Privacy Policy
How Kernolix handles information submitted through this website and early product workspace.
Information you provide
We may process information you intentionally submit, including your name, business email, company, contact message, workspace profile, workflow descriptions, operational estimates, and account credentials. Passwords are stored as one-way hashes rather than plaintext.
Workflow diagnostics and sales follow-up
The public Workflow Diagnostic processes the workflow details and estimates you enter to generate a result. A diagnostic is stored as a sales lead only when you explicitly opt in and provide a valid business email. For opted-in diagnostics we may also store a limited first-touch acquisition record such as UTM source/medium/campaign, the landing path, and the referring hostname. Kernolix does not add advertising IDs or browser fingerprinting for this feature.
Private pilot offers
If Kernolix issues a private pilot offer, we store its scope, success metrics, commercial amounts, validity, lifecycle status, and the business email it was issued to. If you accept, we also store the response email, acceptance time, and a cryptographic hash of the accepted offer snapshot so the accepted commercial version can be identified later. The offer page does not collect card information.
Accounts, connectors and Operator runs
Signed-in workspaces may store Operator plans, actions, execution status, audit records, usage information, and connector configuration. Connector access/refresh tokens are intended to be encrypted at rest when the production application key is configured. If AI or Google integrations are enabled, relevant data may be sent to those providers to perform the requested function.
Essential technical data
Kernolix uses an essential session cookie for authentication, CSRF protection, language/session state, and first-touch attribution. Security and audit systems may process request identifiers and a keyed hash derived from the connecting IP address; the operational audit trail is designed not to store the raw IP address.
Payments
The first-customer billing flow uses manual USD payment / Payoneer coordination outside the public offer page. Do not submit bank credentials or full payment-account details through Kernolix public forms.
How we use information
We use submitted information to operate the service, respond to requests, provide controlled workflow execution, evaluate product fit, prepare and administer pilots, verify paid activation, secure the application, troubleshoot failures, and improve the product.
Data minimization
Do not submit passwords, API keys, card numbers, health records, government identifiers, or other sensitive data through public forms or workflow descriptions unless a later written agreement explicitly supports that category of data.
Service providers
The production service may rely on hosting/email infrastructure and, when configured, OpenAI and Google APIs. Manual payment may involve Payoneer. The exact production vendor list should be reviewed whenever infrastructure changes.
Retention and requests
Operational and commercial records may be retained while needed to provide the service, maintain security/audit history, or administer a customer relationship. For access, correction, or deletion questions, contact hello@kernolix.com. Some records may need to be retained where required for security, accounting, dispute, or legal purposes.
Last updated: August 2026. This early-stage policy is not a claim of GDPR, SOC 2, or other certification/compliance status and should be reviewed against the final legal entity, infrastructure, contracts, and markets before broader commercial scale.