Your data and your clients’ data

Privacy Policy

Last updated September 18, 2026 · Version 2026-09-18
The date above is the version your account is bound by. Questions: legal@kavvim.com.

What personal information we collect, why, how we use it, and the rights you and your clients have over it.

Two different relationships

Kavvim LLC (“Kavvim,” “we,” “us”) provides studio management software to interior design businesses in the United States. This policy explains what we collect, why, and what you can do about it. How it applies depends on who you are.

  • If you are a Kavvim customer or a user at a customer studio, we are the business responsible for your personal information, and this policy governs it directly.
  • If you are a client of a studio that uses Kavvim, the studio decides what information about you goes into the Service and why. We process it on the studio’s behalf, under their instructions. Contact the studio you work with for questions about your information, or to request access or deletion. We will assist them in responding. Our handling of that information is governed by our Data Processing Addendum with the studio.

1. Information we collect

Account information you give us: name, email address, password (stored only as a cryptographic hash), job title, display preferences, time zone, and optionally a profile photograph. For the studio: business name, address, industry, currency, and logo.

Billing information: billing name and email, subscription and seat details, and payment card metadata, meaning brand, last four digits, expiration, and cardholder name. We never receive or store full card numbers or security codes. Those go directly from your browser to Stripe.

Content you put into the Service: projects, tasks, items, vendors, schedules, time entries, invoices, presentations, messages, files, and images. Much of this is information about your clients, including their names, contact details, home addresses, and photographs of their properties.

Employment and rate information where a studio records it: hourly rates, overtime rates, weekly capacity, and time entries.

Usage and technical information: authentication events, last login time, audit records of changes made in the Service, and AI usage metering.

Error reports. When something goes wrong, our software sends a diagnostic report to a third-party error monitoring provider so we can find and fix the fault. A report contains the error, a stack trace, your browser and operating system, and the sequence of actions leading up to it. It can include your user identifier and the page or screen you were on. We configure it not to send request contents, form values, cookies, or your IP address.

IP addresses are used transiently for rate limiting and abuse prevention. They are not stored in our database.

Approximate location, only if you allow it. The first time you click into an address field, your browser may ask whether you want to share your location. This is your browser’s own prompt, not ours, and you can decline. If you allow it, we round the coordinates to roughly 100 meters and send them to our address autocomplete provider as a ranking hint, so nearby addresses appear first in the suggestions. It does not change which addresses can be found, only their order.

The location is held in your browser’s memory for that page visit only. It is never written to our database, never logged, and never stored in a cookie or in local storage. It is discarded when you close the tab. If you decline, or if your browser cannot determine a location, address autocomplete works exactly as before. You can change or revoke the permission at any time in your browser’s site settings.

What we do not collect: we do not use analytics, advertising, session replay, or behavioral tracking of any kind. There is no Google Analytics, no advertising pixel, and no tag manager anywhere in the Service. We do not collect precise location, do not track location in the background or continuously, do not collect location anywhere other than address fields, and do not use location for analytics, advertising, or profiling.

2. How we use information

To provide and operate the Service; to authenticate you and secure your account; to process payments and manage subscriptions; to send transactional email; to provide support; to detect and prevent abuse and fraud; to comply with law; and to improve the Service through aggregate operational metrics.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have never done so.

We do not train AI models on your data, and we do not permit our AI providers to. See Section 4.

3. Legal basis and consent

We process your account and content data to perform our contract with you. We process security and abuse-prevention data on the basis of our legitimate interest in operating a safe service.

We rely on your consent for approximate location, which is collected only through your browser’s own permission prompt and can be revoked at any time in your browser’s site settings.

AI features are enabled by default and are described in Section 4. A studio administrator can disable any or all of them at account setup or later in Settings.

4. Artificial intelligence

Optional AI features transmit content to third-party providers. Which content, and when:

FeatureProviderWhat is sent
Studio assistantAnthropicYour questions, plus data the assistant retrieves to answer them, which may include client names, contact details, addresses, and notes
Presentation generationGoogle, AnthropicDeck topic, audience, notes, and page content, plus the project photographs the feature is pointed at
Image captioningGoogleThe image itself
Image editingGoogleThe target image and any reference images
Background removalPhotoroomThe image being cut out, which is typically a product, furniture, or project interior photograph

AI features are on by default. We show you what each one transmits during account setup, and a studio administrator can disable any or all of them at that point or later in Settings → AI. Turning them off does not affect any other part of the Service.

No AI provider we use is permitted to train on your content. For Anthropic and Google this is a term of our commercial agreements with them. For Photoroom it is an account setting we have enabled. Content is retained by providers only briefly, for abuse detection or for the duration of the request, per their published terms. We record which categories of data each AI request included, so we can tell you what was sent.

If you are a studio, consider whether your agreements with your clients permit this before leaving these features on. That assessment is yours.

5. Who we share information with

Service providers (subprocessors). We use vendors to operate the Service. Each is bound by a written agreement limiting them to processing on our instructions. The current list, with what each receives, is published on our Subprocessors page and incorporated here. We do not use advertising networks, and we do not run product-analytics or help-desk software that receives your data.

Your studio. If you are a user at a studio, your studio administrators can see your account information, your activity in the Service, and audit records of your changes.

Legal and safety. We may disclose information where required by law, valid legal process, or to protect the rights, safety, or property of Kavvim, our customers, or the public. Where we are permitted to notify you, we will.

Business transfer. If Kavvim is acquired or merges, information may transfer as part of that transaction. We will notify you and the successor will be bound by commitments no less protective than these.

We do not disclose personal information to any third party for that party’s own marketing purposes.

6. Where information is processed

Kavvim operates entirely within the United States. Our application servers, database, object storage, and backups are located in the United States. We do not currently offer data residency outside the US, and we do not market the Service outside the US.

If you are outside the United States, understand that using the Service involves transferring your data to the United States.

Our subprocessors may process information in other locations under their own terms; each is identified on our Subprocessors page.

7. Retention

DataRetained for
Account and content data, active subscriptionDuration of the subscription
Account and content data, after a deletion request30-day export window, then 90 days retained, then permanently deleted (120 days total)
Account and content data, after a subscription ends365-day export window, then permanently deleted
Audit logs18 months live, then archived; archives retained 7 years
Data exports you generate3 days
Error and diagnostic reports90 days with our monitoring provider
Approximate locationNot retained. Held in browser memory for the page visit only
Background-removal resultsCached in our object storage for the life of the studio account, then deleted with the account
Sales enquiries from our website24 months
Refresh tokens30 days
Verification, reset, and MFA tokensMinutes to 24 hours, per type
Financial recordsAs required by tax and accounting law

Records soft-deleted within the Service, meaning archived projects and clients, are permanently deleted after 24 months. We notify studios before that runs.

You can start the deletion timeline yourself at any time from Settings → Closing your account, and cancel it from the link in the confirmation email at any point before the deletion date. We email you the exact dates when a timeline starts, and again before it runs out.

To ask a question about any of this, email privacy@kavvim.com.

8. Security

We describe our technical and organizational measures on our Security page, which states plainly both what is implemented and what is not. In summary: encryption of sensitive fields at rest using AES-256-GCM with key management through AWS KMS; a zero-knowledge credential vault where we cannot decrypt what you store; BCrypt password hashing with an enforced complexity policy; short-lived signed access tokens with rotating refresh tokens; optional multi-factor authentication; row-level tenant isolation; rate limiting on authentication; and audit logging of changes.

No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you without undue delay and in any event within 72 hours of confirming it, and will provide what we know about scope, impact, and remediation.

9. Your rights

Residents of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have rights that vary by state but generally include:

  • Know and access - what we hold about you and how we use it.
  • Correct - inaccurate personal information.
  • Delete - your personal information, subject to legal retention.
  • Portability - a copy in a portable format.
  • Opt out of sale or sharing - we do not sell or share, so there is nothing to opt out of, but the control exists.
  • Non-discrimination - we will not treat you worse for exercising a right.

How to exercise them. Email privacy@kavvim.com from the address on your account, or use the controls in Settings. We respond within 45 days, extendable once by another 45 where necessary, and will tell you if we need more time.

If you have a Kavvim account, you can record the opt-out yourself: sign in and use “Do Not Sell or Share My Info” at the bottom of the app. It is stored against your account rather than in your browser, so it survives clearing your site data and applies on every device you sign in from. If you do not have an account, email privacy@kavvim.com and we will record it for you.

Global Privacy Control. We honor the GPC browser signal as a valid opt-out of sale and sharing. If the browser you sign in with sends one, we record the same opt-out on your account without waiting for you to click anything, we do not re-date a record you already have, and we will not let it be withdrawn while the signal is still being sent.

Verification. We will verify your identity before acting on a request, usually by confirming control of the account email. For deletion requests we may require additional confirmation.

Authorized agents may submit requests on your behalf with written authorization; we may contact you to confirm.

If you are a client of a studio, direct your request to that studio. They control the information and decide how it is used. We will help them fulfill it.

Appeals. If we deny a request, you may appeal by replying to our response or writing to privacy@kavvim.com with “Appeal” in the subject. We will respond within 45 days. If we deny the appeal, residents of certain states may contact their state Attorney General.

10. Children

The Service is a business tool and is not directed to anyone under 18. We do not knowingly collect information from children. If we learn we have, we will delete it. Contact privacy@kavvim.com.

11. Changes

We may update this policy. For material changes we will give at least 30 days’ notice by email and in-app, and ask you to acknowledge the new version. The version and effective date are shown at the top, and prior versions are available on request.

12. Contact

Privacy questions and requests: privacy@kavvim.com. Postal mail: Kavvim LLC, 180 Woodbury St, Apt 328, Manchester, NH 03102.

Document history

2026-09-18First published version of all nine documents. (current)
Related