The Services Kilter Runs On
Chosen by Wyzie LLC to run Kilter. Each one processes personal data on Wyzie LLC’s behalf.
| Service | What it does | What it receives | Where |
|---|---|---|---|
| Cloudflare | Hosts kilter.work and app.kilter.work on Workers, passes live updates between the people in a workspace through Durable Objects, holds the application’s secrets and request logs, runs the database on D1, keeps the contents of attached files in R2, and runs Turnstile, the check on the forms that need no account | Everything the application handles, while it is handled; everything Kilter holds, which D1 stores; the contents of every file attached to a card, note, event, reminder or assistant conversation, which R2 stores; for Turnstile, the page, the browser and the address a form was sent from | Cloudflare’s global network, near where each request is made; the database in D1, in eastern North America; attached files in R2, in eastern North America |
| PurelyMail | Sends Kilter’s email | The recipient’s address and name, the workspace’s name, and the words of each email: account email such as address verification, password resets and security notices; invite codes and waitlist email; workspace invitations; notices to every account holder; and notifications | United States (Amazon Web Services, Virginia) |
PurelyMail offers no data processing agreement and no Standard Contractual Clauses. The privacy policy says where personal data is processed and on what terms.
Push Notifications
A notification sent to a phone or a computer goes through the push service that device’s browser uses, for example Google’s Firebase Cloud Messaging for Chrome or Mozilla’s push service for Firefox. The browser chooses it, not Kilter. The notification is encrypted so the push service cannot read it; it sees only where to deliver it and when.
Ways to Sign In
| Service | What passes |
|---|---|
| Google, Microsoft or GitHub | Your name, email address and profile picture, when you choose to sign in with one; for Microsoft, also your profile photo |
| A company’s own identity provider | Identity for single sign on over OIDC or SAML, and membership for provisioning over SCIM, when that company sets it up |
Accounts a Person Can Connect
Chosen by the person who connects one. A connected account is that person’s, never the workspace’s. Kilter reads it on their behalf and writes nothing back; its tokens or password are stored encrypted.
| Account | How it connects | What Kilter reads |
|---|---|---|
| OAuth | Google Calendar and Google Tasks during the closed beta. Gmail and Google Drive are not offered until Google’s security assessment is complete. | |
| Microsoft 365 | OAuth | Outlook mail and calendar, OneDrive and Microsoft To Do |
| HubSpot | OAuth | Contacts, companies and deals |
| Notion | OAuth | The pages and databases shared with Kilter |
| Linear | OAuth | Issues |
| Jira | OAuth | Issues |
| iCloud, or another CalDAV server | An Apple ID and an app-specific password, over CalDAV | Apple Calendar and Reminders, or that server’s calendars |
| MCP server | An address the person gives | Whatever tools that server offers, which the assistant can call |
Model Providers a Workspace Can Connect
Kilter supplies no model. A workspace’s admins choose from these and connect each with the workspace’s own key, and the workspace’s agreement with that provider governs what it does with the text. With no connection, nothing is sent.
| Provider | Where the text goes |
|---|---|
| Anthropic | Anthropic’s API |
| OpenAI | OpenAI’s API |
| Google Gemini | Google’s Gemini API |
| xAI | xAI’s API |
| OpenRouter | OpenRouter’s API, and on to whichever model is named |
| Mistral | Mistral’s API |
| DeepSeek | DeepSeek’s API |
| Perplexity | Perplexity’s API |
| Ollama | A runtime at an address the workspace gives, usually its own machine |
| LM Studio | A runtime at an address the workspace gives, usually its own machine |
| Custom | Any endpoint speaking the OpenAI API, at an address the workspace gives |
What is sent is the part of the workspace a request needs: the message, the conversation, the records the assistant reads to answer, attached files, and, when a person asks Kilter to watch a mailbox, each new message’s sender, subject, time and the start of its body. The privacy policy says more.
Other Addresses the Server Reaches
- A link somebody saves: Kilter’s server fetches that address to read the page, and for a YouTube, TikTok or Vimeo video, asks that site for the video’s details. The site receives the address and a request from Kilter.
- Error alerts: a line the server logs as an error can be sent to an alerting address Wyzie LLC configures. Log lines carry no IP address and no secrets. The service that receives them is named on this list before it receives any.
Changes to This List
A service added to Kilter is added to this list in the same release, and the date at the top says when the list last changed.
A service Wyzie LLC chooses is named here, and account holders are emailed, before it receives any personal data.