Legal

Privacy

Last updated 2026-09-02

This page says what kcode (company name to be filled in) collects when you use kcode and kcode.sh, and why.

Account

Your email address, used for sign-in links and billing notices. Sign-in tokens and session cookies exist only to keep you signed in.

Devices

For each Mac you approve: a device name, the macOS version, the kcode version, when it was first seen, and when it last checked in. This is what enforces the two-Mac limit and what your account page shows you. License check-ins carry the same fields and nothing about your code or prompts.

Payments

Paddle, as merchant of record, processes payment and holds card details. We receive the subscription status, the period dates, and a customer reference; never the card.

Feedback

When you send feedback from the app, we receive the message you wrote, the kcode version, the macOS version, the build id, and, when the Mac is signed in, which device and account it came from. It is stored in a spreadsheet we control, so that we can follow up and reproduce problems.

Analytics on kcode.sh

When analytics are enabled the site uses PostHog to count page views. PostHog runs with local storage instead of cookies, respects the browser's Do Not Track setting, does not capture form fields, and profiles only people who sign in.

Analytics in the app

kcode will send usage analytics to kcode (company name to be filled in). The current build sends none. Its only export is OpenTelemetry, which stays off until you set one of the telemetry_otel keys, and then reports to the collector you chose, not to us. A test in kcode enforces that those metrics carry no paths, prompts, or file content. Crash bundles and logs stay under ~/.kcode.

Before the first build that sends usage analytics, this section will say what the reports contain, which service receives them, and how to turn them off.

Your code and prompts

kcode runs on your Mac. Your prompts, files, and model replies go to the providers you configured, with your keys. They do not pass through kcode.sh.

Retention and rights

Account and device records last as long as the account. Ask us to export or delete them at support@kcode.sh; deleting the account ends the subscription.