What Kalea keeps on the device, what our website and store collect, and what we do with it — written to be read, not just agreed to.
Effective September 15, 2026 | Last Updated: September 15, 2026 · Kalea Intelligence, LLC
THE SHORT VERSION. Kalea the device keeps what you say to her on the device. She has no account, no subscription, no telemetry, and no way to send us your conversations — the runtime has no endpoint that reports to us. What we do collect comes from our website and store: your order details when you buy, your email when you subscribe or apply for developer access, and the questions you type into the “Ask Kalea” online guide (kept 90 days). We do not sell or share personal information for advertising, and do not use data brokers. The privacy policy is physics; this document covers the parts that aren’t.
This Privacy Policy is issued by Kalea Intelligence, LLC (“Kalea Intelligence,” “we,” “us,” or “our”), the maker of the Kalea device and the operator of openkalea.com. It explains what personal information we collect, how we use it, who we share it with, how long we keep it, and the rights and choices you have.
It covers two very different things, so it is written in two parts. Part One (Sections 3–5) is about the Kalea device and what happens on it. Part Two (Sections 6–13) is about our website, our store, the “Ask Kalea” guide, our newsletter and developer programs, and our email. This Policy is referenced by our Terms & Conditions at openkalea.com/terms-and-conditions.html; if the two conflict about our handling of personal data, this Policy controls for that issue.
“Personal information” means information that identifies, relates to, or could reasonably be linked to you or your household. It does not include information that has been de-identified so that it cannot reasonably be linked back to you.
We say “on the device” to mean stored only in the storage inside your Kalea, in your home. We say “leaves the device” to mean any transmission off that storage — to a phone, a USB drive, a local network, or the internet. We say “we receive” only when information actually reaches Kalea Intelligence. Nothing in Part One reaches us.
Nothing is sent to us. Kalea runs her language models, speech recognition, and voice on the device. She does not need an account, a subscription, or an internet connection for the core experience, and she has no telemetry, analytics, crash reporting, or “phone home” function. We do not receive your conversations, your family’s content, your child’s learning history, or any record of how you use her. If you never connect her to a network, nothing about her use can leave your home.
What she stores, on the device. Depending on configuration and on which user profile is active, Kalea keeps the following in storage inside the device:
She does not create voiceprints or other biometric identifiers, does not identify people by their voice, does not have a camera, and does not record continuously; she listens for her name while asleep and processes short clips only to detect it and a few spoken commands.
Who can see what is on the device. Anyone with physical access to the device’s desktop, or to a phone paired over off-grid messaging with the PIN, can view, export, and delete what she has stored — including a parent or guardian reviewing a child’s conversations. That is by design: the guardian surface runs on the device and nowhere else. The person who sets Kalea up (the “Owner” in our Terms) is responsible for telling household members, guests, students, residents, staff, and anyone else who talks to her what she keeps and who can see it, and for any consent the law where they live requires.
Each of the following moves information off the device only when a person turns it on or performs the action. None of them send anything to Kalea Intelligence.
Exports and backups. A user or the Owner can export a profile’s history to a USB drive or to the device’s own desktop, and can make a full backup of the device. A full backup contains everything above, including the PIN and any identity keys; keep it somewhere safe.
Off-grid messaging (Bluetooth). With a compatible third-party messaging app on a nearby phone, you can text Kalea, configure her, switch users, and export history over Bluetooth Low Energy with no internet and no account. Direct messages between the phone and the device are encrypted; the phone app is made by a third party under its own privacy policy. We do not see this traffic.
Wi-Fi, when you switch it on. Wi-Fi is off unless the Owner enables it, and it exists for three things: software updates, downloading better models to trade up to, and agent errands you have approved (below). When the device checks for an update it fetches a public file from our code-hosting provider (GitHub); that provider sees the device’s IP address and nothing else — no account, no identifier, no content. The same is true when it downloads a model. We do not learn which devices check or download.
Agent errands and household mesh (forthcoming; off by default). When enabled, a household’s designated “broker” device may fetch information from the internet on a user’s behalf (for example, to check a fact). The request goes from your device to the site or service you or the errand chose, not to us; those third parties see what any web request shows them. Where more than one Kalea is joined in a household, only synthesized signals — a summary, a category, a presence — cross between devices over your local network, encrypted under a key that never leaves your household; raw conversations never cross. Which signals flow, and to whom, is set by the Owner on the device. Nothing in the mesh reaches us.
Support. If you email us about a problem and choose to attach an export, a log, or a screenshot, we receive what you send (Section 9).
If you return a device to us, or send it for repair, it may still contain the information described in Section 3. We erase and reflash every returned unit before it is used again, and we do not read, copy, or keep its contents. Wiping the device before you send it is your choice, never a condition of a refund or a repair. If a repair requires reimaging the device, what was on it is lost; back up first.
We collect personal information only when you do something that needs it. By activity:
Visiting the site. Our hosting provider keeps standard web-server logs — the IP address, pages requested, browser type, referring page, and time of each request — which we consult only for security and troubleshooting. We do not run advertising or analytics trackers on openkalea.com. Our pages currently load typefaces from Google Fonts; when your browser fetches them, Google receives your IP address and browser details under Google’s privacy policy.
Buying a Kalea. On our checkout page we ask for your email address and the country you are shipping to. You then complete payment on a page hosted by Stripe, our payment processor, where you enter your name, shipping address, phone number, and card details. We never see or store your card details. After payment, Stripe sends us your name, email, phone number, shipping address, the amount paid, and the country, and we keep those as your order record so that we can build, ship, support, and warranty your device and meet our tax and accounting obligations. Stripe processes your information under its own privacy policy and is independently responsible for fraud screening on its pages.
The “Ask Kalea” guide. The chat guide on our site is an AI assistant that runs in the cloud (not on a Kalea device). When you send it a question, the text of your question is sent to Anthropic, the AI provider whose model answers it, and the question and the reply are logged by us so we can see what people ask and improve the answers. Alongside each turn we store a salted, one-way hash of your IP address — not the address itself — so that we can group a visitor’s conversation, rate-limit abuse, and see returning visitors without being able to identify you; we do not store the page you were on or any account. Logs are deleted after 90 days. Please do not type sensitive personal information into the guide; it is for questions about the product.
Newsletter. If you subscribe to “Ideas from the edge,” we keep your email address and the date you subscribed, plus the same hashed-IP value for a few minutes to stop automated sign-ups. Every email we send carries an unsubscribe link and our postal address.
Developer early access and “next vessel” forms. If you ask for early access to our code repositories or write to us about hardware, we keep your email address, whatever handles you choose to give us (GitHub, X, Instagram, YouTube), the area you are interested in, and your note, so that we can reply and grant access. You are not added to the newsletter unless you also subscribe.
Emailing us. When you write to kalea@openkalea.com — about an order, a return, a warranty claim, a security report, an accessibility barrier, a source-code request, an arbitration opt-out, or anything else — we keep the correspondence so we can respond and keep a record of what was agreed.
Social media and community. Our accounts on X, Instagram, YouTube, TikTok, Reddit, Discord, and GitHub are run on those platforms under their privacy policies. What you post there is governed by them; we see what the platform shows us.
We use the information in Section 6 to: fulfil, ship, and support your order and honor the warranty; answer your questions; send the newsletter you asked for; run the developer programs you applied to; keep the site and store secure and prevent fraud and abuse; comply with tax, accounting, consumer-protection, export, and other legal obligations; and handle disputes.
For visitors in the United Kingdom, the European Economic Area, and other places whose law asks us to name a legal basis: we process order and support information because it is necessary to perform our contract with you; we process security logs, the hashed-IP values, and the “Ask Kalea” logs in our legitimate interests in running a secure, useful site (balanced against your interests, which is why the address is hashed and the logs are short-lived); we send the newsletter and grant developer access on the basis of your consent, which you may withdraw at any time; and we keep order records for as long as legal obligations require.
We do not use your personal information to make automated decisions with legal or similarly significant effects, and we do not use it to train AI models.
We share personal information only with the service providers we need to run the site and store, and only for those purposes:
We may also disclose personal information when the law requires it — for example, in response to a valid legal process — when necessary to protect the safety or rights of a person, or as part of a merger, acquisition, financing, or sale of the business, in which case this Policy continues to apply to it until the new owner tells you otherwise.
We do not sell personal information, and we do not share it with anyone for cross-context behavioral advertising. We have not done so in the past twelve months and have no plans to. We do not use advertising networks, data brokers, or tracking pixels. Because we do not sell or share, there is nothing for a Global Privacy Control or “Do Not Track” signal to opt you out of; we honor them by having nothing to disable.
openkalea.com uses no advertising or analytics cookies. It uses your browser’s own storage for small conveniences that stay in your browser: your cart and the country you chose to ship to, whether you have dismissed the newsletter prompt, and a per-visit conversation id so the “Ask Kalea” guide can keep a thread together while you move between pages. None of this is sent to us except as part of an action you take (placing an order, sending a chat message). Stripe’s checkout page sets its own cookies under Stripe’s policy. You can clear browser storage at any time; the site keeps working.
Kalea Intelligence is in the United States, and our website, store, and email are hosted there. If you are in the United Kingdom, the European Economic Area, Canada, Australia, or elsewhere, your order and support information is transferred to and processed in the United States. For transfers from the UK and EEA we rely on the standard contractual clauses / International Data Transfer Agreement with our providers, and you can ask us for a copy of the safeguards we use.
We protect your information with measures appropriate to what we hold: the site and store run over HTTPS; payments are handled entirely by Stripe, which is PCI-DSS certified; IP addresses in our logs are hashed with a salt that never leaves the server; store and log data are kept outside the public web root with restricted permissions; secrets are kept in server-side files that are never published; and access to the order and conversation records is limited to the people who need it to serve you. No system is perfectly secure, and we cannot guarantee that information will never be accessed without authorization. If a breach affects your personal information, we will notify you and any regulator as the law requires. If you believe you have found a security vulnerability in the site or the device, please email kalea@openkalea.com with the subject line “Security Report.”
openkalea.com and our store are for adults. We do not knowingly collect personal information online from children under 13 (or under the age at which parental consent is required where you live), and we ask that children not use the “Ask Kalea” guide or our forms. If you believe a child has given us personal information, email us and we will delete it.
The Kalea device is used by children, and a child’s information on it — profile, conversations, learning history — stays on the device under the control of the household (Part One). We do not receive it. If we ever add an optional online feature that would collect a child’s personal information, we will describe it here first and obtain verifiable parental consent as the law requires before it is enabled.
Wherever you live, you can ask us to: tell you what personal information we hold about you and give you a copy; correct it; delete it; stop using it for a particular purpose; move it to you or someone else in a portable format; and withdraw consent you have given (for the newsletter, just use the unsubscribe link). We apply these rights to everyone, not only where the law requires them. Email kalea@openkalea.com. We will need to confirm it is you — usually by replying from the email address on the record — and we will respond within the time your local law sets, and in any case within 45 days. We will not treat you differently for exercising a right, and you may use an authorized agent where your law allows.
Some information cannot be deleted while we still need it — an order record during the warranty period or the retention period tax law requires — and we will tell you when that is the case. Information on your Kalea device is yours to view, export, and delete on the device itself; we cannot access it and so cannot delete it for you.
If you are not satisfied with our answer, you may complain to your data-protection regulator: in the UK, the Information Commissioner’s Office; in the EEA, your national supervisory authority; in Canada, the Office of the Privacy Commissioner; in Australia, the Office of the Australian Information Commissioner; in the United States, your state attorney general or the Federal Trade Commission.
California. In the past twelve months we have collected the following categories of personal information, for the purposes in Section 7 and from the sources in Section 6: identifiers (name, email address, phone number, postal address, hashed IP address); commercial information (orders and payments); internet activity (server logs, “Ask Kalea” questions); and, for developer applicants, professional handles. We do not collect sensitive personal information as defined by California law except payment details, which Stripe handles and we never see. We disclose these categories only to the service providers in Section 8. We do not sell or share personal information, and we do not knowingly sell or share the personal information of anyone under 16. You have the rights to know, to delete, to correct, and to non-discrimination described in Section 14. California’s “Shine the Light” law: we do not disclose personal information to third parties for their own direct marketing.
United Kingdom and European Economic Area. Kalea Intelligence, LLC is the controller of the information in Part Two. The legal bases are in Section 7, the transfer safeguards in Section 11, and your rights — including the rights to object to processing based on legitimate interests and to lodge a complaint with your supervisory authority — in Section 14.
Canada. We collect, use, and disclose personal information with your consent and for the purposes described here, consistent with PIPEDA and applicable provincial law. Your information may be processed in the United States and be subject to the laws there.
Australia. We handle personal information consistently with the Australian Privacy Principles to the extent they apply to us. Your information is disclosed to overseas recipients in the United States as described in Section 11.
We may update this Policy as the product and the law change. We will revise the “Last Updated” date and, for changes that matter to you — a new kind of collection, a new category of recipient, a change to Part One — we will tell you by email if we have your address, by a notice on openkalea.com, or on the device before the change takes effect. We will never change Part One so that the device sends us your conversations without asking you first.
Kalea Intelligence, LLC · kalea@openkalea.com · 13771 N Fountain Hills Blvd #114-245, Fountain Hills, AZ 85268 · openkalea.com. For privacy requests, put “Privacy Request” in the subject line.