In short
- We collect only what Kavro needs to run your account, your license and your downloads.
- No ads, no tracking, no analytics, no selling data. The website uses one sign-in cookie and nothing else.
- Your projects never leave your computer. Kavro doesn’t upload them.
- Passwords are never stored — only a strong one-way hash.
- You can delete your account yourself at any time, and ask us for a copy of your data.
1. Who is responsible
Kavro (“we”, “us”) is responsible for the personal data described here. For anything about your data, write to [email protected].
This policy covers kavro.pro, your Kavro account and the Kavro desktop app. Our Terms describe the rules for using Kavro.
2. What we collect and why
| Data | Why | Legal basis |
|---|---|---|
| Account name, email address, password hash, date joined, whether your email is confirmed | To create and run your account, sign you in, and send you account emails | Contract |
| License and purchases plan, license key, redeemed keys, subscription status and renewal date, order number, amount, date, refunds | To give you the plan you paid for and keep records of purchases | Contract; legal obligation (tax records) |
| Computers computer name, Windows version, a one-way hash of the computer’s ID, first and last time seen | To activate Kavro on your computers, show them in your dashboard and enforce the computer limit | Contract |
| Sign-ins IP address, browser or app version, time — for each active session | To keep you signed in and let you sign out other sessions | Contract |
| Security log sign-ins, failed sign-ins (with the email that was typed), password and account changes, purchases, with IP address and time | To protect accounts against attacks and abuse, investigate problems and prevent fraud | Legitimate interest (security) |
| Support your messages to us and our notes about your case | To answer you and remember what was agreed | Contract; legitimate interest |
| Technical logs IP address, time, page or request, result | To keep the servers running and find errors | Legitimate interest |
We do not collect payment card details — the payment provider handles them (see section 5).
3. The Kavro app
- Your projects stay on your computer. The app never uploads your designs, code, images or fonts to us.
- Kavro AI (optional, Pro). Only when you use it, the app sends your prompt and the parts of your project needed to answer it directly from your computer to the AI provider you chose (Google Gemini, AiHubMix, OpenRouter, Ollama, Anthropic Claude or OpenAI), using your own API key. We don’t receive or store your prompts, the answers or your API key. The provider’s own privacy policy and terms apply to what you send; some providers may use it in line with their own settings. Ollama can also run models on your own computer, in which case nothing leaves it.
- When you are signed in, the app contacts kavro.pro about every 6 hours to renew your license. It sends your sign-in token and the one-way hash of your computer’s ID — nothing else.
- To offer updates, the app sends the version number you are using. Downloaded updates are checked against a digital signature before they install.
- Your sign-in is stored on your computer, encrypted with Windows’ own data protection. Settings stay on your computer too.
- The app contains no analytics, no crash reporting to third parties and no advertising.
6. Data outside the EU
Some of the providers above are based in the United States. Where data leaves the European Economic Area, it is protected by the European Commission’s Standard Contractual Clauses and/or the EU–U.S. Data Privacy Framework, as offered by each provider.
7. How long we keep it
- Account, computers and license — while your account exists. When you delete it, they are removed at once.
- Sign-in sessions — until you sign out or they expire (website: 30 days at most; app: 90 days without use).
- Email links — password reset links work for 30 minutes, confirmation links for 3 days, each only once.
- Security log — 12 months, then deleted automatically (also after an account is deleted, so abuse can still be investigated).
- Technical logs — up to 30 days.
- Backups — up to 30 days, then overwritten. A deleted account disappears from backups within that time.
- Purchase records — as long as tax law requires (usually 5 years), even after an account is deleted, without your other account data.
8. How we protect it
- Every connection is encrypted (HTTPS).
- Passwords are stored only as Argon2id hashes; sign-in codes and email links only as one-way hashes.
- Repeated wrong passwords are slowed down and blocked, and important account changes are logged.
- Licenses are digitally signed, and access to the administration of Kavro requires a second factor.
- Servers are isolated from other systems, updated automatically and backed up.
If a breach ever puts your data at risk, we will tell you and the authorities as the law requires.
9. Your rights
You have the right to:
- see the data we have about you and get a copy of it;
- correct it — your name can be changed in the dashboard; for your email, write to us;
- delete it — delete your account in the dashboard, or ask us;
- take it with you in a common format;
- object to processing based on legitimate interest, and restrict processing in certain cases.
Write to [email protected] from the email address of your account. We answer within one month. You can also complain to a data protection authority — in the country where you live or work, or where we are established.
We don’t make automated decisions with legal or similarly significant effects about you. Automatic limits only temporarily block repeated wrong passwords to protect accounts.
10. Children
Kavro is not meant for children under 16, and we don’t knowingly collect their data. If you think a child has created an account, tell us and we will delete it.
11. Changes to this policy
When we change how we handle data, we update this page and the date at the top. For important changes we tell you by email or in the app before they apply.