Your data stays yours. Kaen only reads it.
Read-only access, encryption in transit and at rest, and nothing ships without your approval. Here is exactly how.
- GDPR · DPA published
- Data hosted in the EU
- Read-only access
- No training on your data
What Kaen does. What Kaen never does.
What Kaen does
- Reads your analytics, read-only
GA4 or PostHog connect through OAuth under your own account. We ask for the narrowest scope that is enough, and you can revoke it in your Google or PostHog settings at any time.
- Encrypts in transit and at rest
TLS on every connection; storage encrypted at rest with our suppliers. Findings, reports and leads live in Supabase in Frankfurt.
- Keeps findings, not raw data
We store what the analysis derived, not copies of your datasets. Where aggregated or pseudonymised data is enough, that is what we use.
- Names every person with access
Individual named accounts with two-factor authentication where the tool supports it, access logged and reviewed, removed when the engagement ends.
- Waits for your approval
Every hypothesis and every experiment is proposed in your shared channel and waits for your yes. He asks before anything he can’t undo.
What Kaen never does
- Never trains on your data
Analysis runs on models from Anthropic and OpenAI under commercial terms that exclude training on inputs. We send the smallest slice the analysis needs, and no contact details unless the analysis requires them.
- Never touches your codebase
Kaen writes the brief. Your developer or agency ships the change. We do not need, and do not ask for, write access to your site, product or repository.
- Never shares between customers
Each customer’s data and findings are separate. Nothing from one engagement is reused for another.
- Never sees your card
Payments go through Stripe. Card numbers never reach our systems.
- Never keeps data after you leave
Access is removed when the engagement ends and the data we hold is deleted within 30 days, or returned first if you ask.
How we use AI, in plain words
Kaen is an AI growth buddy. That raises questions a spreadsheet never did, so here are the answers.
- Which models
Large language models from Anthropic (Claude) and OpenAI, chosen per task. Every provider we use is on our public subprocessor list with its location and safeguards, and we announce a change 30 days ahead.
- No training on your inputs
Under both providers’ commercial terms, what we send is not used to train their models. This is contractual, not a setting we hope stays on.
- Credentials stay out of the model
Access tokens live in our systems. The model receives query results and writes findings; it never holds your keys and cannot connect to anything on its own.
- Approval before action
The model proposes. It does not push changes, does not run experiments and does not message your customers. A person on your side approves every step.
Where your data goes, step by step
The loop Kaen runs, with what leaves your systems at each step.
- 01
Connect
You grant read-only access to GA4 or PostHog with OAuth, under your own account. Credentials stay in our backend; the model never sees them.
- 02
Analyse
Kaen queries your funnel and sends the minimum the analysis needs to the model. Aggregated and pseudonymised data first, raw records only when nothing else works.
- 03
Store the findings
Derived findings, cases and reports are stored in Supabase in the EU (Frankfurt), encrypted at rest. Report pages are served by Vercel.
- 04
You decide
The case lands in your Slack channel and waits for your approval. Your team ships it. Kaen measures the result from the same read-only data.
Found a vulnerability?
We would rather hear about it from you than read about it. Write to hello@kaen.cz with “Security report” in the subject.
In scope
- kaen.cz and its subdomains
- Customer report pages we serve
- Our API endpoints
What we do
- Acknowledge your report within 5 business days
- Keep you updated while we investigate and fix
- Credit you publicly if you want, once the fix is live
What we ask
- Don’t access, change or delete data that isn’t yours
- No denial of service, no social engineering, no physical attempts
- Give us reasonable time to fix before you publish
If you follow these rules in good faith, we will not take legal action against you. We do not run a paid bounty programme.
Send a security reportCompliance and infrastructure
What is in place, what is published, and what we do not claim.
- GDPR In place
- Data Processing Agreement under Art. 28(3) GDPR, accepted by using the service. We sign a copy on request.
- Data Processing Agreement
- Subprocessors Published
- Public list with purpose, location and safeguards for every supplier. Changes announced 30 days ahead, with a right to object.
- Subprocessor list
- Data residency In place
- Database, authentication and storage in the EU (Supabase, Frankfurt). Product analytics and transactional e-mail in EU regions. Suppliers outside the EEA are covered by standard contractual clauses.
- Subprocessor list
- Breach notification In place
- You hear from us without undue delay, at the latest within 48 hours of us becoming aware, with the information we have.
- DPA, clause 6
- Deletion In place
- Access removed when the engagement ends; data deleted within 30 days, or returned if you ask in that period. Delivered reports stay with you.
- DPA, clause 8
- Audit In place
- Once per calendar year on 30 days’ notice; more often after an incident or when a supervisory authority asks.
- DPA, clause 9
- Payments In place
- Handled by Stripe, a PCI DSS Level 1 provider. Card data never enters Kaen’s systems.
- Terms of Service
- SOC 2 / ISO 27001 Not certified
- Not certified. We are a small team and say so rather than imply otherwise. Ask us and we will walk you through the controls above in detail.
- hello@kaen.cz
FAQ
Does Kaen need write access to anything?
No. Analysis runs on read-only access to your analytics, granted under your own account. Changes and test variants are shipped by your developer or agency from the brief Kaen writes.
Is our data used to train AI models?
No. Analysis runs on models from Anthropic and OpenAI under commercial terms that exclude training on inputs, and we send only the slice the analysis needs, aggregated or pseudonymised wherever possible.
Where is our data stored?
Findings, reports and account data live in Supabase in Frankfurt, encrypted at rest. Product analytics of kaen.cz runs on PostHog’s EU cloud. The full list of suppliers, with locations, is on the subprocessor page.
Who at Kaen can see our data?
Only named people working on your engagement, each with an individual account and two-factor authentication where the tool supports it. Access is logged, reviewed and removed when the engagement ends.
Can we revoke access ourselves?
Yes. The OAuth grant lives in your Google or PostHog settings, so you can revoke it any time without asking us. Access to your Slack channel or other tools is yours to remove as well.
What happens when we stop working together?
We remove our access without undue delay and delete the data we hold within 30 days, or return it first if you ask within that period. Reports and cases already delivered stay with you.
Do you sign a DPA?
The DPA is published and accepted by using the service, so no signature is needed. If your process needs a signed copy, ask and we sign one.
Can we send you a security questionnaire?
Yes. We do not hold a SOC 2 or ISO 27001 certificate and will say so in the answers, and we will describe the controls we do have in as much detail as you need.
What if a subprocessor changes?
We update the public list and e-mail you at least 30 days before the change. You can object on data protection grounds, and if we cannot find a solution you can end the affected part of the service without penalty.