Privacy Notice
This notice explains how Infiverse uses personal data for the hosted Kern Cloud service.
Last updated 3 September 20261. Controller and contact
Infiverse operates the Kern Cloud service and is the controller for the account and service operations described here.
Privacy questions and rights requests can be sent to [email protected].
2. Data we collect
- Account data: email address, account identifiers, login tokens, and security events.
- Hosting data: agent name, deployment state, encrypted admin credentials, operation history, and support messages.
- Host content: any data stored on or processed by a host, including all data on attached Amazon EBS volumes.
- Billing data: credit balance, the ledger of starter grants, purchases, and usage charges, and the Stripe Checkout Session identifier for each purchase. Card numbers are entered on Stripe's own checkout and never reach Infiverse; Stripe holds the name, billing address, and tax details you give it.
- Technical data: IP address, browser and device information, request logs, and essential session-cookie data.
3. Why we use data
- To authenticate you, deploy and operate hosts, execute instructions, and provide support because this is necessary to perform our contract.
- To secure, debug, monitor, and improve the service and prevent abuse, based on our legitimate interests in operating a reliable service.
- To send requested login codes and service messages, and respond to you.
- To take payment, apply credit, meter usage, and manage service access when a balance is insufficient because this is necessary to perform our contract.
- To keep company, accounting, tax, fraud-prevention, and legal records where required by law.
- To establish, exercise, or defend legal claims and protect users where our legitimate interests or legal obligations apply.
We do not sell personal data or use private host content to train general AI models. We do not make solely automated decisions about you that have legal or similarly significant effects.
4. Host content and business users
Kern Cloud deployments run in infrastructure administered by Infiverse, but we do not routinely inspect host content. Authorised personnel may access the minimum necessary data for support you request, security, legal compliance, or incident response.
If you use Kern to process personal data for your organisation, you decide the purpose and means of that processing and are normally the controller; Infiverse may act as your processor for the hosted service. Contact us for the applicable data-processing terms before placing regulated or third-party personal data in the service.
5. Who receives data
We use providers needed to operate the service, including AWS for cloud infrastructure, Cloudflare for network and access security, Vercel for the console, Stripe for card payments and tax calculation, and email providers for login delivery and service notices. Stripe acts as an independent controller for the payment data it collects and is subject to its own privacy policy. Host content is sent to any provider or third party you connect as your configuration and instructions require.
Providers act under their own terms when independently supplying a service to you and under contractual safeguards when processing for us. We may disclose data to professional advisers, authorities, or a buyer of the business where lawful and necessary.
6. International transfers
Some providers may process personal data outside the United Kingdom. We use the protections required by UK data protection law for those transfers. Contact us for more information.
7. Retention and deletion
Account and deployment data is kept while needed to provide the service. Destroying an agent permanently removes its instance and volumes. Backups, where present, expire through their normal rotation rather than being selectively rewritten.
Billing ledger entries and payment records are retained for the period tax and accounting law requires, which is longer than the account itself. Operational and security logs are retained only as long as reasonably needed for those purposes. On account deletion, we remove or anonymise other data unless a limited record must be retained for law, security, or legal claims.
8. Cookies and security
The console uses only the cookie needed to keep you signed in and secure the session. We do not use advertising or analytics cookies, so no optional-cookie banner is shown. If optional cookies are added, we will update this notice and request consent where required.
We use scoped access, encryption in transit, encrypted storage, and secret management designed to protect personal data. No system is risk-free. Tell us promptly if you believe an account or data has been compromised.
9. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection, or portability, and may withdraw consent where consent is the basis. We may need to verify your identity. We respond within the time required by applicable law, including any permitted extension. You may complain to the data protection authority that applies to you.
10. Children
The service is not directed to anyone under 18, and we do not knowingly create accounts for children.
11. Changes to this notice
We update this notice when processing materially changes and give prominent notice where a change meaningfully affects your rights.