Also, do you have plans to support deletion of indexed data?
So Kite should be able to avoid this fear by asking only for limited license. For example, a license can expire after 1 year, or be untransferable (or perhaps expire at bankruptcy?).
Facebook does this to some extent: "This IP License ends when you delete your IP content or your account unless your content has been shared with others, and they have not deleted it."
Here's what Heroku does: "Heroku claims no ownership or control over any Content or Application. You retain copyright and any other rights you already hold in the Content and/or Application, and you are responsible for protecting those rights, as appropriate. By submitting, posting or displaying the Content on or through the Heroku Services you give Heroku a worldwide, royalty-free, and non-exclusive license to reproduce, adapt, modify, translate, publish, publicly perform, publicly display and distribute such Content for the sole purpose of enabling Heroku to provide you with the Heroku Services. [...]"
(IANAL)
A lot of companies' privacy policies have a section explicitly dealing with how data is transferred when company ownership changes. Sometimes this just says that all data will be transferred, but sometimes there are stipulations (for instance, my company doesn't sell or rent user data for marketing purposes, and its privacy policy requires that an acquiring company won't do that either).
Of course, there are edge cases (like what happens if the privacy policy changes) that complicate things, but the FTC has a pretty helpful discussion of all of this: https://www.ftc.gov/news-events/blogs/business-blog/2015/03/...
Some technical solutions might be possible, in terms of allowing users provably to withdraw their data, but it would be messy and probably not bulletproof.
Even if you have to ship individual backend modules (when more languages get supported). One place might only need the bash/python/js syntax whereas another might need only php, etc.
I'm no security expert but one way I can think of is creating an encryption system which works like this: all my source code will be stored encrypted on your (non-ephemeral) databases. The decryption key will be stored on my computer, and it'll be transferred to the server when I run Kite and destroyed as soon as I quit Kite. The key will be stored in your server only in an ephemeral storage (in-memory database etc.)
There's a difference between trusting someone not to redistribute your work versus having it in writing. Both are important.