Legal

Privacy Policy

Last updated 29 July 2026

KYBR is a licensed Growth Operating System used by businesses to run their own marketing. That shape matters for privacy, because two very different kinds of personal data flow through the platform: information about our clients, and information about our clients' customers and leads.

We are the controller of the first and a processor of the second. Section 02 explains what that means in practice, and Section 05 lists every third party that data reaches.

01Who this covers

This policy applies to the KYBR platform at kybrmarketing.ai and its API. The legal entity responsible is Beard Growth Partners [ confirm registered entity form — LLC / Inc ], registered at [ registered address ].

It does not cover our clients' own websites, forms, or marketing. When you give your details to a business that happens to use KYBR, that business decides how your information is used — this policy describes what we do on their instructions.

02The two roles we play

For client account data, we are the controller. If you sign up for KYBR, we decide how your account information is handled and you can exercise the rights in Section 08 directly against us.

For contact and lead data inside a client's workspace, we are a processor. Our client is the controller. We hold and process that data to provide the service and on their instructions — we do not sell it, rent it, use it to build our own marketing lists, or use it to train AI models. If you are an individual whose details sit in a client's workspace and you want them accessed, corrected, or deleted, the fastest route is the business you dealt with. Contact us and we will help identify and assist them.

03What we collect

CategoryWhat it includesWhere it comes from
Client account dataName, email address, organisation name, hashed password, or a Google account identifier if you sign in with Google.You, at signup.
Business profilePositioning, mission, target audiences, products and services, brand voice — what the platform calls the KYBR Brain.You, during onboarding and afterwards.
Contact and lead dataNames, email addresses, phone numbers, tags, pipeline stage, lead scores, and opt-out status for your contacts.Mirrored from your connected CRM, and from events it sends us.
Content and assetsCopy, images, and files generated in or uploaded to the platform.You, and the AI models acting on your instructions.
Operational recordsAudit entries, AI token usage and cost, webhook and job history, error logs.Generated automatically as you use the service.

We do not intentionally collect special category data (health, biometrics, political or religious views, and so on). Please do not place it in free-text fields.

04How AI processing works

KYBR uses third-party AI models to generate marketing copy and to qualify leads. This is the part of the platform most likely to surprise people, so we describe it precisely.

Content generation sends your business profile and the brief you supply. It does not send your contact lists.

Lead qualification does send information about an individual contact. For each lead scored, the model receives:

  • the contact’s first and last name, where present;
  • the contact’s email address;
  • whether a phone number exists on the record — never the number itself;
  • any tags on the record, and its pipeline stage;
  • your business profile, as the ideal-customer profile to score against.

The model returns a score from 0 to 100. We store that score and pass it back to your CRM. We do not use your data, or your contacts' data, to train or fine-tune any model, and our AI providers are engaged under terms that prohibit them from doing so on our behalf.

Lead scores influence automation — a high score can tag a contact and trigger a workflow in your CRM. Scores are advisory inputs to your own marketing decisions, not automated decisions producing legal effects, and you can inspect and override any score in the platform.

05Who we share data with

We use the sub-processors below. We do not sell personal data, and we do not share it for advertising.

Sub-processorPurposeData reaching them
Amazon Web ServicesApplication hosting.All categories, in transit and in memory.
NeonManaged PostgreSQL database.All stored categories.
CloudflareObject storage for assets (R2), plus network and DNS.Uploaded files and request metadata.
OpenAIContent generation and lead qualification.Business profile, briefs, and the lead fields listed in Section 04.

Where you connect a CRM, it is your own account with that provider, governed by your agreement with them. KYBR reads from and writes to it on your instruction; message delivery, opt-out handling, and deliverability are performed by that platform, not by us.

We may also disclose data where the law requires it, to protect our rights or someone's safety, or to a buyer or successor in a merger or acquisition — in which case this policy continues to apply until you are told otherwise.

06Where data is held and how long we keep it

Our infrastructure is hosted in [ hosting region — e.g. US East ]. If you are in the UK, EEA, or Switzerland, your data may be transferred outside your region; where that happens we rely on [ transfer mechanism — e.g. Standard Contractual Clauses ].

  • Client account data is kept while your account is active.
  • Contact and lead data is kept while your workspace holds it. Deleting a contact in the platform removes our mirrored copy; it does not delete the record in your CRM, which you control.
  • Operational records, including audit and usage history, are retained for up to 24 months so we can investigate incidents and bill accurately.
  • After termination we delete or irreversibly anonymise your data within [ retention window — e.g. 30 days ], except where we must keep records for legal or accounting reasons.

07How we protect it

  • All traffic runs over TLS.
  • CRM access tokens are encrypted at rest with AES-256-GCM, and the API never returns a stored token — it is write-only from the interface.
  • Each client workspace is logically separated, and every request is scoped to the workspace that made it.
  • Access to production data is limited to personnel who need it to operate and support the service.
  • Inbound webhooks are cryptographically verified before we act on them.

No system is perfectly secure. If a breach affects your personal data we will notify you and any regulator as required by law and without undue delay.

08Your rights

Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, restrict or object to processing, withdraw consent, receive it in a portable format, and not be discriminated against for exercising any of these.

Write to [ privacy contact email ] and we will respond within the period the applicable law requires — one month under UK and EU GDPR, 45 days under the CCPA. As noted in Section 02, if your details are in a client's workspace we will direct you to that client and help them respond.

You may also complain to your data protection authority. In the UK that is the Information Commissioner's Office.

09Cookies and children

We use only what is necessary to run the service: a session token to keep you signed in, and our infrastructure providers' security and load-balancing cookies. We do not run advertising or cross-site tracking cookies on the application.

KYBR is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16; if you believe we have, contact us and we will delete it.

10Changes

We will update this page when our processing changes, and revise the date at the top. For changes that materially affect your rights we will give notice in the platform or by email before they take effect. This policy is governed by [ governing law ].

Questions: [ privacy contact email ]. See also our Terms of Service.