KENOS · Kohenoor Operating System

Privacy Policy

Effective 28 September 2026 · Kohenoor Technologies

How Kohenoor Technologies collects, uses, shares and protects personal data when you use KENOS, KAI and the KENOS applications, and the rights you have.

Who we are

KENOS (the Kohenoor Operating System, at www.kohenoor.net), KAI and the KENOS applications and Android app (together, the "Services") are provided by Kohenoor Technologies FZC, Sharjah Publishing City Free Zone, United Arab Emirates (Trade License 4428529.01), together with Kohenoor Technologies LLC, State of Georgia, USA (Control No. 23261659), and affiliated group entities in the Kingdom of Saudi Arabia and Pakistan. In this policy "Kohenoor", "we", "us" and "our" mean these entities. For data-protection purposes, Kohenoor Technologies FZC is the controller of personal data processed through the Services, jointly with the group entity that provides a particular service to you.

Contact for privacy questions and requests: [email protected] (subject: "Privacy request").

Summary

Personal data we collect

Account and profile data. Email address (required and confirmed), full name, country, account type (individual or business), profile picture, and, if you add them, phone number, postal address and company details. We record when you confirmed your email and accepted our terms.

Sign-in data. If you sign in with Google, we receive your name, email address, profile picture and Google account identifier. If you sign in with GitHub, we receive your username, name, verified email address, profile picture and GitHub account identifier. If you sign in with a Web3 wallet, we receive your public wallet address and a signed sign-in message (no transaction and no gas). We never receive your passwords for these services.

Identity verification (KYC) data, only for features that require it: identity document images (passport, national ID, driving licence or residence permit), an optional selfie, and the verification outcome and reviewer notes.

Payment and wallet data. KEN balances and a ledger of charges, credits and refunds; KAI plan and token usage; purchase records; on-chain transaction identifiers you submit. Card payments are processed by Stripe: we receive the payment status, amount, currency and a Stripe customer reference, and, if you choose to save a card, its brand, last four digits and expiry. We never receive or store full card numbers or security codes.

Content you provide. Messages to KAI and your KAI conversation history; answers, prompts and files you submit to KENOS applications (for example PromptEx, DevCon, KEN Sentinel, KENFI Advisory and PixilPro) and the outputs produced for you; documents you upload (for example settlement documents, payment proofs, dispute evidence and certificates); support requests and messages you send us.

Technical and security data. IP address, device and browser type, pages and features used, timestamps, error and security logs, request counts used for usage limits, and bot-detection signals from our security provider.

We do not ask for special-category data (such as health, religion or political opinion). Please do not include it, or passwords, seed phrases, private keys or card numbers, in messages to KAI or other applications.

Where we get it

From you; from the sign-in provider you choose (Google, GitHub or your wallet); from Stripe for payment outcomes; from public blockchain networks for transactions you ask us to verify; and from our security and hosting providers for technical and security data.

How we use it, and our legal bases

PurposeLegal basis (EU/UK GDPR and similar laws)
Create and secure your account; sign you in; confirm your emailPerformance of our contract with you
Provide KAI and the KENOS applications, and deliver what you request or buyContract
Process payments, KEN credits and refunds; keep financial recordsContract; legal obligation
Identity verification, anti-money-laundering, sanctions and fraud controlsLegal obligation; legitimate interests in preventing financial crime
Security, abuse prevention, usage limits and bot protectionLegitimate interests in keeping the Services safe and available
Service messages (confirmations, receipts, security and account notices)Contract; legitimate interests
Expert-vetted (human-reviewed) tiers you chooseContract
Improving reliability and quality using aggregated or de-identified usage informationLegitimate interests
Marketing emails (only if you opt in; you can unsubscribe at any time)Consent
Responding to lawful requests and enforcing our termsLegal obligation; legitimate interests

Where we rely on consent, you can withdraw it at any time without affecting processing before withdrawal.

AI processing

KAI and the KENOS applications use large-language-model and vision providers to generate answers. When you use them, we send the provider only what is needed to answer your request (your message or answers, the relevant context and any image you attach). The instructions and knowledge that power KAI are held on our servers. We do not use your content to train AI models and we do not provide it to providers for training.

AI outputs are informational and can be wrong. We do not make decisions that produce legal or similarly significant effects about you solely by automated means. Automated checks (for example fraud, usage-limit and risk-classification checks) may route a request to human review or limit access; you can contact us to ask for human review of any such outcome.

If you choose an expert-vetted tier, a qualified KENOS reviewer sees your submission and the draft output in order to review it.

Google user data

If you sign in with Google, KENOS requests only your basic profile: name, email address and profile picture (the openid, email and profile scopes). We do not request access to Gmail, Google Drive, Contacts, Calendar or any other Google data.

We use this information only to create and sign you in to your KENOS account, show your name and picture in your account, and contact you about your account and the Services you use. We do not sell it, use it for advertising, use it to train AI models, or transfer it to others except the service providers that host our Services, as described below, or where the law requires.

KENOS's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can remove KENOS's access at any time in your Google Account (Security, Third-party apps with account access), and you can ask us to delete your account data by writing to [email protected].

Who we share it with

We share personal data only as needed to provide the Services, under contracts that require the recipient to protect it and use it only on our instructions:

We may also disclose data to competent authorities, courts or advisers where the law requires it or to establish, exercise or defend legal claims, and to a successor in a merger, acquisition or restructuring, with notice to you. Blockchain transactions are public by design and cannot be altered or deleted by us.

International transfers

Our providers operate in several countries, including the United States, the European Union and other regions where AI providers process requests. When personal data leaves your country, we rely on appropriate safeguards required by applicable law, such as the European Commission's Standard Contractual Clauses (and the UK Addendum), adequacy decisions, or other lawful transfer mechanisms under the Saudi and UAE data-protection laws. You can ask us for a copy of the relevant safeguards.

How long we keep it

How we protect it

Encryption in transit; database row-level security so each person can read only their own records; private storage for identity documents and sensitive uploads, reachable only through short-lived signed links for the owner and authorised staff; credentials and proprietary logic held only on our servers; confirmed-email accounts; per-account usage limits and bot protection; least-privilege staff access. No system is completely secure. If a breach affects you, we will notify you and the relevant authorities as the law requires. Keep your sign-in credentials and wallet keys safe: we will never ask for your password, seed phrase or private keys.

Your rights

Depending on where you live, you may have the right to: know what personal data we hold and receive a copy (access and portability); correct it; delete it; restrict or object to certain processing (including processing based on legitimate interests); withdraw consent; and not be subject to decisions based solely on automated processing that significantly affect you. You also have the right to complain to a data-protection authority.

How to exercise them: write to [email protected] with the subject "Privacy request" from the email address on your account. We may need to verify your identity. We respond within one month (EU/UK), 45 days (California) or the period your local law sets, and will tell you if we need more time. Some data must be kept for legal reasons even after a deletion request; we will explain when that applies.

Cookies and local storage

We use only what the Services need: your sign-in session and preferences (such as theme and language) stored in your browser, and security cookies set by Cloudflare to detect automated traffic. We do not use advertising or cross-site tracking cookies. You can clear stored data in your browser; you will then need to sign in again.

Children

The Services are intended for people aged 18 and over and are not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

Changes to this policy

We will post any update on this page with a new effective date, and where changes are material we will notify you by email or in the Services before they take effect.

Contact

Kohenoor Technologies FZC, Sharjah Publishing City Free Zone, United Arab Emirates. Email: [email protected]. Corporate website: www.kohenoor.tech.