Kenn

Your information

Kenn Privacy Policy

Effective 15 September 2026. This notice covers Kenn’s website, mobile apps and website bot. Kenn is operated by Biovell Company Limited. For privacy requests, contact biovellcompanylimited@gmail.com.

The short version

Kenn uses information to run your account, organise business work and respond to customers. Biovell does not sell personal data or use customer data for advertising. Important account actions require verification. You can ask for a copy of your data or delete your account.

Information Kenn handles

  • Your account: your name, email address, phone number, account identifiers, verification status, preferences and sign-in sessions.
  • Your business: website address, business information, customer and lead details you provide, conversations, tasks, plans, sales records, approvals and saved work.
  • Support: messages, requests and information you send to customer care.
  • Payments and usage: subscription status, billing references, credit balances and service usage. Stripe handles card entry on its payment pages. Kenn does not receive your full card number or security code.
  • Technical information: IP addresses, request times, security events, browser or device information, app and operating-system versions, and service errors handled by Kenn’s infrastructure and sign-in providers.

The current mobile app does not request your device address book, precise location, photo library or microphone. Customer contact details are information you enter into Kenn, not a scan of your phone. If you voluntarily put personal or sensitive information in a message or record, it becomes part of that content. Please include only information you are entitled to use.

Why the information is used

Kenn uses account information to verify identity and provide the service you request. Business records and messages support customer conversations, follow-ups and workspace features. Usage records enforce allowances and protect spending limits. Technical and audit records protect against abuse, investigate faults and secure the service. Payments are processed to perform your subscription contract and meet applicable accounting obligations.

Where UK or European data-protection law applies, these purposes rely on providing the requested service, legitimate interests in operating a secure service, legal obligations, or consent where required. You may withdraw consent for optional processing without changing the lawfulness of earlier processing.

Providers and sharing

Google Firebase and Google Cloud provide authentication, SMS verification, hosting, databases and infrastructure. Google may process phone numbers and security signals to prevent abuse. See Firebase’s privacy information.

Stripe processes website payments and may keep transaction records under its own legal obligations. See Stripe’s privacy policy. The mobile app is a companion to the website account and does not sell subscriptions inside the app.

When an AI feature is available and you use it, the relevant prompt, conversation context and business facts needed to answer are sent to OpenAI through the Kenn service. AI answers can be inaccurate; review important outputs. AI availability is subject to account allowances, provider availability and platform spending limits. New purchases remain paused. Provider processing and retention are explained in OpenAI’s API data documentation; disabling response storage does not mean no provider security logs exist.

Your website customers’ messages and submitted contact details are visible to the business operating that bot and its authorised team. The business decides how to use those records; contact that business for requests about its use of your information. Biovell can help identify and process requests concerning the Kenn service. Access by Biovell staff is limited to authorised operational and support purposes. Information may also be disclosed when required by law or necessary to protect rights and security.

These providers operate internationally. Processing may occur outside your country, including in the United Kingdom, European Economic Area and United States. Provider terms describe their processing locations and applicable transfer safeguards. Contact Biovell for information about a transfer concerning your data.

Security and local storage

Kenn uses HTTPS for network connections and protected account access. Mobile sign-in credentials are kept in the device’s secure storage. Essential cookies or browser storage keep you signed in and remember your preferences. No system can guarantee absolute security. Never share a password, SMS code, private deletion receipt or verification link with support.

Retention and deletion

Account and workspace information is kept while needed to provide your account, or until you delete it. Open Help and settings → Delete account to confirm permanent deletion. Your identity is checked, access is locked, linked Kenn Stripe subscriptions are cancelled, and account-associated active-service records and the Firebase sign-in identity are removed. Workspaces you own are removed; other members’ separate accounts and other businesses’ workspaces are not deleted. Deletion does not automatically issue a refund.

Deletion advances on your progress checks or an authorised owner action, not on a repeating cloud worker. The signed-in deletion screen checks for up to five minutes while open. Large accounts or provider interruptions may require additional checks. If you leave the screen, use your receipt to return or contact Kenn support to continue the saved request. Only a completed status confirms deletion. See the deletion page for instructions and help.

The completion receipt contains no account ID, email, sign-in identity or billing reference. It can be used for seven days after completion. An expired receipt is removed when next checked; without a repeating cleanup worker, an unchecked, non-identifying receipt may remain stored longer.

Cloud security and operational logs are separate from account records. Kenn’s current Google Cloud log retention is 30 days for ordinary logs and 400 days for the required audit-log bucket. Google Authentication may retain logged IP addresses for a few weeks under its published policy. No scheduled Firestore backups or extended point-in-time recovery are currently configured. Provider infrastructure recovery copies are governed by provider retention and deletion processes, not an instant-erasure promise.

Only information needed for payments, fraud prevention or legal obligations may be retained beyond account deletion, and only as long as that purpose requires. Payment providers may retain legally required transaction history. Information you or another authorised person already exported outside Kenn is not remotely erased by deleting the account.

Your choices and rights

You can update your profile, request access or correction, export supported account records, or initiate deletion. Depending on your location, you may also have rights to portability, restriction, objection, withdrawal of consent, and a complaint to your local data-protection authority. Biovell will verify requests proportionately without asking for your password or SMS code. The UK Information Commissioner’s Office provides information about complaints in the UK.

Kenn is a business service, not a service directed to children. Please contact Biovell if you believe a child’s personal information has been provided without appropriate authority.

Changes and contact

Updates will be posted here with a revised effective date. Material changes will be explained through the service where appropriate. For questions, rights requests or trouble accessing deletion, email biovellcompanylimited@gmail.com.