Privacy Policy
Last updated 18 August 2026
This policy explains what Kitea collects, why, who it is shared with, and how to get it removed. It is written to be read, not to be survived.
1. Who we are
Kitea is a search-visibility platform operated by Simple Optimum Solutions ("Simple OpS", "we", "us"). Kitea is provided to businesses ("Customers") to manage their own websites, business listings, and marketing channels.
This policy covers kitea.ai and the Kitea application. Questions: support@kitea.ai.
2. Information we collect
Account information. Name, email address, business name, business address and locations, industry, and billing details. Payment card data is collected and stored by Stripe, never by us.
Connected-account data. When you authorise a connection, we access data from that account strictly to operate the features you enabled. This includes search performance and analytics data, business-listing content and reviews, social page content, and content management system posts and media.
Your published content. We read your website's public pages and existing posts to build the writing-style profile used to draft new content in your voice.
Content we generate. Drafts, published posts, reports, and a full log of every action taken on your behalf.
Free audit requests. When anyone submits a domain for a free audit, we record the domain, publicly available data about it, and the requester's IP address for rate limiting.
Usage data. Standard server logs, and application error reports via Sentry with personal data scrubbed.
3. Google API Services — Limited Use disclosure
Kitea's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We request read access to Google Search Console and Google Analytics, and management access to your Google Business Profile, only for accounts you explicitly connect.
- We use this data solely to provide and improve the user-facing features you enabled — reporting, content generation, and publishing you approve.
- We do not transfer this data to third parties except as necessary to provide those features, comply with applicable law, or as part of a merger or acquisition with notice to you.
- We do not use this data for advertising, and we do not sell it.
- We do not allow humans to read this data, except with your explicit consent for specific messages, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymised.
Kitea requests no restricted Google scopes. We do not request access to Gmail, Drive, or any other restricted scope, and we do not read your email.
You can revoke Kitea's access at any time from your Google Account permissions page or from within Kitea. Revoking access stops the affected features immediately.
4. How we use information
- To operate the features you enabled: auditing, tracking, content generation, publishing, citation building, and reporting.
- To generate drafts in your voice, using your own published material as the reference. Your content is used only for your account and is never used to train third-party models or to serve other customers.
- To bill you, support you, and notify you about your account.
- To detect and prevent abuse of the free audit and the platform.
We do not sell, rent, or trade personal information, and we do not use behavioural advertising.
5. Service providers
We use the following providers, each processing data only as needed to deliver Kitea:
- Google Cloud and Firebase — application hosting, database, and key management.
- Vercel — web hosting and delivery.
- Anthropic — content generation. Data sent for generation is not used to train Anthropic's models.
- DataForSEO — search-ranking, keyword, and backlink data.
- Stripe — subscription billing and payment processing.
- Amazon Web Services (SES) — transactional email delivery.
- Sentry — error monitoring, with personal data scrubbed.
Meta, LinkedIn, Pinterest, Apple, and your CMS receive only the content you approve for publication to your own accounts.
6. Protected health information
Kitea serves medical, dental, and aesthetic practices, and is designed to operate entirely outside the scope of protected health information.
- Kitea does not connect to electronic medical records, practice management systems, or any patient database.
- Review responses drafted by Kitea never confirm that someone is a patient and never reference treatment details. This is enforced by an automated check before any draft reaches you.
- Outreach features require a dedicated marketing mailbox, never a clinical inbox, so Kitea never holds credentials to an account carrying patient correspondence.
- Customers must not submit protected health information to Kitea. Free-text fields are screened and obvious patient identifiers are rejected.
Kitea is not a HIPAA business associate and does not enter business associate agreements for this service.
7. Security and tenant isolation
Credentials. Access tokens and API keys are encrypted with a per-customer key using envelope encryption backed by Google Cloud Key Management Service. They are decrypted only at the moment of use, for a single customer.
Isolation. Customer data is stored under a per-customer path, and every read is scoped to the authenticated session's customer. Requests are never scoped from a client-supplied identifier. Automated tests assert that one customer cannot read another's data, and they run on every change.
Access. Simple OpS personnel do not access connected-account data except as described in section 3.
No system is perfectly secure, but we will notify affected Customers without undue delay if a breach affecting their data occurs.
8. Retention and deletion
We retain account and content data for as long as your subscription is active.
On cancellation you may request a full export. Connected-account credentials are destroyed immediately on disconnection or cancellation. Remaining account data is deleted within 90 days of cancellation, except records we must keep for tax, accounting, or legal reasons.
Free audit results are cached for 30 days and then discarded.
To request access, correction, export, or deletion, contact support@kitea.ai.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, and to object to or restrict certain processing. We honour these requests regardless of jurisdiction. We will not discriminate against you for exercising them.
Kitea is not directed to children and we do not knowingly collect information from anyone under 18.
10. Changes and contact
We will post any changes to this policy on this page and update the date above. Material changes affecting how we handle connected-account data will be notified by email before taking effect.
Simple Optimum Solutions · support@kitea.ai · simple-ops.ai