This text is in English. The English version is the one that applies.
DRAFT, to be reviewed by a lawyer. Not legal advice. Written by an AI assistant from the KohAI code and docs.
KohAI privacy notice
Last updated: [DATE OF PUBLICATION] (draft of 3 October 2026)
The short version
- The KohAI app keeps your code, chats, progress and settings on your own computer. It never sends them to us.
- The app talks to us for one thing: your KohAI account (signing in, your plan, and gems you buy).
- Your code and messages go to the AI tool you connected yourself (Claude Code, Codex or Gemini CLI). That company handles them under its own terms, not ours.
- On the website we keep only what you give us: your email for the waitlist or your account.
- We do not sell your data. We use marketing cookies only if you say yes.
Who we are
KohAI is made by [LEGAL NAME], trading as VNP Media, [ADDRESS], the Netherlands, registered with the Dutch Chamber of Commerce (KvK) under number [KVK NUMBER]. We are the "controller" of the personal data in this notice: we decide what is collected and why.
Contact for anything about privacy: [privacy@trykohai.com]. We answer within one month.
We have not appointed a data protection officer, because the law does not require one for what we do. LAWYER: confirm.
1. The KohAI app on your computer
What stays on your computer
KohAI keeps these files in a folder called .kohai in your home folder. They never leave your computer through KohAI:
| What | File | What is in it |
|---|---|---|
| Progress | progress.json, progress.js | Your level, XP, streak, the concepts you practised, your last 200 answers (date, score, which part of the app) |
| Settings | settings.json | Which AI tool you use and your preferences |
| Lessons, weekly tests, review | learn.json, weekly.json and similar | Which lessons you finished and how |
| Wallet | wallet.json | Chests opened, gems earned and spent, items you own and wear, badges |
| Saved chats | chats/ | Your chat cards per project, so you can pick up where you left off. You can turn this off and clear it in Settings |
| Practice drafts | write-drafts.json | The last code you wrote for each practice exercise |
| Pictures you attach | KohAI's own folder | Copies of screenshots you add to a message |
| Crash log | a short log file | The kind of error and where in KohAI it happened, with personal text removed |
| Account | account.json | Your email, name, plan, when it was last checked, and your sign in token, encrypted by your operating system |
Delete the .kohai folder and all of this is gone. Uninstalling KohAI does not remove this folder, so your progress is still there if you install again; delete the folder yourself to remove it. SAM: confirm on a real uninstall; the installer settings in app/package.json do not delete it.
What the app sends to us
Only app/main/account.js in KohAI may use the internet, and only to talk to trykohai.com. It sends:
- When you sign in: your email and password, once. The password is checked and never stored by the app.
- After that: only your sign in token, to ask which plan you have. This happens at most about twice a day, in the background.
- When you look at gems: a request for the gem packs and your bought gem balance.
- When you buy gems: your token, the pack you chose and that you confirmed you are an adult.
- When you sign out: your token, so we can end that session.
The app never sends us your code, file names, changes, chats, prompts, progress, settings or anything you dictate. It has no analytics, no tracking and no crash reporting.
When you create an account or sign in too often, the app may open a small window with Cloudflare's human check (Turnstile). That window talks to Cloudflare, like any website with that check.
Your AI tool
KohAI is not an AI. It starts the AI program you installed and signed in to yourself (Claude Code by Anthropic, Codex by OpenAI or Gemini CLI by Google) on your own computer. Your code, messages, screenshots you attach and the files that tool reads go from that program straight to its company, exactly as when you use it without KohAI. KohAI never sees, stores or passes on your login or API key.
That company is responsible for that data, under its own terms and privacy policy:
- Anthropic: https://www.anthropic.com/legal/privacy
- OpenAI: https://openai.com/policies/privacy-policy
- Google: https://policies.google.com/privacy and the Gemini API terms
Worth knowing: on Google's free (unpaid) Gemini API tier, Google may use your prompts and answers, and may have people read them, to improve its products. Google's terms also say that apps offered to people in the European Economic Area, Switzerland or the United Kingdom may use only the paid tier, so if you live there, use a paid Gemini API key. Do not send code with secrets or other people's personal data through a free tier. Check your own AI tool's settings for whether your chats are used for training.
Speaking instead of typing
When you use the microphone, KohAI turns your voice into text on your computer with a built in open source model (whisper.cpp). The recording is not stored and never sent anywhere. The text then goes into your message like typed text.
Feedback by email
The feedback button opens your own email program with a message to [feedback@trykohai.com] already filled in. Nothing is sent until you press send in your email program. If you send it, we receive your email address and what you wrote.
Tester version
If you take part in testing (tester mode), KohAI keeps a short log on your computer: which screens you opened, lesson scores and times, how long a Build turn took and the kind of error, the steps of the Getting started list, and your answers on the "How did that go?" card, including any comment you type. It never holds prompts, chat text, code, file names, folders or account details.
The log stays on your computer. Nothing is sent by KohAI. Only if you press "Make tester report" and then send that file to us yourself do we receive it. Sending it is your choice. We use it to find where KohAI is hard to use, and we delete it within 12 months of receiving it, or sooner when testing ends. SAM: confirm. Testing is by invitation, for people aged 18 and over. You can delete the log in Settings at any time, and ask us to delete a report you sent.
Legal basis: your consent (you choose to send the report). You can withdraw it by writing to us.
2. The website, trykohai.com
| What | When | Why | Legal basis | Kept for |
|---|---|---|---|---|
| Your level test answers | When you take the test | To work out your level. This happens in your browser; we never receive the answers | None needed, nothing is collected | Until you close the tab |
| Your email, test result, the campaign you came from (utm tags), your marketing cookie choice | When you join the waitlist | To email you when KohAI can be downloaded, and to learn which campaigns work | Your consent | Until you ask us to delete it (every email from the waitlist has a link that deletes your signup at once, with one click), or [24 months] after we last emailed you SAM: decide |
| A scrambled version (hash) of your internet address | When you sign up, create an account, sign in or ask for a reset link | To stop abuse and password guessing | Our legitimate interest in keeping the service safe | Deleted automatically within about two hours |
The site uses Cloudflare Web Analytics to count visits. It sets no cookies and does not follow you across sites. See the cookie notice.
3. Your KohAI account
| What | Why | Legal basis | Kept for |
|---|---|---|---|
| Name and email | To run your account. Your email is how you sign in | Contract (the account you asked for) | Until you delete your account |
| Password, only as a salted, slow hash (PBKDF2). Nobody can read it back | To check it when you sign in | Contract | Until you delete your account or set a new password |
| Plan, account creation date, whether you confirmed your email | To give you the right features | Contract | Until you delete your account |
| Whether you want news by email, and when you said so | To respect your choice | Consent | Until you delete your account |
| The language you want your emails in | To write password, confirmation and purchase emails in your language | Contract | Until you delete your account |
| For each device you are signed in on: a hash of its sign in key, when you signed in and were last active, whether it is the website or the app, and the first 100 characters of its browser or app description | To keep you signed in and stop misuse | Contract and legitimate interest | Until you sign out, or 90 days after you last used it |
| A hash of a one time link for a password reset or email confirmation | To check the link | Contract | 30 minutes, or until it is used |
We do not store your internet address with your account.
Deleting your account. On your account page you can download all data we hold about your account, and delete the account. Deleting wipes your name, email, password and sign in keys at once and signs out every device. An empty record with a random number and dates stays for 30 days and is then removed. Deleting the account does not remove a waitlist signup with the same email; write to us for that.
4. Buying gems [not live yet]
When you buy gems, we keep a record of the purchase: a random id, the pack, the number of gems, the price and currency, the status (pending, paid, refunded, failed), the payment provider's order number and dates. We also keep a ledger of every change to your bought gems.
Why: to give you your gems, handle refunds and support, and keep our books. Legal basis: contract, and our legal duty to keep accounting records.
Kept for: 7 years, because Dutch tax law requires it. If you delete your account, these records stay but no longer point to you: your name and email are wiped, and the records only carry a random number.
Payment is handled by Stripe. We are the seller; Stripe processes the payment and works out the right VAT or sales tax for where you live (Stripe Tax). For that Stripe receives your email, your country and, where needed, your postcode. We never see or store your card or bank details. Stripe also decides some things for itself, for example to prevent fraud and meet its own legal duties; see Stripe's privacy policy.
Tax law asks us to keep evidence of the country where each customer lives. That evidence is kept in Stripe with the payment. LAWYER: check whether we must also keep it ourselves; the KohAI database does not store a country today.
Plans (subscriptions) are not on sale yet. When they are, we keep the same kind of record for each payment, plus the plan, its start and end, and whether it continues. We email you 30 days before a yearly plan's year ends.
5. Who else handles your data
| Company | What for | Data | Where |
|---|---|---|---|
| Cloudflare, Inc. | Hosting the website and account service (Workers), the database (D1), file storage (R2, for example the installer downloads), the human check (Turnstile), cookie free visit counts | Everything stored on the website | Worldwide network; [database region: SAM to fill in from the Cloudflare D1 setting] |
| Meta Platforms Ireland Ltd. | Only if you accept marketing cookies: measuring which ads led to a visit or signup | The Meta pixel cookies. When you join the waitlist after accepting, our server also sends Meta one event: a hash of your email, your internet address, your browser description, the two Meta cookie values and the page address | EU and United States |
| Resend | Sending password reset, email confirmation, purchase confirmation and plan reminder emails | Your email address and the message | United States SAM: check whether Resend offers an EU sending region, and fill in Resend's legal entity |
| Stripe | Taking payment for gems and, later, plans; working out tax (Stripe Tax) | Your email, country and postcode, what you bought, the price; card or bank details go only to Stripe | EU and United States |
Cloudflare and Resend work for us under a data processing agreement. Stripe processes payments for us and also decides for itself on fraud prevention and its own legal duties. For the Meta pixel, Meta and we are joint controllers for collecting and sending the data; Meta is responsible for what it does with it afterwards. LAWYER: check the joint controller wording and Meta's Controller Addendum.
For the human check, Cloudflare reads your internet address, browser description and connection details to tell people from bots, and may also use them to improve its bot detection; see the Turnstile privacy addendum.
We do not sell your personal data, and we do not use it for automated decisions that have legal or similar effects on you.
6. Data outside the European Union
Some of these companies process data outside the European Economic Area, mainly in the United States. Where they do, the transfer is covered by the EU and US Data Privacy Framework where the company is certified, and otherwise by the European Commission's standard contractual clauses. You can ask us for a copy of the safeguards. LAWYER: the Data Privacy Framework is under appeal at the EU Court of Justice (case C-703/25 P); keep the standard contractual clauses in each contract as a fallback.
7. Your rights
You can ask us to:
- show you the personal data we hold about you, and give you a copy
- correct it
- delete it
- limit how we use it
- give it to you in a file you can take elsewhere
- stop using it for something based on our legitimate interest (object)
- stop email marketing, at any time. Every news email has a link that does it with one click; account holders can also switch news off on the account page
You can withdraw your consent at any time. That does not undo what we did before.
Account holders can download and delete their data themselves on the account page. Anyone can write to [privacy@trykohai.com]. We answer within one month. We may ask you to prove who you are first.
You can complain to a data protection authority. In the Netherlands that is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). You can also complain in the country where you live.
8. Age
KohAI is for people aged 18 and over. Some of the AI tools it works with set the same minimum (Claude and the Gemini API: 18). We ask you to confirm your age when you create an account. We do not knowingly collect data from anyone under 18; if you think a child gave us data, write to us and we delete it. SAM: confirm 18 for the public launch; testing is already 18 and over.
9. Security
Passwords are stored only as salted, slow hashes. Sign in keys and links are stored only as hashes. The website uses encrypted connections only. The app keeps its sign in token encrypted by your operating system. If a breach puts your data at risk, we tell the Dutch authority within 72 hours and tell you when the law requires it.
10. If you are in a particular country
United Kingdom. The same rights apply under UK data protection law. You can complain to the Information Commissioner's Office (ico.org.uk). LAWYER: whether a UK representative is needed.
California and other US states. We do not sell personal information. When you accept marketing cookies, the Meta pixel may count as "sharing" for cross context behavioral advertising under California law; you can opt out by declining or withdrawing marketing cookies with the "Cookie settings" link, and we treat a Global Privacy Control signal as an opt out. You have the right to know, delete, correct and not be treated differently for using your rights.
Japan. We handle personal information under the Act on the Protection of Personal Information. Some data is stored with Cloudflare, which may process it in the United States and other countries; the United States has no privacy law the Japanese government treats as equivalent, and Cloudflare protects data under its own agreements and security measures. Purpose of use, our contact point and how to ask for disclosure are in this notice. LAWYER: check the APPI cross border wording.
11. Changes
When we change this notice, we change the date at the top. For important changes we tell account holders by email or in the app before they apply.
Questions about this text? Contact us