Privacy Policy

Last updated: September 5, 2026

Kev is one brain for a business's marketing and its customers, operated by ChangeMastr FZ-LLC (United Arab Emirates). This policy explains what we collect, why, and who we share it with. We keep it plain and current: when we add or remove a sub-processor, we update this page.

Who we are

ChangeMastr FZ-LLC, United Arab Emirates. Contact: service@changemastr.com.

What Kev does

Kev is an AI system that manages a business's marketing relationships: customer conversations across connected channels (WhatsApp, Telegram, email), contact and lead management, marketing content creation and scheduling, appointment booking, and marketing analytics. AI-generated outbound messages are reviewed by the business owner before sending, unless the owner has explicitly enabled direct sending for a specific channel.

What we collect

  • Account data: name, email, authentication identifiers, billing details.
  • Contact and conversation data: contacts, leads, messages, media, notes, calendar events, and analytics the customer's business processes through Kev.
  • Usage data: logs, device and browser metadata, feature usage, error diagnostics.

Your customers' data

When a business uses Kev to communicate with its own customers, that customer data is processed by us on the business's behalf. The business is the controller of that data; ChangeMastr FZ-LLC is the processor.

Purpose limitation

We use data to operate the product the customer signed up for: routing messages, generating and scheduling content, syncing connected accounts, producing analytics, billing, support, and security. We do not sell personal data, and we do not use customer content to train third-party foundation models.

Google API Limited Use disclosure

Kev's use and transfer of information received from Google APIs (Google Analytics, Google Search Console, Google Ads, Google Business Profile, Google Calendar, and Google Meet, each connected only when the customer explicitly authorises it) adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use data received from Google Workspace APIs, including raw or derived data, to develop, improve, or train generalized or foundation AI/ML models. That data is used only to operate the specific feature the customer connected it for (for example, producing that customer's own analytics summaries, or booking that customer's own calendar events) within that customer's own account.

Sub-processors

We share data with the following categories of sub-processors. Data is shared with a given processor only when the relevant feature is used or connected. This list evolves as features are added, removed, or connected; the current list lives on this page.

AI model routing

  • OpenRouter: routes prompts and voice note audio to model providers, including Anthropic and others.

Hosting, database, storage

  • Lovable: application hosting.
  • Supabase: PostgreSQL database and object storage.

Payments

  • Stripe: subscription billing and payment processing.

Messaging channels

  • Meta Platforms: WhatsApp Business API, Instagram, and Meta advertising APIs.
  • Telegram: Telegram messaging.
  • Resend: transactional, conversational and marketing email delivery and receiving, on sending domains the customer verifies.

Google services (customer-connected)

  • Google Analytics, Google Search Console, Google Ads, Google Business Profile, Google Calendar / Meet: used only when the customer connects their Google account.

Marketing data

  • DataForSEO: SEO and marketing data.

Research and data aggregation

  • Monid: routes to research providers including Tikhub, Apify, Exa, Akta, and Apollo.

Social publishing

  • LinkedIn: publishing posts to the LinkedIn account the customer connects.
  • Facebook and Instagram publishing uses the Meta Platforms APIs already listed above.

Website publishing (customer-connected)

  • WordPress: publishing to the customer's own site through the WordPress REST API, using an application password the customer creates. Used only when the customer connects their site.

Document OCR

  • OCR.space: optical character recognition for uploaded documents.

Code and skill content hosting

  • GitHub: hosting of code and skill content.

Access by ChangeMastr staff

ChangeMastr staff cannot read a business's brain content or customer conversations without a time-limited access grant that the account owner creates, with a stated purpose, from Settings. Every content read made under a grant is logged and shown to the owner; the list of file names under a grant is shown without a log entry. Grants expire automatically and can be revoked at any time.

To bill partners for the leads Kev delivers, platform administrators can read contact names, campaign names, campaign content and attribution fields across accounts, outside the grant system. This is the one standing exception and it is disclosed in the same words inside the product.

Retention

We retain account and tenant data for as long as the account is active. On deletion (see below), we remove account data, tenant data, conversations, and stored media from our systems within 30 days, except where we are required by law to retain records (e.g. tax and payment records). Backups are purged on their normal rotation.

Data deletion

To request deletion of your account and associated data, see Data Deletion.

Security

Data is encrypted in transit. Access to production systems is restricted to authorised personnel. Report suspected vulnerabilities to service@changemastr.com.

Contact

Questions or requests: service@changemastr.com.