Privacy Policy
Last updated: June 21, 2026
Koda is built local-first. Your code, your terminals, your AI agents and your provider credentials live and run on your own machine — not on a Koda server. This policy explains the limited data Koda does process: principally the Koda account you sign in with (which starts your free trial and, if you subscribe, carries your plan).
The short version
- The desktop app is local-first. Your code, shells, agents and API keys never leave your device through Koda. There is no Koda backend that receives them.
- Using Koda requires a Koda account (it anchors your 7-day free trial and, if you subscribe, your plan). The account is the only Koda-side data about you.
- An account stores very little — essentially your email, how you signed in, your plan tier and your trial dates — to let you sign in and access the app.
- We never proxy or store your provider credentials (Anthropic, OpenAI, Google, xAI, etc.). The app runs the real first-party CLIs; you authenticate to them directly.
- We don't sell your data, and we don't run hidden analytics on your code.
Who we are
"Koda", "we", "us" refers to [Legal entity], the provider of the Koda desktop application and this website. For privacy questions, contact us at hello@devkoda.online.
How the desktop app handles your data
Koda is a desktop application that hosts coding-agent CLIs in real terminals. By design:
- Your source code, files, and terminal sessions are read and written on your machine. Koda does not upload them.
- Your API keys are stored in an OS-encrypted vault (your operating system's
safeStoragekeychain), bound to your OS user, and decrypted only inside Koda's main process. They are never transmitted to us. - Coordination state for multi-agent workspaces is written to a gitignored
.koda/folder in your project — local files only. - Koda does not run its own analytics or telemetry service that collects your usage or code.
Software updates
To keep itself current, the app checks GitHub Releases on launch and periodically, and downloads updates. These requests go to GitHub under GitHub's privacy terms; GitHub may log standard request metadata (such as IP address). Koda does not attach your identity to these checks.
The optional usage meter
Koda includes an opt-in usage meter that can display your official Claude.ai usage. If — and only if — you connect it, it stores your own Claude.ai web session locally (OS-encrypted) and uses it solely to call Claude.ai's own usage API for your numbers. That session is sent only to Claude.ai, never to us, and there is no Koda backend to send it to. You can disconnect it at any time, which deletes the stored session. If you never connect it, no usage requests are made.
Information we collect when you create a Koda account
Creating an account is optional and only needed to unlock paid features. When you sign up on this website, we process:
| Data | Why | Source |
|---|---|---|
| Email address | To create and identify your account and contact you about your account. | You, or your OAuth provider |
| Authentication details | To sign you in securely (a salted password hash, or a Google / GitHub OAuth identifier). We never see your OAuth password. | You / Google / GitHub |
| Plan tier | To know whether you have access to paid features. | Set by us |
| Session & technical data | A login session token (stored in your browser) and standard server logs from our auth provider. | Automatic |
We do not require a name, phone number, or address to use Koda.
Payments
If you purchase a paid plan, payment is handled by a third-party payment processor. We do not receive or store your full card number. We may keep a record of your subscription status and billing email to provide the service.
Service providers we use
We rely on a small number of third parties to run the account and website. They process data on our behalf under their own terms:
- Authentication & account database (Supabase). Stores your account record (email, auth credentials, plan tier) and issues login sessions. Data is held in Supabase's infrastructure in the [data-region] region.
- OAuth providers (Google, GitHub). If you choose social sign-in, the provider authenticates you and shares a basic identifier and email with us.
- GitHub Releases. Hosts the app installer and update files you download.
- Payment processor. Handles checkout and billing if you subscribe.
The AI agent CLIs you run inside Koda (Claude Code, Codex, Gemini, Grok, and others) talk to their providers directly under their privacy terms. Koda is not in that data path and does not receive that traffic.
Cookies & local storage
This website does not use advertising or cross-site tracking cookies. Our auth provider stores a login session in your browser's local storage so you stay signed in. Clearing your browser storage or signing out removes it.
How we use account data
- To provide, maintain, and secure your account and paid features.
- To process payments and manage subscriptions.
- To contact you about your account, security, or material changes to the service.
- To comply with legal obligations and enforce our Terms.
We do not sell your personal data, and we do not use your code or files to train models.
Data retention
We keep your account data for as long as your account exists. When you delete your account, we delete or anonymize the associated personal data, except where we must retain limited records (for example, billing records) to meet legal obligations.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can:
- View and update your email and plan from your account page.
- Request access to or deletion of your account data by emailing hello@devkoda.online.
We will respond within the timeframe required by applicable law.
Security
Account access is protected by your authentication provider and row-level security so that you can only read your own record. On your device, API keys and any usage-meter session are encrypted by your operating system and bound to your OS user. No system is perfectly secure, but we design Koda to keep the most sensitive data — your code and credentials — on your machine and out of our reach.
Children
Koda is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their personal data.
International users
If you access Koda from outside the region where our service providers store data, your account data may be transferred to and processed in [data-region]. By using Koda you consent to that transfer, carried out with appropriate safeguards where required.
Changes to this policy
We may update this policy as Koda evolves. We'll revise the "Last updated" date above and, for material changes, take reasonable steps to notify account holders.
Contact
Questions about privacy? Email hello@devkoda.online.
