Skip to Content

Legal

Privacy Policy

What Kilter holds about you, why, how long it is kept, who else receives it, and how to take it with you or erase it.

Issued by Wyzie LLC. Last updated .

Who Runs Kilter

Kilter is the website at kilter.work, the application at app.kilter.work and the Kilter desktop app. It is operated by Wyzie LLC, and “we” in this policy means Wyzie LLC.

Wyzie LLC is a North Carolina limited liability company ( wyzie.io).

Send any question or request about your data to support@kilter.work.

This policy covers what Kilter does. The outside accounts you connect and the model provider your workspace connects are run by other companies under their own policies.

What Kilter Holds About You

Your Account

Your name, your email address and whether it is verified, a picture if the way you signed in provided one, and when the account was made. A password is stored only as a salted hash. If you sign in with Google, Microsoft or GitHub, Kilter keeps the link to that account and the tokens it issued, encrypted, and takes your name, email address and profile picture from it; signing in with Microsoft also fetches your profile photo from Microsoft. If you turn on a second factor, its secret and your backup codes are stored encrypted.

Each signed in session keeps the IP address and browser it was started from, which workspace it is working in, and when it expires.

What You Put in a Workspace

Cards, notes and up to a hundred earlier versions of each note, events, reminders, comments, checklists, custom fields, templates, saved views and sticky notes; files you attach, up to 10 MB each, whose name, type and size are kept in Kilter’s database and whose contents are kept in Cloudflare R2; links you save, with what Kilter’s server read at that address (the page’s title, description, author, a thumbnail and its readable text); and the last five hundred changes to each board, so they can be undone. All of it belongs to the workspace, and the people in it can see what is shared with the workspace. A card, note, event or reminder you keep to yourself is seen only by you and the people you name on it.

Your membership of each workspace, your role, any roles and permissions a workspace admin gave you, and whose work you are assigned to or watching.

Your Settings and Notifications

Your theme, motion and text size, how dates read, which notification channels are on, standing instructions you wrote for the assistant, and small choices the interface remembers. The schedules you set for being told about something, the notifications that fired, and for each device you turn push notifications on for, the address its push service gave it, the browser’s public keys and a label.

Conversations With the Assistant

Each conversation, every message in it, what the assistant did while answering, files you attached (up to 5 MB each), which model answered and how many tokens it counted. Only the person who had a conversation can open it.

Joining the Beta

If you join the waitlist at kilter.work: your email address, which page you signed up from, the address that referred you if one was sent, where your place stands, the invite code sent to you and when, and which version of this policy was in force when you signed up. Every email about the waitlist carries a link that removes your address from the list. If you redeem an invite code: the email address you redeemed it with, the IP address and browser it was redeemed from, and when. If a workspace invites you: your email address, the role offered, who invited you and whether you accepted.

Security Records

A record of security events: signing in (with the IP address and browser), a failed sign in (with the email address that was tried), signing up, verifying an address, turning a second factor on or off, changing a password, linking a sign in provider, role and permission changes, invitations, removals, single sign on and provisioning changes, and deleting an account or a workspace. You can read your own in Settings. A workspace’s admins can read only the events that belong to that workspace, never your sign ins. Each security record is deleted ninety days after it was made, except two that stay: the record of which version of the terms and this policy you agreed to when you made your account, and the record that an account was erased.

To slow down repeated attempts at signing in, joining the waitlist, redeeming a code and a few other actions, the IP address a request came from, or your account, is kept in a counter for about an hour.

Each request to app.kilter.work writes a log line: the method, the path, the result, how long it took, a request reference, and the ids of the account and workspace involved. It does not record your IP address, and anything that looks like a password, token or cookie is removed first.

Notices We Send You

When a change is coming that the terms or this policy promise you notice of, every account holder with a verified email address is emailed the same notice. Kilter records which notice was sent to your account, when, and whether it could be delivered, as the record that you were told.

Why It Is Used

  • To run Kilter for you: signing you in, keeping your work in sync across devices and colleagues, delivering the notifications you set, and answering when you ask the assistant.
  • To keep it secure: sessions you can end, security records you and your admins can read, limits on repeated attempts, and investigating abuse.
  • To run the closed beta: the waitlist, invite codes and invitations.
  • To send the email the service needs: account email (verifying your address, resetting a password, confirming a change of address, security notices, confirming an erasure), invite codes and waitlist email, workspace invitations, notices of a change the terms or this policy promise you notice of, and notifications, which you can turn off in Settings or from the link in any notification email. Kilter sends no marketing email.

Kilter does not sell personal data, does not show advertising, and does not use what you put in it to train any model.

Legal Bases in the European Economic Area and the United Kingdom

Where the GDPR or the UK GDPR applies, each use above rests on one of these:

  • Our contract with you: running Kilter for you, including signing you in, keeping your work in sync, the notifications you set, the assistant when you ask it, the accounts you connect, and the email the service needs.
  • Legitimate interests: keeping Kilter secure and free of abuse (security records, limits on repeated attempts, request logs and operator review) and running the closed beta. You can object to these at any time.
  • Your consent: push notifications on a device, and joining the waitlist. You can withdraw it at any time, from Settings or from the link in any waitlist email.
  • Legal obligations: keeping or disclosing data when the law requires it.

When an Organization Runs the Workspace

Wyzie LLC is the controller of your account, your settings and what you do on kilter.work. When a company or other organization runs a workspace, that organization decides how the workspace is used and is the controller of what is put into it, and Wyzie LLC processes that content on its behalf. Some requests about that content go to the organization’s admins. An organization that needs a data processing agreement can ask at support@kilter.work.

The Assistant and Your Model Provider

Kilter supplies no model. A workspace’s admins connect its own model providers, each with the workspace’s own key, and a provider handles the text under the workspace’s agreement with it. With no connection, nothing is sent anywhere and the assistant is simply absent.

A workspace can connect Anthropic, OpenAI, Google Gemini, xAI, OpenRouter (which passes the request on to whichever model is named), Mistral, DeepSeek or Perplexity; a runtime such as Ollama or LM Studio at an address the workspace gives, usually its own machine; or any other endpoint that speaks the OpenAI API, which Settings calls Custom. The key is stored encrypted and is never shown again beyond its last four characters.

When you use the assistant, the provider receives your message, the conversation so far, the records of the workspace the assistant reads to answer (cards, notes, events, reminders, columns, tags and people), files and pictures you attach, and your standing instructions. Smaller features send the part of the workspace they need: naming a note, sorting what you captured, ranking a search, suggesting when to be reminded.

If you ask Kilter to watch a connected mailbox, it checks for new mail every ten minutes and sends each new message’s sender, subject, time received and up to 6,000 characters of its body to the workspace’s provider, which proposes cards and reminders from it. Kilter keeps the proposal and the message’s subject, sender, link and time. It does not keep the body. Nothing is added to your workspace until you accept a proposal.

Accounts You Connect

You can connect Google, Microsoft 365 (Outlook mail and calendar, OneDrive and Microsoft To Do), HubSpot, Notion, Linear, Jira, iCloud or any other CalDAV server, or an MCP server at an address you give. A connected account is yours, never the workspace’s, and the assistant reads it only in a conversation you are having.

During the closed beta, a Google account connects Google Calendar and Google Tasks. Gmail and Google Drive are not offered until Google’s security assessment of them is complete, and this policy will say so before they are.

Kilter reads these accounts on your behalf and writes nothing back to them. An MCP server is the exception in kind rather than in intent: the assistant can call the tools that server offers, and what a tool does is decided by whoever runs the server. Kilter stores the account’s address or id, what you granted, the tokens or password it issued (encrypted), for an MCP server its address and the tools it lists, and when it was last used. Removing a connected account deletes the stored credential.

Reading is live: what the assistant reads is not copied into Kilter. An import is the exception. When you import a calendar or a task list, its events and tasks from thirty days back to a year ahead, up to a thousand of them, become events, reminders or cards in the workspace you choose, and Kilter records which outside item became which so a second import does not duplicate them.

Google API Services User Data Policy

Kilter’s use of information received from Google APIs, and its transfer of that information to any other app, adheres to the Google API Services User Data Policy, including its Limited Use requirements. In particular:

  • Google user data is used only to provide the features you use it for: showing and importing your calendar and tasks, and answering what you ask the assistant about them.
  • It is transferred only to provide those features (to your workspace’s model provider, when you ask the assistant about it), for security, to comply with the law, or as part of a merger, acquisition or sale of assets with notice to you.
  • It is not used for advertising, is not sold, and is not used to develop, improve or train generalized artificial intelligence or machine learning models.
  • No person at Wyzie LLC reads it unless you ask us to about a specific item, it is needed for security or to investigate abuse, the law requires it, or it has been aggregated and made anonymous for internal operations.

Who Else Receives It

  • The services Kilter runs on: Cloudflare, which hosts both sites, carries live updates between people in a workspace, runs the database on D1 and keeps the contents of attached files in R2; and PurelyMail, which sends Kilter’s email. The subprocessor list says what each receives.
  • Push services: a notification sent to a device goes through the push service that device’s browser uses, encrypted so that service cannot read it.
  • Services you or your workspace choose: the accounts you connect, the workspace’s model provider, the service you sign in with, and a company’s own identity provider for single sign on and provisioning.
  • The people in your workspace: whatever is shared with the workspace, and who is online and what they have open while Kilter is open. Cloudflare’s realtime service holds that in memory to pass it between you and stores none of it.
  • Anyone with a board’s link: a workspace member can make a read only link to a board. It shows the board’s shared cards (their titles, text, tags, due dates and checklist progress) and the workspace’s name, and never a private card, a conversation, a file or who is in the workspace. Links can expire and can be revoked.
  • The sites behind links you save: Kilter’s server fetches the address to read the page, so the site sees Kilter rather than you. For a YouTube, TikTok or Vimeo video it also asks that site for the video’s details.
  • Wyzie LLC’s operators: a small number of people who run the beta can open an internal panel that shows the data Kilter holds, to answer support requests, work the waitlist and investigate abuse. What they do there is recorded, with their email address and IP address, and the record is deleted after ninety days.
  • When the law requires it. We disclose personal data to law enforcement, a court or a government only when the law requires it, in answer to valid legal process such as a subpoena, court order or warrant, and only what that process covers. We tell the person concerned first, unless the law forbids it or there is an emergency that puts somebody in danger.
  • If Wyzie LLC changes hands. In a merger, acquisition or sale of assets, personal data can pass to the new owner, which stays bound by this policy for the data collected under it. Account holders are emailed before their data becomes subject to a different policy.

Cookies and Storage on Your Device

kilter.work sets no cookies and runs no analytics. Its fonts are served from kilter.work itself, and the share buttons on a blog post are plain links that load nothing from the network they point to.

app.kilter.work sets only the cookies that signing in needs, all its own: the session, which lasts up to thirty days and is renewed as you use Kilter; a five minute copy of the session so each page does not ask the database; a note that you chose not to be remembered; and short lived cookies, ten minutes at most, that carry a sign in through a second factor or an outside provider. If you ask Kilter to trust a device for your second factor, that cookie lasts thirty days. There are no analytics, advertising or tracking cookies, which is why there is no cookie banner.

The forms that need no account (joining the waitlist, redeeming an invite code, making an account and asking for a password reset) run Cloudflare Turnstile, a check that a person rather than a script is filling them in. It is the one script either site loads from another company: it runs in Cloudflare’s own frame, sees the page’s address and your browser, and hands the form a token Kilter checks with Cloudflare once. It is not used to track you and nothing about it is kept by Kilter.

Cloudflare may set a strictly necessary security cookie of its own on either site, such as __cf_bm, to tell people from automated traffic. It is not used to track you, and Kilter does not read it.

On your device, the application keeps your display preferences, a copy of the data it last loaded so it opens without a connection, and up to two hundred changes made offline until it can send them. These stay in your browser until its data for app.kilter.work is cleared. The desktop app keeps its sign in token in your operating system’s keychain.

How Long It Is Kept

Where Kilter’s code sets how long something is kept, it is below.

WhatHow long
A notification you have readThirty days after it fired
A notification you have not readUntil you read it or erase the account
A mail proposal you accepted or dismissedThirty days after it was made
Earlier versions of a noteThe newest hundred
A board’s history of changesThe newest five hundred
A session, with the IP address and browser it started fromExpires thirty days after it was last renewed, and is deleted ninety days after it expires
An email verification linkExpires after one hour, and is deleted ninety days after it expires
A workspace invitationExpires after seven days, and is deleted ninety days after it expires
Security records, with the IP addresses, browsers and email addresses they holdNinety days
The record of which terms and privacy policy an account agreed to, and that an account was erasedAs long as the account’s record exists, including after it is erased
An invite redemption, with the address, IP address and browser it came fromNinety days
What Wyzie LLC’s operators did in the internal panelNinety days
An IP address or account in a rate limit counterAbout an hour
A file attached to a message you never sentRemoved after a day, the next time you attach one
A device registered for push notificationsUntil you remove it, or its push service says it is gone
What you put in a workspaceUntil it is deleted, or the workspace is deleted

Everything else is kept only as long as it serves the reason it was collected:

  • A waitlist address: until you leave the list, which every waitlist email links to.
  • An assistant conversation: until you delete it, or its workspace is deleted.
  • The record that a notice was sent to your account: kept, as the record that you were told.
  • Server logs: up to seven days, on Cloudflare.
  • Database backups: thirty days, the window Cloudflare D1 can restore the database to, after which they are gone.
  • What an erased account leaves behind, described below: for as long as the workspace it belongs to exists.

Taking It With You, and Erasing It

Taking It With You

From Settings you can download everything Kilter holds about you as one JSON file: your account, sign in methods, sessions with their IP addresses and browsers, preferences, workspaces and roles, connected accounts (without their tokens), notification schedules and notifications, push devices, mail proposals, assistant conversations, imports, comments, the details of files you attached, sticky notes, your private saved views, invite redemptions and your security records. Each kind of record is capped at a thousand rows; write to support@kilter.work for anything past that. You can also download a workspace’s calendar as an .ics file, and a workspace’s admins can download its audit log.

Erasing Your Account

From Settings you can erase your account. Kilter asks you to have signed in within the last twenty four hours and to type your email address. Erasure removes your sessions, your password and sign in links, your second factor and backup codes, your preferences, connected accounts, push devices, notifications and their schedules, mail proposals, roles and permission overrides, and your place on everything you were named on or watching. It ends your membership of every workspace, takes your sticky notes with it, and withdraws invitations you sent that nobody accepted. A workspace you were the only member of is deleted with everything in it. Your name and email address are overwritten.

What you made in a workspace other people still use stays with that workspace, because it is theirs too, and is shown as made by Deleted Account. That includes cards, notes, events, reminders, comments, files and your assistant conversations in that workspace, which nobody else in the workspace can open. An invite redemption keeps the fact that a seat was used and loses your address, IP address and browser. The record that the account existed and was erased stays, and so does the record of which terms it agreed to. Your other security records are deleted ninety days after they were made, as everybody’s are.

A company that manages your membership through its own directory can end that membership. That touches nothing else about your account.

Your Other Rights

You can ask to see, correct or erase what Kilter holds about you, or object to a use of it, at support@kilter.work. What you put in a company’s workspace is also that company’s, and some requests about it go to its admins.

Depending on where you live, including the European Economic Area, the United Kingdom, California and other US states with privacy laws, you can ask to know what we hold about you and get a copy, correct it, delete it, restrict or object to how it is used, receive it in a portable form, and withdraw a consent you gave. Kilter does not sell personal data or share it for targeted advertising, so there is nothing to opt out of there, and nobody is treated differently for using these rights.

Write from the email address on your account, or the address the request is about. We confirm a request comes from you through that address, or by asking you to confirm while signed in, before acting on it. Somebody you authorize in writing can make a request for you. We answer within one month, or sooner where the law requires, and tell you if a complex request needs longer where the law allows it. If we turn a request down, we say why, and you can appeal by replying to that answer.

In the European Economic Area or the United Kingdom, you can also complain to your data protection authority, such as the Information Commissioner’s Office in the United Kingdom.

How It Is Protected

  • Every connection to kilter.work and app.kilter.work is encrypted.
  • Tokens from sign in providers and connected accounts, model provider keys, and second factor secrets are encrypted before they are stored. Passwords are stored only as salted hashes.
  • Secrets that somebody presents, such as a board’s link or a provisioning token, are stored only as a digest, so the database cannot give them back.
  • Addresses you give Kilter to fetch (an MCP server, a CalDAV server, a model endpoint, a saved link) are checked so they cannot reach inside Kilter’s own network.

To report a security problem, see how to report a vulnerability.

Where It Is Processed

Kilter runs on Cloudflare’s global network, so a request is handled near where it was made. The database is kept in Cloudflare D1, and the contents of attached files in Cloudflare R2.

Wyzie LLC is in the United States, and personal data is processed there and wherever the subprocessor list says each service processes it. Cloudflare’s data processing terms include the European Commission’s Standard Contractual Clauses, and the United Kingdom’s addendum to them, for transfers of personal data out of the European Economic Area and the United Kingdom.

PurelyMail, which sends Kilter’s email from the United States, offers no data processing agreement and no Standard Contractual Clauses. An email’s recipient and its words reach PurelyMail only because sending that email requires it.

Children

You must be at least sixteen to hold a Kilter account, and Kilter is not directed at children. We do not knowingly collect personal data from anybody under sixteen. If we learn that an account belongs to somebody younger, we close and erase it. If you believe that has happened, write to support@kilter.work.

Changes to This Policy

When what Kilter collects, keeps or sends somewhere changes, this page changes in the same release, and the date at the top says when.

If a change is material, such as a new use of your personal data, a new kind of service receiving it, or fewer rights over it, we email account holders before it takes effect.

Contact

Wyzie LLC, a North Carolina limited liability company ( wyzie.io). Write to support@kilter.work about your data or this policy.