PRIVACY POLICY

Pivotalchat.ai

Last updated: February 15, 2026


1. INTRODUCTION

This Privacy Policy aims to inform you about how KIMIND (hereinafter "we", "our" or "Kimind") collects, uses, shares and protects your personal data in connection with the use of the Pivotalchat.ai service (hereinafter "the Service" or "the Platform").

Kimind attaches great importance to the protection of your personal data and undertakes to process it in compliance with:

  • The General Data Protection Regulation (GDPR - Regulation EU 2016/679)
  • The French Data Protection Act of January 6, 1978, as amended
  • Any other applicable data protection regulations

2. DATA CONTROLLER

The data controller for your personal data is:

KIMIND
Registered office: 17 rue du Colisée, 75008 Paris, France
Email: legal@kimind.com
Phone: +33 1 75 43 82 33

Data Protection Officer (DPO):
Email: rgpd@kimind.com


3. SUBCONTRACTOR: DUST.TT

3.1 Role of Dust.tt

Dust.tt acts as a subcontractor for Kimind for the processing of conversational data and access to artificial intelligence models.

3.2 Data flow

Data follows this path:

  1. Collection on Pivotalchat.ai (Kimind servers)
  2. Transit via Kimind's servers
  3. Transmission to Dust.tt for AI processing
  4. Processing by AI models (OpenAI, Anthropic, Mistral, Google) via Dust.tt
  5. Return of response via Dust.tt
  6. Storage of history on Kimind's servers

3.3 Dust.tt guarantees

Dust.tt guarantees:

  • Zero data retention: no retention of your data by AI operators (OpenAI, Anthropic, Mistral, Google)
  • No training: your conversations are never used to train AI models
  • HIPAA certification: compliance with strict US healthcare data security standards
  • GDPR compliance: compliance with the General Data Protection Regulation

Dust.tt privacy policy:
https://dust.tt/home/platform-privacy

3.4 Joint responsibility

Although Dust.tt is a subcontractor, the use of Pivotalchat.ai requires prior creation of a Dust.tt account by the user. You are therefore also subject to Dust.tt's privacy policy for aspects relating to your Dust.tt account.


4. DATA COLLECTED

4.1 Identification and contact data

When creating your account, we collect:

  • Email address (required for authentication and communications)
  • Dust.tt account identifier (linked to your Pivotalchat.ai account)
  • Username (if provided)
  • Profile information (if voluntarily provided)

4.2 Conversational data

As part of using the Service, we collect and store:

  • Conversation content: all your exchanges with AI models
  • Prompts and queries: your questions and instructions to AI models
  • Generated responses: responses provided by AI models
  • Conversation history: all your past interactions
  • Metadata: timestamp, AI model used, exchange length, conversation settings

Retention period: Conversations and history are retained as long as you do not delete them yourself. This functionality is an integral part of the Service and allows you to access your history at any time.

4.3 Technical and connection data

Automatically collected during your use of the Service:

  • Connection data: IP address, browser type, operating system
  • Usage data: pages viewed, features used, AI models requested, frequency of use, date and time of connection
  • Cookies and technical identifiers: see section 7

4.4 Payment data

For paid subscriptions:

  • Billing information: name, billing address
  • Banking data: processed directly by our payment provider (we do not store your complete banking data)

4.5 Dust.tt data

Your Dust.tt account and associated data are governed by Dust.tt's privacy policy. We receive from Dust.tt only the information necessary for the operation of the Service (account identifier, API settings).


5. PURPOSES AND LEGAL BASES OF PROCESSING

We process your personal data for the following purposes:

PurposeLegal basisData concerned
Account creation and managementContract performanceEmail, identifiers, Dust.tt link
Service provision (AI conversations)Contract performanceAll conversational data
History retentionContract performanceConversations, history
Subscription and payment managementContract performanceBilling data
Customer supportContract performance / Legitimate interestEmail, account data, conversations (if necessary)
Service improvementLegitimate interestUsage data, metadata
Anonymized statisticsLegitimate interestAnonymized usage data
Compliance with legal obligationsLegal obligationBilling data, logs
Security and fraud preventionLegitimate interestConnection data, logs
Transmission to Dust.tt for AI processingContract performancePrompts, queries, conversational context

Important: Your conversations are never used to:

  • Train AI models (Dust.tt "no training" guarantee)
  • Be resold to third parties
  • Feed marketing databases
  • Be commercially exploited by Kimind or Dust.tt

6. DATA RECIPIENTS

Your personal data is processed by:

6.1 Authorized Kimind staff

Only Kimind staff members who need access to your data in the course of their duties (technical support, development, security) have access to it.

6.2 Host

Lovable Labs Sweden AB, Tunnelgatan 5, 11137 Stockholm, Sweden (lovable.dev): Platform and data hosting

6.3 Main subcontractor: Dust.tt

Dust.tt receives and processes:

  • Your queries and prompts
  • The context of your conversations
  • Metadata necessary for processing

Guarantees:

  • Zero data retention by AI operators
  • No training: your data is not used to train models
  • HIPAA certification
  • GDPR compliance

6.4 AI model operators (via Dust.tt)

Your queries are transmitted by Dust.tt to the following operators, depending on the AI model you use:

  • OpenAI (GPT models)
  • Anthropic (Claude models)
  • Mistral AI (Mistral models)
  • Google (Gemini models)

Dust.tt contractual guarantees with these operators:

  • Zero data retention: no retention of your data
  • No training: your data is not used to improve their models
  • Immediate deletion after processing

6.5 Service providers

We use subcontractors for:

  • Payment processing (PCI-DSS compliant payment processor)
  • Sending transactional emails
  • Statistical analysis (anonymized data only)

All our subcontractors are carefully selected and contractually required to comply with GDPR.

6.6 Legal authorities

We may be required to communicate your data to competent authorities if required by law or to protect our legal rights.


7. COOKIES AND SIMILAR TECHNOLOGIES

7.1 Cookies used

The Service uses the following types of cookies:

Technical cookies (strictly necessary):

  • Authentication and session management
  • Link with your Dust.tt account
  • Service security
  • Language and interface preferences

Statistical cookies:

  • Audience and usage measurement (anonymized data)
  • User experience improvement
  • Service performance analysis

7.2 Cookies NOT used

Kimind does NOT use any:

  • Advertising cookies
  • Behavioral tracking cookies for commercial purposes
  • Third-party social media cookies
  • Invasive profiling mechanisms
  • Data resale cookies

7.3 Cookie management

You can manage your cookie preferences (except strictly necessary cookies) via:

  • Your account settings
  • Your browser settings

Refusing technical cookies may prevent the use of certain Service features, including linking with your Dust.tt account.


8. DATA RETENTION PERIOD

We retain your personal data for the following periods:

Type of dataRetention period
Active account dataAs long as the account is active
Conversations and historyUntil the user deletes them
Data after account deletion30 days (recovery period) then permanent deletion
Billing data10 years (legal accounting obligation)
Connection and security logs12 months maximum
Conversation metadataLinked to conversations (deleted with them)

History retention:
Retention of your conversation history is a Service feature. You can delete individual conversations or your entire history at any time from your account.

At Dust.tt and AI operators:
In accordance with "zero data retention" guarantees, your data is not retained by Dust.tt or AI operators (OpenAI, Anthropic, Mistral, Google) after processing each query.

At the expiration of indicated periods, your data is either permanently deleted or irreversibly anonymized.


9. DATA SECURITY

Kimind and Dust.tt implement appropriate technical and organizational measures to protect your personal data against:

  • Accidental loss
  • Unauthorized access
  • Fraudulent use
  • Unauthorized modification or disclosure

9.1 Kimind security measures

  • Encryption of data in transit (HTTPS/TLS)
  • Encryption of data at rest
  • Secure authentication
  • Strict access control
  • Regular security monitoring and audits
  • Backup procedures
  • Production environment isolation

9.2 Dust.tt security measures

  • HIPAA certification (healthcare data security standards)
  • End-to-end encryption
  • Multi-level secure architecture
  • Regular security audits
  • Compliance with international security standards

9.3 User-side security

Despite these measures, no data transmission over the Internet can be guaranteed as completely secure. You are responsible for:

  • The confidentiality of your login credentials (Pivotalchat.ai and Dust.tt)
  • The security of your equipment
  • Prudent use of the Service (not sharing ultra-sensitive information)

10. DATA TRANSFERS OUTSIDE THE EU

10.1 Main hosting

Your personal data is primarily hosted and processed within the European Union.

10.2 Transfers via Dust.tt

As part of processing by Dust.tt and AI operators, your data may transit or be temporarily processed outside the European Union, including:

  • In the United States (OpenAI, Anthropic, Google)
  • In other jurisdictions depending on Dust.tt's infrastructure

10.3 Protection guarantees

For all transfers outside the EU, we ensure that:

  • Appropriate safeguards are in place (EU Commission standard contractual clauses, adequacy decisions, etc.)
  • The level of protection of your data is equivalent to that of GDPR
  • "Zero data retention" and "no training" guarantees apply systematically
  • Dust.tt's HIPAA certification also covers these transfers

11. YOUR RIGHTS

In accordance with GDPR and the French Data Protection Act, you have the following rights:

11.1 Right of access

You can obtain confirmation that your data is being processed and access that data, including:

  • All your conversations
  • Your account data
  • Metadata of your interactions

11.2 Right of rectification

You can request correction of your inaccurate or incomplete data.

11.3 Right to erasure ("right to be forgotten")

You can request deletion of your data in certain cases (withdrawal of consent, objection to processing, unlawfully processed data, etc.).

History deletion:
You can delete your conversations and history at any time directly from your account, without contacting us.

11.4 Right to restriction of processing

You can request restriction of processing of your data in certain circumstances.

11.5 Right to data portability

You can receive your data (particularly your conversations) in a structured and commonly used format (JSON, CSV), and transmit it to another data controller.

11.6 Right to object

You can object to the processing of your data for legitimate reasons, particularly for processing based on legitimate interest.

11.7 Right to withdraw consent

Where processing is based on your consent, you can withdraw it at any time.

11.8 Right to define post-mortem directives

You can define directives regarding the fate of your data after your death.

11.9 Exercising your rights

To exercise your rights, contact us:

  • By email: rgpd@kimind.com
  • By mail: KIMIND - DPO, 17 rue du Colisée, 75008 Paris, France

We undertake to respond within a maximum period of one month from receipt of your request. This period may be extended by two months in case of complexity, in which case you will be informed.

Proof of identity may be requested to secure your request.

Export your conversations:
You can export your conversations at any time from your account settings, without contacting us.

11.10 Right to lodge a complaint

You have the right to lodge a complaint with the French National Commission for Information Technology and Civil Liberties (CNIL):

  • Website: www.cnil.fr
  • Address: 3 Place de Fontenoy - TSA 80715 - 75334 PARIS CEDEX 07
  • Phone: +33 1 53 73 22 22

12. PROCESSING PRINCIPLES

In accordance with GDPR, we undertake to:

  • Lawfulness, fairness, transparency: process your data lawfully, fairly and transparently
  • Purpose limitation: collect your data for determined, explicit and legitimate purposes (AI Service provision)
  • Data minimization: collect only adequate, relevant and necessary data
  • Accuracy: keep your data accurate and up to date
  • Storage limitation: retain your data only as long as necessary (or as long as you do not delete them for history)
  • Integrity and confidentiality: guarantee the security of your data through appropriate technical and organizational measures

13. NO-RESALE AND NO-TRAINING COMMITMENT

Kimind formally undertakes to:

  • Never sell your personal data to third parties
  • Never rent your personal data to third parties
  • Never share your data for third-party advertising or marketing purposes
  • Never use your conversations to train AI models
  • Only collect data strictly necessary for the operation of the Service

Dust.tt guarantees:

  • Zero data retention: no retention by AI operators
  • No training: your conversations never serve to train AI models (neither Dust.tt's, nor OpenAI's, Anthropic's, Mistral's or Google's)

Your data is used exclusively to provide you with the Service and improve it generally (anonymized statistics), never to train AIs or for any commercial exploitation of your content.


14. CONVERSATION CONFIDENTIALITY

14.1 Access to conversations

Your conversations are private and confidential. Kimind accesses your conversations only in the following strict cases:

  • Technical support: if you contact us for a problem and explicitly ask us to examine a specific conversation
  • Legal obligation: if required by a competent judicial authority
  • Security: in case of suspected fraudulent or illegal use

Outside these cases, your conversations are never consulted by our staff.

14.2 Automated processing only

Conversations transit through our servers in an automated manner to be transmitted to Dust.tt and returned. No manual processing or human consultation is performed in the normal course of the Service.

14.3 Data sensitivity

Important recommendation: Although we implement robust security measures, we recommend that you do not share in your conversations:

  • Ultra-sensitive medical information
  • Passwords or access codes
  • Complete credit card numbers
  • Personal data of third parties without their consent
  • Critical industrial or commercial secrets

15. MINORS

The Service is not intended for minors under 16 years of age. We do not knowingly collect personal data from minors. If you are a parent or legal guardian and discover that your child has provided us with personal data, contact us at rgpd@kimind.com so we can delete it.


16. PRIVACY POLICY MODIFICATIONS

We may modify this Privacy Policy at any time to reflect:

  • Service developments
  • Legal or regulatory changes
  • Changes to our subcontractors (particularly Dust.tt)
  • Improvements to our data protection practices

Any substantial modification will be notified to you by email and/or via the Service at least 30 days before it takes effect. The date of last update is indicated at the top of this document.

In case of change concerning Dust.tt or AI operators, we will inform you as soon as possible.

We encourage you to regularly consult this Privacy Policy.


17. CONTACT

For any questions regarding this Privacy Policy or the processing of your personal data:

Data Protection Officer:
Email: rgpd@kimind.com

KIMIND
17 rue du Colisée
75008 Paris, France
Email: legal@kimind.com
Phone: +33 1 75 43 82 33

For questions related to Dust.tt:
Visit their privacy policy: https://dust.tt/home/platform-privacy


18. TRANSPARENCY AND GDPR COMPLIANCE

Kimind is committed to complete transparency regarding the processing of your personal data. This Privacy Policy aims to inform you clearly and accessibly about:

  • The data we collect
  • The reasons for this collection
  • The role of Dust.tt and AI operators
  • "Zero data retention" and "no training" guarantees
  • Who has access to your data
  • Your rights and how to exercise them

We regularly conduct GDPR compliance audits and update our practices to ensure the highest level of protection for your personal data.


19. AI-SPECIFIC FEATURES

19.1 Nature of processing

Processing of your conversations by AI models occurs in real-time. Your queries are:

  1. Transmitted to Dust.tt
  2. Processed by the selected AI model
  3. Returned immediately
  4. Deleted immediately after processing by Dust.tt and AI operators (zero data retention)

19.2 No machine learning on your data

Absolute guarantee: Your conversations are never used to:

  • Train AI models (OpenAI, Anthropic, Mistral, Google)
  • Improve Dust.tt algorithms
  • Feed learning databases
  • Create user profiles for AI

19.3 Data isolation

Each conversation is processed in isolation. Your data is never:

  • Shared with other users
  • Used to improve other users' experience
  • Aggregated with data from other users for AI training

19.4 Certification and audit

  • Dust.tt is HIPAA certified, guaranteeing the highest level of security and confidentiality
  • Regular audits are conducted to verify compliance with "zero data retention" and "no training" guarantees
  • Kimind performs regular checks of Dust.tt's compliance

20. PROCESSING REGISTER

In accordance with Article 30 of GDPR, Kimind maintains a register of processing activities. You can obtain a copy by contacting rgpd@kimind.com.


21. IMPACT ASSESSMENT (DPIA)

A data protection impact assessment (DPIA) has been conducted for the Pivotalchat.ai Service, given the potentially sensitive nature of conversations. This DPIA is available upon request at rgpd@kimind.com.


Last updated: February 15, 2026