Kimi
Privacy policy rating
- Your data trains their AI unless you opt out by form or email.
- Your data is used for personalized ads, including by third-party ad companies.
- Data is shared with partners and affiliates; you can opt out.
- The documents do not say who can read your content.
Kimi collects chats, device IDs, location and voiceprints, trains models unless you email to opt out, and shares with partners.
Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.
Collected
Account info, chats, files, device IDs, logs, and sometimes location, clipboard, and voiceprint.
Read the exact line
Privacy policy
“we may collect other information such as your precise location information, clipboard information, and voiceprint information.”
Training
They use your chats to run the service and, unless you email them, to optimize models.
Read the exact line
Privacy policy
“we will use the content you input and output to optimize our models, or use your access to and use of our products for data analysis”
Sharing
Service providers, affiliates, SDKs, payment processors, and ad partners may get some data.
Read the exact line
Privacy policy
“we may share your personal information with partners (including our affiliates and other third parties) to enable the normal use of functions such as API interfaces and software development kits (SDKs).”
Kept
They keep data in China for as long as they say they need it; no exact delete-by date.
Read the exact line
Privacy policy
“Unless otherwise provided by national laws and regulations, we retain your personal information only for the period necessary to achieve the service purposes.”
Controls
You can delete chats and your account in Settings, turn off memory, and email to stop training.
Read the exact line
Privacy policy
“If you do not want your content to be used for model training, you may contact our customer service through the contact details set out in Section 11 of this Policy and make a request.”
Fine print
Major policy changes get a notice, but keeping using the app means you accept the new rules.
Read the exact line
Privacy policy
“If you continue to use our products and services, it means you have fully understood and agreed to accept this update.”
Expand “Read the exact line” to see the source alongside the explanation.
What you can turn off
The controls and opt-outs their own documents describe, and where they say to find them.
Ask them to stop using your content for model training
Email support@moonshot.cn or in-product feedback (Section 11)
Turn off conversation memory and manage saved content
Product settings page
Delete chats or delete your account
App: Settings → Account Security → Delete Account; also Chat History → Delete Chat. Web: Settings → Account Settings → Delete Account
Refuse microphone, camera, or location permissions you do not need
Device permission settings or in-app permission prompts
If a switch is not where they say, the deletion request above still applies.
Line by line
The lines that matter most, worst first.
Your chats can be used to improve their AI unless you email them and they verify you.
Read the exact line
Privacy policy
“If you do not want your content to be used for model training, you may contact our customer service through the contact details set out in Section 11 of this Policy and make a request.”
For example, a private story you typed in Kimi could be used to train models until support processes your request.
They work with ad companies and may give them data to show and measure ads.
Read the exact line
Privacy policy
“To display advertisements for Kimi products and services to you on third-party websites, applications, and other platforms and to measure the effectiveness of such advertising, we may cooperate with advertising partners”
For example, you might see a Kimi ad on another app because they shared info with an ad platform.
Your data can go to affiliates and other companies that power parts of the app.
Read the exact line
Privacy policy
“we may share your personal information with partners (including our affiliates and other third parties) to enable the normal use of functions such as API interfaces and software development kits (SDKs).”
For example, an SDK inside the app could receive device or account data so a feature works.
If you use custom voice features, they keep a voiceprint, which they call sensitive.
Read the exact line
Privacy policy
“Under this feature, we will collect your voiceprint information to provide you with personalized, customized voice services. Voiceprint information is your sensitive personal information.”
For example, recording a reply voice can create a voiceprint they store until you delete it on that page.
Location features can collect precise location, which they also call sensitive.
Read the exact line
Privacy policy
“If you use location-based services, we will collect your location information.”
For example, asking about nearby weather can send your exact location if you turned that permission on.
Pasting, and some other needs, lets them collect what is on your clipboard.
Read the exact line
Privacy policy
“When you paste content from the system clipboard into the conversation input box, or when clipboard content is used for other business needs, we need to collect and use your clipboard information.”
For example, copying a password then pasting into chat could send clipboard contents to them.
The app can keep a lasting summary of things you said to use in later chats.
Read the exact line
Privacy policy
“we may remember, organize, or summarize information you mention in conversations, using it as background reference for generating subsequent replies.”
For example, if you mention your job, later answers may assume that unless you turn the feature off.
You can see, manage, and switch off that conversation memory in settings.
Read the exact line
Privacy policy
“You can disable or re-enable the relevant feature through the product settings page, and can also view and manage the saved content.”
For example, you can open settings, review saved notes about you, and turn the feature off.
You can delete your account yourself in the app or on the website.
Read the exact line
Privacy policy
“You can, in [Account Security] under [Settings] in the App, select [Delete Account]; or in [Account Settings] under [Settings] in the web end, select [Delete Account].”
For example, you tap Settings then Account Security then Delete Account on your phone.
After they change the policy, using the app again counts as agreeing.
Read the exact line
Privacy policy
“If you continue to use our products and services, it means you have fully understood and agreed to accept this update.”
For example, opening Kimi after a pop-up update can lock you into the new rules.
They ask under-18s to get guardian consent but admit they cannot really check age.
Read the exact line
Privacy policy
“Due to limitations of technical means and legal provisions, we cannot accurately identify minors during registration and use.”
For example, a 16-year-old can still sign up with a phone number without a real age check.
Words to know
Legal words from the lines above, in plain English.
- precise geolocation
- Your exact position, usually from GPS, often accurate to within a few metres. For example, an app can tell not just your city but which building you are in right now.
- biometric
- Measurements of your body that identify you, like your face, fingerprint or voice. For example, a selfie used to unlock the app or a voice recording matched to you.
- inputs and outputs
- Inputs are what you type, say or upload to an AI; outputs are what it gives back to you. For example, the question you ask a chatbot is an input and its answer is an output, and both may be stored.
- personal data
- Any information that is about you or can be linked to you, from your name to your phone's ID. For example, your email, your IP address and the list of apps on your phone are all personal data.
- affiliates
- Other companies owned by or connected to the same parent company. For example, if you use one app, its sister apps under the same owner may also get your data.
- third parties
- Any company or person other than you and the app, such as advertisers, partners or analytics firms. For example, an analytics company that receives a record of every screen you tap is a third party.
- tracking pixels
- Tiny invisible images or bits of code in a page, app or email that report back when and where you opened it. For example, a pixel in a marketing email tells the sender the moment you read it.
- retention
- How long a company keeps your data before deleting it. For example, a policy might keep your messages for 30 days after you delete them, or for as long as it likes.
- model training
- Using your content and conversations as examples to teach an AI system, which can then echo them in future answers. For example, a story you write in a chatbot may be studied by the company to make the next version of the bot.
- sensitive personal information
- Data that could hurt you if exposed, like health, religion, sexuality, race, exact location or bank details. For example, telling a chatbot about a medical condition creates sensitive data that some laws protect more strictly.
How we got here · grade F · score 33/100 · 15 of 15 policy answers backed by a verified quote · 6 not stated
What does the app collect beyond what it needs to work?
Besides account and chats, they collect device identifiers, logs, and may collect precise location, clipboard, sensors, and voiceprint.
Does it record your voice, face or body, and what happens to that?
Voice features collect voiceprint information, which they call sensitive; they say you can delete it on the relevant page.
Are your chats and uploads used to train AI models, and is that off by default?
They use your input and output to optimize models unless you contact customer service and they verify you.
Can employees or contractors read your conversations, and when?
Not stated in the documents.
Are you profiled or tracked for advertising?
They cooperate with advertising partners and may give them anonymized personal information to show and measure ads.
Do they sell or share your data, and can you opt out?
They share with affiliates, third parties, SDKs, payment processors, and ad partners. You can withdraw consent or delete your account.
What rights do they take over what you type and what the AI makes?
Not stated in the documents.
How long do they keep your data after you delete it, and can you delete it in the app?
Not stated in the documents.
Does it build a lasting memory or profile of you, and can you see, edit or turn it off?
They may remember and summarize conversation details; you can view, manage, and turn that feature off in settings.
Do they commit to basic security, and have they leaked data?
They describe encryption, access limits, backups, and breach response, but not an independent audit or VDP.
Is there a real age gate, and are teens protected?
They say the product is mainly for adults and under-18s need guardian consent, but they cannot accurately identify minors.
Will they tell you when the rules change, and is the policy specific?
The policy is dated. They say they will notify you of major updates, but continued use means you accept.
Can they close your account without warning, and can you get your data out first?
Not stated in the documents.
If something goes wrong, who pays?
Not stated in the documents.
Do subscriptions renew on their own, and can you get a refund?
Not stated in the documents.
The privacy policy is 6,143 words at a college graduate level (Flesch reading ease 30.3).