This Privacy Policy explains what personal data Kodosi ("we", "us" or "our") collects when you use the Kodosi website, the sign-in service and the hosted service that the Kodosi apps connect to (together, the "Service"), how we use it, and the rights that you have. If you have questions, write to [email protected].
1. What We Cannot See
Terminal data and room content (messages, tasks and repository links) are encrypted end to end. The keys are created and kept on your devices, and we never have them. We cannot read this content, give it to anyone or recover it.
- Terminal data travels between devices over TLS 1.3 with a hybrid X25519/ML-KEM-768 key exchange. Our servers relay it in memory and never store it.
- Room content is encrypted on your device with AES-256-GCM, and we store it only in encrypted form.
- Your terminals, files and commands stay on your computers. We have no access to them.
To connect you, we need some information that is not encrypted end to end. Section 2 lists all of it. Our security documentation has the details.
2. Information We Collect
Account information
Your username, your email address and, if you give them, your first and last name; your password, which is stored only as a hash, or the public key of your passkey; and the settings of your sign-in methods. If you sign in with GitHub or Google, we receive your account identifier, email address, name and username from that provider.
Devices
The name of each device that you approve, which comes from the name of the computer; the public keys and certificates of your devices; your signed list of devices; and a record of the devices that you removed.
Friends, rooms and terminals
Your friends and friend invitations; the names, owners and members of rooms and the invitations to them; the names of shared terminals, the device that runs each of them, who they are shared with, and when they start and end; and, for each message or task, which account and device wrote it and when, but not what it says.
Encrypted data
The encrypted content of rooms; the keys of each room, encrypted for each device that may open it; and, if you make a recovery key, a copy of your keys encrypted with that recovery key. We never receive the recovery key.
Technical information
- Website: our host, Cloudflare, processes the IP address, browser, page and time of each request to deliver and protect the website. We see only totals and use no analytics.
- Sign-in: the time, IP address, app or browser and result of each sign-in and account change, and web server logs with the IP address, time, page (without its query), result and browser of each request.
- Relay: IP addresses, device identifiers, connection times and data volumes, used only to route the traffic. They are not recorded, except in an error log when a request fails. Rate-limit counters are kept in memory for one minute, and totals such as the number of connections are not linked to anyone.
- Errors: technical logs of our servers, which may contain IP addresses and account or device identifiers.
- Robot check: Cloudflare Turnstile checks the sign-up and password reset forms.
Emails to us
Your email address, your message and any attachments.
What we do not collect
The apps send no telemetry, analytics or crash reports, and their diagnostic log stays on your computer unless you send it to us. We never receive your sign-in to GitHub, Gitea or your agents, or what you ask your agents. We do not buy data about you.
3. How We Use Information
We use personal data only for these purposes, on these legal bases under the GDPR:
- to provide the Service: your account, devices, friends, rooms and shared terminals (contract);
- to keep the Service secure, prevent abuse and fix problems (our legitimate interest);
- to send account and security emails and notices of changes (contract and legitimate interest);
- to send news about Kodosi, only if you ask for it (consent, which you can withdraw at any time);
- to comply with the law (legal obligation).
We do not sell your data, use it for advertising, or use it to train AI models. We make no automated decisions that have legal or similar effects on you.
5. International Transfers
Our servers are in the European Union. Cloudflare, Resend and Google may process data in other countries, including the United States. For these transfers we rely on adequacy decisions of the European Commission, such as the EU-U.S. Data Privacy Framework, or on its standard contractual clauses. You can ask us for a copy of these safeguards.
6. Data Retention
- Account, devices and friends: until you delete your account.
- Rooms and their content: until the owner deletes the room or their account. Messages that you wrote in other people's rooms stay there after you delete your account, no longer linked to it.
- Records of shared terminals: two minutes after the terminal ends. Terminal data is never stored.
- Device approval codes: they expire after ten minutes and are deleted within a day.
- Sign-in records: 30 days. Web server logs, including error logs: 15 days. Other technical logs: until newer logs replace them.
- Rate-limit counters: one minute, in memory only.
- Deleted accounts: for 30 days, only a record that the sign-in was deleted, so that an old sign-in cannot recreate the account.
- Backups: up to 30 days.
- Emails to us: as long as needed to help you, and at most two years.
8. Your Rights
You have the right to access your personal data, to correct it, to delete it, to restrict its use, to receive it in a portable format, and to withdraw any consent that you gave. You can also complain to a data protection authority, in particular the one where you live; the European Data Protection Board lists them.
You can change your details, remove devices and delete your account yourself in the apps and on your account page. For anything else, write to [email protected]. We answer within one month and may ask you to confirm that the account is yours. Because your content is encrypted, only your apps can show it in readable form.
9. Deleting Your Account
You can delete your account at any time on your account page; the apps open it for you. We then delete your account, your devices and their keys, your recovery data, your friends and sharing, and the rooms that you own with their content, which close for everyone in them. Messages that you wrote in other people's rooms stay there, no longer linked to your account. Copies in backups are removed within 30 days. A deletion cannot be undone.
10. Self-Hosted Servers
If you use a Kodosi server that someone else runs, its operator is responsible for your data there, and this policy does not apply to it. We receive no data from such servers.
11. Children
The Service is not for anyone under 16, and we do not knowingly collect data from children. If you believe that a child has given us personal data, contact [email protected], and we will delete it.
12. Security
Besides end-to-end encryption, we protect the data that we hold with encrypted connections, restricted access and regular updates. No service is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal data, we will inform you and the authorities as the law requires. Report security problems to [email protected].
13. Changes to This Policy
We may update this policy from time to time. We will give you at least 30 days' notice of material changes by email or in the apps. The date at the top of this page shows when it was last updated.
14. Contact
Privacy questions and requests: [email protected]. Security problems: [email protected]. Anything else: [email protected].
