Privacy Policy

Kyu, the desktop companion by GetKyu · Last updated: September 9, 2026

The short version: Kyu runs entirely on your computer. We operate no server for your data, require no account, and collect no analytics or telemetry unless you switch on Help improve Kyu in Settings (off by default, counts only, never text) — and as of this version even that has nowhere to arrive, because the address it posts to does not exist yet. The website counts nothing at all today; the cookie-free counter it is built for is not switched on. What Kyu learns about you is stored on your device and nowhere else. The app talks to the internet only for the specific purposes listed below — most of them only if you turn them on.

1. What we don't do

Kyu has no user accounts, no sign-in, and no backend server that holds your data. We do not collect usage analytics, telemetry, crash reports, advertising identifiers, or behavioral data — with one exception you control: if you switch on Help improve Kyu in Settings (off by default), the app sends a few counts once a day (which setup step you reached, which features are on, what kind of error happened, how often you talk to Kyu). It never sends what you type, your name, your coordinates, your calendar or mail, any key, or file names, and you can reset the random install number at any time with Forget everything. As of this version those counts have nowhere to arrive. The address the app posts them to — stats.getkyu.com — does not exist yet: it has no DNS record, so even with the switch on, the request cannot reach anybody, and we have received nothing. The website is in the same state: getkyu.com is built to count visits without cookies or accounts on a small worker of ours at that same address, but the counting script is not in the page today — the site counts nothing at all. If we do switch either of them on, this is the whole of what would be recorded and nothing more: for the website, the page, the referring site (host name only), the campaign tag in the link (from a short fixed list), coarse device, OS, browser, language and screen-width labels, which of a few buttons you clicked, how far you scrolled, and how long you stayed (bucketed); the worker would note the country, region and city the request came from and then discard the IP address. Nothing would identify you across visits, and we will not add cookies in order to. We do not sell, rent, or share personal information — we never receive it in the first place. Kyu does not watch your keystrokes, your browsing history, or your files, except for the specific items you hand to it yourself (for example, a file you drop on Kyu or an image you paste into chat). Kyu can look at your screen, but only in the narrowest way: one still frame of whichever window is in front, only at the moment you ask — never on a timer, never in the background, and never the whole desktop. It is off by default; you switch it on under The window in front, and macOS asks for Screen Recording permission separately, which only you can grant. Nothing is written to disk: the frame is encoded in memory, sent to the AI provider you connected, and released. Kyu's own window is excluded from that frame, and if he cannot identify his own windows he refuses to capture at all. This needs macOS 14 or newer; on macOS 13 the feature is simply absent, and on Windows it does not exist at all — the Windows build has no such code, and the app asks the shell whether this machine can do it — when the answer is no it leaves the row out of the privacy card altogether, rather than offering a switch that would do nothing.

2. What stays on your device

Everything Kyu knows lives in local storage on your computer: the name you give Kyu, chat history, Kyu's diary, your routine rhythm, preferences and wardrobe, things you asked Kyu to remember, and streak records. To mirror your context (for example, strumming along while you play music), Kyu can also note locally which application is in front and for roughly how long. The record itself — the list of app names and minutes — stays on your computer and is never uploaded. What is drawn from it does travel in one case, and only one: when you chat with an AI provider you have configured, the standing note Kyu sends along can include a short summary of it — the two or three apps you hold longest with rounded times (for example “Figma, 3 hours”), what kind of work those add up to (“design, 3 hours”), and whether you tend to stay on one thing or move around. Never window titles, file names, or anything you typed. That summary goes to the provider whose key you entered, nowhere else, and only when you are chatting. The switch in Settings (Which app is in front) stops the observation: with it off, no new app time is recorded. It does not erase what was already recorded, and the summary drawn from that earlier record still travels with the system prompt while you chat. Forget everything in Settings clears the stored facts. API keys and mail credentials are stored in a local file readable only by your user account (file permission 600); they are excluded from Kyu's export file by design. Deleting the app's data (or using Settings → Forget everything) removes this information. The export/import feature ("carry") produces a local file under your control — it is never uploaded by us.

3. When the app talks to the internet

Kyu's network access goes through a single module with a short, fixed list of purposes. As of this version:

PurposeWhereWhat is sentWhen
Weatherapi.open-meteo.comYour latitude/longitude rounded to two decimals (~1.1 km — a square that holds thousands of homes) and timezone name. No key, no account, no cookies.If weather is on
Location setupgeocoding-api.open-meteo.comThe place name you type (e.g. a city) is sent once to look up its coordinates; afterwards only the rounded coordinates above are used. If you use the Mac's own location service instead, that lookup happens on-device and nothing is sent here.Only when you set your location by name
CalendarThe ICS URL you provide (Google/Apple/other)A fetch of that URL. The URL stays on your device and is stripped from exports.If you add a calendar
NewsOfficial publisher RSS feedsA plain feed request. Headlines and links are shown with sources.If news is on
MarketsIndex quotes (e.g. ^GSPC)Index symbols only — never your holdings, which we don't know.If market brief is on
AI chatThe AI provider you configure (using your own API key)The messages and attachments you choose to send — and, so Kyu answers as himself, a short standing note about you: what he has learned from living alongside you (including the app summary described in section 2 — which apps you hold longest, what kind of work that is, whether you switch around), what you have told him to remember, and travel-shaped items he picked up (a flight, a stay, an event, a meeting). If you have switched on The window in front and then ask him about what you are looking at, the single still frame described in section 1 goes here too, with that message and no other. Deliveries, orders, subscriptions and amounts stay on your machine and are never in that note. This traffic is between your machine and your chosen provider, under their terms and privacy policy.When you chat with AI configured
MailYour IMAP server, if you connect oneSign-in with the app password you provide (stored locally), then a read-only fetch. Kyu reads headers from recent mail — sender, subject, list markers — and, for the newest 120 messages, the message text as well, so he can spot a delivery or a booking. That reading happens on your computer. From it he keeps only the machine-readable booking and order blocks that shops and airlines embed in their own mail: for each one, what kind it is and a short name (a flight number, a hotel, an event, a carrier, a shop, a channel), a date, and — where the block contains them — a destination city, a tracking number, an item name and an amount. The message text and the subject line are never kept: the subject is scanned for patterns and then discarded, and the body is read and released inside the app on your machine. Sender addresses are not kept either — only the root domain of a sender, and only to notice ones that write repeatedly (that is how a subscription is spotted). Of everything above, only travel-shaped items (a flight, a stay, an event, a meeting) are ever included in the standing note sent to an AI provider you configure; deliveries, orders, subscriptions, item names and amounts stay on your machine. Mail is opened without marking anything as read, and the message text never leaves your computer — we run no server to send it to. You can disconnect mail at any time in Settings: Kyu deletes the app password and forgets everything he took from your mail.If you connect mail
Tools (MCP)Servers you explicitly attachTool calls you enable. Off by default; each connection is opt-in.If you attach tools
Licenseapi.polar.shYour license key and, after the first time, the activation id for this machine. No account, no email, no device fingerprint. Direct-purchase copies only — the Steam version never makes this call.Once when you enter your key, then only if more than 7 days have passed since the last check. If it can’t reach Polar, Kyu keeps working for 30 days.
Help improve Kyu (only if you switch it on)stats.getkyu.com (our worker)Once a day: counts and fixed labels — setup step reached/done/skipped, AI provider name, features on, error kinds, number of chats, license result — plus app version, OS, language, and a random install number. Never text, names, coordinates, calendar, mail, keys, or file names. The worker keeps only the country the request came from — never region or city — and discards the IP address.Daily while the switch is on; nothing while it is off. As of this version that address does not resolve, so the request reaches nobody — see section 1.
Update checkgetkyu.com (a static file)A plain request for the version file. No identifiers are added by the app.Not used at launch — the Steam build updates through Steam. This applies only to a direct-download build, if we offer one.

If a feature above is off, the corresponding request simply doesn't happen. As of this version, there are no other network destinations in the app. If we ever add one — for example, an optional way to pass letters between friends — this policy will be updated before that feature ships, and the table above will name it.

4. Third-party services you choose

When you bring your own AI key, connect mail, or attach an MCP tool server, your data flows directly from your computer to that service under your agreement with them. We are not a party to that traffic, we cannot see it, and we encourage you to review those providers' privacy policies.

5. Children

Kyu is not directed to children under 13, and you must be at least 13 to use it. We do not knowingly collect personal information from anyone — including children. As of this version the app has no mechanism to collect it: the complete list of what leaves your computer is the table in section 3.

6. Your choices and rights

Because we hold no data about you on any server, there is nothing for us to hand over, correct, or erase on our side — your data is already in your hands. You can export it (Settings → export), delete it (Settings → Forget everything, or removing the app's two data folders: ~/Library/Application Support/com.getkyu.app and ~/Library/WebKit/com.getkyu.app), and inspect what the app stores at any time. If you have questions about privacy rights under laws such as the CCPA or GDPR, the honest summary is: as of this version we hold no records of you. We run no server that stores your data, and the one address we have built to receive anything at all — the cookie-free counter at stats.getkyu.com named in sections 1 and 3 — does not exist yet, so nothing has ever arrived there. When it does exist it will hold only counts and fixed labels attached to a random install number you can reset at will, plus, for the website, a country, region and city with the IP address discarded. That is still not a record of you, and this section will be rewritten the day it stops being true. Anything you would want to export, correct, or erase is on your own machine, where you can already do all three.

7. Purchases

GetKyu is a paid app. You buy it here, and Polar — our merchant of record — processes the payment, any applicable taxes, and your receipt. We never receive or store your card details, and we operate no payment server of our own. Your licence key is checked against Polar when you enter it and now and then afterwards; that check sends the key and a device name, nothing else. We also plan to sell on Steam, where Valve handles payment and receipts the same way. The same holds for any optional paid upgrade or subscription we may add.

8. Changes

If this policy changes in a way that matters, the new version will be posted at this address with an updated date. Because the app makes no silent data collection, changes here will track visible product changes.

9. Contact

Questions: getkyu.ai@gmail.com

GetKyu is an independent software project.