PostgreSQL database hosted by Supabase; the application runs on Vercel (Singapore region); image attachments and certain webhook payloads are stored in Cloudflare R2 object storage. All transport is TLS-encrypted. Because our providers and our AI subprocessors operate internationally, your data and your customers' data may be transferred and processed outside your own country.

4.2 How long we keep it

  • By default, support data (threads, messages, chat sessions, attachments) is retained for as long as your workspace is active, so the AI can keep learning and retrieve context.
  • A retention window can be configured for your workspace in Settings → Privacy & data (180, 365 or 730 days; kept forever by default). When set, a daily job permanently deletes attachments older than that window from object storage and anonymizes the messages behind them: sender and recipient addresses are replaced with a redacted placeholder, subjects are replaced, and message bodies, translations and headers are erased.
  • Regardless of your setting, we always purge messaging-platform callback events after 72 hours and delivery-ledger rows for failed or skipped card messages after 30 days.
  • Records of a redaction keep only a salted hash and a masked form of the email address, never the address itself.

4.3 Deletion

  • You can delete your own account from Settings → Security at any time. This immediately removes your user record, your membership of any workspace, and — in the same operation — every workspace you own on your own, together with all of its threads, messages, chat sessions, knowledge archive entries and attachments. No email to us is required.
  • A workspace that still has other members is not deleted, and neither is your account. Deleting it would erase your colleagues' work as a side effect, so the request is refused and you are asked to transfer ownership to another member, or remove the remaining members, first. Once you are its only member, deleting your account erases it.
  • You can disconnect a mailbox at any time, which stops synchronization immediately.
  • If you use Shopify, we honour Shopify's mandatory privacy webhooks: a customer redaction request erases that consumer's support data, a shop redaction request purges the whole workspace's support data and attachments, and a customer data request produces an export.
  • We may retain records we are legally required to keep, such as transaction records for tax and accounting purposes.

4.4 IP addresses

We read the client IP address of requests to our public chat endpoints and use it to enforce rate limits, which is how we stop a single visitor or bot from draining a merchant's AI credits. For the more expensive endpoints the IP is written into a short-lived counter row in our database and is automatically removed once that rate-limit window has expired. We do not use IP addresses for profiling or advertising.

5. Subprocessors and third-party services

We do not sell your data or your customers' data. We share it only with the providers below, only for the stated purpose, and only to the extent the purpose requires.

ProviderPurposeData involved
VercelApplication hosting, scheduled jobsAll request traffic, server logs
SupabasePostgreSQL database, realtime updatesAll stored application data
CloudflareObject storage (R2) for attachments; bot protection (Turnstile) on sign-up; DNS; outbound mail delivery when configured as our mail providerAttachments, webhook payloads, sign-up challenge tokens and IP, outbound notification emails
Google (Gemini API, paid tier)AI classification, drafting, image understanding, real-time chat repliesEmail and chat text, order context, image attachments
DeepSeekAI classification, summarization and knowledge extraction; fallback providerEmail and chat text
Cloudflare Email ServiceTransactional email to you (verification, password reset, notifications)Your name and email address
WaffoSubscription and top-up payment processingYour billing contact details and payment instrument, handled by Waffo directly
ShopifyOrder lookup, when you connect your storeOrder and fulfilment data for the orders a support conversation is about
ApifyAmazon storefront and product ingestion, when that feature is enabled for your workspacePublic product listing URLs and content of your own listings; no consumer data
JinaRendering public web pages during website and knowledge ingestion, when enabledPublic URLs of your own website; no consumer data
Feishu / DingTalk / WeComApproval and review cards, only if you connect oneThe review card content you choose to route there

We may also disclose data when required by law, or where necessary to establish, exercise or defend legal claims.

We do not use any advertising network, retargeting pixel or cross-site tracker, and we run no third-party web analytics.

6. Cross-workspace learning (opt-in)

Cross-workspace learning is off by default. Your workspace contributes to our shared standard library — the reusable question patterns, reply structures and policy templates that benefit every merchant on the platform — only after someone with owner or manager rights turns it on under Settings → Privacy & data in the dashboard. Until that switch is on, nothing in your workspace is read for this purpose.

When it is on, what is contributed is confirmed knowledge archive entries and the reply patterns you adopted, generalized and de-identified: brand and personal names, email addresses, order and tracking numbers, amounts and addresses are stripped, and brand-specific values become placeholders. This is internal product improvement, not model training and not disclosure to other merchants.

You can withdraw at any time with the same switch — your workspace leaves the pool immediately and no later run reads its data. Material already generalized into the shared library contains nothing that identifies you or your customers and is retained.

Design partners who have signed a separate written data agreement with us are covered by that agreement, which is recorded against their workspace; to end it, write to support@kefuagents.com.

7. Your rights

Depending on where you are, you may have the right to access, correct, export, restrict, object to, or delete your personal data, and to withdraw consent where processing is based on consent. To exercise any of these, email support@kefuagents.com; we respond within 30 days.

If one of your end customers exercises data rights against you — for example asking you to delete their support history — contact us and we will carry out the erasure or export on your behalf, as your processor.

If you believe we have handled your data improperly, you may also complain to your local data protection authority.

8. Security

Credentials and secrets (mailbox passwords, commerce access tokens, messaging app secrets) are encrypted at rest with AES-256-GCM. Passwords are hashed. All traffic is served over TLS. Access to production data is limited to what operating the service requires. No system is perfectly secure; if a breach affects your data we will notify you without undue delay and, where required, the relevant authority.

9. Children

The service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16 as an account holder.

10. Cookies

We use only strictly necessary and preference cookies. We set no analytics, advertising or tracking cookies. See the Cookie Policy for the full list.

11. Changes

Material changes will be announced in-app or by email at least 14 days before they take effect. The "last updated" date above always reflects the current version. Continued use of the service after a change takes effect constitutes acceptance of the updated policy.

Contact

For questions about this policy, to exercise your data rights, or to request erasure of a workspace, email support@kefuagents.com or use our contact form.