Your data stays yours. Kaen only reads it.

Read-only access, encryption in transit and at rest, and nothing ships without your approval. Here is exactly how.

  • GDPR · DPA published
  • Data hosted in the EU
  • Read-only access
  • No training on your data

What Kaen does. What Kaen never does.

What Kaen does

  • Reads your analytics, read-only

    GA4 or PostHog connect through OAuth under your own account. We ask for the narrowest scope that is enough, and you can revoke it in your Google or PostHog settings at any time.

  • Encrypts in transit and at rest

    TLS on every connection; storage encrypted at rest with our suppliers. Findings, reports and leads live in Supabase in Frankfurt.

  • Keeps findings, not raw data

    We store what the analysis derived, not copies of your datasets. Where aggregated or pseudonymised data is enough, that is what we use.

  • Names every person with access

    Individual named accounts with two-factor authentication where the tool supports it, access logged and reviewed, removed when the engagement ends.

  • Waits for your approval

    Every hypothesis and every experiment is proposed in your shared channel and waits for your yes. He asks before anything he can’t undo.

What Kaen never does

  • Never trains on your data

    Analysis runs on models from Anthropic and OpenAI under commercial terms that exclude training on inputs. We send the smallest slice the analysis needs, and no contact details unless the analysis requires them.

  • Never touches your codebase

    Kaen writes the brief. Your developer or agency ships the change. We do not need, and do not ask for, write access to your site, product or repository.

  • Never shares between customers

    Each customer’s data and findings are separate. Nothing from one engagement is reused for another.

  • Never sees your card

    Payments go through Stripe. Card numbers never reach our systems.

  • Never keeps data after you leave

    Access is removed when the engagement ends and the data we hold is deleted within 30 days, or returned first if you ask.

How we use AI, in plain words

Kaen is an AI growth buddy. That raises questions a spreadsheet never did, so here are the answers.

  • Which models

    Large language models from Anthropic (Claude) and OpenAI, chosen per task. Every provider we use is on our public subprocessor list with its location and safeguards, and we announce a change 30 days ahead.

  • No training on your inputs

    Under both providers’ commercial terms, what we send is not used to train their models. This is contractual, not a setting we hope stays on.

  • Credentials stay out of the model

    Access tokens live in our systems. The model receives query results and writes findings; it never holds your keys and cannot connect to anything on its own.

  • Approval before action

    The model proposes. It does not push changes, does not run experiments and does not message your customers. A person on your side approves every step.

Where your data goes, step by step

The loop Kaen runs, with what leaves your systems at each step.

  1. 01

    Connect

    You grant read-only access to GA4 or PostHog with OAuth, under your own account. Credentials stay in our backend; the model never sees them.

  2. 02

    Analyse

    Kaen queries your funnel and sends the minimum the analysis needs to the model. Aggregated and pseudonymised data first, raw records only when nothing else works.

  3. 03

    Store the findings

    Derived findings, cases and reports are stored in Supabase in the EU (Frankfurt), encrypted at rest. Report pages are served by Vercel.

  4. 04

    You decide

    The case lands in your Slack channel and waits for your approval. Your team ships it. Kaen measures the result from the same read-only data.

Found a vulnerability?

We would rather hear about it from you than read about it. Write to hello@kaen.cz with “Security report” in the subject.

In scope

  • kaen.cz and its subdomains
  • Customer report pages we serve
  • Our API endpoints

What we do

  • Acknowledge your report within 5 business days
  • Keep you updated while we investigate and fix
  • Credit you publicly if you want, once the fix is live

What we ask

  • Don’t access, change or delete data that isn’t yours
  • No denial of service, no social engineering, no physical attempts
  • Give us reasonable time to fix before you publish

If you follow these rules in good faith, we will not take legal action against you. We do not run a paid bounty programme.

Send a security report

Compliance and infrastructure

What is in place, what is published, and what we do not claim.

GDPR In place
Data Processing Agreement under Art. 28(3) GDPR, accepted by using the service. We sign a copy on request.
Data Processing Agreement
Subprocessors Published
Public list with purpose, location and safeguards for every supplier. Changes announced 30 days ahead, with a right to object.
Subprocessor list
Data residency In place
Database, authentication and storage in the EU (Supabase, Frankfurt). Product analytics and transactional e-mail in EU regions. Suppliers outside the EEA are covered by standard contractual clauses.
Subprocessor list
Breach notification In place
You hear from us without undue delay, at the latest within 48 hours of us becoming aware, with the information we have.
DPA, clause 6
Deletion In place
Access removed when the engagement ends; data deleted within 30 days, or returned if you ask in that period. Delivered reports stay with you.
DPA, clause 8
Audit In place
Once per calendar year on 30 days’ notice; more often after an incident or when a supervisory authority asks.
DPA, clause 9
Payments In place
Handled by Stripe, a PCI DSS Level 1 provider. Card data never enters Kaen’s systems.
Terms of Service
SOC 2 / ISO 27001 Not certified
Not certified. We are a small team and say so rather than imply otherwise. Ask us and we will walk you through the controls above in detail.
hello@kaen.cz

FAQ

Does Kaen need write access to anything?

No. Analysis runs on read-only access to your analytics, granted under your own account. Changes and test variants are shipped by your developer or agency from the brief Kaen writes.

Is our data used to train AI models?

No. Analysis runs on models from Anthropic and OpenAI under commercial terms that exclude training on inputs, and we send only the slice the analysis needs, aggregated or pseudonymised wherever possible.

Where is our data stored?

Findings, reports and account data live in Supabase in Frankfurt, encrypted at rest. Product analytics of kaen.cz runs on PostHog’s EU cloud. The full list of suppliers, with locations, is on the subprocessor page.

Who at Kaen can see our data?

Only named people working on your engagement, each with an individual account and two-factor authentication where the tool supports it. Access is logged, reviewed and removed when the engagement ends.

Can we revoke access ourselves?

Yes. The OAuth grant lives in your Google or PostHog settings, so you can revoke it any time without asking us. Access to your Slack channel or other tools is yours to remove as well.

What happens when we stop working together?

We remove our access without undue delay and delete the data we hold within 30 days, or return it first if you ask within that period. Reports and cases already delivered stay with you.

Do you sign a DPA?

The DPA is published and accepted by using the service, so no signature is needed. If your process needs a signed copy, ask and we sign one.

Can we send you a security questionnaire?

Yes. We do not hold a SOC 2 or ISO 27001 certificate and will say so in the answers, and we will describe the controls we do have in as much detail as you need.

What if a subprocessor changes?

We update the public list and e-mail you at least 30 days before the change. You can object on data protection grounds, and if we cannot find a solution you can end the affected part of the service without penalty.

Want to see how it works with your data?

Thirty minutes, free and with no obligation. Bring your security questions; we answer them on the call.

Book demo