KvyPrivacy

Privacy

Last updated: July 27, 2026

What Kvy is

Kvy is end-to-end encrypted mission control for coding agents. Session transcripts, titles, and related agent content are encrypted on your devices before they reach our servers. The server stores ciphertext it cannot read.

Account data

When you create an account we store the identifiers needed to sign you in (for example email address, OAuth subject, hashed password credentials) and device/session metadata required for auth, pairing, and push delivery. We do not use your agent transcripts for advertising or model training.

Encryption keys

Encryption keys stay on your devices. New browsers receive keys only after you approve a device-to-device or CLI pairing flow. Losing every device that holds your keys means encrypted history cannot be recovered; your account identity can still be retained if you choose to start a fresh key epoch.

Notifications

If you enable Web Push or a fallback channel (such as Telegram or ntfy), we store the subscription endpoint needed to deliver generic alerts (for example that a session needs permission). Notification payloads do not include transcript content.

Self-hosting

If you run Kvy yourself, this policy describes the hosted product defaults. Your own deployment is under your control and your operators' policies.

Contact

Questions: support@kvy-cli.tkvy.dev.