Back to Kernel

Privacy

Your information, in context.

This notice explains how Kernel’s public website, private beta application, and optional connections handle information. Kernel is operated by Simon Corcos.

Last updated September 8, 2026

The website and the application

This public website has no accounts, submission forms, or client-side analytics. Its hosting service may process request information, such as an IP address, browser information, requested URL, and timing, to deliver and protect the site.

The separate, invite-only Kernel application handles workspace information you provide: tasks, projects, time records, schedules, preferences, attachments, and activity history. Public booking guests may provide a name, email address, and optional message. Booking information is sent to Google when needed to create calendar events, meeting links, and invitations.

Google sign-in is not mailbox access

Kernel uses Clerk for account authentication. Basic Google sign-in provides identity information such as your Google account identifier, verified email, name, and profile image, together with authentication and session information. Signing in does not itself authorize Kernel to read Gmail or manage your calendar. Those features use a separate Google connection and permission request.

Optional Google and Slack connections

When you connect Google Calendar, Kernel reads your calendar list, events, and availability to display selected calendars, plan work, and prevent booking conflicts. On calendars you can edit, it can create, update, reschedule, delete, and respond to events, including bookings with meeting links and attendees.

Optional Gmail read-only access imports message headers, participants, and bounded message or thread text for inbox and task features. Automatic intake starts with recent inbox messages and follows later changes; explicitly importing a Gmail link can retrieve an older or archived thread. Kernel does not send, modify, or delete Gmail messages. Connecting Gmail requires the separate integration disclosure and consent.

An optional Slack connection reads accessible message and channel information for the configured inbox features. Kernel stores imported information and connection credentials to support synchronization. The information processed depends on the connection, permissions, and features you enable.

AI-assisted features

When enabled, AI features send relevant context through OpenRouter to a model provider to generate suggestions or organize information. Inputs can include bounded message or thread text, draft suggestions, task and project context, owner email addresses, connected identities, time zone, and workspace guidance. Results and related metadata may be stored in Kernel.

New task and event suggestions require your review before creation. Enabled inbox features can also add context to linked tasks and complete a previously accepted task when its source conversation explicitly confirms completion. Integration disclosures explain the processing before consent.

Kernel’s inbox AI requests ask OpenRouter to route to providers that do not collect the inputs and outputs for training, and request that responses not be stored. These request settings are not a promise that every intermediary keeps no records: operational metadata, routing, and provider retention rules also apply. Contact us for the current model and processing configuration.

Google data and Limited Use

Kernel’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Kernel uses Google Workspace data and derived information only for the disclosed user-facing features. It does not sell this data, use it for advertising, or use it to train general-purpose AI models. Transfers and human access are limited to Google’s permitted purposes and consent requirements.

Service providers and security

Kernel uses Vercel for hosting and attachment storage, Neon for the application database, Google Cloud for background processing, Clerk for authentication, and OpenRouter and the selected model providers for enabled AI features. These providers process information needed for their roles.

Application logs can contain IP addresses, user agents, routes, response status, timings, and actor or workspace identifiers. If enabled, PostHog can receive product events, errors, and masked session replay. This is separate from the public website, which does not include client-side analytics. Selected imported content and credentials use server-side encryption; Kernel is not an end-to-end encrypted service, and not every database field has that additional application-level encryption.

Retention, deletion, and contact

Disconnecting a service and deleting imported copies are separate actions. Deleting imported data alone does not stop an active connection from importing again. Accepted tasks or events, task/time/audit history, and Google authorization history may remain. Account removal is operator-assisted and does not mean every historical record is erased. Cleanup and backup expiration are not immediate.

Read the data management and deletion instructions before making a request. Kernel does not apply a single automatic expiration period to all workspace records. For privacy questions or requests about retained information, contact Simon Corcos at simoncorcos.ing@gmail.com. Material new uses of Google data require updated disclosure and consent before that use begins.