Privacy policy

Last updated: July 14, 2026

Chorrie, Inc. d/b/a Kilvin ("Kilvin," "we," "our," or "us") values your privacy. This Privacy Policy describes how we collect, use, and protect personal information when you engage Kilvin for custom software development, access software we build for you, or otherwise use our websites, client portal, and related services (collectively, the "Service").

By using the Service, you agree to this Privacy Policy. If your organization has a separate signed agreement, BAA, or Data Processing Addendum with us, that agreement controls in case of conflict.

1. Information We Collect


Account Information. We collect your name, email, organization, and role for authentication and account management. Authentication is handled directly by Kilvin — we do not use a third-party identity provider. Passwords are never stored in plain text; they are hashed using the Argon2 algorithm before storage.

Client Data. In the course of building software for you, we receive and process data you provide or that we integrate with on your behalf — including business records, user lists, source code repositories, and data from third-party systems you connect (e.g., custodians, CRMs, market-data providers). You determine what data flows into the Service.

Credentials & Secrets. Credentials for third-party systems you authorize us to integrate with are stored encrypted at rest. We store provider-issued tokens where possible and do not retain raw credentials beyond what is necessary to operate the Service. Internal service credentials are managed in AWS Secrets Manager; where supported, we use short-lived, automatically rotated credentials instead of static secrets.

Billing Information. Invoicing and payment processing are handled by Stripe. We do not collect, store, or have access to your payment card information.

Usage, Telemetry & AI Usage Metering. We collect error logs, performance traces, and feature usage metrics through our own instrumentation, stored within our AWS environment. We do not use third-party analytics services, advertising trackers, or data brokers. When you or software we build for you uses AI features, we record per-request usage metadata (model used, token counts, timestamps, and your organization) for billing, capacity, and abuse-prevention purposes; these usage records do not include the content of your prompts or data.

Regulated Data. Where an engagement involves Protected Health Information (PHI) or other regulated data, we process it only under a duly executed Business Associate Agreement (BAA) or equivalent data processing terms.

2. How We Use Information

We use the information we collect to:

  • Provide, operate, maintain, secure, and improve the Service and the software we build for you

  • Authenticate and authorize users

  • Deliver engagements, integrations, and support under an SOW

  • Respond to inquiries and provide customer support

  • Process billing, meter AI usage, and manage accounts

  • Comply with legal and regulatory obligations

We do not sell, rent, or trade your personal information, and we do not share it with advertisers or data brokers.

3. AI Model Providers

AI features in the Service — including AI-assisted development and any AI capabilities in software we deliver — are served through Kilvin's own model gateway. All model traffic exits our environment through this single controlled path to three upstream providers:

  • Anthropic — direct API access to Claude models. Anthropic does not use API inputs or outputs to train models.

  • AWS Bedrock — model inference within AWS. Amazon does not use Bedrock inputs or outputs to train models.

  • OpenRouter — a model-routing service that provides access to models from providers such as Anthropic, OpenAI, and Google, with zero-data-retention (ZDR) routing enabled where available.

Data submitted to AI models through the Service is not used to train models, subject to the upstream providers' terms. Our model gateway does not retain prompt or response content; it records only the usage metadata described in Section 1. Separately, when you interact with AI features that maintain a conversation — such as AI agent sessions — the conversation transcript is stored within your organization's workspace as part of the Service, so you can review and resume your sessions. Transcripts are subject to the same access controls, encryption, retention, and deletion terms as your other Client Data.

4. Data Sharing and Disclosure

We share personal information only with third-party service providers necessary to operate and deliver the Service:

  • AWS — cloud infrastructure: compute, PostgreSQL database, file storage, logging and monitoring, and AI model inference (Bedrock)

  • Anthropic — AI model inference (Claude models, direct API)

  • OpenRouter — AI model routing (ZDR enabled where available)

  • Resend — transactional email (account verification, notifications)

  • Stripe — invoicing and payment processing

  • GitHub — source code hosting and repository access, where your engagement involves code repositories you connect

  • Browser push services (Apple, Google, Mozilla) — delivery of push notifications you opt into

This list may change as the Service evolves; material changes will be reflected in updates to this Policy.

5. Data Retention and Deletion

Personal information is retained for as long as your engagement or account remains active. Upon termination or account deletion, your data is generally retained for thirty (30) days to allow for recovery, after which it is permanently deleted, subject to any legal or BAA-mandated retention requirements. AI usage metering records may be retained longer as billing records. Clients under a HIPAA BAA are governed by the retention terms in that agreement.

6. Security

We implement reasonable technical and organizational measures to protect your information, including:

  • Encryption in transit (TLS) and at rest for databases, file storage, and stored credentials

  • Single-tenant-scoped database access enforced with row-level security

  • Isolated, network-restricted execution environments for AI agent sessions, separated from production databases

  • A single controlled egress path for all AI model traffic, with per-organization authentication

  • Least-privilege access controls and short-lived credentials across our AWS environment

  • A web application firewall on public-facing endpoints

  • SOC 2 Type II-aligned practices across our environment

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Your Privacy Rights

You may update your account information at any time within the Service. To request access to, correction of, or deletion of your personal data, contact us at privacy@kilvin.ai. Clients subject to HIPAA, GDPR, CCPA, or other privacy regulations retain all rights afforded under those laws.

8. International Data Transfers

The Service is operated from the United States, and our infrastructure is hosted in AWS regions in the United States. If you are accessing the Service from outside the US, your information may be transferred to and processed in the United States, which may have data protection laws that differ from those in your jurisdiction. By using the Service, you consent to such transfer and processing in accordance with this Policy and applicable law.

9. Contact Information



  • Email — privacy@kilvin.ai

  • Mailing Address — Chorrie, Inc. d/b/a Kilvin, 122 Greenwich Avenue, Apt 4, New York, NY 10011, USA

10. Changes to This Privacy Policy

We may update this Privacy Policy at any time. Changes will be reflected by an updated "Last Updated" date. Your continued use of the Service following any changes constitutes acceptance of the revised policy.

Work with tools you actually need.

Stop settling for software that wasn't built for you.
Let's build something better.

Work with tools you actually need.

Stop settling for everyone else's software.
Let's build something better.

Work with tools you actually need.

Stop settling for software that wasn't built for you.
Let's build something better.