KvyPrivacy
Privacy
Last updated: July 27, 2026
What Kvy is
Kvy is end-to-end encrypted mission control for coding agents. Session transcripts, titles, and related agent content are encrypted on your devices before they reach our servers. The server stores ciphertext it cannot read.
Account data
When you create an account we store the identifiers needed to sign you in (for example email address, OAuth subject, hashed password credentials) and device/session metadata required for auth, pairing, and push delivery. We do not use your agent transcripts for advertising or model training.
Encryption keys
Encryption keys stay on your devices. New browsers receive keys only after you approve a device-to-device or CLI pairing flow. Losing every device that holds your keys means encrypted history cannot be recovered; your account identity can still be retained if you choose to start a fresh key epoch.
Notifications
If you enable Web Push or a fallback channel (such as Telegram or ntfy), we store the subscription endpoint needed to deliver generic alerts (for example that a session needs permission). Notification payloads do not include transcript content.
Self-hosting
If you run Kvy yourself, this policy describes the hosted product defaults. Your own deployment is under your control and your operators' policies.
Contact
Questions: support@kvy-cli.tkvy.dev.