Last updated: May 2026
RIDING BYTES GmbH (“we”, “us”) develops Kaisho (“Software”) and operates the optional Kaisho hosted service. This policy explains what personal data we collect, why, and how we protect it.
1. Who We Are
RIDING BYTES GmbH
Registered in Germany
Contact: info@ridingbytes.com
2. What Data We Collect
Kaisho is local-first. When you run it fully self-hosted, no data is sent to us — your tasks, time entries, customer data, and everything else stay on your device and your own infrastructure.
If you subscribe to a hosted plan (Companion, Pro, or Team) or buy a token pack, we collect:
Account email and a hashed password — to sign you in and send essential service communications.
A hashed API key — to authenticate your desktop app and mobile companion to the hosted sync and AI gateway.
Data you choose to sync — tasks, time entries, customers, and notes you sync to the hosted service are stored in our database so they are available across your devices.
AI prompts and context — when you use the hosted AI features, the relevant text is sent to our AI provider to generate a response; we store per-month token usage for metering.
Connected integrations (Pro) — access tokens for services you connect (Google Calendar, Slack, Linear, GitHub) are stored encrypted so the advisor can act on your behalf.
Stripe customer and subscription ID — for billing (we never store card numbers).
3. Cookies and Tracking
The Kaisho application uses no analytics or tracking cookies. The website (kaisho.dev) uses no analytics or advertising cookies.
4. Data Processors
To run the hosted service we use Supabase (database and authentication hosting), our AI model provider (to process the prompts you send to the hosted AI features), and Stripe (payment processing). Where you connect integrations, the respective provider (Google, Slack, Linear, GitHub) processes the requests you trigger. Each processor’s own privacy terms govern the data they handle. We do not sell, rent, or share your data with any third party for advertising.
5. Data Retention
Account and synced data are retained while your subscription is active. If you cancel or delete your account, your synced data and personal data are removed within 30 days, except where retention is required by law. You can delete synced entries at any time from the app.
6. Your Rights (GDPR)
If you are in the EEA, you have the right to access, correct, or delete personal data we hold about you. Contact: info@ridingbytes.com
7. Security
All communications are over TLS. Passwords and API keys are stored as hashes, and connected-integration credentials are encrypted at rest.
8. Changes
Material changes will be communicated via email. The “Last updated” date reflects the current version.
9. Contact
Questions? info@ridingbytes.com