Privacy

Privacy Policy

Last updated:

Summary

Konsil is an invite-only AI council operated by Konsil Pte. Ltd. Konsil AI Academy is a separate, lecturer-led AI-literacy course for children aged 6 to 8 in Singapore, with parent-supervised take-home activities. We collect the account, waitlist, conversation, Academy, memory, sharing, and usage data needed to run these services. We do not sell personal data, use it for advertising, or use your conversations to train our own models.

What we collect

  • Account data: your email address, Google OAuth profile identifiers, name, image, and role or access status.
  • Waitlist data: the use case you submit, status, confirmation and invitation delivery metadata, and coarse abuse-prevention data such as waitlist attempt timestamps.
  • Conversation content: messages, generated answers, decision memo structures, source links, thread titles, and image references you add to a chat.
  • Memory facts: short durable facts Konsil extracts or that you add manually so future council runs can tailor advice.
  • Sharing data: frozen conversation or memo snapshots, visibility settings, revocation status, and lightweight memo view or CTA events.
  • Usage telemetry: model names, provider family, token counts, latency, status, costs, search counts, error details, and related operational metadata.
  • Browser-local data: IndexedDB conversation cache, per-tab private chats in sessionStorage, theme preference, and strictly necessary auth/session state.
  • Konsil AI Academy data: the parent's account email, an encrypted child nickname, the fixed age band 6–8, consent and policy records, a hashed parent PIN, and, once take-home activities and parent-typed questions are enabled, encrypted activity results and encrypted redacted questions and displayed answers with safety category, model, policy version, and timestamps.
  • Course enquiry data: if you hold a place on a course, the parent's name and email address, the child's school level, the session times that suit you, an optional reaction to the price, and an optional note. The name and note are encrypted at rest. No child's name is requested or stored, and none of it is ever sent to an AI provider.

How we use your data

  • To authenticate you, manage invite-gated access, and keep your threads available across devices.
  • To run the council workflow: advisor responses, challenge rounds, synthesis, decision memo creation, citations, and optional web evidence.
  • To personalize advice with memory facts when memory is enabled for a non-private chat.
  • To operate sharing, revocation, public memo visibility, usage limits, cost accounting, abuse prevention, reliability debugging, and support.
  • To send waitlist confirmations, invitations, account-related notices, and critical service updates.
  • To let a consenting parent set up a child profile, start or leave child mode, review or delete everything stored about the child, enforce safety and usage limits, and operate the Singapore-only course.
  • To contact you about a course you asked to hold a place on, to schedule cohorts around the times families can attend, and to understand whether the price works. We do not use course enquiry details for any other marketing.

AI providers and web search

When you invoke the council, the relevant parts of your prompt, attached images, prior conversation context, and selected memory facts may be sent to configured AI providers through Vercel AI Gateway or direct provider APIs. Search-warranting prompts may also be sent to a search provider to collect evidence sources. Advisors may see anonymized versions of other advisors' answers during challenge rounds. In Konsil AI Academy, children never type into an AI model. Lecturers generate classroom examples through Vercel AI Gateway, and every example passes a safety screen before a class sees it. Where a parent types a question on a child's behalf, the locally redacted question is sent through Vercel AI Gateway to OpenAI for safety classification, a short answer, and a final safety review. The Academy does not use open-web search, uploads, or other council providers for child-facing content. Konsil uses this content to produce the response you requested. Provider handling of API data is governed by the applicable provider terms and data-processing commitments.

Storage and security

Primary app data is stored in Neon Postgres. Image uploads use private Vercel Blob storage when enabled. Resumable non-private streams may use Redis when configured. Waitlist and invitation email delivery uses Resend. Text and JSON user-content columns are application-encrypted at rest before they are written to Postgres. This protects stored database rows, but it is not end-to-end encryption: the server decrypts content while operating features you request.

Service providers and transfers

Konsil relies on infrastructure and AI providers that may process data outside Singapore, including authentication, hosting, storage, email delivery, AI model access, search, and operational telemetry services. We use these providers to operate Konsil and expect them to protect the data they process under their service terms, security controls, and data-processing commitments.

Private mode

Private mode narrows Konsil-side persistence. Private chats are kept in this browser tab, are not written as server threads, skip durable memory extraction, skip saved memory injection, use an in-memory job buffer, and keep images as in-flight data rather than uploading them to Blob. AI providers still see the prompts and images they answer while the private run is in progress, and operational telemetry may still record cost and rate-limit data.

Sharing

If you create a share link, Konsil stores an encrypted frozen snapshot of that conversation or memo. Anyone with the link can view an active share. Conversation shares are unlisted and marked noindex. Memo shares can be unlisted or public; public memos may be indexed by search engines. Revoking a link disables Konsil's active copy but may not remove external screenshots, caches, or forwarded copies.

Your choices

  • Delete saved conversations from the sidebar.
  • Review, edit, or clear memory facts from the Memory settings page.
  • Use Private mode for chats you do not want stored as durable Konsil threads.
  • Revoke shared links from the share dialog.
  • In the Academy parent dashboard, review and delete individual records, clear the full history, or delete the child profile and its consent and activity records.
  • Request access to your personal data, correction of inaccurate data, account export, deletion, or withdrawal of consent by emailing privacy@konsil.app.

Retention

We keep account, conversation, memory, waitlist, sharing, and telemetry records while they are needed to provide the service, comply with legal or operational requirements, resolve disputes, prevent abuse, and maintain security. Academy parent-typed question records expire from Konsil's active database 30 days after they are created and are also removed by a daily deletion job. Parents can delete them sooner. Academy profile and consent records remain until the parent deletes the profile or withdraws consent. Course enquiry records are kept until the cohort you enquired about has run, and are deleted on request at any time by emailing us. Deleted data may remain temporarily in infrastructure backups or provider logs under their retention practices before aging out.

Cookies

Konsil uses strictly necessary cookies and browser storage for authentication, authorization, session continuity, waitlist flow state, theme preference, and the eight-hour Academy child-mode session. We do not use advertising cookies.

Children

The ordinary Konsil council remains an adult service and is not directed at children under 13. The separate Konsil AI Academy is a lecturer-led AI-literacy course designed only for children aged 6 to 8 in Singapore. In class, adults operate every AI tool and children never type into an AI model. At home, a parent-owned account is used after the parent confirms guardianship, age, location, provider processing, parent review, and retention. Any child-facing screen states that the helper is an AI, can make mistakes, and is visible to their grown-up. The Academy redirects sensitive or uncertain questions to a safe adult and is not a substitute for a parent, teacher, doctor, emergency service, or other qualified person. Parents may withdraw consent by deleting the Academy profile or contacting us.

Changes

We will update this page when the policy changes and revise the date at the top. For material changes, we will notify active users by email or in-app notice when practical.

Contact

Questions or privacy requests for Konsil Pte. Ltd.? Email our data protection contact at privacy@konsil.app.