Legal

Privacy Policy

Last updated: August 7, 2026

Please read this Privacy Policy carefully. It explains what information we collect across the Kenoo product suite, how we use it, and the choices available to you.

1. Who we are

This Privacy Policy describes how WALLS Entertainment Group Inc., doing business as Kenoo ("Kenoo," "Company," "we," "our," or "us"), collects, uses, and shares personal information when you visit kenoo.io, create an account, or use the Kenoo business operating system, websites, mobile applications, and related services (collectively, the "Services").

Kenoo includes connected product areas such as the marketing site, authentication portal, Settings, CRM, Projects, Calendar, Ledger (finance), Wallie (AI assistant), AdPilot (ads), Health, Admin, and related APIs. Feature availability depends on your workspace, plan, and permissions.

2. Scope and roles

This Policy applies to personal information we process as a provider of the Services. For Customer Content you and your organization store in Kenoo (such as CRM contacts, emails, deals, projects, invoices, and files), your organization is typically the data controller (or equivalent) and Kenoo acts as a processor or service provider, except where we process information for our own purposes described in this Policy (for example account administration, security, billing, and product analytics).

If you are an end user invited into a customer workspace, that organization may control access to your workspace data. We may redirect privacy requests about that data to the relevant organization administrator.

3. Information we collect

We collect information you provide directly, information generated through your use of the Services, information from third-party services you choose to connect, and information from service providers that help us operate Kenoo.

  • Account and profile information: name, email addresses (work and personal), phone number (including mobile numbers you provide for optional SMS notifications), date of birth, address, timezone, country or tax region, avatar, LinkedIn or other profile links, role, and authentication identifiers.
  • SMS notification preferences: whether you have opted in to Kenoo text notifications, the phone number associated with that consent, consent and opt-out timestamps, and related audit records needed to honor STOP requests and legal requirements.
  • Organization and membership data: workspace name, slug, website, description, contact details, icons, member invitations, and app access permissions.
  • Workspace and Customer Content: CRM companies, people, leads, deals, pitches, sequences, notes, deliverables, commissions, contracts, documents, invoices, projects, tasks, calendar events, attendees, messages, Wallie chat threads, writing profiles, and similar business records you create or import.
  • Communications content: email bodies, headers, recipients, attachments, drafts, and thread metadata when you connect Gmail or use Kenoo email features; support and sales messages you send us.
  • Financial and payout information: ledger transactions, invoice details, recipient legal name and type, bank account details, addresses, and KYC-related status fields processed through Wise or similar payout providers. We do not store full payment card numbers on our servers when cards are handled by payment processors.
  • Advertising data: Meta and Google Ads account identifiers, campaign and creative metadata, budgets, spend, performance metrics, and automation settings when you connect AdPilot.
  • Health and fitness data (optional Health module): sex, height, weight, date of birth used for derived metrics, activity level, nutrition logs, goals, workout activities, heart-rate or similar metrics from connected providers, and raw activity payloads where stored to power the feature.
  • Voice and media: audio you submit for transcription or speech features in Wallie, plus generated audio responses where applicable.
  • Technical and usage data: IP address, device and browser information, app version, pages and features used, session and analytics events, approximate location derived from IP, and security logs including login history.
  • Enrichment and research data: business contact and company information obtained from enrichment providers (such as Apollo) or public web research tools you or your workspace enable.
  • Integration credentials: OAuth access and refresh tokens, API keys, and connection metadata for services you authorize (for example Google Workspace APIs, Google Ads, Meta, Strava, or Wise).

4. How we collect information

We collect personal information through registration and profile forms; workspace activity; OAuth and API connections you authorize; payment and payout providers; enrichment and search providers; cookies and similar technologies; and, where applicable, background sync jobs, webhooks, and admin provisioning tools used by authorized administrators.

5. How we use information

We use personal information to operate, secure, and improve Kenoo, and to communicate with you about the Services.

  • Authenticate users, enforce MFA, manage sessions, and control app and workspace access.
  • Provide product features across CRM, projects, calendar, finance, ads, health, AI assistance, settings, and admin tools.
  • Sync and process connected email, calendar, ads, fitness, and payout accounts as you configure them.
  • Send outreach, sequences, invoices, notifications, and other communications you initiate through the Services.
  • Send automated transactional and operational SMS messages you opt in to receive (for example account, workflow, application, and user-configured alerts such as AdPilot performance alerts).
  • Process subscriptions, invoices, payouts, and related billing or treasury activity.
  • Detect, prevent, and investigate fraud, abuse, spam, and security incidents.
  • Analyze product usage to improve reliability, performance, and design.
  • Provide customer support and respond to sales or partnership inquiries.
  • Send product updates or marketing communications where permitted by law; you can opt out of marketing at any time.
  • Comply with legal obligations and enforce our Terms of Service.

6. Google user data (Gmail, Calendar, Contacts, and Google Ads)

If you connect Google services, Kenoo may access Google user data according to the OAuth scopes you approve. Depending on the integration, this may include Gmail (reading, sending, modifying, and organizing email), Google Calendar (reading and writing events, including Google Meet details), Google Contacts needed for messaging and scheduling, and Google Ads account data needed for AdPilot (accessible customer accounts, campaign structure, budgets, and performance metrics).

We use Google user data only to provide and improve user-facing features that are apparent in the Kenoo interface, such as inbox sync, sending or scheduling email, CRM email sequences, invoice delivery, calendar sync, AdPilot reporting and spend automation you enable, and related product features. We do not sell Google user data. We do not use Google user data for serving advertisements unrelated to the advertising accounts you connect. We do not allow humans to read Google user data unless you give us permission for support, it is necessary for security or legal compliance, or the data is aggregated and anonymized for internal operations.

Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. You may disconnect Google integrations in Settings (or AdPilot settings for Google Ads), after which we will stop new syncing and delete or de-identify stored Google tokens and related synced data in accordance with our retention practices, except where retention is required for security, legal, or accounting purposes.

7. AI features (including Wallie)

Kenoo includes AI features in Wallie and across other apps (for example CRM search and email assistance, and project scope generation). When you use these features, prompts, selected workspace content, chat history, tool results, and, for voice features, audio may be processed by Kenoo and by third-party model providers such as OpenAI, Anthropic, or Perplexity, and by our Wallie backend infrastructure.

AI features are designed to support your team's work within Kenoo. We do not sell your Customer Content as training data to unrelated third parties. Where we use third-party model providers, we require contractual protections consistent with this Policy and applicable law. You should avoid submitting sensitive personal information to AI features unless necessary for the task.

8. CRM, enrichment, and outreach

Our CRM may store personal information about your customers, leads, and other third parties that you import, capture from email, or enrich through providers such as Apollo. You are responsible for ensuring you have a lawful basis to collect, enrich, store, and contact those individuals, including compliance with anti-spam and telemarketing laws.

Outbound email sequences, scheduled messages, and similar outreach tools process recipient contact details and message content as configured by your workspace.

9. Finance, invoices, and payouts

Ledger and related finance features process transaction history, invoices, recipient information, and payout metadata. Bank and KYC-related details may be shared with Wise or other payout providers to create and manage recipients and transfers.

Invoice features may generate shareable links or tokens that allow recipients to view or download invoice PDFs. Anyone with the link may be able to access that invoice, so treat share links as confidential.

10. Advertising (AdPilot)

If you connect Meta or Google Ads accounts to AdPilot, we process ad account identifiers, campaign and creative metadata, budgets, spend, performance metrics, and automation settings you configure. We may call Meta Marketing APIs and the Google Ads API (using OAuth credentials you grant plus Kenoo's developer credentials where required) to list accessible accounts, sync insights, and execute or preview budget and campaign actions you authorize.

AdPilot is designed for operators and authorized client workspaces. Connected advertiser data is stored as Customer Content within the Kenoo workspace that completed the connection, subject to that workspace's access controls.

11. Health and fitness data

The Health module is optional. If you use it, we may process health, biometric, nutrition, and fitness information you enter or sync from providers such as Strava. This information can be sensitive. We use it only to provide Health features you enable (for example activity tracking, goals, and analytics) and related security and support.

You can disconnect Strava or stop using Health features in the product. Do not use Health features for medical diagnosis or treatment; Kenoo is not a medical device or healthcare provider.

12. SMS notifications

If you opt in to SMS notifications in Kenoo Settings, we use the mobile phone number you provide to send automated transactional and operational text messages from Kenoo and Kenoo applications (such as AdPilot). These messages may include account notifications, workflow notifications, application activity alerts, and user-configured alerts (for example advertising-performance or threshold alerts).

SMS is optional and is not enabled merely because a phone number is stored on your profile. Message frequency varies based on your notification settings and account activity. Message and data rates may apply. You can disable SMS in Kenoo Settings at any time, or reply STOP to opt out and HELP for help.

We do not sell your phone number or SMS opt-in information, and we do not share it with third parties for their own marketing purposes. We share phone numbers and message content with communications providers such as Twilio only as needed to deliver the texts you requested and to process standard carrier keywords such as STOP and HELP.

Providing SMS consent is not a condition of purchasing Kenoo. Consent records (including timestamps and the disclosure version accepted) may be retained as needed for compliance, audit, and to honor opt-out requests.

13. How we share information

We do not sell your personal information. We may share information in the following circumstances:

  • With service providers and subprocessors that help us host, authenticate, store, process, analyze, communicate (including SMS delivery via providers such as Twilio), pay out, enrich, or secure the Services (including providers such as Supabase, Vercel, Cloudflare, Google (including Google Ads API), Meta, Strava, Wise, OpenAI, Anthropic, Perplexity, Apollo, Twilio, search/enrichment providers, and infrastructure used to run Wallie), under confidentiality and data-protection obligations.
  • With other members of your Kenoo workspace according to permissions set by your organization, including administrators with elevated access.
  • With third-party integrations you choose to enable.
  • With invoice or document recipients when you create share links or send communications.
  • If required by law, legal process, or to protect the rights, safety, or property of Kenoo, our users, or the public.
  • In connection with a merger, acquisition, financing, or sale of assets, subject to appropriate safeguards.

14. Cookies and similar technologies

We use cookies and similar technologies to keep you signed in across Kenoo apps (including shared authentication cookies where configured), remember preferences, measure site and product performance, and understand how the Services are used. You can control cookies through your browser settings, though disabling certain cookies may affect functionality.

15. Data retention

We retain personal information for as long as needed to provide the Services, fulfill the purposes described in this Policy, resolve disputes, enforce agreements, and meet legal or accounting requirements. Backups, security logs, billing records, and SMS consent or opt-out records may persist for a limited additional period where needed for compliance.

When an account or workspace is closed, or when you disconnect an integration, we delete or de-identify personal information within a reasonable period, except where retention is required by law or for legitimate business purposes such as security investigation, fraud prevention, or financial recordkeeping.

16. Security

We use administrative, technical, and organizational measures designed to protect personal information, including encrypted transport, access controls, optional multi-factor authentication, and restricted admin tooling. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Please use strong credentials, enable MFA where available, and protect access to your workspace and connected accounts.

17. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, export, or restrict processing of your personal information, or to object to certain processing. You may also have the right to withdraw consent where processing is based on consent, including for optional Health features, SMS notifications, marketing, or certain integrations.

You can often manage profile data, SMS notification preferences, disconnect integrations, and control workspace content directly in Kenoo. You may also reply STOP to opt out of Kenoo SMS messages. To exercise privacy rights, contact us at hello@kenoo.io. We may need to verify your identity before responding. If your request relates to Customer Content controlled by an organization, we may redirect you to that organization's administrator.

18. International transfers

Kenoo may process and store information in countries other than the one where you live, including through cloud, communications, and AI subprocessors. When we transfer personal information internationally, we use appropriate safeguards required by applicable law.

19. Children's privacy

The Services are not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.

20. Changes to this Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, provide additional notice. Continued use of the Services after an update becomes effective constitutes acceptance of the revised Policy.