PRIVACY POLICY
Pivotalchat.ai
Last updated: February 15, 2026
1. INTRODUCTION
This Privacy Policy aims to inform you about how KIMIND (hereinafter "we", "our" or "Kimind") collects, uses, shares and protects your personal data in connection with the use of the Pivotalchat.ai service (hereinafter "the Service" or "the Platform").
Kimind attaches great importance to the protection of your personal data and undertakes to process it in compliance with:
- The General Data Protection Regulation (GDPR - Regulation EU 2016/679)
- The French Data Protection Act of January 6, 1978, as amended
- Any other applicable data protection regulations
2. DATA CONTROLLER
The data controller for your personal data is:
KIMIND
Registered office: 17 rue du Colisée, 75008 Paris, France
Email: legal@kimind.com
Phone: +33 1 75 43 82 33
Data Protection Officer (DPO):
Email: rgpd@kimind.com
3. SUBCONTRACTOR: DUST.TT
3.1 Role of Dust.tt
Dust.tt acts as a subcontractor for Kimind for the processing of conversational data and access to artificial intelligence models.
3.2 Data flow
Data follows this path:
- Collection on Pivotalchat.ai (Kimind servers)
- Transit via Kimind's servers
- Transmission to Dust.tt for AI processing
- Processing by AI models (OpenAI, Anthropic, Mistral, Google) via Dust.tt
- Return of response via Dust.tt
- Storage of history on Kimind's servers
3.3 Dust.tt guarantees
Dust.tt guarantees:
- Zero data retention: no retention of your data by AI operators (OpenAI, Anthropic, Mistral, Google)
- No training: your conversations are never used to train AI models
- HIPAA certification: compliance with strict US healthcare data security standards
- GDPR compliance: compliance with the General Data Protection Regulation
Dust.tt privacy policy:
https://dust.tt/home/platform-privacy
3.4 Joint responsibility
Although Dust.tt is a subcontractor, the use of Pivotalchat.ai requires prior creation of a Dust.tt account by the user. You are therefore also subject to Dust.tt's privacy policy for aspects relating to your Dust.tt account.
4. DATA COLLECTED
4.1 Identification and contact data
When creating your account, we collect:
- Email address (required for authentication and communications)
- Dust.tt account identifier (linked to your Pivotalchat.ai account)
- Username (if provided)
- Profile information (if voluntarily provided)
4.2 Conversational data
As part of using the Service, we collect and store:
- Conversation content: all your exchanges with AI models
- Prompts and queries: your questions and instructions to AI models
- Generated responses: responses provided by AI models
- Conversation history: all your past interactions
- Metadata: timestamp, AI model used, exchange length, conversation settings
Retention period: Conversations and history are retained as long as you do not delete them yourself. This functionality is an integral part of the Service and allows you to access your history at any time.
4.3 Technical and connection data
Automatically collected during your use of the Service:
- Connection data: IP address, browser type, operating system
- Usage data: pages viewed, features used, AI models requested, frequency of use, date and time of connection
- Cookies and technical identifiers: see section 7
4.4 Payment data
For paid subscriptions:
- Billing information: name, billing address
- Banking data: processed directly by our payment provider (we do not store your complete banking data)
4.5 Dust.tt data
Your Dust.tt account and associated data are governed by Dust.tt's privacy policy. We receive from Dust.tt only the information necessary for the operation of the Service (account identifier, API settings).
5. PURPOSES AND LEGAL BASES OF PROCESSING
We process your personal data for the following purposes:
| Purpose | Legal basis | Data concerned |
|---|---|---|
| Account creation and management | Contract performance | Email, identifiers, Dust.tt link |
| Service provision (AI conversations) | Contract performance | All conversational data |
| History retention | Contract performance | Conversations, history |
| Subscription and payment management | Contract performance | Billing data |
| Customer support | Contract performance / Legitimate interest | Email, account data, conversations (if necessary) |
| Service improvement | Legitimate interest | Usage data, metadata |
| Anonymized statistics | Legitimate interest | Anonymized usage data |
| Compliance with legal obligations | Legal obligation | Billing data, logs |
| Security and fraud prevention | Legitimate interest | Connection data, logs |
| Transmission to Dust.tt for AI processing | Contract performance | Prompts, queries, conversational context |
Important: Your conversations are never used to:
- Train AI models (Dust.tt "no training" guarantee)
- Be resold to third parties
- Feed marketing databases
- Be commercially exploited by Kimind or Dust.tt
6. DATA RECIPIENTS
Your personal data is processed by:
6.1 Authorized Kimind staff
Only Kimind staff members who need access to your data in the course of their duties (technical support, development, security) have access to it.
6.2 Host
Lovable Labs Sweden AB, Tunnelgatan 5, 11137 Stockholm, Sweden (lovable.dev): Platform and data hosting
6.3 Main subcontractor: Dust.tt
Dust.tt receives and processes:
- Your queries and prompts
- The context of your conversations
- Metadata necessary for processing
Guarantees:
- Zero data retention by AI operators
- No training: your data is not used to train models
- HIPAA certification
- GDPR compliance
6.4 AI model operators (via Dust.tt)
Your queries are transmitted by Dust.tt to the following operators, depending on the AI model you use:
- OpenAI (GPT models)
- Anthropic (Claude models)
- Mistral AI (Mistral models)
- Google (Gemini models)
Dust.tt contractual guarantees with these operators:
- Zero data retention: no retention of your data
- No training: your data is not used to improve their models
- Immediate deletion after processing
6.5 Service providers
We use subcontractors for:
- Payment processing (PCI-DSS compliant payment processor)
- Sending transactional emails
- Statistical analysis (anonymized data only)
All our subcontractors are carefully selected and contractually required to comply with GDPR.
6.6 Legal authorities
We may be required to communicate your data to competent authorities if required by law or to protect our legal rights.
7. COOKIES AND SIMILAR TECHNOLOGIES
7.1 Cookies used
The Service uses the following types of cookies:
Technical cookies (strictly necessary):
- Authentication and session management
- Link with your Dust.tt account
- Service security
- Language and interface preferences
Statistical cookies:
- Audience and usage measurement (anonymized data)
- User experience improvement
- Service performance analysis
7.2 Cookies NOT used
Kimind does NOT use any:
- Advertising cookies
- Behavioral tracking cookies for commercial purposes
- Third-party social media cookies
- Invasive profiling mechanisms
- Data resale cookies
7.3 Cookie management
You can manage your cookie preferences (except strictly necessary cookies) via:
- Your account settings
- Your browser settings
Refusing technical cookies may prevent the use of certain Service features, including linking with your Dust.tt account.
8. DATA RETENTION PERIOD
We retain your personal data for the following periods:
| Type of data | Retention period |
|---|---|
| Active account data | As long as the account is active |
| Conversations and history | Until the user deletes them |
| Data after account deletion | 30 days (recovery period) then permanent deletion |
| Billing data | 10 years (legal accounting obligation) |
| Connection and security logs | 12 months maximum |
| Conversation metadata | Linked to conversations (deleted with them) |
History retention:
Retention of your conversation history is a Service feature. You can delete individual conversations or your entire history at any time from your account.
At Dust.tt and AI operators:
In accordance with "zero data retention" guarantees, your data is not retained by Dust.tt or AI operators (OpenAI, Anthropic, Mistral, Google) after processing each query.
At the expiration of indicated periods, your data is either permanently deleted or irreversibly anonymized.
9. DATA SECURITY
Kimind and Dust.tt implement appropriate technical and organizational measures to protect your personal data against:
- Accidental loss
- Unauthorized access
- Fraudulent use
- Unauthorized modification or disclosure
9.1 Kimind security measures
- Encryption of data in transit (HTTPS/TLS)
- Encryption of data at rest
- Secure authentication
- Strict access control
- Regular security monitoring and audits
- Backup procedures
- Production environment isolation
9.2 Dust.tt security measures
- HIPAA certification (healthcare data security standards)
- End-to-end encryption
- Multi-level secure architecture
- Regular security audits
- Compliance with international security standards
9.3 User-side security
Despite these measures, no data transmission over the Internet can be guaranteed as completely secure. You are responsible for:
- The confidentiality of your login credentials (Pivotalchat.ai and Dust.tt)
- The security of your equipment
- Prudent use of the Service (not sharing ultra-sensitive information)
10. DATA TRANSFERS OUTSIDE THE EU
10.1 Main hosting
Your personal data is primarily hosted and processed within the European Union.
10.2 Transfers via Dust.tt
As part of processing by Dust.tt and AI operators, your data may transit or be temporarily processed outside the European Union, including:
- In the United States (OpenAI, Anthropic, Google)
- In other jurisdictions depending on Dust.tt's infrastructure
10.3 Protection guarantees
For all transfers outside the EU, we ensure that:
- Appropriate safeguards are in place (EU Commission standard contractual clauses, adequacy decisions, etc.)
- The level of protection of your data is equivalent to that of GDPR
- "Zero data retention" and "no training" guarantees apply systematically
- Dust.tt's HIPAA certification also covers these transfers
11. YOUR RIGHTS
In accordance with GDPR and the French Data Protection Act, you have the following rights:
11.1 Right of access
You can obtain confirmation that your data is being processed and access that data, including:
- All your conversations
- Your account data
- Metadata of your interactions
11.2 Right of rectification
You can request correction of your inaccurate or incomplete data.
11.3 Right to erasure ("right to be forgotten")
You can request deletion of your data in certain cases (withdrawal of consent, objection to processing, unlawfully processed data, etc.).
History deletion:
You can delete your conversations and history at any time directly from your account, without contacting us.
11.4 Right to restriction of processing
You can request restriction of processing of your data in certain circumstances.
11.5 Right to data portability
You can receive your data (particularly your conversations) in a structured and commonly used format (JSON, CSV), and transmit it to another data controller.
11.6 Right to object
You can object to the processing of your data for legitimate reasons, particularly for processing based on legitimate interest.
11.7 Right to withdraw consent
Where processing is based on your consent, you can withdraw it at any time.
11.8 Right to define post-mortem directives
You can define directives regarding the fate of your data after your death.
11.9 Exercising your rights
To exercise your rights, contact us:
- By email: rgpd@kimind.com
- By mail: KIMIND - DPO, 17 rue du Colisée, 75008 Paris, France
We undertake to respond within a maximum period of one month from receipt of your request. This period may be extended by two months in case of complexity, in which case you will be informed.
Proof of identity may be requested to secure your request.
Export your conversations:
You can export your conversations at any time from your account settings, without contacting us.
11.10 Right to lodge a complaint
You have the right to lodge a complaint with the French National Commission for Information Technology and Civil Liberties (CNIL):
- Website: www.cnil.fr
- Address: 3 Place de Fontenoy - TSA 80715 - 75334 PARIS CEDEX 07
- Phone: +33 1 53 73 22 22
12. PROCESSING PRINCIPLES
In accordance with GDPR, we undertake to:
- Lawfulness, fairness, transparency: process your data lawfully, fairly and transparently
- Purpose limitation: collect your data for determined, explicit and legitimate purposes (AI Service provision)
- Data minimization: collect only adequate, relevant and necessary data
- Accuracy: keep your data accurate and up to date
- Storage limitation: retain your data only as long as necessary (or as long as you do not delete them for history)
- Integrity and confidentiality: guarantee the security of your data through appropriate technical and organizational measures
13. NO-RESALE AND NO-TRAINING COMMITMENT
Kimind formally undertakes to:
- Never sell your personal data to third parties
- Never rent your personal data to third parties
- Never share your data for third-party advertising or marketing purposes
- Never use your conversations to train AI models
- Only collect data strictly necessary for the operation of the Service
Dust.tt guarantees:
- Zero data retention: no retention by AI operators
- No training: your conversations never serve to train AI models (neither Dust.tt's, nor OpenAI's, Anthropic's, Mistral's or Google's)
Your data is used exclusively to provide you with the Service and improve it generally (anonymized statistics), never to train AIs or for any commercial exploitation of your content.
14. CONVERSATION CONFIDENTIALITY
14.1 Access to conversations
Your conversations are private and confidential. Kimind accesses your conversations only in the following strict cases:
- Technical support: if you contact us for a problem and explicitly ask us to examine a specific conversation
- Legal obligation: if required by a competent judicial authority
- Security: in case of suspected fraudulent or illegal use
Outside these cases, your conversations are never consulted by our staff.
14.2 Automated processing only
Conversations transit through our servers in an automated manner to be transmitted to Dust.tt and returned. No manual processing or human consultation is performed in the normal course of the Service.
14.3 Data sensitivity
Important recommendation: Although we implement robust security measures, we recommend that you do not share in your conversations:
- Ultra-sensitive medical information
- Passwords or access codes
- Complete credit card numbers
- Personal data of third parties without their consent
- Critical industrial or commercial secrets
15. MINORS
The Service is not intended for minors under 16 years of age. We do not knowingly collect personal data from minors. If you are a parent or legal guardian and discover that your child has provided us with personal data, contact us at rgpd@kimind.com so we can delete it.
16. PRIVACY POLICY MODIFICATIONS
We may modify this Privacy Policy at any time to reflect:
- Service developments
- Legal or regulatory changes
- Changes to our subcontractors (particularly Dust.tt)
- Improvements to our data protection practices
Any substantial modification will be notified to you by email and/or via the Service at least 30 days before it takes effect. The date of last update is indicated at the top of this document.
In case of change concerning Dust.tt or AI operators, we will inform you as soon as possible.
We encourage you to regularly consult this Privacy Policy.
17. CONTACT
For any questions regarding this Privacy Policy or the processing of your personal data:
Data Protection Officer:
Email: rgpd@kimind.com
KIMIND
17 rue du Colisée
75008 Paris, France
Email: legal@kimind.com
Phone: +33 1 75 43 82 33
For questions related to Dust.tt:
Visit their privacy policy: https://dust.tt/home/platform-privacy
18. TRANSPARENCY AND GDPR COMPLIANCE
Kimind is committed to complete transparency regarding the processing of your personal data. This Privacy Policy aims to inform you clearly and accessibly about:
- The data we collect
- The reasons for this collection
- The role of Dust.tt and AI operators
- "Zero data retention" and "no training" guarantees
- Who has access to your data
- Your rights and how to exercise them
We regularly conduct GDPR compliance audits and update our practices to ensure the highest level of protection for your personal data.
19. AI-SPECIFIC FEATURES
19.1 Nature of processing
Processing of your conversations by AI models occurs in real-time. Your queries are:
- Transmitted to Dust.tt
- Processed by the selected AI model
- Returned immediately
- Deleted immediately after processing by Dust.tt and AI operators (zero data retention)
19.2 No machine learning on your data
Absolute guarantee: Your conversations are never used to:
- Train AI models (OpenAI, Anthropic, Mistral, Google)
- Improve Dust.tt algorithms
- Feed learning databases
- Create user profiles for AI
19.3 Data isolation
Each conversation is processed in isolation. Your data is never:
- Shared with other users
- Used to improve other users' experience
- Aggregated with data from other users for AI training
19.4 Certification and audit
- Dust.tt is HIPAA certified, guaranteeing the highest level of security and confidentiality
- Regular audits are conducted to verify compliance with "zero data retention" and "no training" guarantees
- Kimind performs regular checks of Dust.tt's compliance
20. PROCESSING REGISTER
In accordance with Article 30 of GDPR, Kimind maintains a register of processing activities. You can obtain a copy by contacting rgpd@kimind.com.
21. IMPACT ASSESSMENT (DPIA)
A data protection impact assessment (DPIA) has been conducted for the Pivotalchat.ai Service, given the potentially sensitive nature of conversations. This DPIA is available upon request at rgpd@kimind.com.
Last updated: February 15, 2026