OneKit

Legal

Privacy Policy

Effective date: April 19, 2026  ·  Last updated: September 9, 2026

OneKit is operated by AISquads LLC, a California limited liability company ("AISquads," "we," "us," or "our"). This Privacy Policy explains how we collect, use, share, and protect information about you when you use the OneKit desktop application and any related services (collectively, the "Service"). By using the Service you agree to this policy.

1. Information We Collect

Account Information

When you sign up, we collect your email address to create and manage your account. We use Supabase for authentication and data storage.

Connected Service Credentials

When you connect third-party services (Gmail, X/Twitter, LinkedIn, Instagram, TikTok, YouTube, Google Calendar), we store OAuth access and refresh tokens on your behalf so OneKit can act on your instructions. We also store your platform user ID and display name for each connected service so we can show you which account is linked. We never store your passwords for these services. Disconnecting removes the selected connection and its stored credentials. Other connections to the same account may remain active; disconnecting a feature is different from deleting your OneKit account or the content created through it. See "Google: Gmail, Contacts, and Calendar" and "Data Retention" below.

Content You Create or Import

We store content you create or import through the Service, including contacts and email addresses you upload, email drafts and sent-email records, social media posts you compose, meeting notes and voice transcriptions, and documents you upload for processing.

E-Signature Records

When E-Signatures is used, we process the uploaded document, envelope and recipient details, field values, drawn or typed signature images, signing and viewing timestamps, IP address, browser/device information, audit events, document hashes, and completion-email and signed-copy download events. A recipient does not need a OneKit account to sign a document sent to them.

Kit Conversations

Your conversations with Kit are stored in your account so they sync between your devices and stay searchable. To improve OneKit, members of our team may read conversations from accounts that have left sharing on (it is on by default; you are told this the first time you use the app and can turn it off at any time in Settings → General → Privacy). Sharing never includes conversations that touched Mail, Calendar, Passwords or Files, and the tool inputs and results inside a conversation — the content of a note, a search, a web page — are withheld even when the conversation itself is shared. Shared conversations are used only to fix and improve the product. They are never used to train AI models and never sold.

Usage Data

We collect information about how you use the Service to improve reliability and performance: which apps you open and when, how long each Kit turn took, which tools it ran and whether they succeeded, how many tokens it used and what it cost, error types, and your thumbs-up / thumbs-down on Kit's answers with any reasons or comment you add. This usage data never contains the text of your messages, notes, emails or files. The desktop app also sends crash reports (Sentry) that describe the failure, not your content. Our website uses cookieless page analytics (Vercel) and remembers, in your own browser only, the link that brought you here so we can attribute a signup to its source.

Payment Information

Payments are processed by a third-party payment processor. We do not store full credit card numbers or payment credentials on our servers.

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Execute actions you request (send emails, publish posts, sync calendars, transcribe audio) using your connected accounts
  • Authenticate you and keep your account secure
  • Communicate with you about your account, updates, and support
  • Monitor usage against plan limits and enforce them
  • Improve and develop new features based on aggregate, anonymized usage patterns
  • Improve Kit by reviewing conversations from accounts that have left sharing on (see “Kit Conversations” above) and the feedback you give on its answers
  • Understand how people find OneKit (the referral source you tell us, and the link that brought you to the site)
  • Comply with legal obligations
  • Deliver signature requests, verify signing state, create the completed PDF, and preserve an audit trail

We do not sell your personal information to third parties. We do not use your email content, contact lists, or documents to train AI models without your explicit consent. This exception does not apply to Google user data: we do not use Google user data to train AI models.

Email Tracking

When you send marketing emails through OneKit's Email tool, we may embed a small tracking pixel (a 1×1 transparent image) and rewrite links in your emails to measure open and click-through rates. This tracking data is visible to you in the campaign report. You can disable tracking on a per-email basis using the tracking toggle in the compose view. Recipients can opt out of future emails at any time via the unsubscribe link included in every marketing email.

Content Repurposing (Auto-Post)

When you enable auto-post for TikTok or Instagram, OneKit periodically polls your own account (using the OAuth credentials you provided) to detect new content you have published. OneKit downloads your content, temporarily stores it on our servers for the purpose of publishing it to your other connected platforms, and deletes the temporary copy after publishing. If you enable AI caption rewriting, your original caption is sent to Anthropic's Claude API to generate a platform-adapted version. OneKit only accesses content from your own authenticated accounts — it does not access or download content from other users' accounts.

3. Third-Party Services

The Service integrates with third-party platforms. When you connect them, their own privacy policies also apply:

  • Supabase — database, authentication, and file storage
  • Anthropic (Claude) — AI responses and content generation. Prompts you send are processed by Anthropic subject to their usage policies.
  • OpenRouter and model providers — AI request routing and processing. OneKit's shared AI service sends prompts and relevant context through OpenRouter to the provider serving the selected model, including Claude models and the default DeepSeek Mail classifier. The serving provider depends on the model and available routing.
  • Groq — voice transcription. When you use the Whisper dictation feature, your audio is sent to Groq's transcription API (Whisper Large v3 model) for processing. The resulting text is stored locally on your device; audio is not retained by OneKit after transcription. Groq's data usage policies apply to audio processed through their API. Meeting notes use a local transcription engine and are never sent to any external service.
  • Google — Gmail inbox access, sending and mailbox organization; contact lookup and sender photos; and Calendar and booking features
  • Resend — transactional delivery of signing notices and short-lived links used to retrieve completed signed documents
  • X (Twitter), LinkedIn, Instagram, TikTok, YouTube — social media publishing

We only request the permissions these services require to perform the actions you explicitly instruct.

Google: Gmail, Contacts, and Calendar

When you connect Google, OneKit requests access for the features you enable. Gmail access includes message contents, headers, attachments, and labels so you can read and search mail, compose and send messages, and organize your inbox by marking messages read, starring, archiving, or marking spam. Mail synchronizes messages into a local index and message cache on your device for display and search. Contacts access covers saved contacts, Other Contacts, and, where available, your Google Workspace directory. It supports recipient lookup and sender names and photos. Calendar access supports displaying calendars and events, managing events, and providing booking links.

Google data in AI features

Mail's AI classification, briefs, and reply drafting process relevant email content and thread context. Kit can also use connected Google data when you ask it to work with Mail or Calendar. These AI requests pass through OneKit's backend and OpenRouter to the selected model provider; processing does not happen entirely on your device. Google OAuth access and refresh tokens are stored encrypted in OneKit's backend. Calendar features also synchronize event information through the backend. We do not use Google data for advertising, market research, or AI model training. Conversations that touch Mail or Calendar are excluded from optional staff conversation review.

Disconnecting Google and deleting data

You can disconnect Mail and Calendar in Settings. Disconnecting one feature or workspace does not remove another active connection to the same Google account. Mail's local message index and HTML cache are removed when no Mail connection remains for the account; while another workspace still uses it, those shared caches remain available. Disconnecting does not automatically erase every derived brief, saved draft, conversation, contact-photo cache, or other record already created through the Service. For deletion of retained records, including help clearing data stored on your device, contact support@onekit.co. You can also revoke OneKit's access in your Google Account; revoking access prevents future access but does not itself delete records already held by OneKit.

LinkedIn

When you connect your LinkedIn account, OneKit collects your LinkedIn profile name and user ID (one time only, during connection) and stores an OAuth access token to publish posts on your behalf. OneKit does not access, read, or store your LinkedIn feed, connections, messages, or any other LinkedIn content beyond what is listed here. Posts are only published when you explicitly approve them. OneKit does not use LinkedIn data for advertising, analytics, or any purpose other than publishing posts you author. You can withdraw consent at any time by disconnecting LinkedIn from the Repurpose page, which permanently deletes all stored LinkedIn data including your access token and profile information. You may also request full deletion of your LinkedIn data by contacting us at support@onekit.co. OneKit's use of the LinkedIn API is subject to the LinkedIn API Terms of Use.

Instagram (via Meta Platform)

When you connect your Instagram account, OneKit accesses your Instagram Business Account username and ID through the Facebook Graph API, and stores a Facebook Page access token to publish content on your behalf. This requires an Instagram Business or Creator account linked to a Facebook Page. When auto-post is enabled, OneKit periodically reads your Instagram feed to detect new posts for cross-platform repurposing (see Section 2, "Content Repurposing"). OneKit does not access or store your followers, direct messages, insights, or engagement metrics. We request only the permissions required for publishing: pages_show_list, instagram_basic, and instagram_content_publish. Posts are only published when you explicitly approve them. OneKit does not use Instagram or Facebook data for advertising, profiling, surveillance, eligibility determinations, or any purpose other than publishing posts you author. You can withdraw consent at any time by disconnecting Instagram from the Repurpose page, which permanently deletes all stored Instagram and Facebook Page data including your access token and account identifiers. You may also request full deletion by contacting us at support@onekit.co. OneKit's use of the Meta Platform is subject to the Meta Platform Terms and Meta Developer Policies.

TikTok

When you connect your TikTok account, OneKit collects your TikTok creator username, nickname, and account privacy/interaction settings (such as allowed privacy levels and whether comments, duets, or stitches are enabled on your account). We store an OAuth access token and refresh token to publish video content on your behalf. Before each post, OneKit queries your current creator settings to ensure your chosen privacy level and interaction preferences are valid and respected. OneKit does not access, read, or store your TikTok feed, followers, direct messages, analytics, or any content beyond what is listed here. Videos are only published when you explicitly approve them and select your privacy and disclosure preferences. OneKit does not use TikTok data for advertising, profiling, or any purpose other than publishing content you author with settings you choose. You can withdraw consent at any time by disconnecting TikTok from the Repurpose page, which permanently deletes all stored TikTok data including your access token, refresh token, creator username, and saved posting preferences. You may also request full deletion by contacting us at support@onekit.co. OneKit's use of the TikTok API is subject to the TikTok Terms of Service and TikTok API Terms of Service.

OneKit's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, market research, or AI model training. Google user data is used only for the connected user-facing features described in this policy, including background synchronization and AI briefs that you enable.

4. Data Sharing

We share your information only in the following circumstances:

  • Service providers — vendors who help us operate the Service (e.g. Supabase for the database, Stripe for payments, Sentry for crash reports, Vercel for hosting and cookieless site analytics, Resend for email) under confidentiality obligations
  • Business transfers — if AISquads LLC is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction
  • Legal requirements — when required by law, court order, or to protect our legal rights or the safety of others
  • With your consent — for any other purpose with your explicit permission
  • Signature participants — the sender and designated recipients receive the document, signing status, and completed signed copy as needed to complete the transaction

5. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. When you disconnect a third-party service, the selected connection and its credentials are removed. Content and derived records already created through the Service may remain, and other active connections to the same account continue to operate as described above. If you delete your account, we will delete or anonymize all of your personal data within 30 days, except where we are required to retain it for legal, tax, or compliance purposes.

Signed documents and their audit evidence are retained while the sender's account remains active so the sender and designated recipients can access the completed record. A deletion request may be limited or delayed where retention is reasonably necessary to preserve transaction evidence, resolve a dispute, prevent fraud, or comply with law. We will explain any applicable exception when responding to a request.

6. Security

We use industry-standard security measures including encryption in transit (TLS) and infrastructure-level encryption at rest provided by our hosting platform. OAuth tokens are encrypted and stored in access-controlled databases with row-level security policies. No method of transmission over the Internet is 100% secure; we cannot guarantee absolute security but we take reasonable steps to protect your information.

7. California Residents — CCPA Rights

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):

  • Right to Know — request disclosure of the categories and specific pieces of personal information we have collected about you
  • Right to Delete — request deletion of your personal information, subject to certain exceptions
  • Right to Opt Out of Sale — we do not sell personal information
  • Right to Non-Discrimination — we will not discriminate against you for exercising any of these rights

To exercise your rights, contact us at support@onekit.co. We will respond within 45 days.

8. EU/EEA/UK Residents — GDPR Rights

If you are located in the European Union, European Economic Area, or the United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR):

  • Right of Access — request a copy of the personal data we hold about you
  • Right to Rectification — request correction of inaccurate or incomplete personal data
  • Right to Erasure — request deletion of your personal data, subject to certain legal exceptions
  • Right to Restrict Processing — request that we limit how we use your data in certain circumstances
  • Right to Data Portability — request your data in a structured, machine-readable format
  • Right to Object — object to processing of your data based on legitimate interests, including for direct marketing purposes

Lawful basis: We process your personal data on the basis of contractual necessity (to provide the Service you signed up for) and legitimate interest (to improve and secure the Service). Where we rely on consent (such as for optional email tracking), you may withdraw consent at any time.

To exercise any of these rights, contact us at support@onekit.co. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

9. International Users

The Service is operated from the United States. If you access it from outside the US, your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country. By using the Service, you consent to this transfer.

10. Children's Privacy

The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn we have collected such information, we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice in the app at least 14 days before the change takes effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

12. Data Deletion Requests

If you would like to request deletion of all data OneKit has stored in connection with your account — including OAuth tokens, platform user IDs, and any content you created through the Service — please contact us at support@onekit.co. Include the email address or username associated with your account so we can locate your data. We will process your request and permanently delete all associated data within 30 days.

You can also disconnect any individual platform (Instagram, X, LinkedIn, TikTok, YouTube, Gmail) at any time from within the OneKit app, which removes that connection and its stored credentials. See the Google section and Data Retention for how other active connections, local caches, and previously created records are handled.

13. Contact Us

If you have questions about this Privacy Policy or want to exercise your rights, contact us at:

AISquads LLC

California, United States

support@onekit.co