Legal
Privacy Notice
Version 1.0 · Effective 29 August 2026
This notice explains how Weganar Consulting LLC, a Nevada limited liability company doing business as Last Furlong (we, us or our), handles personal information when it operates the hosted kavilo service at kavilo.cloud (the Service).
It covers account holders, people visiting kavilo.cloud, and people who use a Kavilo chat agent or contact form on a customer's website or app. A customer decides why its agent collects visitor messages and leads; we process that information to provide the Service for the customer. The customer's own privacy notice should explain its purposes. Separately distributed, self-hosted Kavilo deployments are controlled by the organisation running them and are not covered by this notice unless we operate part of that deployment for it.
1. Information we collect
- Account information: your verified email address, OAuth sign-in provider, account and session identifiers, and support communications.
- Billing information: plan, subscription status, Stripe customer and subscription identifiers, and transaction records. Stripe receives and processes payment-card details; we do not store full card numbers.
- Agent configuration: bot names, allowed domains, prompts, Context, Guardrails, imported page text, appearance settings, transcript destinations, and MCP settings and responses when configured.
- Conversation and lead information: visitor messages, model replies, conversation identifiers, summaries, and contact details or notes a visitor chooses to submit.
- Technical information: request time, IP address and origin information used for delivery, security and rate limiting; operational logs; and browser or device information ordinarily included in HTTP requests.
The widget stores a signed conversation identifier in the visitor's browser local storage so a conversation can continue across pages. Kavilo does not use advertising cookies or third-party analytics on kavilo.cloud.
2. How we use information
We use information to:
- create and authenticate accounts, provide chat replies, deliver transcripts and leads, and operate requested integrations;
- process subscriptions, enforce plan allowances, prevent abuse, secure and troubleshoot the Service, and provide support;
- maintain business, tax and accounting records and comply with legal obligations; and
- understand and improve reliability and product behavior using operational information. We do not use Customer Content to train models.
3. When information is disclosed
We may disclose information to:
- the Kavilo customer that configured the agent, including through its portal and transcript or lead destination;
- Google or GitHub when you choose that provider for OAuth sign-in;
- Stripe for subscriptions and billing;
- email, network, hosting and other infrastructure providers that help us deliver and secure the Service;
- an MCP server or other integration configured by the customer;
- professional advisers, authorities or other persons when reasonably necessary to comply with law, protect rights and safety, or investigate misuse; and
- a successor in a merger, financing, reorganisation or sale of the Service or business, subject to this notice or notice of a replacement policy.
We do not sell personal information, use it for targeted advertising, or allow third parties to collect personal information on kavilo.cloud to track people over time across unrelated websites. We do not send hosted visitors' messages to a third-party model provider for inference.
4. Retention
Conversations and captured leads are removed by the hosted Service's periodic retention sweep. The configured period is currently instance-wide rather than different for each plan. Deleting a bot invalidates its key immediately but does not immediately erase its stored conversations or leads.
We keep account, support, security, billing and legal records only for as long as reasonably needed for the purposes above, including fraud prevention, accounting, dispute resolution and legal requirements. Information may remain briefly in backups after deletion. A visitor can clear the widget's local storage through browser controls.
5. Your choices and requests
Account holders can review and change most account and bot information in the portal. You may ask to access, correct or delete personal information by emailing hello@kavilo.cloud. We may need to verify your identity and may retain information when required by law or for legitimate security, billing or dispute purposes.
If your request concerns a conversation or lead collected through another organisation's agent, contact that organisation first because it controls the agent and can identify the relevant record. You may also contact us, and we will assist the customer where appropriate. Nevada consumers may use the same address to submit a verified request concerning sale of covered information; Kavilo does not sell covered information.
6. Security and data location
The hosted model and stored conversations run on our hardware in the United States. Our Security page explains the controls and their limits, including that stored conversations are not encrypted at rest. No system is perfectly secure, so do not submit secrets, protected health information or other regulated data unless we have agreed in writing to the necessary safeguards.
7. Children
Kavilo is not directed to children under 13, and account holders must be able to enter into the Terms of Service. If you believe a child submitted personal information through the Service, contact us so we can investigate and take appropriate action.
8. Changes and contact
We may update this notice. We will post the revised version here with a new effective date and provide additional notice when a change is material. For privacy questions or requests, contact Weganar Consulting LLC, doing business as Last Furlong, at hello@kavilo.cloud.