Privacy Policy

Effective 10 August 2026 Last updated 10 August 2026 Version 1.0

Kinobi builds a graph of companies and the people who make buying decisions at them, from public sources. That means we process personal data about people who never signed up with us. This page explains exactly what we hold, why we believe we are allowed to, and how you get it removed.

On this page
  1. Who we are
  2. The short version
  3. Data about visitors and customers
  4. Data about business contacts in the Kinobi graph
  5. Where graph data comes from
  6. Why we are allowed to process it
  7. Who we share data with
  8. How long we keep it
  9. Your rights, and how to use them
  10. International transfers
  11. Security
  12. Changes to this policy
  13. Contact

1. Who we are

Kinobi is a B2B sales-intelligence product operated by Kinobi, Inc., a Delaware corporation (“Kinobi”, “we”, “us”), with its principal place of business at 11 Franklin St, San Francisco, CA 94102, United States.

For people in the UK, EU, or Switzerland, Kinobi is the data controller for the business-contact data in our graph, and a processor for data our customers upload or ask us to enrich on their behalf.

2. The short version

QuestionAnswer
Do you track me on this website?No. This site loads no analytics, no advertising pixels, and no third-party cookies. Our Content-Security-Policy blocks third-party scripts outright, so this is enforced, not just promised.
Do you set cookies?The marketing site sets none. The signed-in product uses strictly necessary cookies for authentication only.
Do you hold data about me even if I never signed up?Possibly, if you are named publicly in a work context — see section 4.
Do you sell personal data?We do not sell data to advertisers or data brokers. But we do make business-contact records available to our customers, and under California law that can count as a “sale” or “sharing”. We treat it as such and honour opt-outs — see section 9.
How do I get removed?Submit a removal request. We action verified requests within 30 days and suppress your identifiers so you are not re-added.
Do you use my data to train AI models?We use third-party language models to read and structure public web pages. We do not sell or license data for third-party model training, and our providers are contractually barred from training on our API inputs.

3. Data about visitors and customers

What we collect

What we do with it

We use it to respond to your request, plan the engagement, give you access, keep the service secure, and — if you asked for it — send product updates. Every marketing email has a one-click unsubscribe. We do not add customer contact details to the company graph.

Legal basis (UK/EU): performance of a contract for account and support data; legitimate interests for security and service communications; consent for marketing email, withdrawable at any time.

4. Data about business contacts in the Kinobi graph

This is the part that matters most, and the part most companies in our category bury. Kinobi maintains a graph of organisations and the people associated with them in a professional capacity. If you are publicly identified as working somewhere — on a company team page, a conference speaker list, a regulatory filing, or a public professional profile — you may be in it.

Categories of personal data we may hold

CategoryExamples
Professional identityName; current job title, function, level, and department; employer; work location
Business contact detailsWork email address; work phone number, where published
Public professional linksProfessional network profile URL, public code-hosting username, personal or professional website
Career historyPrevious employers and titles, role start dates, publicly listed education
Role changesTitle changes and departures, where publicly announced
Derived dataA short profile summary and a numeric vector (“embedding”) generated from the above, used for search; an assessment of whether the role is likely to be a decision-making one
ProvenanceThe source URL and timestamp for every fact, so any record can be traced back and checked
What we deliberately do not do

We do not collect special-category data (health, race, religion, political opinions, sexual orientation, trade-union membership, biometrics) and we do not want it. We do not collect personal email addresses, home addresses, or personal phone numbers. We do not scrape content behind a login, paywall, or CAPTCHA, and we do not buy contact lists from data brokers. We do not build profiles of private individuals acting outside a professional context.

If you find any of the above in a Kinobi record, that is a defect as well as a rights issue — please tell us and we will remove it and fix the source.

5. Where graph data comes from

Every fact in the graph carries the URL it came from and the date it was read. Our sources are:

We collect only from publicly accessible pages. If you are responsible for a site and would rather we did not collect from it at all, email the domain to ankit@kinobi.so and we will stop and delete what we hold — see how to opt out.

6. Why we are allowed to process it

UK/EU (UK GDPR and GDPR): we rely on legitimate interests under Article 6(1)(f) — our interest, and our customers’, in identifying relevant business counterparties, balanced against your rights. We have assessed that balance: the data is professional rather than private, it is already public, it is limited to what a business context requires, we hold no special-category data, we publish exactly what we hold, and we make objection easy and unconditional. We will share our legitimate-interests assessment on request.

Because we obtain this data from sources other than you, Article 14 requires that we tell you. This page, our removal page, and the notice we include when a record is first surfaced are how we do that. If you would rather we did not process your data at all, you have an absolute right to object where it is used for direct marketing, and we will honour it without asking why.

California (CCPA/CPRA): we collect the categories of personal information described in section 4 for the business purposes described in this policy. Making business-contact records available to our customers may constitute a “sale” or “sharing” as those terms are defined by the CPRA. You may opt out at any time via Do Not Sell or Share My Personal Information. We do not knowingly collect information about anyone under 16, and therefore do not sell or share it.

7. Who we share data with

We do not sell data to advertisers or data brokers. We share personal data with:

8. How long we keep it

DataRetention
Sales and early-access contactUntil you unsubscribe or ask us to delete it, or 24 months after the last contact
Account dataFor the life of the account, then 90 days
Server logs30 days
Graph contact recordsWhile the underlying source remains public and the record stays current; re-verified periodically and removed when the source disappears
Suppression listIndefinitely — a one-way hash of your identifiers, kept for the sole purpose of never re-adding you

9. Your rights, and how to use them

Wherever you live, and whether or not you are our customer, you can ask us to:

Use the data request form, or email ankit@kinobi.so with “Data request” in the subject. We respond within 30 days (extendable once by 60 days for complex requests, with notice). We do not charge for this. We may ask for enough information to confirm the request really is about you — we will ask for the minimum needed, and we delete verification material afterwards.

You can also authorise someone to act for you. If we cannot verify an authorised agent, we will tell you why.

If we get it wrong, you can complain to your data-protection regulator — in the UK the ICO, in the EU your national supervisory authority. We would rather you told us first: ankit@kinobi.so.

10. International transfers

We are based in the United States and our infrastructure is hosted there. If you are in the UK, EU, or Switzerland, your personal data is transferred to the US. We rely on the UK and EU Standard Contractual Clauses (with the UK International Data Transfer Addendum where applicable) with each of our subprocessors, plus the supplementary measures described on our Trust page.

11. Security

Data is encrypted in transit (TLS 1.2+) and at rest. Access to production data is limited to those who need it, requires multi-factor authentication, and is logged. Secrets are held in a managed secret store, never in source control. We run automated dependency and vulnerability scanning on every change.

We are an early-stage company and we will not pretend to certifications we do not hold — see the Trust page for exactly where we are on SOC 2 and what compensating controls we run today. To report a vulnerability, see security.txt.

12. Changes to this policy

We version this page and keep the date at the top current. For any change that materially affects your rights, we will announce it here at least 14 days before it takes effect, and email registered users.

13. Contact

Privacy contact: ankit@kinobi.so

Post: Kinobi, Inc., 11 Franklin St, San Francisco, CA 94102, United States

Fastest route for removal: kinobi.so/data-request