Skip to content

Legal

Privacy Policy

Last updated: May 6, 2026

Who we are

KASII is a case management agent operated by KASII (“KASII,” “we,” “us”). KASII is provided to boutique law orgs (each, a “Org”) so they can run client check-ins, treatment-adherence tracking, loss-theory intake, and case updates with their clients (“Clients”).

This Privacy Policy explains what information KASII collects, how it is used, and the choices available to you. If you have questions, contact us at support@kasii.ai.

Information we collect

  • Account information from Orgs: name, work email, role, org name, billing details.
  • Client information provided by Orgs: name, mobile phone number, email, date of birth, mailing address, and case-related context the Org chooses to share with KASII (e.g. treatment plan, injury narrative).
  • Messaging content: SMS, MMS, and email exchanges between KASII and a Client, including responses, timestamps, and delivery status.
  • Usage data: log data, device/browser information, IP address, and product analytics about how Orgs use the dashboard.

How we use information

  • To deliver the case management service the Org has engaged us for.
  • To send SMS/MMS check-ins, reminders, and case updates to Clients on the Org's behalf.
  • To operate, secure, debug, and improve KASII.
  • To meet legal, regulatory, and contractual obligations.

SMS, MMS, and mobile information

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing to subcontractors that support the service (for example, our messaging carrier Telnyx) is permitted only to deliver the messages you have consented to receive. All categories of data exclude text-messaging originator opt-in data and consent; this information will not be shared with any third parties.

Clients receive messages from KASII because their Org has added them to a case and the Client has provided their mobile number to the Org in connection with that representation. Clients may opt out at any time by replying STOP to any message, or get help by replying HELP. Message frequency varies based on the case. Message and data rates may apply.

How we share information

We share information only as needed to run the service:

  • With the Orgthat represents the Client — KASII acts on the Org's behalf and the Org sees the messages KASII exchanges with its Clients.
  • With service providers who help us deliver the product (cloud hosting, telephony/SMS providers, email infrastructure, analytics, error monitoring), each bound by confidentiality and data-processing terms.
  • For legal reasons — to comply with law, valid legal process, or to protect the rights, safety, and property of KASII, our users, or others.
  • In a corporate transaction — if KASII is involved in a merger, acquisition, or sale of assets, information may transfer subject to this Policy.

We do not sell personal information, and we do not share mobile phone numbers or SMS opt-in data with third parties or affiliates for their own marketing.

Sub-processors and service providers

We rely on a small number of trusted service providers (“sub-processors”) to operate KASII. Each processes information only on our instructions and is bound by confidentiality and data-processing terms. We require sub-processors to apply safeguards consistent with this Policy. The categories we use are:

  • Database hosting — MongoDB Atlas: stores Org and Client records, case context, and messaging history.
  • Application hosting and platform — Vercel: hosts the KASII web application and dashboard, and provides the AI Gateway and firewall/rate-limiting layer through which our requests are routed.
  • AI model providers (via the Vercel AI Gateway) — Anthropic, OpenAI, and Google: generate chat responses, summaries, and attorney-ready briefs from case content. We route these requests through the gateway rather than contracting with providers directly.
  • Billing and payments — Stripe: processes Org subscription and payment information. KASII does not store full card numbers.
  • Media and file storage — Cloudflare (R2 and image delivery): stores and serves files and images uploaded in connection with a case.
  • SMS/MMS messaging — Telnyx: our telephony carrier for delivering text-message check-ins, reminders, and case updates to Clients.
  • Transactional email — our transactional email provider: delivers account, notification, and case-related email on our behalf.

This list reflects the providers we use today and may change as the service evolves. We aim to keep it current; the categories above describe the role each provider plays.

Data retention

We retain Org and Client information for as long as the Org's account is active or as needed to provide the service. Messaging records are retained for the length of the engagement plus a reasonable period required to meet legal, audit, and dispute-resolution obligations. Orgs may request deletion of a Client's record at any time by contacting us.

Security

We use industry-standard administrative, technical, and physical safeguards (encryption in transit, access controls, audit logs) to protect information. No method of transmission or storage is perfectly secure; we work to address vulnerabilities promptly when they are reported.

Your choices and rights

  • SMS opt-out: reply STOP to any KASII message to unsubscribe from that program. Reply HELP for support.
  • Access, correction, deletion: Clients may contact their Org or email us at support@kasii.ai to request access, correction, or deletion of their information, subject to applicable law and the Org's legal/ethical retention obligations.
  • State-specific rights: residents of certain US states (including California, Colorado, Connecticut, Virginia, and Utah) may have additional rights regarding their personal information. To exercise them, contact us at the address above.

Children

KASII is not directed to children under 13 and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us so we can delete it.

International data transfers

KASII is operated from the United States, and the sub-processors listed above are primarily US-based. By using KASII, you understand that information will be processed in the United States, which may have different data-protection laws than your jurisdiction.

Where information is transferred from the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards for such transfers — typically the European Commission's Standard Contractual Clauses (and the UK / Swiss equivalents) or another lawful transfer mechanism — as contemplated by Chapter V of the GDPR. You may contact us (see below) to ask about the safeguards that apply to a specific transfer.

Changes to this Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the dashboard or by email. Continued use of KASII after the effective date constitutes acceptance of the updated Policy.

Contact and data protection

Questions or requests? Email support@kasii.ai.

For data-protection matters — including access, correction, deletion, or questions about international transfers — you can reach our data protection contact at privacy@kasii. (TODO: the Org must set a real Data Protection / DPO contact address before publishing.)