# Trust: you stay the approver, and every change is recorded | BYOM

URL: https://byom.co/trust  
Markdown: https://byom.co/trust.md  
Last updated: 2026-10-04

> Kina can draft any change, but only a named person on your team can let it touch your store. Every change is recorded, supported changes can be undone for 24 hours, your data is stored in the UK and credentials stay with whoever connected them.

## Principles

- You stay the approver: Kina can draft any change. Only a named person on your team can let it touch your store.
- Kina stays accountable: Every change and every run is recorded: the evidence, the decision and what your store confirmed.
- Your data stays yours: Your records are stored in the UK, Kina works only on your data, and we delete it on request.
- Your keys, your model: Credentials are encrypted and never shown to Kina. Bring your own model and the same approval gate applies.

## What Kina can do

- Read the tools you connect, within the access you grant
- Draft replies, changes and cards, with the evidence behind them
- Suggest memories for your team to keep
- Tell you when something needs your decision

## What Kina cannot do

- Change your store without a named person's approval
- Approve its own changes, or its own memories
- Call a change done before your store confirms it
- Work on another company's data

## Your data

- Stored in the UK: Your records are stored in the UK, including your approvals, change history and memory.
- Credentials stay locked: Credentials are encrypted with AES-256-GCM and never shown to Kina. Kina reaches your tools through BYOM, within the access you grant.
- Tied to your company: Every record is tied to your company, and that boundary is enforced in the database itself, not only in the app.
- Sessions you can see: Every signed in session is listed in your account, and you can sign any of them out.
- Bring your own model: Connect your own model or endpoint. BYOM checks it before you switch, the same approval gate applies, and you can switch back in one click.
- Shared memory you control: Company memory is approved by an owner or admin before Kina uses it. Personal memory stays private. Forget anything, any time.
- Only your data: Kina works only on your data.
- Deletion on request: Ask us to delete your data and we confirm scope and timing in writing.
- Data processing agreement: Ask us about our data processing agreement.

## Mechanisms

- Approval: Every write to your store is an Action. A named person approves, and you set when a second person is needed. Riskier changes ask you to confirm it's you.
- Receipts: Every change is recorded: what changed, who approved it, on what evidence, and whether it can be undone. Export the record any time.
- Undo: Supported writes can be undone for 24 hours, and the undo is recorded too.
- Execution once: An approved change is written once.
- Credentials: Credentials are encrypted and never shown to Kina.
- Judgment engine: An independent check on Kina's work before it reaches you. It never writes, never approves a change and is never trained on your data.
- Your model: Bring your own model or endpoint, and the same approval gate applies.
- Kina: Kina works only on your data. Approvals and records live in BYOM.
- Data: Your records are stored in the UK. Deletion on request.
- DPA: Ask us about our data processing agreement.

## Go deeper

- Approvals: https://byom.co/approvals
- Receipts: https://byom.co/receipts
- Rails: https://byom.co/rails
- Shared memory: https://byom.co/workspace#memory
- Privacy policy: https://byom.co/legal/privacy
- Terms of service: https://byom.co/legal/terms
- Data processing terms: https://byom.co/legal/dpa
- Subprocessors: https://byom.co/legal/subprocessors
- Cookie policy: https://byom.co/legal/cookies

## In the Shopify app

- Every change is a proposal the merchant confirms. Unconfirmed proposals expire quickly.
- Instructions found inside product or catalogue text are reported to the merchant, never acted on.
- The assistant never asks for a Shopify password or key.

## This website

byom.co uses Google Analytics, which sets a cookie and sends visit data to Google. Page visits and waitlist signups are also counted on our own server at Cloudflare, without a cookie and without an IP address or other identifier. Fonts and logo images are served from byom.co itself.

## Questions

- Can Kina change my store without asking? No. Every change to your store arrives as a card that a named person on your team approves. Until then nothing is written.
- Who can approve a change? The owners and admins on your team. You choose how much approval each kind of work needs, and replies to customers can require a second person. Kina never approves its own work, and riskier changes also ask the approver to confirm it's them.
- What if an approved change turns out to be wrong? Supported changes can be undone for 24 hours. The undo is approved like any other change and recorded too. If someone has edited the same thing by hand since, BYOM tells you rather than overwriting their work.
- Where is our data stored? Your records are stored in the UK: your data, approvals, change history and memory. Some processing, including the AI models, runs outside the UK. Ask us for the current data location note.
- Who holds the credentials for our tools? Credentials are encrypted and never shown to Kina. Kina reaches your tools through BYOM, within the access you grant.
- Can we use our own model? Yes. Connect your own model or endpoint and BYOM checks it before you switch. The same approval gate and records apply whichever model drafts the work. Usage on your own keys stays off your BYOM bill.
- What does Kina remember about our business? What your team tells it, and what it suggests and you keep. Personal memory stays private. Company memory is approved by an owner or admin before Kina or the team uses it, and anyone can forget a memory at any time.
- Can we get a record for an audit or a client? Yes. Owners and admins can export the governance record for one change or a date range, as JSON and as a readable summary. Each entry says whether it was recorded at the time or worked out at export.
- Can you delete our data? Yes. Write to hello@byom.co and we confirm scope and timing in writing.
- Do you have a data processing agreement? Ask us about our data processing agreement at hello@byom.co.
