Website Privacy Policy
Effective date: July 14, 2026
Last updated: July 14, 2026
This Website Privacy Policy explains how Kavroth handles information through the public website and its Request Early Access form. In this policy, “Kavroth,” “we,” “us,” and “our” refer to Kavroth Labs.
1. Scope
This policy applies to visits to the public Kavroth website and information submitted through its Request Early Access form. The website is a marketing and early-interest site. It is not a client portal, secure professional document-transfer system, customer application, or production service.
The website describes product direction and a private preview, but it does not currently provide logins, authenticated workspaces, customer document uploads, payments, production AI inference, integrations, or public API accounts. Future product data will be governed by separate customer agreements and a product-specific privacy notice. Customer documents are not used to train Kavroth models by default; that product principle does not mean this website currently receives customer documents.
2. Information you submit through the Request Early Access form
The form may collect the following information:
- full name;
- work email address;
- firm or organization;
- professional role;
- primary industry;
- interest in product early access, the API developer preview, or both;
- firm size;
- primary workflow challenge;
- current tools or systems;
- preferred deployment;
- an optional message; and
- an acknowledgement that Kavroth is under development and submission does not guarantee access.
Required fields: full name, work email, firm or organization, role, primary industry, preview interest, primary workflow challenge, and the development-status acknowledgement. Firm size, current tools or systems, preferred deployment, and the message are optional.
3. Information processed automatically
Although Kavroth has not configured an analytics provider or advertising tracker in the current website code, the eventual hosting, infrastructure, security, or network providers may automatically process ordinary technical request information needed to deliver and protect the website. Depending on the provider selected, this may include:
- IP address;
- browser, device, and operating-system information;
- requested URL and access time;
- referring page;
- diagnostic information and server logs; and
- fraud, spam, abuse, or security signals.
Kavroth does not use this technical information for advertising or cross-site profiling. The exact infrastructure processing and retention must be reviewed after a production host is selected.
4. Honeypot and spam prevention
The form includes a hidden field named “company_website.” It is not intended for people to complete and is used only as a honeypot to detect automated spam. If that field is filled, the website returns a silent success response but does not validate, forward, or store the submission through the request-access route. For valid submissions, the hidden field is removed before any forwarding or optional development storage.
5. How Kavroth uses information
Kavroth may use submitted information to:
- receive, review, administer, and respond to an early-access or developer-preview request;
- understand professional roles, industries, organization sizes, workflows, tools, and deployment preferences;
- evaluate potential preview participants and plan relevant follow-up;
- improve the website, preview planning, and product direction using aggregated or de-identified observations where practical;
- detect spam, fraud, abuse, and security incidents;
- maintain records of communications and active business discussions; and
- comply with law, resolve disputes, and enforce applicable agreements.
Submitting the form permits Kavroth to respond to and administer the request. The acknowledgement checkbox confirms development status and lack of guaranteed access; it is not general marketing consent. Unrelated promotional email should require an appropriate separate opt-in.
6. Form processing, service providers, and webhook delivery
The browser sends the form as JSON to Kavroth’s /api/request-access route. The server coerces expected fields, normalizes and length-limits free-text values, validates required inputs, removes the honeypot, and forwards a valid submission to the server-side endpoint configured as REQUEST_ACCESS_WEBHOOK_URL. If configured, REQUEST_ACCESS_WEBHOOK_SECRET is sent as a bearer credential to authenticate that server-to-server request. No webhook, CRM, hosting, or form-processing provider is named in the repository today.
A selected webhook, CRM, hosting, infrastructure, network, communications, or security provider may process information on Kavroth’s behalf to provide its contracted service. Provider identity, location, safeguards, and retention must be reviewed before production configuration. If no production webhook is configured, the route fails closed and does not report a successful submission.
For local testing only, a submission may be appended to .dev-data/request-access.log when no webhook is configured, NODE_ENV is not “production,” and ENABLE_DEV_FORM_SINK is exactly “true.” This development sink is hard-disabled in production and does not cause the form to report success.
7. Other disclosures
Kavroth may disclose relevant information:
- to service providers and professional advisers that need it to perform services for Kavroth;
- when reasonably necessary to comply with law, legal process, or a valid governmental request;
- to protect the rights, safety, security, and integrity of Kavroth, the website, visitors, or others;
- to investigate or prevent fraud, spam, abuse, or violations of applicable terms; and
- in connection with a proposed or completed financing, merger, acquisition, reorganization, sale of assets, or similar business transfer, subject to appropriate confidentiality and legal requirements.
8. Cookies, analytics, and advertising
The current website code does not configure an analytics provider, advertising pixel, cross-site behavioral advertising technology, payment processor, or intentional advertising cookie. Kavroth does not currently use website information for cross-context behavioral advertising, and does not currently sell personal information.
No cookie banner is provided because the current site does not install non-essential tracking. Ordinary infrastructure behavior may change when a production host is selected. This policy and any consent mechanism must be reassessed before adding analytics, marketing tools, advertising technology, or non-essential cookies.
9. Data retention
Early-access submissions may be retained for up to 24 months after the most recent interaction, unless a longer period is reasonably necessary for an active business discussion, security, legal compliance, dispute resolution, or enforcement of agreements.
Technical request information, security records, provider copies, and backups may follow separate, appropriately limited retention schedules. The final production retention policy and selected providers’ schedules remain publication decisions requiring review.
10. Information security
Kavroth intends to use reasonable administrative, technical, and organizational safeguards appropriate to the website and the information processed. No transmission, storage system, or security measure can be guaranteed completely secure. The public form is not designed for sensitive or confidential professional information.
11. Privacy requests
You may ask to access, correct, or delete information you submitted by emailing privacy@kavrothlabs.com. Requests are subject to applicable law, reasonable identity verification, and exceptions needed for security, legal compliance, dispute resolution, or recordkeeping. Kavroth does not claim that any particular privacy law necessarily applies to every visitor or request.
- Identify the email address used for the submission.
- Describe whether you request access, correction, or deletion.
- Provide any additional information reasonably needed to locate the submission and verify the request.
12. Email and communications
Kavroth may use the work email you provide to confirm, administer, and respond to your request; discuss a possible preview or business relationship; provide requested information; and send operational or legal notices relevant to that interaction. You may ask Kavroth to stop non-essential follow-up. Transactional, security, or legally required communications may still be sent where appropriate.
13. Children’s privacy
The website is intended for business and professional audiences and is not directed to children under 13. Kavroth does not knowingly collect personal information from children under 13 through the Request Early Access form. If you believe a child submitted information, contact privacy@kavrothlabs.com.
14. International visitors
The website may be accessed from locations outside the country where Kavroth or its future providers operate. Information may therefore be processed in jurisdictions with different data-protection rules. Provider locations and any required transfer safeguards must be evaluated after the operating entity, production host, and form processor are selected.
15. Third-party links
The website may link to websites or services operated by others. Their privacy practices are governed by their own notices, not this policy. Kavroth is not responsible for third-party content or privacy practices, and a link does not imply endorsement.
16. Changes to this policy
Kavroth may update this policy to reflect changes in the website, providers, practices, or law. The updated version will show a revised “Last updated” date. Material changes will be communicated in a manner appropriate to the nature of the change and applicable law.