Who we are
Kitsuvo, the app and kitsuvo.com, is made by Rattana Devs (“we”, “us”). This policy explains what information Kitsuvo handles, where it goes and what you can do about it. Questions go to hello@kitsuvo.com.
The Kitsuvo app
What stays on your computer
Your history, bookmarks, downloads list, site icons, zoom levels, settings, scores, evidence and verdict corrections are stored on your computer. API keys you add are kept in macOS Keychain or Windows Credential Manager. Local detection does not upload this information to us. Results you explicitly request through a connected AI client follow the automation disclosure below. You can export or erase local data at any time in Settings › Privacy.
AI engines you connect
If you add your own key for an AI engine (Jev through TypeSafe or OpenRouter, Claude through Anthropic, or OpenAI) and turn it on or ask it a question, Kitsuvo sends that provider a short digest of the page. The digest holds the page address without its query string, the title, description, headings, the scripts and technologies on the page, up to 4,000 characters of its text, and Kitsuvo’s own signals. It never includes cookies, form data or passwords. Sign-in pages and local or private network addresses are never sent. The digest goes straight from your computer to the provider, under your own account and that provider’s privacy policy. It does not pass through us. Local only in Settings › Privacy stops all of it.
Kitsuvo Plus key
With Kitsuvo Plus, the same digests go from your computer straight to OpenRouter on a key we issue to you. They do not pass through our servers. OpenRouter shows us usage records for the keys we issue: when a request was made, which model ran, and how much it cost. We use these to run the monthly cap and to prevent abuse. We keep OpenRouter’s prompt logging off for Plus keys, so we do not see the digests themselves.
Automatic updates
Automatic updates are off until you turn them on. When they’re on, Kitsuvo asks kitsuvo.com once a day whether a new version exists, and downloads it from our download storage when one does. Like any download, these requests show your IP address and the time to our hosting provider, Vercel. They carry nothing about your browsing, and no identifier for you or your device. Turn this off in Settings › More › Updates. Local only pauses it too.
The web engine
Kitsuvo loads pages with your system’s web engine: WebView2 on Windows and WKWebView on macOS. The websites you visit receive what any browser sends them, under their own policies. Kitsuvo turns off the engine features that would send the addresses you visit to Microsoft, Google or Apple. A few things stay under your operating system’s control: on Windows, WebView2’s diagnostic data follows your Windows Diagnostic data setting and the engine updates itself through Microsoft; on macOS, crash reports follow Share Mac Analytics, and features you start yourself, such as Writing Tools, follow Apple’s terms.
No telemetry
The app sends us no usage statistics, crash reports or identifiers.
Plugins and browser automation
Kitsuvo’s local MCP plugin lets the AI client you connect operate your installed desktop browser. Automation uses a separate local profile by default and refuses sensitive sign-in pages and password fields. Tool arguments may include URLs and text you ask it to enter. Results returned to the connected client may include personal data in page text, snapshots, reports and supported screenshots. That client handles these results under its own privacy policy.
Navigation contacts the websites you choose. Interactions you request can send entered text to those websites, under their own policies. The local plugin adds no analytics or Kitsuvo-hosted upload service. Separately enabled native cloud verdict providers follow the settings and provider policies described above.
The native agent profile can retain cookies, history, preferences and downloaded files locally until you clear the profile or delete the files. There is no fixed automatic deletion period. Clearing browser data does not remove copies already received by websites or a connected AI client. Installing the plugin does not install the native browser or enable a public cloud service.
Optional cloud MCP relay
The separately started cloud connector forwards selected tool arguments and results, including page snapshots, supported screenshots and detection reports, through a Kitsuvo relay hosted by Fly.io to the MCP client you explicitly authorize. It requires consent in your local terminal and operates an isolated agent profile. It does not upload your normal browsing history or native control credentials. Native sensitive-page restrictions remain enabled.
Connection and authorization state is held temporarily in relay memory. Tool payloads are processed in transit and are not saved in application logs or a page archive. Access tokens expire after ten minutes; rotated refresh tokens expire after one day. Disconnecting the connector or restarting the service revokes its grants. Fly.io handles network connection information as the hosting provider, and the AI client handles the results it receives under its own policy. Close the connector to stop forwarding; deleting local browser data cannot remove copies already received by an authorized client.
Kitsuvo on iOS and Android
The mobile apps use Kitsuvo’s local detector on your device. Page snapshots and reports are not uploaded to us or to a cloud analysis service. Identity-provider pages are excluded, and input values are removed from the snapshot used for analysis. The mobile apps have no Kitsuvo accounts, advertising SDKs, app analytics or cloud analysis integrations.
Bookmarks, normal browsing history and preferences stay on your device. Private visits do not write browsing history. iOS private tabs use a nonpersistent WebKit data store. Android private browsing uses a separate WebView process and data directory; its website data is cleared at session boundaries. Private browsing does not hide activity from websites or networks and does not guarantee that no device traces exist.
Browsing, search and sharing make requests to the websites or apps you choose. iOS uses WKWebView and Android uses Android System WebView. Engine updates, platform diagnostics and security services follow Apple’s or Google’s platform settings and policies. Android Safe Browsing remains enabled. Files are available to a website only when you choose them through the system file picker.
App Store and Google Play downloads, updates, testing feedback, purchase/account records and platform crash reports are handled by those platforms under their own policies. The sandboxed Mac App Store build receives updates through Apple rather than Kitsuvo’s standalone updater.
Browser extensions
The Kitsuvo extension checks known AI-builder fingerprints locally after you choose Scan this page. It does not upload page content, collect telemetry, access cookies, or keep browsing history or page reports. The only saved settings are the search-filter preference and guide version, in local extension storage.
Default permissions let it read the current tab after your action, run its bundled detector, and save those settings. The optional search filter asks for persistent access only to the supported Google.com, Bing, and DuckDuckGo hosts. It reads result links to identify known builder hosting; it never visits a result to inspect it. Turning the filter off removes that optional access. You can reveal hidden results on the search page.
Page scans skip identity-provider sign-in pages, pages with password fields, and private tabs. Inputs and editable content are removed from a detached page copy before local analysis. No cloud AI or native desktop companion is used. Browser-store platforms separately process installation, update, account, and review information under their own policies.
kitsuvo.com
Our website is hosted by Vercel. Like most web servers, it records each request, including your IP address, browser type, the page requested and the time, to deliver the site and keep it secure. Vercel keeps these logs for a limited time under its own policy. The site runs no analytics, advertising or third-party scripts, and sets no cookies. Your browser’s local storage remembers whether you’ve seen the site tour; that never leaves your browser.
Installers and updates are served from Vercel Blob storage, which logs downloads the same way.
Kitsuvo Plus
When you subscribe, Stripe runs the checkout and stores your payment details. We never receive your full card number. Through Stripe we can see your email address, the billing details you enter (such as country and postal code), the type and last four digits of your card, and the history of your subscription and payments. We use this to provide Plus, send receipts, answer support requests and meet tax and accounting obligations.
When checkout finishes, we create an OpenRouter key for you and show it to you once. We don’t store the key. We store only a one-way fingerprint of it on your Stripe subscription, so we can switch it off if payment fails and delete it when your subscription ends.
Service providers
We rely on these companies to run Kitsuvo. Each handles information only to provide its service to us:
- Vercel: hosting for kitsuvo.com, the Plus server, downloads and updates.
- Fly.io: hosting and network transport for the optional cloud MCP relay.
- Stripe: subscription checkout, payments and the customer portal.
- OpenRouter: AI requests made with Kitsuvo Plus keys.
AI providers you connect with your own keys work for you, not for us, under your agreement with them.
How long we keep information
We keep Plus billing records for as long as your subscription lasts, and afterwards for as long as tax and accounting law requires, usually up to seven years. We delete your Plus key when your subscription ends. Server and download logs are kept by Vercel for its standard retention period.
Your choices and rights
You can ask us to access, correct, export or delete the personal information we hold about you, which in practice means your Plus billing records. Email hello@kitsuvo.com. We’ll answer within 30 days. We may need to keep some records that tax law requires us to keep.
If you live in California, you have the rights the California Consumer Privacy Act gives you, including to know, delete and correct personal information, and to opt out of its sale or sharing. We don’t sell or share personal information, and we won’t treat you differently for using these rights. If you live in the European Economic Area or the United Kingdom, you also have the right to object to or restrict our use of your information and to complain to your data protection authority. We use your information to provide the subscription you bought (contract), to keep our services secure (legitimate interests), and to meet legal obligations. Our providers may process information in the United States.
Security
Connections to our services use HTTPS. The app accepts updates only if they are signed with Kitsuvo’s update key. No system is perfectly secure; if we learn of a breach that affects you, we’ll tell you as the law requires.
Children
Kitsuvo Plus is not for children under 13, and we don’t knowingly collect their personal information. If you think a child has given us information, contact us and we’ll delete it.
Changes to this policy
When we change this policy, we update the date at the top. We also note significant changes in the changelog, and email Plus subscribers about changes that affect them.
Contact
Rattana Devs · hello@kitsuvo.com