Privacy policy
Draft, pending legal review Last updated 2026-09-18.
The short version
Kruvo is local-first. The desktop app keeps your conversations, files, connector tokens and model keys on your machine. Nothing is sent to Kruvo unless you sign in to Kruvo Cloud, and even then we never receive your conversations, files or model keys.
What the desktop app stores locally
- Conversations and audit records, in your user profile folder.
- Connector tokens and model API keys, in the app's secret store with user-only permissions.
- Deliverables, in the workspace folder you chose.
The app talks to the model providers and integrations you configure, using your credentials, directly from your machine.
What the desktop app sends to Kruvo
- Update checks: a request for the update manifest at download.kruvo.ai. No identifiers beyond what an HTTP request carries.
- Licence checks (paid plans): licence id, plan, app version and a device identifier, to issue and renew your entitlement.
- Telemetry (signed-in users, opt-out in Settings): content-free events such as "a session of type X was started", app version and platform. Never prompts, outputs, titles, file paths or connector content.
What Kruvo Cloud stores
When you sign in: your account email, plan and billing state (through our merchant of record), OAuth tokens for the connections you choose to broker through Kruvo Cloud, and relay metadata needed to route messages to your desktop. Tokens are encrypted at rest and revocable from the app.
Payments
Purchases are processed by our merchant of record, which handles payment details, invoices and taxes under its own privacy policy. We receive the transaction outcome, not your card details.
Your rights
You can export or delete your account data by writing to [email protected]. Local data is yours to delete at any time by removing the app's profile folder.
Contact
Kruvo, Portugal. [email protected].