Privacy Policy

Effective July 22, 2026

Who we are and how this policy works

Kerux is a customer-support helpdesk. This policy explains what personal data we handle, why, and the choices you have. It is written to be GDPR-ready: we follow the principles below for everyone, everywhere.

Kerux handles data in two roles. For the account you create with us — your name, email, company details, and billing — we decide how the data is used (we act as the data controller). For the support conversations flowing through your helpdesk — your customers' names, email addresses, and message content — we process that data on your behalf and on your instructions (we act as a data processor; you are the controller).

What we collect

We collect only what the Service needs to run:

  • Account data: your name, email address, and login credentials (managed by Supabase Auth; we never see your password in plain text).
  • Company data: your company name, team members, helpdesk settings, saved replies, and help-center articles.
  • Support conversations: inbound emails from your customers and the replies sent from Kerux — this includes end-customer names, email addresses, and message content.
  • Billing data: your plan, seat count, and invoices. Payment card details are collected directly by Stripe and never stored on Kerux servers.
  • Usage data: aggregated page-view analytics (via Vercel) and per-ticket AI activity records (which model ran, when, and with what outcome) used to power your analytics dashboard.

How we use it

We use personal data to run your helpdesk: turning inbound email into tickets, letting your team reply, drafting or sending AI answers when you enable them, billing your subscription, and sending transactional email such as team invites. We do not sell personal data, we do not use your support conversations for advertising, and we do not use your data to train AI models.

AI processing

When AI features are enabled for your workspace, ticket content is sent to the AI provider configured in your Settings for classification and answer drafting. The default provider is Groq. If you connect your own provider key, ticket content is sent to that provider instead, under your own agreement with them. AI activity is logged per ticket so you can always see what the AI did and why.

Subprocessors

These are the third-party services that process data on Kerux's behalf. Each is bound by its own data-processing terms:

ServiceWhat it doesData it processes
SupabaseDatabase, authentication, and file storageAll application data: account profiles, company settings, tickets, messages, help-center articles, and uploaded files.
VercelApplication hosting and aggregated page analyticsWeb requests to the Service (IP address, user agent) and aggregated, non-identifying page-view statistics.
StripeSubscription billingBilling name, email, and payment details. Card numbers are entered directly with Stripe and never touch Kerux servers.
ResendEmail delivery, inbound and outboundThe content of support emails your customers send you and the replies you (or the AI) send back, plus transactional email to your team.
Your configured AI provider (Groq by default)AI ticket classification and answer draftingThe content of support tickets (including customer names, email addresses, and message text) sent for classification and answer drafting. If you connect your own AI provider key in Settings, ticket content goes to that provider under your agreement with them.

Security

Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Kerux is built on SOC 2 Type II certified infrastructure — Supabase, Vercel, and Stripe. Every database query is scoped to your company by row-level security, enforced in the database itself, so one company's data is isolated from every other's.

Retention, export, and deletion

We keep your data for as long as your account is active. You can request an export of your company's data, or deletion of your company and all its end-customer data, by emailing support@kerux.io — we honor these requests without undue delay. When a deletion completes, the data is removed from the live database; it may persist in encrypted backups for a limited period before those backups expire.

If you are an end-customer of a company that uses Kerux, that company controls your data — send your request to them and we will assist them in fulfilling it.

Your rights

Depending on where you live, you may have the right to access, correct, export, delete, or object to the processing of your personal data. Email support@kerux.io and we will act on your request without undue delay. If you believe we have mishandled your data, you can also lodge a complaint with your local data-protection authority.

Cookies

Kerux uses cookies only to keep you signed in (authentication session cookies from Supabase Auth). We do not use advertising or cross-site tracking cookies.

Children

The Service is for businesses and is not directed to children. You must be at least 18 to create an account.

Changes to this policy

If we make material changes — including adding a subprocessor — we will update this page and provide notice, for example by email or in-app. Continued use of the Service after changes take effect constitutes acceptance.

Contact

Questions about privacy or this policy? Email support@kerux.io.