Legal
Privacy Policy
Last updated: August 24, 2026
This Privacy Policy (the “Policy”) describes how Kaelor Labs (“Kaelor Labs”, “we”, “us”, or “our”) collects, uses, discloses, and otherwise processes personal information in connection with MissionSmith, this website, waitlists, demos, accounts, and related services (the “Service”).
It is intended to meet our transparency obligations under applicable privacy law, including Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”) and substantially similar provincial statutes, and, where they apply, the EU/UK General Data Protection Regulation and United States state privacy laws such as the California Consumer Privacy Act as amended by the CPRA.
By using the Service, you acknowledge this Policy. Our Terms of Service govern use of the Service. If there is a conflict about how personal information is handled, this Policy controls.
1.Who we are
Kaelor Labs is the organization responsible for the personal information described in this Policy. For PIPEDA, we are the organization. Where GDPR or UK GDPR applies, we are the controller of personal information we collect for our own business purposes (for example, accounts, billing, waitlists, and website operations).
If your organization provides us with personal information of its personnel or end users so that we can supply the Service to that organization, we process that information as a service provider or processor on the organization’s instructions, except where we must process it for our own legal, security, or billing purposes.
Privacy inquiries: hello@kaelorlabs.com.
2.Scope
This Policy applies to personal information we collect when you visit the website, join a waitlist, book a demo, create or use a MissionSmith account, communicate with us, or otherwise interact with the Service. It does not apply to third-party websites or services we do not control, including linked aviation, mapping, or scheduling sites, which have their own policies.
“Personal information” (and “personal data”) means information about an identifiable individual. Mission plans, coordinates, and site notes may or may not be personal information depending on whether they identify a person. We treat Customer Content as confidential under the Terms regardless.
3.Personal information we collect
We collect the categories of personal information described below. We do not require you to provide more than we need to operate the relevant part of the Service.
Account and identity
Name, email address, authentication identifiers, hashed credentials or tokens, organization or team name if you provide one, and profile details you choose to store. If you sign in with a third-party identity provider (for example Google via Firebase Authentication), we receive the identifiers that provider shares with us, which typically include your email address and a stable account ID, and may include your display name and profile image.
Waitlist, demo, and communications
When you request early access we collect your name, work email, the page or campaign source of the request, and the time of submission. A hidden “website” field is used only as an anti-spam trap and is not used as a business data field. If you book a demo, our scheduling provider collects the details you enter on that booking page. We also keep the content of emails, support messages, and similar correspondence you send us.
Mission, workspace, and usage data
Mission briefs, chat prompts and replies, map selections, geofences, home points, waypoints, aircraft and payload choices, validation results, plan versions, exports you generate, and related workspace metadata. We also collect technical logs such as IP address, device and browser type, approximate location derived from IP, timestamps, referring URLs, feature-usage events, performance diagnostics, and security logs.
Payment information
If you purchase a paid plan, our payment processor collects payment-card or other billing details as needed to transact. We receive limited billing metadata (for example last four digits, expiry month, plan, and invoice history). We do not store full payment-card numbers on our own systems.
Information we generate or infer
We may generate identifiers, session IDs, plan-status labels, and product-analytics events. We do not use personal information to make fully automated decisions that produce legal effects about you without human involvement, other than routine security automation (for example blocking abusive traffic).
4.How we collect it
- Directly from you, when you fill forms, create an account, chat with the agent, upload or draw mission geometry, or contact us.
- Automatically, through cookies, local storage, logs, and similar technologies as described in Article 11.
- From identity, map, model, analytics, and scheduling providers acting on our instructions or jointly as needed to run a feature you use.
- From your organization, if an administrator invites you or uploads workspace data that includes your information.
5.How we use personal information
We use personal information to:
- provide, operate, maintain, and secure the Service, including authentication, workspaces, planning, validation, simulation, export, and support;
- create and manage accounts, seats, and access invitations, and to communicate about the Service (including waitlist status, security notices, and product changes);
- process transactions and send invoices or receipts where you purchase a plan;
- monitor reliability, debug errors, prevent fraud and abuse, and protect the rights and safety of users and the public;
- understand how the Service is used so we can improve it, prioritize features, and measure early-access quality;
- comply with law, enforce the Terms, and establish, exercise, or defend legal claims;
- with your direction or consent, send optional product updates. You may withdraw marketing consent as described below. Transactional and security messages are not marketing.
6.Legal bases (EEA, UK, and similar regimes)
Where a legal-basis requirement applies, we rely on one or more of the following:
- Contract: to provide the Service you request, including accounts and paid plans.
- Legitimate interests: to secure and improve the Service, understand product usage, prevent abuse, and communicate service notices, balanced against your rights.
- Consent: for optional cookies or marketing emails where consent is required, and for waitlist communications under Canada’s Anti-Spam Legislation where the request itself is the consent to hear from us about early access.
- Legal obligation: to keep records, respond to lawful requests, and meet accounting or aviation-adjacent record duties that may apply to us as a vendor.
7.Artificial intelligence processing
Chat messages, mission briefs, selected map context, and related workspace data may be sent to large-language-model and inference providers so the Service can propose routes, explanations, and revisions. Independent geometry and clearance checks also process mission geometry. Providers process this information on our instructions to return results for your session. They must not use it to identify you for their own unrelated advertising.
Prompts and outputs may be logged in our application database and in operational tracing tools so we can debug failures, improve reliability, and support you. Do not include information in prompts that you are not authorized to process. Mission Output can be wrong; human review remains required under the Terms.
8.Mission, site, and spatial data
The Service is built to store mission and session data in your workspace so you can resume planning. That data often includes coordinates, site descriptions, aircraft types, and operator-supplied notes (for example, a crane that is not in the map). If those materials identify an individual (a named pilot, a home address used as a takeoff point, a face in a snapshot), they are personal information and are handled under this Policy.
Map tiles and 3D imagery are generally streamed from map providers and are not stored by us as a substitutable copy of the provider’s tileset, except for limited operational caches, thumbnails, or user-captured view snapshots needed to run a feature. Those snapshots may depict real-world locations. You are responsible for not capturing or uploading imagery that you are not allowed to process.
9.How we share information
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We disclose personal information only as follows:
Service providers
We use vendors who process information on our instructions and under contracts that restrict their use of it. Categories include:
- cloud hosting, databases, and object storage (including Google Cloud);
- authentication (Firebase Authentication);
- photorealistic 3D map and geocoding providers (including Cesium and Google Maps Platform);
- large-language-model and inference providers used to generate planning assistance;
- product analytics and session diagnostics (including PostHog in the application, which may use cookies or local storage and, if enabled, session replay with input masking);
- error monitoring (including Sentry);
- LLM tracing and quality tools (including Langfuse);
- demo scheduling (Cal.com);
- email and transactional-message delivery;
- payment processing, when you purchase a plan.
Other disclosures
- Within your organization, to other users of a shared workspace you join.
- If we are involved in a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality.
- If we believe disclosure is required by law, court order, or to protect the Service, our users, or the public from harm or illegal activity.
- With your direction, for example if you ask us to export a mission to a third-party tool.
10.International transfers
We and our providers operate in Canada, the United States, and other countries. Personal information may be transferred to, stored, and processed in those countries. Those jurisdictions may have privacy laws that differ from the laws of your home country. Where required, we use appropriate safeguards for cross-border transfers, such as contractual clauses with providers.
By using the Service from outside the country in which our systems or a provider’s systems are located, you understand that your information will be processed in those locations as described in this Policy.
11.Retention
We retain personal information only as long as needed for the purposes described in this Policy, including to provide the Service, comply with law, resolve disputes, and enforce agreements. In practice:
- Account and workspace data is kept for the life of the account and a reasonable wind-down period after closure, unless you request earlier deletion and we are not required to keep it.
- Waitlist records are kept until we have completed the relevant access cycle or you ask us to remove them, and thereafter as needed to show we respected a suppression request.
- Security, billing, and server logs are kept for a limited operational period, then deleted or aggregated, unless needed for an investigation or legal hold.
- Backups may persist for a short period after deletion from live systems until they rotate.
When retention ends, we delete or irreversibly de-identify the information, except where a backup or legal hold still applies.
12.Security
We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encrypted transport, access controls, authentication, and monitoring. No method of transmission or storage is completely secure. You are responsible for controlling access to your accounts and for the devices you use.
If we become aware of a breach of security safeguards involving personal information under our control, we will assess the risk of harm and notify affected individuals and regulators as required by applicable law, including PIPEDA’s breach-notification rules.
13.Cookies and similar technologies
We and our providers use cookies, local storage, pixels, and similar technologies.
- Essential: authentication session cookies and security tokens needed to sign in and keep you logged in.
- Preferences: local storage on this website remembers whether the cursor-following drone animation is on or off. That value is stored on your device and is not used to identify you across unrelated sites.
- Analytics and diagnostics (application): if enabled for your environment, PostHog may set cookies or use local storage to understand product usage and, where configured, record masked session replays. Inputs of type password and email are masked; you should still avoid typing secrets into unmasked fields.
You can control cookies through your browser. Blocking essential cookies will prevent sign-in. We do not currently respond to “Do Not Track” signals as there is no common industry standard; we do honor required opt-out mechanisms under applicable US state law as described below.
14.Your rights and choices
Subject to legal limits, you may:
- request access to personal information we hold about you, and information about how we have used and disclosed it;
- request correction of inaccurate or incomplete personal information;
- request deletion or de-indexing, subject to accounts we must retain for legal, security, or billing reasons;
- withdraw consent where processing is based on consent, including marketing emails, without affecting processing that occurred before withdrawal;
- object to or request restriction of certain processing, and request portability, where those rights apply (including GDPR);
- lodge a complaint with a supervisory authority.
To exercise these rights, email hello@kaelorlabs.com from the address associated with your account or waitlist entry and describe the request. We may need to verify your identity. We will respond within the time required by applicable law (generally 30 days under PIPEDA, subject to permitted extensions).
If we decline a request, we will explain why, subject to legal restrictions, and tell you how to challenge the decision, including by contacting the Office of the Privacy Commissioner of Canada or your local authority.
15.California and other US state rights
If you are a resident of California or another US state with a comprehensive privacy law, you may have the right to know, access, correct, delete, and obtain a portable copy of personal information, and to opt out of “sale” or “sharing” for cross-context behavioral advertising. We do not sell personal information and we do not share it for cross-context behavioral advertising as those terms are defined in the CPRA.
We also do not use or disclose sensitive personal information for purposes that require a right to limit under the CPRA, other than as needed to provide the Service. We will not discriminate against you for exercising privacy rights. You may designate an authorized agent as permitted by law; we will require proof of authority and identity.
Categories collected in the last twelve months correspond to those in Article 3 (identifiers, commercial information if you purchase a plan, internet or electronic activity, geolocation in mission data you supply, and professional information such as work email). We disclose those categories to service providers as described in Article 9. We do not have actual knowledge that we sell or share the personal information of consumers under 16.
16.Children
The Service is for adults engaged in professional or otherwise authorized aviation-related planning. It is not directed to children under 18, and we do not knowingly collect personal information from them. If you believe we have collected such information, contact us and we will delete it.
17.Changes to this Policy
We may update this Policy from time to time. We will change the “Last updated” date and, for material changes, provide additional notice where required by law (for example, by email or an in-product notice). The updated Policy applies from its effective date. If you do not agree, you must stop using the Service and may request deletion of your account.
18.Contact and complaints
The person accountable for privacy at Kaelor Labs can be reached at hello@kaelorlabs.com. Write “Privacy” in the subject line. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, if GDPR/UK GDPR applies, your local data-protection authority. California residents may also contact the California Attorney General or the California Privacy Protection Agency.
Also see our Terms of Service.