Privacy Policy
Kori is an AI-powered support agent provided by Inite ("we", "us") to support and monitor the integration platform Inite builds and operates for your organization. Kori is available as a Microsoft Teams app and is operated on infrastructure controlled by Inite. This policy explains what data Kori collects, how it is used, and the choices you have. If you have questions, contact us at support@inite.co.
ChatMessage.Read.Chat) — not only messages that @-mention
Kori. Messages that do not require a response are used only for
conversation routing and context and do not trigger a reply. Similarly,
when Kori's Issues tab is added to a group chat, every
member of that chat — including guest users your organization has
admitted — can view the issue data it displays.
1. Who we are
The service is developed and operated by Inite for its customers. Customers access Kori through Microsoft Teams as guest users in Inite's Microsoft 365 tenant. Microsoft Teams itself is governed by Microsoft's own terms and privacy statement; this policy covers what happens once a message reaches Kori.
2. Data we collect
- Message content. The text of messages sent in Teams chats where Kori is installed, including group-chat messages that do not mention Kori (see notice above), and direct (personal) messages sent to Kori.
- Sender information. Your Teams display name and user identifier, and — where needed to verify that you belong to a registered customer organization — your email address or user principal name, from which we derive your organization's email domain.
- Conversation metadata. Conversation and message identifiers, reply threading information, and tenant/channel identifiers, used to route messages to the right support case.
- Feedback. Ratings (helpful / not helpful) and optional comments you submit through the Teams feedback controls on Kori's responses.
- Issues tab sign-in data. When you open Kori's Issues tab in a group chat, we receive a Microsoft Entra ID single sign-on token containing your tenant and user identifiers and your email address or user principal name. We use it to verify your identity, confirm that you are a member of that chat (by checking the chat's member roster), and determine what you can view or edit. The Issues tab does not use cookies or browser tracking technologies.
- GitHub repository data. To display and keep the Issues tab current, we retrieve issue data from your organization's designated repository — issue titles, labels, milestones, priorities, assignees, and requester identities — and receive automated notifications from GitHub when issues, comments, labels, or milestones in that repository change. This data is visible to members of the chat where the tab is installed, including guest users your organization has admitted.
- Customer account information. Information your organization provides to Inite during onboarding and support engagements — such as company name, contact names and roles, email domains, repository details, and architecture documentation — kept in a customer knowledge base so Kori can provide accurate support.
- Operational platform data. When investigating a support case, Kori may query your organization's connected integration platform (for example, workflow and invocation status from a Restate deployment your organization has connected) to diagnose issues.
- Service logs. Technical logs of service activity, including conversation identifiers, routing decisions, case events, and errors, used for operations, troubleshooting, and audit.
3. How we use data
- To answer support questions and investigate issues with your integration.
- To route messages to the correct support case and keep conversational context.
- To verify that a sender belongs to a registered customer organization or is an Inite operator, and to refuse service to unknown senders.
- To create and track engineering work: with the customer's involvement, Kori can file GitHub issues in the customer's designated repository describing a proposed fix, and file case feedback in Inite's internal feedback repository.
- To let members of your Kori group chat view open issues in the Issues tab, and to let authorized users update them (for example, changing an issue's priority, milestone, or a milestone's due date). Edit rights depend on a role derived from your verified email domain: Inite operators and users from your organization's registered domains can make changes; other chat members have read-only access.
- To maintain an audit trail of support cases and any actions taken, for quality and accountability.
- To improve the reliability and quality of the service.
4. AI processing
Kori uses large language models (LLMs) to understand messages and generate responses. Message content and relevant case context are sent to AI models operated by our infrastructure providers (Cloudflare Workers AI, and/or Meta AI models accessed through Cloudflare AI Gateway, depending on configuration) for the purpose of generating support responses. Responses produced by AI are labeled as AI-generated in Teams. We do not use your messages to train our own models. However, the service currently uses Meta's "contributor" model tier, under which Meta may use content — both the prompts sent to the model and the responses it generates — to train and improve Meta's AI models. Meta states that before using such content for training, it takes steps designed to disassociate it from the account and API key that submitted it; see Meta's data commitments and terms of service. Please do not include personal or confidential information in a support request beyond what is needed to resolve it (see the Terms of Use). AI output can be inaccurate; see the Terms of Use for how AI-generated content should be treated.
5. Where data is stored and who processes it
Kori runs on Cloudflare's global platform. We rely on the following service providers to operate the service:
- Microsoft — Microsoft Teams and the Bot Framework, which deliver messages between you and Kori.
- Cloudflare — application hosting, conversation and case state storage, the customer knowledge base, logging, and AI model serving / gateway.
- Meta — LLM inference, when the service is configured to use Meta AI models (such as the muse-spark model family) via Cloudflare AI Gateway. When a "contributor" model tier is in use, Meta may use prompts and model responses to train and improve its AI models (see section 4). Meta's developer platform is governed by its own terms of service and privacy policy.
- GitHub — issue tracking. Fix requests are filed in your organization's own repository and feedback issues in an Inite repository; the Issues tab reads issue data from your organization's repository and applies updates made by authorized users; and GitHub sends us automated notifications when issues, comments, labels, or milestones in that repository change.
Our providers operate globally, so data may be processed outside your country, including in the United States. Where data protection law applies to these transfers, we rely on our providers' contractual safeguards. For data relating to your organization, Inite generally acts as a processor on your organization's behalf, and your organization's agreement with Inite governs that processing.
6. Sharing
We do not sell your data and we do not share it with third parties for advertising. Data is shared only with the service providers listed above as needed to run the service, with your own organization (for example, GitHub issues filed in your repository, or responses visible to other participants in your Teams chat), and where required by law.
7. Retention
Conversation history kept for generating responses is limited to a bounded window of recent messages per support case. Case records (triage summaries, actions taken, filed issues, and related audit entries) are retained so that support outcomes remain traceable. Technical logs are retained according to our logging platform's retention settings. We retain data for as long as needed to provide support to your organization and meet our legal obligations, after which it is deleted or anonymized. You can request deletion of your data by contacting us.
8. Security
Data in transit is encrypted with TLS. Inbound bot traffic is authenticated against Microsoft's Bot Framework, and inbound GitHub notifications are authenticated with signed payloads. Actions the agent takes on customer systems (for example, restarting a workflow invocation) require explicit human approval and are restricted to authorized operators. Issue updates made through the Issues tab are gated by server-side role checks tied to a verified Microsoft Entra ID sign-in and confirmed chat membership. Internal audit endpoints are access-protected.
9. Your rights
Depending on your jurisdiction, you may have rights to access, correct, or delete personal data we hold about you, or to object to or restrict its processing. To exercise these rights, contact support@inite.co. Your organization's agreement with Inite may also govern how data relating to your organization is handled.
10. Changes to this policy
We may update this policy from time to time. The "Last updated" date above reflects the current version. Material changes will be communicated to customer organizations.
11. Contact
Inite — support@inite.co