Legal
Privacy Notice
Last updated: 21 July 2026
This notice explains how KaiTerm processes personal data through kaiterm.dev, the KaiTerm desktop application, the KaiTerm account service, and KaiTerm Pro. The data controller for these services operates under the KaiTerm name. Privacy questions and requests can be sent to [email protected].
Data we process
- Account data: your email address, account identifiers, authentication sessions, passkey public credentials, and hashed recovery or verification data.
- Subscription data: Paddle customer, transaction, subscription, plan, price, and entitlement identifiers and status. KaiTerm does not receive your full payment-card details.
- Encrypted sync data: encrypted settings blobs and related synchronization metadata. Encryption and decryption occur in the desktop application; the sync service is not intended to hold plaintext connection passwords, private keys, passphrases, or AI API keys.
- Communications: messages you send for support and transactional email delivery records.
- Technical data: security, request, and error information that may include timestamps, IP addresses, user-agent information, and server logs.
- Website preferences: the selected website theme is stored locally in your browser. See the Cookie Policy.
How we use data and our legal bases
- To create and authenticate accounts, provide Pro entitlements, encrypted sync, support, and requested services under our contract with you.
- To secure accounts, prevent abuse, diagnose failures, and improve service reliability where this is in our legitimate interests.
- To administer subscriptions, accounting, refunds, and legal obligations.
- To send verification, security, purchase, and service messages necessary to provide the service. We do not currently use account email addresses for unrelated marketing.
AI providers and remote connections
When you configure an AI provider in KaiTerm, requests are sent from the desktop application to the provider you selected, using the credentials you supplied. Prompts may contain text you enter, approved connection context, and terminal output you explicitly include. Those providers process data under their own terms and privacy notices. KaiTerm does not route those AI requests through its account server.
SSH, Mosh, SFTP, FTP, local shell, tunnel, and command traffic is initiated by the desktop application toward destinations you configure. You are responsible for having authority to connect to and process data on those systems.
Service providers and disclosures
We use service providers where necessary to operate KaiTerm, including Paddle for checkout, tax, subscription, and payment administration; Brevo for transactional email; hosting and infrastructure providers for the website and account service; and GitHub for public releases and issue reporting. Each provider processes data under its own terms. We may also disclose information where required by law or necessary to protect users, KaiTerm, or others.
International transfers
Some providers may process data outside Ireland or the European Economic Area. Where applicable, transfers are made using an adequacy decision, contractual safeguards, or another lawful transfer mechanism.
Retention
We retain account and service data only for as long as reasonably necessary to provide the service, secure it, resolve disputes, and meet legal, tax, and accounting requirements. Short-lived authentication codes expire automatically. Subscription and transaction records may need to be retained after cancellation. Encrypted sync data is retained while the sync account remains active or until it is deleted in accordance with an applicable request and legal obligations.
Security
KaiTerm uses technical and organisational safeguards appropriate to the data processed. No system is completely secure, so you should keep local backups, protect your device and recovery material, and use strong authentication.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection, or portability of your personal data and may withdraw consent where processing relies on consent. You may also complain to the Irish Data Protection Commission or your local supervisory authority. Send requests to [email protected]. We may need to verify your identity before completing a request.
Changes
We may update this notice when KaiTerm, its providers, or legal requirements change. Material changes will be communicated where required.