KohAI privacy notice

The short version

Who we are

KohAI is made by [LEGAL NAME], trading as VNP Media, [ADDRESS], the Netherlands, registered with the Dutch Chamber of Commerce (KvK) under number [KVK NUMBER]. We are the "controller" of the personal data in this notice: we decide what is collected and why.

Contact for anything about privacy: [privacy@trykohai.com]. We answer within one month.

We have not appointed a data protection officer, because the law does not require one for what we do. LAWYER: confirm.

1. The KohAI app on your computer

What stays on your computer

KohAI keeps these files in a folder called .kohai in your home folder. They never leave your computer through KohAI:

WhatFileWhat is in it
Progressprogress.json, progress.jsYour level, XP, streak, the concepts you practised, your last 200 answers (date, score, which part of the app)
Settingssettings.jsonWhich AI tool you use and your preferences
Lessons, weekly tests, reviewlearn.json, weekly.json and similarWhich lessons you finished and how
Walletwallet.jsonChests opened, gems earned and spent, items you own and wear, badges
Saved chatschats/Your chat cards per project, so you can pick up where you left off. You can turn this off and clear it in Settings
Practice draftswrite-drafts.jsonThe last code you wrote for each practice exercise
Pictures you attachKohAI's own folderCopies of screenshots you add to a message
Crash loga short log fileThe kind of error and where in KohAI it happened, with personal text removed
Accountaccount.jsonYour email, name, plan, when it was last checked, and your sign in token, encrypted by your operating system

Delete the .kohai folder and all of this is gone. Uninstalling KohAI does not remove this folder, so your progress is still there if you install again; delete the folder yourself to remove it. SAM: confirm on a real uninstall; the installer settings in app/package.json do not delete it.

What the app sends to us

Only app/main/account.js in KohAI may use the internet, and only to talk to trykohai.com. It sends:

The app never sends us your code, file names, changes, chats, prompts, progress, settings or anything you dictate. It has no analytics, no tracking and no crash reporting.

When you create an account or sign in too often, the app may open a small window with Cloudflare's human check (Turnstile). That window talks to Cloudflare, like any website with that check.

Your AI tool

KohAI is not an AI. It starts the AI program you installed and signed in to yourself (Claude Code by Anthropic, Codex by OpenAI or Gemini CLI by Google) on your own computer. Your code, messages, screenshots you attach and the files that tool reads go from that program straight to its company, exactly as when you use it without KohAI. KohAI never sees, stores or passes on your login or API key.

That company is responsible for that data, under its own terms and privacy policy:

Worth knowing: on Google's free (unpaid) Gemini API tier, Google may use your prompts and answers, and may have people read them, to improve its products. Google's terms also say that apps offered to people in the European Economic Area, Switzerland or the United Kingdom may use only the paid tier, so if you live there, use a paid Gemini API key. Do not send code with secrets or other people's personal data through a free tier. Check your own AI tool's settings for whether your chats are used for training.

Speaking instead of typing

When you use the microphone, KohAI turns your voice into text on your computer with a built in open source model (whisper.cpp). The recording is not stored and never sent anywhere. The text then goes into your message like typed text.

Feedback by email

The feedback button opens your own email program with a message to [feedback@trykohai.com] already filled in. Nothing is sent until you press send in your email program. If you send it, we receive your email address and what you wrote.

Tester version

If you take part in testing (tester mode), KohAI keeps a short log on your computer: which screens you opened, lesson scores and times, how long a Build turn took and the kind of error, the steps of the Getting started list, and your answers on the "How did that go?" card, including any comment you type. It never holds prompts, chat text, code, file names, folders or account details.

The log stays on your computer. Nothing is sent by KohAI. Only if you press "Make tester report" and then send that file to us yourself do we receive it. Sending it is your choice. We use it to find where KohAI is hard to use, and we delete it within 12 months of receiving it, or sooner when testing ends. SAM: confirm. Testing is by invitation, for people aged 18 and over. You can delete the log in Settings at any time, and ask us to delete a report you sent.

Legal basis: your consent (you choose to send the report). You can withdraw it by writing to us.

2. The website, trykohai.com

WhatWhenWhyLegal basisKept for
Your level test answersWhen you take the testTo work out your level. This happens in your browser; we never receive the answersNone needed, nothing is collectedUntil you close the tab
Your email, test result, the campaign you came from (utm tags), your marketing cookie choiceWhen you join the waitlistTo email you when KohAI can be downloaded, and to learn which campaigns workYour consentUntil you ask us to delete it (every email from the waitlist has a link that deletes your signup at once, with one click), or [24 months] after we last emailed you SAM: decide
A scrambled version (hash) of your internet addressWhen you sign up, create an account, sign in or ask for a reset linkTo stop abuse and password guessingOur legitimate interest in keeping the service safeDeleted automatically within about two hours

The site uses Cloudflare Web Analytics to count visits. It sets no cookies and does not follow you across sites. See the cookie notice.

3. Your KohAI account

WhatWhyLegal basisKept for
Name and emailTo run your account. Your email is how you sign inContract (the account you asked for)Until you delete your account
Password, only as a salted, slow hash (PBKDF2). Nobody can read it backTo check it when you sign inContractUntil you delete your account or set a new password
Plan, account creation date, whether you confirmed your emailTo give you the right featuresContractUntil you delete your account
Whether you want news by email, and when you said soTo respect your choiceConsentUntil you delete your account
The language you want your emails inTo write password, confirmation and purchase emails in your languageContractUntil you delete your account
For each device you are signed in on: a hash of its sign in key, when you signed in and were last active, whether it is the website or the app, and the first 100 characters of its browser or app descriptionTo keep you signed in and stop misuseContract and legitimate interestUntil you sign out, or 90 days after you last used it
A hash of a one time link for a password reset or email confirmationTo check the linkContract30 minutes, or until it is used

We do not store your internet address with your account.

Deleting your account. On your account page you can download all data we hold about your account, and delete the account. Deleting wipes your name, email, password and sign in keys at once and signs out every device. An empty record with a random number and dates stays for 30 days and is then removed. Deleting the account does not remove a waitlist signup with the same email; write to us for that.

4. Buying gems [not live yet]

When you buy gems, we keep a record of the purchase: a random id, the pack, the number of gems, the price and currency, the status (pending, paid, refunded, failed), the payment provider's order number and dates. We also keep a ledger of every change to your bought gems.

Why: to give you your gems, handle refunds and support, and keep our books. Legal basis: contract, and our legal duty to keep accounting records.

Kept for: 7 years, because Dutch tax law requires it. If you delete your account, these records stay but no longer point to you: your name and email are wiped, and the records only carry a random number.

Payment is handled by Stripe. We are the seller; Stripe processes the payment and works out the right VAT or sales tax for where you live (Stripe Tax). For that Stripe receives your email, your country and, where needed, your postcode. We never see or store your card or bank details. Stripe also decides some things for itself, for example to prevent fraud and meet its own legal duties; see Stripe's privacy policy.

Tax law asks us to keep evidence of the country where each customer lives. That evidence is kept in Stripe with the payment. LAWYER: check whether we must also keep it ourselves; the KohAI database does not store a country today.

Plans (subscriptions) are not on sale yet. When they are, we keep the same kind of record for each payment, plus the plan, its start and end, and whether it continues. We email you 30 days before a yearly plan's year ends.

5. Who else handles your data

CompanyWhat forDataWhere
Cloudflare, Inc.Hosting the website and account service (Workers), the database (D1), file storage (R2, for example the installer downloads), the human check (Turnstile), cookie free visit countsEverything stored on the websiteWorldwide network; [database region: SAM to fill in from the Cloudflare D1 setting]
Meta Platforms Ireland Ltd.Only if you accept marketing cookies: measuring which ads led to a visit or signupThe Meta pixel cookies. When you join the waitlist after accepting, our server also sends Meta one event: a hash of your email, your internet address, your browser description, the two Meta cookie values and the page addressEU and United States
ResendSending password reset, email confirmation, purchase confirmation and plan reminder emailsYour email address and the messageUnited States SAM: check whether Resend offers an EU sending region, and fill in Resend's legal entity
StripeTaking payment for gems and, later, plans; working out tax (Stripe Tax)Your email, country and postcode, what you bought, the price; card or bank details go only to StripeEU and United States

Cloudflare and Resend work for us under a data processing agreement. Stripe processes payments for us and also decides for itself on fraud prevention and its own legal duties. For the Meta pixel, Meta and we are joint controllers for collecting and sending the data; Meta is responsible for what it does with it afterwards. LAWYER: check the joint controller wording and Meta's Controller Addendum.

For the human check, Cloudflare reads your internet address, browser description and connection details to tell people from bots, and may also use them to improve its bot detection; see the Turnstile privacy addendum.

We do not sell your personal data, and we do not use it for automated decisions that have legal or similar effects on you.

6. Data outside the European Union

Some of these companies process data outside the European Economic Area, mainly in the United States. Where they do, the transfer is covered by the EU and US Data Privacy Framework where the company is certified, and otherwise by the European Commission's standard contractual clauses. You can ask us for a copy of the safeguards. LAWYER: the Data Privacy Framework is under appeal at the EU Court of Justice (case C-703/25 P); keep the standard contractual clauses in each contract as a fallback.

7. Your rights

You can ask us to:

You can withdraw your consent at any time. That does not undo what we did before.

Account holders can download and delete their data themselves on the account page. Anyone can write to [privacy@trykohai.com]. We answer within one month. We may ask you to prove who you are first.

You can complain to a data protection authority. In the Netherlands that is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). You can also complain in the country where you live.

8. Age

KohAI is for people aged 18 and over. Some of the AI tools it works with set the same minimum (Claude and the Gemini API: 18). We ask you to confirm your age when you create an account. We do not knowingly collect data from anyone under 18; if you think a child gave us data, write to us and we delete it. SAM: confirm 18 for the public launch; testing is already 18 and over.

9. Security

Passwords are stored only as salted, slow hashes. Sign in keys and links are stored only as hashes. The website uses encrypted connections only. The app keeps its sign in token encrypted by your operating system. If a breach puts your data at risk, we tell the Dutch authority within 72 hours and tell you when the law requires it.

10. If you are in a particular country

United Kingdom. The same rights apply under UK data protection law. You can complain to the Information Commissioner's Office (ico.org.uk). LAWYER: whether a UK representative is needed.

California and other US states. We do not sell personal information. When you accept marketing cookies, the Meta pixel may count as "sharing" for cross context behavioral advertising under California law; you can opt out by declining or withdrawing marketing cookies with the "Cookie settings" link, and we treat a Global Privacy Control signal as an opt out. You have the right to know, delete, correct and not be treated differently for using your rights.

Japan. We handle personal information under the Act on the Protection of Personal Information. Some data is stored with Cloudflare, which may process it in the United States and other countries; the United States has no privacy law the Japanese government treats as equivalent, and Cloudflare protects data under its own agreements and security measures. Purpose of use, our contact point and how to ask for disclosure are in this notice. LAWYER: check the APPI cross border wording.

11. Changes

When we change this notice, we change the date at the top. For important changes we tell account holders by email or in the app before they apply.