1. Introduction
This Privacy Policy describes how Konvu, Inc. (“Konvu,” “we,” “us,” or “our”) collects, uses, shares, and protects personal information when you:
- Visit our website at konvu.ai (the “Site”)
- Install or use the Konvu tool for coding agents (the “Service”), which runs on your own machine
- Communicate with us through email, support channels, or events
The Service is open source (MIT) and runs on your machine. Konvu does not receive your prompts, code, transcripts or usage data. Section 3.2 describes local processing, the context review that sends session excerpts to the AI provider that ran the session, and the product telemetry enabled by default, and how to disable each.
If you have questions, please contact us at privacy@konvu.com.
2. Who We Are
Konvu, Inc. is a Delaware corporation with its registered office at:
1111B South Governors Avenue, STE 7673 Dover, Delaware 19904 United States
Konvu operates through its affiliate, Konvu SAS, incorporated in France. For the purposes of EU and UK data protection law, Konvu, Inc. is the data controller for personal information collected through the Site. The Service sends product telemetry by default as described in Section 3.2.
Privacy contact: You can reach us on any privacy matter at privacy@konvu.com or by post at the address above.
3. Information We Collect
3.1 Information You Provide
When you contact us, we may collect:
- Contact and inquiry data: your name, email address, and company name when you email us or submit a form
3.2 Information Processed by the Service on Your Machine
The Service runs on your machine. It reads local session transcripts written by Claude Code and Codex, estimates API-equivalent costs from a bundled model price table, and attributes usage to sessions. It serves a dashboard on 127.0.0.1 only and, if you enable them, sends browser notifications for subscription limits and paid-session forecasts. Derived usage data is stored under ~/.konvu/telemetry, readable by your user only, and normalized session files expire after seven days. The transcripts your agents write are never modified. Setup adds a Claude Code status line and hooks for Codex CLI, Claude Desktop and Codex Desktop; konvu-telemetry uninstall removes the background service, Konvu-owned integrations, the data under ~/.konvu/telemetry and the Homebrew package.
Every two minutes, the Service fetches account limits using the provider logins already on your machine. It contacts Anthropic’s usage endpoint for Claude and asks the local Codex app-server to contact OpenAI for Codex. The Service does not retain credentials, raw provider responses or account IDs in Konvu files or logs. It stores normalized limit data locally.
The context review is on by default for sessions within your subscription plan. For each session active in the last 20 minutes, after every ten new prompts, the Service may send bounded excerpts of that session to the same provider through that provider’s command-line tool and login on your machine, so a small model can rate which context the session still needs. Claude sessions go only to Anthropic and Codex sessions only to OpenAI. Konvu does not receive this content. Claude tools are disabled for these requests, and Codex runs them in its read-only sandbox with shell, web and apps turned off. Sessions billed beyond your plan are reviewed only if you allow it with konvu-telemetry context-analysis on --allow-paid. Short topic summaries, relevance scores and timestamps stay in the session’s local context map, which is deleted seven days after the session was last active. Your agreement with that provider governs how it handles these requests. Run konvu-telemetry context-analysis off to turn the review off.
The Service requires no account or API key. Setup enables anonymous product telemetry to PostHog by default. Any existing telemetry preference remains unchanged.
Product events cover successful setup, the first dashboard-visible snapshot, dashboard opens, one active-day event per day when data is visible, and collector failures at most once per day. Events use a random per-install ID, a capture timestamp and a random deduplication ID to measure activation and repeat use. They do not include prompts, code, transcripts, file paths, command arguments, token usage, raw errors, environment variables, account IDs or workspace IDs. Events do not create PostHog person profiles and request IP discard.
Run konvu-telemetry telemetry off to disable product telemetry and delete unsent events. Use konvu-telemetry telemetry on to re-enable it or konvu-telemetry telemetry status to check your preference. The local queue holds at most 100 events, and failed delivery backs off for up to 24 hours. The source is public at github.com/KonvuInc/konvu-telemetry.
3.3 Information Collected Automatically on the Site
When you visit the Site, we automatically collect:
- Log data: IP address, browser type, operating system, referring URL, pages visited, and timestamps, through our hosting provider Cloudflare
- Device data: device type, screen resolution, and language preferences
- Analytics data: page interactions and navigation patterns, collected through Google Tag Manager and Google Analytics (see Section 7)
We do not collect precise geolocation data (such as GPS coordinates).
4. How We Use Your Information
We use personal information for the following purposes:
- Providing the Service: the Service processes your session data on your machine, and Konvu receives none of it. The context review and product telemetry are described in Section 3.2
- Customer support: to respond to your inquiries and resolve issues
- Service communications: to send product notices and updates to people who asked for them
- Analytics and improvement: to understand how the Site is used and to improve it, and to measure Service activation and repeat use through product telemetry
- Marketing: to send you information about Konvu’s products where you have consented or where we have a legitimate interest to do so. You can opt out at any time
- Security: to detect, prevent, and respond to fraud, abuse, security incidents, and technical issues
- Legal compliance: to comply with applicable laws, regulations, and legal processes
We do not build behavioral profiles of individual users for the purpose of selling advertising, and we do not sell personal information.
5. Legal Bases for Processing (EEA, UK, and Switzerland)
If you are located in the European Economic Area, United Kingdom, or Switzerland, we rely on the following legal bases under the GDPR:
| Processing activity | Legal basis |
|---|---|
| Website analytics (Google Analytics via Google Tag Manager) | Legitimate interest (measuring how the Site is used). No analytics cookies are set in the EEA, UK or Switzerland, so no consent is collected for them (see Section 7.2) |
| Security and abuse prevention (Cloudflare) | Legitimate interest (ensuring security) |
| Customer support | Legitimate interest (resolving issues) |
| Marketing communications | Consent (opt-in; withdrawable at any time) |
| Legal and regulatory compliance | Legal obligation |
You may withdraw consent at any time by contacting privacy@konvu.com or using the unsubscribe link in any email.
The Service processes session data on your machine, under your control. Product telemetry is enabled by default, and you can turn it off at any time with konvu-telemetry telemetry off. The context review can be turned off at any time with konvu-telemetry context-analysis off.
6. Analysis of Session Data
The Service analyzes your session data on your machine to estimate API-equivalent cost from token counts and a bundled price table, forecast the next ten prompts, attribute subscription usage to sessions, and show context, subagent usage and provider-reported account limits. That analysis stays on your machine. The context review described in Section 3.2 is the exception: it sends bounded excerpts of a session to that session’s own provider so a model can rate which context is still needed.
No training on your data: Konvu does not receive your session data and does not use it to train, fine-tune, or improve any machine learning model.
Nothing in the path of your agent: the Service reads transcripts after your agent writes them. It does not proxy, intercept or modify requests between your coding agent and its model provider.
7. Cookies and Analytics
7.1 Website Analytics and Tracking
We use the following services on the Site:
- Google Tag Manager (GTM): to manage and deploy scripts on the Site. GTM itself does not collect personal data, but it loads the services described below. For more information, see Google’s Privacy Policy.
- Google Analytics: to understand how visitors interact with the Site, including page views, traffic sources, and engagement metrics. Outside the countries listed in Section 7.2, Google Analytics sets cookies on your device (for example
_ga,_ga_#). You can opt out at tools.google.com/dlpage/gaoptout. For more information, see Google’s Privacy Policy. - Cloudflare: to host the Site and provide bot protection and security. Cloudflare may set cookies (for example
__cf_bm) to distinguish human visitors from bots. For more information, see Cloudflare’s Privacy Policy.
The Site does not use advertising cookies and does not share your data with advertising networks.
7.2 Analytics Cookies and Your Choices
We use Google Consent Mode. For visitors in the European Economic Area, the United Kingdom and Switzerland, analytics storage is set to denied before any tag loads, so Google Analytics does not set cookies on your device. It may still send cookieless measurement pings, which cannot identify you or follow you between sessions. Advertising storage is denied for every visitor, in every country, and we run no advertising tags.
Outside those countries, analytics storage is granted and Google Analytics sets the cookies described in Section 7.1. You can opt out with Google’s browser add-on, linked above, or manage cookies through your browser settings. Disabling cookies may affect the functionality of certain features.
8. Who We Share Your Information With
We share personal information only as described below. We do not sell personal information.
8.1 Service Providers and Sub-processors
We use the following third-party providers to operate the Site. The Service also uses PostHog for product telemetry, as described in Section 3.2.
| Provider | Purpose | Location |
|---|---|---|
| Cloudflare | Hosting, bot protection and security for the Site | United States |
| Google Analytics | Website analytics (Site only) | United States |
| Konvu SAS | Engineering, support, and operational services (Konvu affiliate) | France |
8.2 Other Disclosures
We may also disclose personal information:
- Legal requirements: to comply with applicable law, regulation, legal process, or government request
- Protection of rights: to enforce our agreements, protect our rights, privacy, safety, or property, and that of our users or the public
- Business transfers: in connection with a merger, acquisition, reorganization, or sale of assets, in which case the successor entity will be bound by this Privacy Policy
9. International Data Transfers
Konvu is based in the United States, and our primary infrastructure is hosted in the US. If you are located outside the United States, your personal information will be transferred to and processed in the United States.
The personal information the Site collects (inquiry, analytics and security data) is processed by the providers listed in Section 8.1. For transfers of that data from the European Economic Area, United Kingdom, or Switzerland to the United States, we rely on the following safeguards:
- EU Standard Contractual Clauses (SCCs) as approved by European Commission Implementing Decision (EU) 2021/914, and the UK International Data Transfer Addendum (IDTA) where applicable, in our agreements with those providers
- The EU-U.S. Data Privacy Framework, where a provider is certified under it
- Swiss Federal Act on Data Protection (FADP): references to the GDPR in the SCCs are interpreted to include the FADP as applicable
Google and Cloudflare document their own transfer mechanisms in their privacy policies, linked in Sections 7 and 8. Konvu does not receive or transfer your session data. When the context review runs, the Service sends session excerpts directly from your machine to the provider that ran the session, as described in Section 3.2.
10. Data Retention
We retain personal information only as long as necessary for the purposes described in this Privacy Policy:
- Session data (Section 3.2): never received by Konvu. It stays on your machine, under your control, except for the context review excerpts sent to your own provider. The Service expires its normalized session files after seven days, deletes a session’s context map seven days after the session was last active, and leaves the agents’ own transcripts untouched
- Backup copies: deleted no later than ninety (90) days after the data they hold, in the ordinary course of backup rotation
- Website analytics data: retained in accordance with Google Analytics’ retention settings (14 months)
- Marketing and inquiry data: retained until you unsubscribe or request deletion, and in any case no longer than twenty-four (24) months after your last interaction with us
When retention is no longer necessary, we delete or anonymize personal information. Data retained for legal or compliance purposes is isolated from active processing and remains subject to the security and confidentiality obligations of this Privacy Policy.
11. Data Security
We maintain administrative, technical, and organizational security measures designed to protect personal information against unauthorized access, disclosure, alteration, or destruction, including encryption in transit and at rest, access controls, and regular security assessments.
No method of transmission or storage is completely secure. While we strive to protect your personal information, we cannot guarantee absolute security.
For details about our security practices, contact us at privacy@konvu.com.
12. Your Privacy Rights (EEA, UK, and Switzerland)
If you are located in the EEA, UK, or Switzerland, you have the following rights under applicable data protection law:
- Access: request a copy of the personal information we hold about you
- Rectification: request correction of inaccurate or incomplete personal information
- Erasure: request deletion of your personal information where it is no longer necessary for the purposes for which it was collected
- Restriction: request that we restrict the processing of your personal information in certain circumstances
- Portability: receive your personal information in a structured, commonly used, machine-readable format
- Objection: object to processing based on legitimate interests, including for direct marketing purposes
- Withdraw consent: where processing is based on consent, withdraw your consent at any time without affecting the lawfulness of prior processing
- Automated decision-making: not be subject to decisions based solely on automated processing that produce legal or similarly significant effects. The Service’s cost estimates and warnings run on your machine, are informational, and produce no such effects
To exercise any of these rights, contact us at privacy@konvu.com. We will respond within thirty (30) days, or within the timeframe required by applicable law.
If you believe we are processing your personal information unlawfully, you have the right to lodge a complaint with the supervisory authority in your member state of habitual residence, place of work, or place of alleged infringement.
13. US State Privacy Rights
This section applies to residents of states with comprehensive privacy laws, including California (CCPA/CPRA), Colorado, Connecticut, Virginia, and other states with applicable privacy legislation.
13.1 Your Rights
Depending on your state of residence, you may have the right to:
- Know what personal information we collect, use, and disclose
- Access and obtain a copy of your personal information
- Correct inaccuracies in your personal information
- Delete your personal information
- Opt out of the sale or sharing of your personal information
- Limit the use of sensitive personal information (we do not collect sensitive personal information as defined under the CCPA/CPRA)
- Not be discriminated against for exercising your rights
13.2 How We Handle Your Data
In the preceding twelve (12) months:
- Categories collected: identifiers (names, email addresses, IP addresses, cookie identifiers), internet and network activity (browsing data, page interactions, referral URLs), and geolocation data (IP-derived, not precise GPS). The session data described in Section 3.2 is not collected
- Categories of sources: directly from you (emails) and automatically through cookies and similar technologies when you visit the Site
- Sensitive personal information: we do not knowingly collect sensitive personal information as defined under the CCPA/CPRA
- Sold: none. We do not sell personal information
- Shared for cross-context behavioral advertising: none. The Site does not use advertising cookies
- Disclosed for a business purpose: personal information is disclosed to the service providers listed in Section 8.1, solely for the purposes described in this Privacy Policy
| Category of PI | Business purpose | Third parties receiving |
|---|---|---|
| Identifiers (name, email address) | Customer support | Konvu SAS |
| Online identifiers (IP address, cookie IDs) | Website analytics, security | Google Analytics, Cloudflare |
| Internet and network activity (browsing, page views, referral URLs) | Website analytics | Google Analytics |
Session data (Section 3.2) does not appear in this table because Konvu never receives it.
13.3 Exercising Your Rights
To exercise your rights, contact us at privacy@konvu.com. We will verify your identity before processing your request and respond within forty-five (45) calendar days. If we need additional time, we will notify you of an extension of up to forty-five (45) additional calendar days.
You may designate an authorized agent to submit a request on your behalf, provided the agent submits proof of authorization.
If we decline your request, you may appeal by emailing privacy@konvu.com. We will respond in writing with our reasons within sixty (60) days. If the appeal is denied, you may contact your state attorney general.
14. Children’s Privacy
The Site and Service are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child under 18, please contact us at privacy@konvu.com and we will take steps to delete it promptly.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will indicate the date of the most recent update at the top of this page. For material changes, we will provide prominent notice on the Site or notify you by email.
We encourage you to review this Privacy Policy periodically.
16. Contact Us
If you have questions about this Privacy Policy, want to exercise your privacy rights, or wish to make a complaint, please contact us:
Privacy Contact Konvu, Inc. 1111B South Governors Avenue, STE 7673 Dover, Delaware 19904 United States
Email: privacy@konvu.com