Local first, transparent when data leaves
Privacy Notice
This notice describes the information handled by the Kairo desktop app, website, reporting Worker, and optional integrations.
1. What remains local
Kairo is designed to keep ordinary library activity on your computer. The following generally remains local unless you deliberately include it in a report:
- installed-game records, paths, queue state, download history, settings, and shortcuts;
- locally imported
.torrentfiles and torrent session state; - mod profiles, backups, installation plans, and local save locations;
- Admin catalog drafts, tokens, and private configuration files.
2. Network requests
When Kairo checks the public catalog, updates, cover media, provider pages, the report service, or an enabled API integration, the receiving service can see ordinary connection data such as your IP address, request time, and user-agent information.
Kairo displays no advertisements during launch and the dormant sponsor system does not fetch creatives, record impressions, or send click events.
3. Optional installation analytics
The public Windows installer offers an unchecked choice to share one installation event. Nothing is sent unless you actively select it. The choice is shown only for a fresh public-app installation; Kairo Admin, updates, repairs, app launches, games, library activity, downloads, and background use do not send analytics events.
| Event | Data retained by Kairo | Purpose |
|---|---|---|
| Installer request | Day, requested Kairo version, request source, and two-letter country, stored only as aggregate counts | Understand public installer demand and release adoption |
| Consented installation | HMAC-protected random installation ID, event times and count, Kairo version, Windows version/build, architecture, interface locale, and two-letter country | Estimate participating installations, operating environments, country percentages, and release health |
The random installation ID is created by the installer and kept locally so you can withdraw later. It is sent over HTTPS and immediately transformed with a secret-key HMAC before D1 storage; the raw ID and raw IP address are not stored in Kairo's analytics database. Cloudflare derives the country from the request at its edge.
You can remove the pseudonymous installation row in Kairo Settings. The local consent record is removed only after the server confirms deletion. Historical daily totals contain no installation ID and remain as identifier-free aggregate statistics.
4. Reports and rights claims
| Submission | Data processed | Purpose |
|---|---|---|
| Bug or suggestion | Category, title, description, reproduction details, app/catalog version, optional contact and screenshots | Diagnose problems, answer users, and improve Kairo |
| Privacy request | Your request, contact details, and any information needed to verify and answer it | Exercise data-protection rights and maintain an audit trail |
| Rights-holder claim | Legal name, organization, role, contact details, work and disputed location, ownership/authority explanation, signature, declarations, and optional image or PDF evidence | Verify authority, temporarily disable disputed material where appropriate, decide final removal, and handle counter-notices |
The reporting service also receives a user agent and a salted, shortened hash derived from the submitting IP address for abuse prevention. The raw IP is not deliberately stored in the report database by Kairo.
5. Legal bases and minimization
The optional installation event is processed with your consent, which you can withdraw in Kairo Settings. Aggregate website installer-request measurement is processed for the legitimate interest of operating and understanding the public release service without cookies or cross-site tracking. Service security, catalog integrity, support, and rights-case review are processed for legitimate interests and, where applicable, compliance with legal obligations. Optional contact details and attachments are submitted at your direction. Kairo asks only for information reasonably needed to review the request.
Do not send passwords, payment information, full identity documents, or unrelated confidential records. Rights holders need detailed proof of ownership or authority, but a passport is not requested by default.
6. Service providers and transfers
- Cloudflare delivers the website, Turnstile verification, Worker API, country derivation, and D1 report and analytics storage.
- GitHub hosts approved public release files and may receive updater or download requests.
- Nexus Mods receives API requests only when that optional integration is enabled and used.
- Independent download providers receive requests when a user opens or downloads from their service.
These providers may process data outside Sweden or the EEA under their own terms and lawful transfer safeguards.
7. Retention and security
Ordinary reports are retained while they are investigated and until they are archived or deleted through Admin. Rights claims, evidence, decisions, and case events may be retained longer where needed for legal claims, repeat-notice handling, audit integrity, or dispute resolution. A fixed automatic deletion schedule has not yet been enabled for the private beta.
Pseudonymous installation rows are automatically deleted 24 months after their last opted-in installation event, or earlier when you withdraw. Identifier-free daily install and installer-request totals may be retained for long-term product and release trends because they contain no installation ID.
Administrative access uses a private token. Responses are marked non-cacheable, evidence size and file types are restricted, and Turnstile is used to reduce automated abuse. No online system can guarantee absolute security.
8. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection, or a portable copy of personal data. You may also complain to the Swedish Authority for Privacy Protection (IMY) or your local supervisory authority.
Some information may be retained when required by law or necessary to establish, exercise, or defend legal claims. Kairo may ask for proportionate verification before disclosing or changing personal data.
9. Changes and contact
Material privacy changes will be published here with a new effective date. Contact the Kairo Project through Support and select Privacy for a data-protection request.
Kairo