Kai MBA
Privacy

What we keep, and what we do with it.

Last updated 3 September 2026.

1. Who we are and how to contact us

Kai MBA Consulting is a product of Kaigen Labs, Inc., a company incorporated in Delaware, United States. Kaigen Labs Inc. is the data controller for the personal data described here, which means we decide what is collected and what happens to it.

This policy covers kaimbaconsulting.com and everything you do on it: the free turns with the clone, a Season Pass account, and any add-on you buy.

Write to kai@kaimbaconsulting.com about anything in this policy, including a request to see or delete your data. For everything else, kai@kaimbaconsulting.com. We have not appointed a data protection officer, because we are not required to. Your request goes to a person either way.

2. What we collect

If you have an account

Accounts run on Clerk. When you sign up we receive your email address, your name if you give one, and a user identifier. If you sign in with Google we receive your name, email address and profile picture from Google, and nothing more. Clerk holds your password or your sign-in method. We never see it.

Your resume

If you upload a resume we store the file and the text taken out of it, so the clone can read your profile. A resume usually holds your name, contact details, employment history, education, test scores and whatever else you chose to put in it. Upload only what you are comfortable sharing.

Your conversations

We store the messages you send the clone and the replies it gives, so you can come back to a conversation and carry on. If you use the free turns without an account, the conversation is tied to an anonymous session identifier rather than to you.

Payment data

Stripe processes the payment. We never see or store your card number. We receive and keep payment metadata: a Stripe customer and payment identifier, the amount, the currency, the date, the last four digits and card brand, the billing country, and whether the payment succeeded. We use that to give you access and to keep our accounts.

Technical data

When you use the site we collect the technical information any web service needs: a hashed version of your IP address, which we use for rate limiting and abuse prevention and which we cannot turn back into your IP address, a browser and device description, timestamps, error reports, and the result of a Cloudflare Turnstile check that tells us whether a request came from a human. Turnstile is a privacy-preserving bot check and does not track you across sites.

What we do not collect

We do not run advertising trackers, we do not build profiles of you for marketing, we do not buy data about you, and we do not ask for special category data such as health, religion or ethnicity. Do not put that kind of information into the chat unless it is genuinely part of your application story.

3. Why we use it, and our lawful basis

Under the UK and EU GDPR we need a lawful basis for each purpose. Here they are, purpose by purpose.

  • To give you the clone, the Playbook, the templates and the live sessions. Basis: performance of our contract with you. Data used: account data, resume, conversations.
  • To let anonymous visitors use ten free turns. Basis: our legitimate interest in letting people try the service before they pay, which also protects them from buying something unsuitable. Data used: anonymous session, resume if uploaded, conversation, hashed IP.
  • To take payment and keep financial records. Basis: performance of our contract, and legal obligation for tax and accounting records. Data used: payment metadata, email address.
  • To send transactional email: receipts, sign-in links, live session details, service notices. Basis: performance of our contract. Data used: email address.
  • To keep the service up, fix bugs and investigate errors. Basis: legitimate interest in a service that works. Data used: technical data, and conversation content where it is needed to reproduce a specific fault.
  • To prevent abuse, fraud and cost attacks on the free turns. Basis: legitimate interest in protecting the service, and in the case of fraud a legal obligation. Data used: hashed IP, Turnstile result, usage counts.
  • To improve the Playbook and the clone by understanding what people ask. Basis: legitimate interest, and we work from aggregated and de-identified patterns rather than from reading individual conversations. Data used: aggregated conversation topics.
  • To send you anything that is not a service email. Basis: your consent, which you can withdraw at any time.
  • To defend or bring a legal claim, or to comply with a lawful request. Basis: legitimate interest, or legal obligation.

Where we rely on legitimate interests we have weighed our interest against your rights, and we have written this policy so you can see the trade we made. You can object, and section 11 says how.

4. We do not train models on your content

Your resume, your conversations and anything you upload are never used to train, fine-tune or evaluate any AI model, ours or a third party’s. They are sent to a model only to produce the reply you asked for, and our model providers are contractually barred from training on what we send them.

We do read conversations when we have to: when you report a problem, when we are investigating abuse, or when we are chasing a fault that we cannot reproduce any other way. That access is limited to the people who need it.

5. Who processes data for us

We do not sell your data, and we do not share it with advertisers. We use a small number of service providers, each under a contract that limits them to acting on our instructions.

  • Clerk. Accounts, sign-in and session management.
  • Convex. The database and file storage. Your resume, conversations and account records live here.
  • Stripe. Payments. Stripe is a controller in its own right for the card data it collects.
  • Resend. Transactional email.
  • Cloudflare. Turnstile bot protection.
  • Vercel. Hosting and delivery of the website.
  • Kaigen Labs infrastructure. The service that runs the clone and connects it to a model.
  • OpenRouter. Routing to the model that generates the clone’s replies.

We may also disclose data to our accountants and professional advisers, or to a public authority where the law requires it.

This list can change as the service changes. The current list is always the one on this page, and the date at the top tells you when we last revised it. If you would like to be told before a change takes effect, ask at kai@kaimbaconsulting.com and we will add you to the notice list.

6. Sending data outside the UK

Several of the providers above are based in the United States or run infrastructure outside the UK and the EEA, so your data will be transferred out of the UK.

Where that happens we rely on one of these safeguards: an adequacy decision covering the country in question, or the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum, backed by an assessment of the risk in that country. Ask at kai@kaimbaconsulting.com and we will tell you which safeguard applies to which provider.

7. How long we keep things

  • A resume uploaded by an anonymous visitor. Deleted thirty days after upload, by an automated job.
  • An anonymous conversation. Kept for thirty days, then deleted or reduced to counts that identify nobody.
  • A member’s resume. Kept until you delete it, or until you close your account. You can delete it from your account at any time.
  • A member’s conversations. Kept for as long as your account is open, so you can come back to them, and deleted when you close it.
  • Account records. Kept while your account is open, and deleted within thirty days of you closing it, apart from the financial records below.
  • Financial records, including payment metadata. Kept for six years from the end of the tax year they relate to, because UK tax law requires it. A deletion request cannot override this.
  • Technical logs. Kept for up to ninety days.
  • Records of a complaint or a legal claim. Kept for as long as the matter is live, and for six years after it ends.

8. How we protect your data

Everything moves over encrypted connections and is stored encrypted at rest by our providers. Access to production data is limited to the people who need it and protected by multi-factor authentication. Secrets and keys are held server side and never sent to the browser. Members can read only their own records, enforced in the database rather than in the interface. The anonymous chat path sits behind a rate limit, a daily cap, a bot check and a kill switch.

No service is perfectly secure. If a breach happens that is likely to put your rights at risk, we will tell the ICO within seventy-two hours of becoming aware of it and tell you without undue delay.

9. Cookies

We use as few cookies as we can, and all of them are necessary for the service to work.

  • Anonymous session cookie. Remembers your free-turn session so your conversation survives a page reload and so we can count your ten turns.
  • Clerk session cookies. Keep you signed in and protect the sign-in flow.
  • Cloudflare Turnstile. Sets a short-lived token to confirm a request came from a human.

There are no advertising cookies, no analytics that follow you between websites, and no third party trackers, which is why you do not see a consent banner. You can block cookies in your browser, and if you do, sign-in and the free turns will stop working.

10. Email we send you

We send service email through Resend: receipts, sign-in links, notices about your pass, and the details of the monthly live session. You cannot opt out of those while you hold a pass, because they are part of the service.

Anything else, such as news about new chapters, goes only to people who asked for it, and every one of those emails has an unsubscribe link.

11. Your rights

Under UK GDPR you have the right to:

  • Access. Get a copy of the personal data we hold about you.
  • Rectification. Have anything inaccurate corrected or completed.
  • Erasure. Have your data deleted, where we do not have an overriding reason or legal duty to keep it.
  • Restriction. Ask us to stop using your data while a dispute about it is sorted out.
  • Portability. Receive the data you gave us in a machine-readable format, or have it sent to another provider.
  • Objection. Object to any use we base on legitimate interests, including a total objection to direct marketing that we must honour.
  • Withdraw consent. Where we relied on your consent, withdraw it at any time, which does not undo what we did before you withdrew it.

To use any of them, write to kai@kaimbaconsulting.com from the email address on your account. We reply within one month. If a request is complicated we may take up to two further months, and if we do we will tell you why within the first month. There is no charge, unless a request is clearly unfounded or excessive. We may ask you to confirm your identity before we release data.

You can delete your resume yourself from your account page at any time, and you can ask us to close your account and delete everything we are not required to keep.

12. Complaining to the ICO

If you think we have handled your data badly, tell us first at kai@kaimbaconsulting.com and we will try to put it right. You also have the right to complain to the UK regulator, the Information Commissioner’s Office, at ico.org.uk, or on 0303 123 1113. If you live in the EEA you may complain to your national data protection authority instead.

13. Children

The service is built for people applying to business school and is not intended for children. Do not use it if you are under 16, and do not create an account for anyone under 16. If we learn that we hold data about someone under 16, we delete it. To buy a Season Pass you must be 18 or older.

14. Automated decision making

We do not make any decision about you by automated means that produces a legal effect or something similarly significant. Nothing in the service decides whether you get admitted, priced differently, or refused anything.

The clone generates guidance automatically, and that guidance is advice for you to weigh. Every decision about your application is yours, and every decision about admission belongs to a school. Where an automated rule does act on your account, such as a rate limit or a bot check blocking a request, you can ask a person to look at it by writing to kai@kaimbaconsulting.com.

15. Changes to this policy

We update this policy when the service changes, when we add or remove a provider, or when the law moves. The date at the top shows the current version. If a change is material and affects people who hold a pass, we will tell you by email or by a notice on the site before it takes effect.

16. How to contact us

Kaigen Labs, Inc., trading as Kai MBA Consulting.

  • Privacy and data requests: kai@kaimbaconsulting.com
  • Everything else: kai@kaimbaconsulting.com