COMPREHENSIVE PRIVACY POLICY, EXHAUSTIVE TREATMENT OF FINANCIAL DATA, AND BLIND AUDIT DECLARATION – "KIBO" ECOSYSTEM

Effective Date and Last Updated: June 23, 2026

Contractual Document ID: KIBO-PRIVEN-20260623-GLOBAL

Responsible Entity and Operating Owner: Kai Studios, S.A.S.

1. INTRODUCTION, IDENTITY OF THE DATA CONTROLLER, AND ABSOLUTE SCOPE OF THE DOCUMENT

Welcome to the Kibo security ecosystem! In strict, unrestricted, and rigorous compliance with converging international data protection legislation, fundamentally including the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) of the United Mexican States, the General Data Protection Regulation (GDPR) of the European Union (EU Regulation 2016/679), the California Consumer Privacy Act (CCPA/CPRA), and the applicable standards of the financial regulatory framework in the jurisdictions where we operate, this legal notice and comprehensive privacy policy is issued, promulgated, and published.

The primary, joint legal data controller, and absolute controller of the relational database architecture, as well as the creator, developer, and operating owner of the multimodal financial assistance technological platform named "Kibo" (hereinafter, the "Platform", the "App", or the "Services"), is the commercial entity legally constituted in Mexico under the corporate name Kai Studios, S.A.S. (hereinafter, the "Company", "We", "Our", or "Kibo").

This policy is not a mere informational notice; it is a legally binding, extensive, and exhaustive contractual document that intricately governs, regulates, and conditions without any exceptions whatsoever the exact manner in which we collect, ingest, asynchronously process, store, encrypt, use, transfer, and destroy your personal, contact, financial (declarative), technological behavior, and multimodal interaction information when you interact with our web interface (askkibo.com), our backend Application Programming Interfaces (APIs), our proprietary Artificial Intelligence engine, and our communication channel through Meta Platforms, Inc. (WhatsApp). By configuring your account, registering your phone number, requesting an OTP code, or using our services in any way, you grant your express, affirmative, informed, and unequivocal consent for the massive processing of your data according to the extensive and colossal terms described herein. If you do not agree, disagree, or reject a single provision, line, or annex of this document, you lack the legal authorization to use the architecture and must immediately cease interacting with Kibo.

2. DETAILED, GRANULAR, AND SPECIFIC INVENTORY OF THE INFORMATION WE COLLECT (STRICT MINIMIZATION PRINCIPLE)

To materialize the "Zero Friction" experience that characterizes the Kibo financial assistant and allow our Artificial Intelligence engine to process unstructured natural language, it is technically and operationally essential to collect, transiently or permanently, certain categories of data. KAI STUDIOS, S.A.S. auditably and aggressively applies the principle of "Privacy by Design", guaranteeing that we only collect the information empirically and logically necessary for the provision of the accounting service.

A. Information Provided Directly, Voluntariamente, and Explicitly by the User (Identity and Access):
  • "Passwordless" Authentication Credentials: We collect your email address (used as the primary key and official channel for the delivery of PDF reports and legal notices) and your cell phone number in international E.164 format, which is the main operational identifier to link your account with the WhatsApp ecosystem.
  • Basic Interaction Profile: We collect the first name or fictitious nickname of your preference, intentionally omitting the request for last names, social security numbers, or direct governmental civil identifiers to favor pseudo-anonymization from the source.
  • Cryptographic Keys (Passkeys): If you opt for biometric authentication, our system collects, registers, and links the Public Key generated by your device's secure enclave (WebAuthn). Biometric Exemption Declaration: Kai Studios, S.A.S. never collects, reads, extracts, transmits, or stores your physical fingerprint, iris scan, or facial topography (FaceID/TouchID). Such biometric data remains hermetically locked in your device's hardware; Kibo only receives a mathematical validation token (True/False).
B. Information Ingested Through Continuous Multimodal Interaction (The AI Engine):
  • Multimedia and Voice Files (Real-Time Ingestion): We collect, transiently download, and process the voice notes (audio files) that you record and send to our chat. These files are subjected to Speech-to-Text conversion systems and deep analysis to extract financial intentions.
  • Analytical Vision and Documentary Photographs: We collect and analyze, through Optical Character Recognition (OCR) and advanced vision models, the photographs of purchase receipts, restaurant bills, payroll stubs, or invoices that you submit to the Platform.
  • Natural Language Interactions (Prompts): We store the history of text messages, commands, financial questions, bill-splitting orders, and the raw context you type to maintain the coherence of the assistant's algorithmic memory (Context Window).
  • The General Ledger (Declarative Financial Ledger): We store in a highly structured relational database (MariaDB) the deduced categories, the extracted monetary amounts, the transaction currency, the temporary peer-to-peer debt balances, the consolidation status of your wealth (investment accounts, cash, credit), and the family budgets that the AI structures from your declarations.
C. Information Collected Systemically, Transactionally, and Automatically (Telemetry and Payments):
  • Payment Integration Metadata (Stripe): We collect your subscription status (active, trial, canceled, past due), the history of issued receipts, renewal dates, and the Customer ID generated by Stripe. Critical Warning: KAI STUDIOS, S.A.S. DOES NOT collect, DOES NOT process on its own servers, and DOES NOT store your Credit Card Number (PAN), expiration date, or CVV security code. The entire burden of bank regulatory compliance (PCI-DSS) is transferred to our exclusive payment processor.
  • Technical Footprint and Traceability (Distributed Tracing): We capture unique correlation identifiers (correlationId) assigned to each Webhook message (incoming from Meta or Stripe), your public Internet Protocol (IP) address, the browser's User Agent string when using the web portal, the exact timestamp (UTC 0) of your actions, and network latency indicators for strict purposes of observability, passive security auditing, and debugging in our log system (Pino).

3. EXHAUSTIVE PURPOSE OF PROCESSING: HOW, WHY, AND WHAT WE USE YOUR INFORMATION FOR

The massive data ingestion described in Section 2 is not collected for idle accumulation or speculative commercialization. It is the structural and logical fuel that allows Kibo to exist as the world's first zero-friction Financial Assistant. We use your data solely and restrictively for the following operational purposes:

A. Primary, Essential, and Contractual Purposes (Necessary for the Service):
  • Structural Operability and Authentication: To create, provision, verify, and maintain your active user profile. To generate and orchestrate the transient sending of One-Time Passwords (OTP) to your email or WhatsApp through the ultra-fast memory layer (Redis) and validate your Passwordless access.
  • Multimodal Processing and AI Inference: To transcribe your audios to text, analyze the pixels of your receipt photographs looking for figures and concepts, and use our proprietary advanced Large Language Model (LLM) to deduce the appropriate budget category without forcing you to fill out manual forms.
  • Ledger Management and Wealth Consolidation: To structure impeccable relational databases, execute arithmetic calculations on your income and expenses, manage shared balances (Kibo Family Plans), and consolidate your cash flow to return exact answers about your remaining monthly balance.
  • Formal Document Generation: To trigger the internal microservice in charge of rendering and exporting "On-Demand" your financial income statement in executive reports in PDF format.
  • Billing, Compliance, and Legality: To process your recurring subscription charges, send you digital payment receipts, cryptographically record your explicit acceptance of these Terms on our AlmaLinux servers, and apply transactional brakes (Rate Limiting) if we detect a volume of requests that threatens our resource quota.
B. Secondary, Analytical, and Algorithmic Refinement Purposes:
  • Refinement of the Artificial Intelligence Engine: KAI STUDIOS, S.A.S. may use unlinked fragments, metadata, and vector representations of interactions to refine the accuracy of the OCR model, improve hit rates in natural language categorization, and decrease AI hallucinations. Safeguard: All data used for this purpose will be rigorously anonymized or stripped of Personally Identifiable Information (PII) prior to its ingestion into training pipelines.
  • Maintenance, Observability (SRE), and Quality Assurance (QA): We use Webhook metadata, JSON logs generated by Fastify/NestJS, and distributed traces so our engineering team can debug latencies, resolve service outages (Downtimes), eliminate vulnerabilities, and ensure the operability of communication tunnels with Meta.

4. THE "BLIND AUDITOR" DOCTRINE, RADICAL PRIVACY, AND THE UNWAVERING COMMITMENT TO NON-COMMERCIALIZATION

FUNDAMENTAL DECLARATION OF CORPORATE ETHICS: KAI STUDIOS, S.A.S. maintains a radical, unwavering, and non-negotiable stance regarding the protection of your financial secrets. The Kibo user is not the product. Our business model is funded entirely and exclusively through the recurring subscription fees paid by our clients.

  • Zero Selling Policy: We formally, corporately, and legally declare that WE DO NOT SELL, RENT, LICENSE, SHARE, OR MONETIZE your personally identifiable information, spending patterns, wealth balances, debt levels, or consumption metadata with ANY third-party corporate entity, commercial insurer, multiple banking institution, mass data broker, risk agency or credit bureau, advertising network, or investment fund under any pretext, legal circumstance, or financial incentive.
  • The Maxim of the "Blind Auditor": Kibo is designed at the database architecture level to act as a non-intrusive entity. Our software engineers, database administrators (DBAs), and support staff are strictly, contractually, and criminally prohibited from accessing the production MariaDB database to read, in plain text, conversational histories, query your restaurant expenses, or view the original photographs of your receipts. Access to these records (JSON columns) is blocked by least privilege policies and is only excepted (with prior written authorization from the owner) when it is humanly indispensable to resolve a severe technical error (Bug) reported by the user themselves, or during automated and impersonal database restoration processes in the event of critical disasters (Point-in-Time Recovery / PITR).
  • Zero Tracking Ad Policy: Kibo deliberately lacks advertising monetization infrastructure. We do not insert Meta tracking pixels, Google Analytics, or third-party ad-tech firms into our dashboard portal to profile your behavior, nor do we use your spending level to bombard you with credit card or loan advertisements.

5. TRANSFERS, TECHNICAL REMISSIONS TO THIRD PARTIES, AND THE META ECOSYSTEM (WHATSAPP)

For Kibo's conversational immediacy and zero latency to exist worldwide, we delegate the physical transit of information to global elite telecommunications, artificial intelligence, and payment infrastructures. By accepting this policy, you explicitly and unequivocally consent to the following cross-border technical remissions:

  • Meta Platforms, Inc. (WhatsApp Ecosystem): All text communication, as well as the initial transit of voice notes and photographs, is compulsorily carried out using the WhatsApp Cloud API (Graph API). You understand that Meta acts as the telecommunications transport conduit or channel. KAI STUDIOS, S.A.S. submits to the terms of the Meta API and encrypts requests via validated webhooks, but has no direct control over WhatsApp's internal routing infrastructure at the mobile device level.
  • Stripe, Inc. (Global Financial Processing): We strictly transfer your email, unique identifier (UUID), and metadata of your selected plan to Stripe for the creation of the "Customer Profile" and the secure orchestration of your subscription billing in a multi-currency scheme. Stripe acts as a payment processor under its own strict international financial regulations.
  • Cloud Infrastructure Providers and AI Engines (E.g., Cloudflare, Tier-1 LLM Providers): We remit transient data to our server hosting providers (Bare Metal/Cloud), content delivery networks (CDN/WAF) for cyberattack mitigation, and to the supercomputing clusters that host the Proprietary Multimodal Artificial Intelligence responsible for executing transcription and visual reasoning. These providers hold the status of "Data Processors" and are subject to ironclad Data Processing Agreements (DPA) that absolutely prohibit them from storing your audios long-term or using your receipts for their own purposes outside the scope of the Kibo API instruction.

6. LEGAL BASES FOR DATA PROCESSING (GDPR, LFPDPPP, AND APPLICABLE JURISDICTIONS COMPLIANCE)

For users residing in the European Economic Area (EEA), Mexico, the United States, and other jurisdictions with advanced data protection regimes, Kibo's colossal processing of your information is technically and inexcusably based on the following legal grounds outlined by Article 6 of the GDPR and Title Two of the LFPDPPP:

  • Performance of a Contract (Art. 6.1.b GDPR): The processing of your phone number, email, basic profile, and the constant ingestion of your finances (the Ledger) is an absolute, imperative, and materially necessary precondition to comply with the Terms and Conditions of Use of the service, create your account, and allow the AI to function as your financial assistant.
  • Explicit, Affirmative, and Informed Consent (Art. 6.1.a GDPR): The processing of your multimedia files, audios, and exact photographs sent to the channel, as well as the linking of your data to generate wealth consolidations, depend exclusively and entirely on your active consent and the direct orders (prompts) you voluntarily issue to the bot in real-time.
  • Compliance with a Legal Obligation (Art. 6.1.c GDPR): The mandatory retention of audit logs of terms acceptance (Timestamp, encrypted IP), the storage of financial transactional logs, and the immutability of billing in Stripe constitute public obligations of a legal, commercial, and fiscal nature that Kai Studios must obey before tax authorities and international e-commerce audits.
  • Legitimate Interest (Art. 6.1.f GDPR): The restrictive use of anonymized usage metadata, failure telemetry (Sentry), and the recording of LLM response times for the continuous improvement of the software code, the application of rate limiting barriers, and the protection of our infrastructure against financial exhaustion attacks (DDoS to AI APIs).

7. CORPORATE-GRADE CYBERSECURITY, DEFENSIVE AUDITING, AND TUNNEL AND REST CRYPTOGRAPHY

We understand that your personal finance information is highly coveted by malicious actors. To safeguard the promise of "Zero Friction" and "Bank Privacy", we have established a militarized technological ecosystem:

  • Advanced Encryption in Transit and at Rest: All communication transmitted between the WhatsApp API, our web portals, and the central Node.js API (api.askkibo.com) inexcusably transits through tunnels with modern cryptographic protocols (TLS 1.2 or higher). Once the information reaches our MariaDB databases or Redis caches, disk-level encryption technology (Data at Rest) is applied using the advanced AES-256 GCM standard or higher, making the physical extraction of a hard drive result in mathematically indecipherable data without the encryption keys from our servers' kernel.
  • Webhook Validation and Request Forgery Prevention: The Kibo backend API uses cryptographic "Guards" and digital signature validation (Signature Verification) for every incoming request (webhook) from Meta and Stripe. If a request does not possess the exact hash signed with our secret server key, it is rejected in milliseconds, preventing any identity spoofing or injection of false information into your Ledger.
  • Isolated Infrastructure and Secure CI/CD: We maintain development environments (Staging) strictly separated from production databases (Production). No line of code is merged without prior security audits. We have Point-in-Time Recovery (PITR) policies that allow us to revert the Ledger to an exact millisecond before a catastrophic failure, ensuring your accounting is never corrupted by a system outage.

8. SOVEREIGNTY OVER YOUR DIGITAL FOOTPRINT: UNRESTRICTED EXERCISE OF ARCO RIGHTS AND PORTABILITY

KAI STUDIOS, S.A.S. guarantees and proactively defends your sovereign power over your digital wealth. You have the inalienable constitutional and regulatory right to:

  • Access and Rectification: Request detailed information about your General Ledger, know the status of your subscription, or demand the technical correction of a financial entry that the Artificial Intelligence may have entered erroneously in the event you cannot correct it via natural language commands.
  • Opposition and Limitation: Object to us sending you non-transactional emails (internal marketing) or suspend the renewal of your premium service directly in the client portal.
  • Structured Portability of Personal Data: You have the absolute power to demand a comprehensive export of your Ledger, spending history, and consolidation statements, which will be rendered and delivered in a structured, universal, and machine-readable electronic format (such as a native JSON file or a tabular CSV format), allowing you to take your history to a traditional spreadsheet or your personal accountant without technological dependence on us.
  • Cancellation (Right to be Forgotten): The unwaivable right to request the unlinking or logical destruction of your account in the application.

For the solemn, formal, and indubitable exercise of any of these constitutional rights (ARCO / GDPR / CCPA), the owner user must obligatorily submit a comprehensive written request to our Regulatory Compliance Department through the only legally valid contact channel: [email protected]. Strict identity validation controls will be applied before proceeding with the execution of your requirement to prevent social engineering.

9. DATA RETENTION POLICY AND USE RESTRICTION FOR MINORS (COPPA)

Data Lifecycle: We will keep your financial and profile information accessible and intact only as long as you maintain an active account, or while there is a post-cancellation grace period in which you can reactivate your subscription without losing the Artificial Intelligence's context. Imperatively by applicable tax legislation, Stripe billing records and legal acceptance logs will remain locked in corporate custody for the peremptory period established by revenue laws (usually 5 to 10 years).

Categorical Restriction to Minors: The use of financial tools, budgets, and wealth tracking requires full legal capacity. Kibo is strictly, categorically, and legally restricted to individuals over eighteen (18) years of age. We do not deliberately collect information from minors. If we detect the presence of a minor in our WhatsApp ecosystem, the account will be immediately struck down and irreversibly disabled.

10. UNILATERAL RIGHT OF FUTURE MODIFICATIONS, AMENDMENTS, AND TACIT ACCEPTANCE

Due to the dizzying pace of innovation in the Multimodal Generative Artificial Intelligence sector and shifting global data sovereignty laws, KAI STUDIOS, S.A.S. arrogates to itself, in a sovereign, unilateral manner and without the right of appeal, the exclusive corporate administrative power to review, amend, purge, entirely rewrite, incorporate, and promulgate partial or total restructurings to this colossal Privacy Policy, at any time and in accordance with the risk and compliance demands of the board of directors.

If the LexTrack AI and Regulatory Compliance Department rules that the alteration is "material" (i.e., a substantial modification in the purposes of processing, the addition of new AI sub-processors, or changes in the billing scheme), we will proactively notify our active database through the forceful interposition of an email to your registered inbox or a native message through the WhatsApp assistant with sufficient advance notice. Your decision, inertial action, or the consecutive sending of voice commands, photographs, or messages to the Kibo chat after the entry into force of said update, formally, unconditionally, and tacitly solidifies, constitutes, and assumes, before local and international courts, your full ratification and legally binding acceptance of the new privacy regulations.

SPECIAL TECHNICAL-LEGAL ANNEX: DEFINITION AND EXECUTION PROCEDURE OF THE "TOMBSTONE PATTERN"

Dear User and/or External Auditor: In Clause 9 of the Terms and Conditions, and when referencing your Right of Cancellation (Right to be Forgotten), we mention the architectural concept of the "Tombstone Pattern". In order to eliminate any ambiguity, we proceed to define its meaning, scope, and critical role as our ultimate technical privacy safeguard.

What does the Tombstone Pattern mean in Kibo?

In advanced relational database engineering (like our MariaDB infrastructure) and event-driven distributed architectures, executing a basic destructive deletion command or deep physical wipe (the classic SQL command DELETE FROM users WHERE id = X) is a technologically reckless and highly dangerous practice. Deleting a user from the root can cause a catastrophic chain reaction (cascading failures), corrupting the referential integrity of interconnected historical financial records, unbalancing bill splits between multiple users (the shared "Ledger" of families), breaking caches in Redis, and generating inconsistencies in asynchronous payment synchronization audits with external gateways like Stripe. To solve this dilemma between the inescapable compliance with the Right to be Forgotten required by law and the preservation of the structural stability of the accounting ecosystem, Kai Studios, S.A.S. implements the Tombstone Pattern technique.

The Cryptographic Execution Procedure consists of the following exact and irreversible steps:

Paso 1: Receipt and Approval of Deletion:

You request the deletion of your account through official channels.

Paso 2: Generation of the Tombstone:

The system does not physically "delete" the row representing your existence in the central user database (the users table). Instead, the system places a logical "Tombstone" or digital flag (usually updating a metadata field like deleted_at = CURRENT_TIMESTAMP).

Paso 3: Destruction and Obfuscation of PII (Irreversible Mutation):

In the exact same transactional millisecond, the algorithm violently and irreversibly overwrites (mutates) all fields containing Personally Identifiable Information (PII). Your name, nickname, primary email, and most critically, your WhatsApp number in E.164 format, are erased in plain text and replaced by randomly generated, unintelligible, and mathematically impossible to revert strings (UUIDs - Universally Unique Identifiers) (for example, your phone +15551234567 permanently becomes something like deleted_user_8f4c2b9a-71d2-4e9f-b5c1).

Paso 4: Hash Isolation in Cold Table (Passive Legal Compliance):

Simultaneously, and prior to the destruction of the PII, the system calculates the cryptographic digital footprint or hash (using the SHA-256 algorithm) of your original email and number. This hash (which is an indecipherable string like a591a6d40bf...) is exported and stored in a parallel, isolated, inactive, and high-security database known as the "Cold Table" (user_deletion_logs). Why do we do this? This serves exclusively as a legal shield for the Company. If in the future a judicial authority requires us for a fraud, or if a malicious user attempts to re-register the same number to repetitively abuse our Free Trials by exhausting Artificial Intelligence API funds, the system can silently verify if the hash of that phone already exists in the "Tombstone", denying the service, without us humans ever knowing who that phone belonged to.

Paso 5: Final Result (Absolute Sanitization):

The original row remains in the database as a statistical "ghost" or "tombstone". The expenses you logged or the bills you split remain present so that the system's mathematics do not collapse and your friends do not lose the record of their shared transactions, but said financial information is no longer linked to any existing human being, phone, or email. You become a mathematically anonymous entity within our General Ledger.

Through the Tombstone Pattern, KAI STUDIOS, S.A.S. radically complies with the destruction of your identity required by the GDPR and LFPDPPP, ensuring your human profile disappears from the ecosystem in a definitive and irrecoverable manner, shielding your privacy to the maximum level possible in current software engineering.