Trust center

Trust center

AI privacy, data retention, tenant isolation, compliance, and audit — everything you need to make a decision, in the open.

01

AI privacy & data handling

Comments and DMs you receive are sent to Anthropic’s Claude API to draft replies. We use Anthropic’s no-training (Enterprise) setting, so your data is never used to train Claude models.

You can opt out anytime: Settings → Notifications → “Don’t generate AI drafts.”

If your customer asks not to receive AI-assisted replies, we show a label saying so, per the EU AI Act.

02

Data retention

Active accounts: we keep your interactions, drafts, and decisions.

After cancellation: your data is kept for 90 days so you can come back, then permanently deleted.

Deletion is automatic and runs daily.

03

Tenant isolation

Every data query is scoped to your account — no other merchant can ever see your data.

On Enterprise BYOK, your Anthropic key is stored and isolated per merchant.

Each merchant’s integrations use their own separate credentials — never shared across accounts.

04

Compliance

Built for GDPR (EU), APPI (Japan), and CCPA (California).

Stripe webhooks are signature-verified with replay protection.

Telegram webhooks are verified with a constant-time secret check.

TLS 1.3, auto-provisioned by Cloudflare.

05

Audit & transparency

Every staff impersonation session auto-ends after 5 minutes, notifies you on Telegram instantly, and is logged.

Status page: /healthz.

Found a vulnerability? Email security@kizuki.smartrich.ai.

Source code: github.com/hanamizukikabukijou/kizuki (private; read access available per merchant).

Need a copy of your audit log?

Pro merchants and above can download all of their activity as JSON / CSV.

Contact trust@kizuki.smartrich.ai