KustomAI

Your data is yours.

You give us your books, your customers, and your staff. We keep them safe, keep them yours, and give them back when you ask.

Last updated: 17 August 2026

The short version

You own it
Every record you enter belongs to your organisation. We are the caretaker, not the owner.
We do not sell it
No ads. No brokers. No third-party analytics that follow your customers around the web.
We do not train on it
Your books, invoices, and messages are never used to train AI models — ours or anyone else’s.
You can export it
CSV or Excel, any time, from inside the product. No ticket, no waiting.
You can delete it
Ask us to close your account and we remove your data within 30 days. Backups roll off within 90.

What we collect

Account
Your name, email, phone, and the password you set (stored as a one-way hash, never in plain text).
Business data
What you type in: sales, purchases, stock, customers, suppliers, staff, and payroll.
Documents
Files you upload — receipts, contracts, ID scans. Encrypted at rest.
Usage logs
Which pages you opened and when. Kept for 90 days to help us fix bugs and answer support tickets.
Payments
Handled by our payment provider. We see the amount and status; we never see your card number.

How we protect it

  • TLS 1.3 in transit for every request
  • Encrypted at rest — database, file storage, and backups
  • Passwords hashed with a modern one-way algorithm
  • Per-organisation row-level isolation in the database
  • Role-based access — staff only see what their role allows
  • Two-factor sign-in available for every user
  • Audit log of who changed what, kept for 7 years
  • Daily encrypted backups with 30-day retention
  • Least-privilege access for our own team — reviewed every quarter
  • Dependencies scanned continuously for known vulnerabilities

Where it lives

Region
Singapore (Fly.io, SIN region). Close to Cambodia, low latency, strong data-protection laws.
On-premise
Enterprise customers can run KustomAI on their own server, in Cambodia or anywhere else. Your data never leaves your building.
Sub-processors
A short list of vetted providers for hosting, email, and payments. The current list is available on request.

Your rights

See it
Log in and view every record we hold about your business. If you want it in one file, ask us.
Correct it
Edit in the product. If a record is locked (posted invoice, closed period), we will help you post a correction.
Take it
Export in CSV, Excel, or accounting-package formats. Your data, ready to move.
Erase it
Email us. We confirm, delete within 30 days, purge from backups within 90, and send you written confirmation.
Refuse it
You can turn off optional features — Telegram, Facebook, email marketing — and their data flows stop the same day.

If something goes wrong

If we discover a security incident that affects your data, we will tell you within 72 hours of confirming it — what happened, what we know, and what we are doing about it. No hiding. No PR spin.

Report a vulnerability or a suspected breach — DM us on Telegram or Messenger. We read every message and reply within one business day.

Contact

Privacy questions, export requests, or a formal complaint — message us on Telegram or Messenger.

KustomAI · Phnom Penh, Cambodia

Have a question we did not answer?

Write to us. A real person replies.