Skip to main content

Plain answers. Real limits.

How Kwilo handles business data, customer details, AI-assisted features, cookies and service responsibilities. Start with the plain-English summary, then open the relevant document for the full wording.

Content updated · 29 August 2026

Four things, in plain English.

The approach in four short rules, with the longer policies below when you need the exact detail.

You control the business records you add.

Your business normally acts as controller for the customer and business-record data it adds. The privacy notice explains Kwilo’s role, why data is used, and when legal or service reasons mean it must be retained.

We do not sell personal data.

The current privacy notice states that Kwilo does not sell personal data. Business information is used to provide, secure and support the service, subject to the purposes and sharing explained in the notice.

Handled carefully.

Kwilo uses reasonable technical and organisational safeguards for business records, customer details and money workflows. No online service can promise perfect security, so account access remains a shared responsibility.

You stay in charge.

Important customer messages, money actions and tax-related records should be reviewed by you or an authorised person. HMRC filing happens through compatible software or an authorised agent outside Kwilo. AI helps; it does not take responsibility.

What you can verify today.

Trust is not a badge collection. These are the practical points a cautious user is likely to check before moving business records in.

PointWhat to expectStatus
Trying Kwilo

Choose “Give it a try” to see whether requests are open. When they are, submit the form, verify your email and wait for human review. Sign in only if invited.

Access requests opened gradually
Data export and deletion

The privacy notice explains controller and processor roles, retention, individual rights and service or legal limits.

Explained in policy

AI can help. You decide.

AI may help with drafting, transcription, summaries or suggestions. It should stay assistive and reviewable, especially around customers, money and tax.

No public-model training without disclosure and authorisation.The current privacy notice says business data is not used to train public AI models unless that use is explicitly disclosed and authorised.
Every output is reviewable.AI-assisted drafts should be reviewed before they are sent, relied on for pricing, or used for tax or compliance work.
Edit, override, or ignore.If a draft is wrong, change it. If a category looks wrong, review it. If a figure matters, check it before relying on it.

Necessary first. Consent for the rest.

The public site should stay light — only what is needed to make it work unless non-essential tools are clearly explained and consented.

Public pages stay available without non-essential consent.Strictly necessary technology may be used where needed. Non-essential use requires a clear explanation and valid consent.
No advertising-tracker default.Advertising or cross-site tracking is not part of the current intended public-site setup. The cookie notice must be updated if that changes.
Consent should be clear.Non-essential cookies should only be used where a proper consent setup explains what they do and how to manage them.

What Kwilo stores, why, and for how long.

The practical categories of data Kwilo may hold, why they are needed, and how retention is handled. The privacy notice carries the full wording and legal context.

DataWhy it is neededHow long it is kept
Your account & sign-in

So Kwilo can recognise your account and send service receipts and reminders.

While needed for the account and legal duties
Quotes, invoices and jobs

So you can find them, send them and use the saved details for billing.

As needed for service or legal duties
Customer contact details

So you can contact customers and route invoices and reminders correctly.

While needed for the record
Voice notes & receipt photos

To turn into quotes, categorise expenses, and back up your records.

As explained in policy
Billing details

To manage subscription billing where payment is set up.

Handled by payment providers
Usage logs

To spot bugs and figure out which features are useful.

As needed to run and secure the service
Protection

Reasonable safeguards, clearly described.

Kwilo uses technical and organisational measures intended to reduce unauthorised access, loss, misuse and disclosure. The security page explains the published boundary.

Access

Access is tied to accounts and permissions.

Signed-in access, workspace roles and permissions help limit who can see or change business records. Businesses still need to manage their users and devices carefully.

Incident

If something goes wrong.

Kwilo investigates reported service and security issues and communicates with affected people where the law or service responsibility requires it.

Read the document that applies.

The summaries above help you find the right subject. These documents contain the detailed wording.

Need to check something specific?

Start with the privacy notice for personal data, the security page for access and incident handling, or the terms for service responsibilities.

Already use Kwilo? Sign in and choose Support from inside your account. Sign in to Kwilo