Kunobi App Privacy Policy
Effective Date: 24 August 2026
Version: 1.1
Controller: Zondax AG, Dammstrasse 16, 6300 Zug, Switzerland
This Privacy Policy explains how Zondax AG ("Zondax", "we", "us") handles personal data for the Kunobi desktop application ("App"), on all release channels. It does not cover the Kunobi or Zondax websites, which have their own policies.
What changed in version 1.1. Section 8 now describes the update and download requests in full: what they carry, and what depends on your diagnostics choice. Version 1.0 described those requests as carrying the App version and platform, which was incomplete. Nothing else has changed. Version 1.0 remains permanently available at https://kunobi.com/privacy/desktop/1.0.
1. Summary
- The App sends no diagnostics or telemetry by default. Diagnostics are opt-in.
- Like any updatable software, the App makes routine operational requests (update and download checks). What those requests describe about your installation depends on your diagnostics choice; Section 8 sets out both cases.
- Your cluster data and credentials stay on your machine. The App does not upload them to Zondax (Section 6).
- Signing in is optional; if you do, we process your account details to provide account features.
- If you connect an AI assistant, content flows to that AI provider through your own account, under your control.
- We do not sell personal data and do not use it for advertising.
2. Data We Collect by Default
The App collects no diagnostics, telemetry, or account data by default. Its only default network activity is the routine update and download requests described in Section 8. App settings, themes, kubeconfig references, and license tokens are stored locally on your device. Authentication tokens are stored in your operating system's keychain or credential manager.
If the App crashes, a crash report is written locally on your device. Two separate, independent things can then happen: if you have enabled diagnostics (Section 3), an anonymous crash counter — category and type only, never the message or stack trace — is reported; the full crash report is transmitted only if you explicitly consent to sending that specific report (Section 4), regardless of the diagnostics setting.
3. Optional Diagnostics (Opt-In)
If you enable diagnostics in the App settings, we collect technical data to improve the App:
- Feature usage counts, performance metrics and traces (e.g. startup time, API latency), and error categories
- App version, operating system type, and processor architecture
- Anonymous crash counters (category and type only — no message or stack trace)
This data is not designed or used to identify you: it carries only a short-lived random identifier (a new one for each App process) and no account, machine, hostname, or user identifier, and we do not link it to you or across your sessions. Cluster names, namespaces, resource names, file paths, and command contents are never included. As with any network transmission, our infrastructure providers can technically observe the sending IP address; we do not use it to identify you. You can withdraw consent at any time in the settings; collection stops immediately. Withdrawal does not affect the lawfulness of processing that happened before it.
4. Crash Reports (Separate, Per-Report Consent)
If the App crashes, you may be asked whether to send the full crash report to us. Only if you agree, the report is transmitted once and then deleted locally. It contains the technical error message and stack trace (with user file paths sanitized and content truncated), crash category, App version, operating system, and architecture. Error messages can occasionally embed names from your environment (such as a cluster or resource name); if your setup is sensitive and you cannot verify the report's contents, simply decline — declining has no effect on your use of the App.
5. Account Data (Optional Sign-In)
The App works without an account. If you sign in, our identity provider processes your credentials and we receive your email address, name, username, and profile picture. We use this to operate your account, your subscription and entitlements, and account-connected features (such as synced notifications). Session tokens are stored in your operating system's keychain.
One local exception: the App checks whether the signed-in email belongs to Zondax staff to exclude staff sessions from telemetry. This check happens on your device; the email is not sent with telemetry.
License and plan entitlements are validated locally from a signed token; the App sends no hardware or device fingerprint for licensing.
6. Your Cluster Data
The App reads your kubeconfig files and communicates directly from your device with your Kubernetes clusters. This data is processed locally to provide the App's functionality. The App does not upload cluster credentials, manifests, or cluster contents to Zondax. The only qualification: a full crash report that you individually consent to send (Section 4) may incidentally contain environment names embedded in an error message.
7. AI-Assisted Features (Optional)
Kunobi can integrate with AI assistants (for example Claude Code or Gemini CLI) that you install and operate under your own provider account. If you connect one:
- The assistant can read cluster information through Kunobi's local interface, and that content is transmitted to your AI provider under your agreement with them — not to Zondax.
- Write operations by assistants are disabled by default and individually gated.
- You control which assistants are connected and can disconnect them at any time.
Review your AI provider's privacy terms before connecting an assistant to sensitive environments.
The App may also offer built-in AI features. When you enable such a feature, the content you choose to process with it (for example text you enter, or resources you make available to the feature) may be transmitted to third-party AI service providers to deliver the feature; we process that content only to provide the feature. These features are off by default, explain what they send when you enable them, and can be disabled at any time. Avoid processing sensitive data with them unless necessary.
8. Updates and Extensions
The App periodically checks for updates, and downloads builds, extension catalogs and extension packages. The address a request asks for already names the release channel, and for a build download the platform, architecture and version too, which is what lets us serve the right file.
Beyond that, what a request describes about your installation depends on the diagnostics choice in Section 3. If you have enabled diagnostics, the update check and the build download that follows it also carry the App version, operating system, processor architecture, release channel and how the App was installed (for example through a package manager), together with two identifiers that are generated fresh each time the App starts and a count of the checks made since it started. Those identifiers exist only while the App is running: they are discarded when it closes, do not persist between runs, and cannot be used to recognize the same installation the next day. If you have not enabled diagnostics, none of that is attached, and extension catalog and package downloads never carry it either way.
The App sends no installation, machine, hardware or account identifier, and nothing about your clusters, your files, or what you do in the App. As with any web request, your IP address is visible to our infrastructure providers so that the response can reach you; we do not use it to identify you.
9. Legal Bases
Under the GDPR: optional diagnostics and crash-report transmission rely on your consent (withdrawable at any time, without affecting the lawfulness of prior processing); account features rely on performance of a contract; routine operational requests (updates, downloads) and service integrity and security rely on our legitimate interest in operating and securing the App. Under the Swiss FADP, we observe its processing principles and, where a justification is required, rely on consent, an overriding private or public interest, or law, as applicable.
10. Recipients and Processors
We use trusted service providers to operate these features: diagnostics storage and analysis, identity and sign-in, backend hosting, and download delivery. They process data on our behalf under confidentiality and data protection obligations; for certain security and platform operations they may act under their own terms. We do not share personal data with third parties for their own marketing.
The current list of our providers, their processing locations, and retention periods is maintained at https://kunobi.com/legal/providers and is updated as our infrastructure evolves.
11. International Transfers
We are based in Switzerland. Where our providers process data outside Switzerland or the EEA, we rely on recognized standard contractual clauses or an applicable adequacy decision. You can request information about the safeguards applying to a specific transfer via the contact in Section 16.
12. Retention
Diagnostics data is retained only as long as needed for the purposes described above and then deleted or anonymized. Account data is kept while your account exists. Local data stays on your device under your control.
13. Your Rights
Depending on applicable law, you may request access, correction, deletion, or portability of your data, object to or restrict processing, and withdraw consent at any time (without affecting the lawfulness of processing before withdrawal): dataprotection@zondax.ch. EU/EEA users may complain to their supervisory authority; Swiss users to the FDPIC.
14. Security
We use appropriate technical and organizational measures: operating-system keychain storage for tokens, signed updates and extensions, integrity-protected local crash files, and transport encryption.
15. Changes to This Policy
The current version of this policy is always available at https://kunobi.com/privacy/desktop, with its version and effective date; every published version remains permanently available at its own versioned address. For material changes, and before any materially new data processing begins, we will inform you through the App or by email where available. Changes to consent-based processing take effect for you only after you have given the corresponding consent.
16. Contact
Zondax AG Dammstrasse 16 6300 Zug Switzerland
Email: dataprotection@zondax.ch