Skip to content
KernlBeta
FeaturesUse casesIntegrationsPricingSecurityFAQ
Download
Privacy

Privacy and security

Kernl can read your files and drive your browser, so this page sets out what runs where, what leaves your device, and what it will not do without asking you.

Last updated: 19 August 2026

Runs on your machine

The built-in AI, your files, and your history all stay on your computer. Switch the optional reporting off, turn off looking for new versions, and leave approving from another device off, and Kernl makes no network requests at all. You do not have to take our word for that: watch it with your own firewall.

You approve what cannot be undone

Inside the folder you opened it edits files and runs commands without stopping each time. Reaching outside that folder, sending anything off your machine, or a delete that spans the workspace stops and waits for you.

Your keys go straight to the provider

If you connect a cloud account, the request goes from your machine to that company directly. It does not pass through anything of ours, so we cannot log it or store it. The key itself is kept in your computer's own password store.

Where your data goes

What each action does, where it runs, whether Kernl asks first, and whether anything leaves your device.
What you doRuns whereWhere your content goes
Chat with the model on your machineYour machine Nowhere else
Chat with your cloud keyYour AI service That message, straight to the service you chose
Read your filesYour machine Nowhere else
Change or delete your filesYour machine Nowhere else
Run commandsYour machine Nowhere else
Browser automationYour machine The website you opened, the same as if you had opened it yourself
Usage reportingYour machine Counts of what happened, to PostHog. Never your content

"Straight to the service you chose" means the request goes from your computer straight to the cloud AI you chose, using your key. Kernl is never in the path. Use a model on your own machine and none of your content leaves. This table is about where your content goes. What Kernl stops and asks you about before it acts is set out on the security page.

Data Controller

Kernl is developed and operated by Kernl Labs LLC, based in New York, United States. For privacy inquiries, contact privacy@getkernl.ai.

What the Kernl app sends us

Three things, kept separate. None of them contains anything you wrote. Each has its own switch, and that switch is what stops it. Usage counts also stop on their own if your system asks applications not to track you. Health reports are sent by the backend and do not currently read that system setting, and neither kind is stopped by Airplane Mode, which governs what the agent may reach rather than what the app reports. If you want them off, use the switch. The switches live in Settings, Privacy: Product analytics for usage counts, Health reports for the reliability counts the backend sends. The update check has its own switch in Settings, About.

Looking for a new version (on by default)

When Kernl starts it asks our download server whether a newer release exists, before it opens anything of yours. The request carries the version you already have and the kind of computer it is running on, and nothing else. It happens whether or not you have paid, and it is separate from your license: a free copy has no license to check.

Turn it off with the auto-update switch in Settings, About. With that off, Kernl makes no update request at all unless you press the button yourself.

Linking a download to an install

When you download Kernl, this site makes up a short random code, twelve characters long, and puts it in the file name. The app reports that same code once, the first time it starts. That is the only thing connecting the download to the install, and it lets us see whether people who download Kernl actually get it working.

The code is random and refers to nothing. It is not derived from your computer, your address, or anything you did, it is never reused, and by itself it identifies nobody. Nothing you type, no file, and no account detail travels with it. If you would rather it did not happen, the Health reports switch in Settings, Privacy stops the app from sending it, and the code in the file name is inert on its own.

Counts of what happened (on by default)

All of it is counters. Something happened, how often, and roughly how long it took. Nothing you wrote, no file names, no paths, and no tool arguments.

Kernl does not work out where you are: the setting that turns an address into a country and city is switched off, so those fields are empty on everything the app sends. Your address does reach PostHog the way it reaches any server you connect to, and is kept with the event for the same 24 months. If you would rather it were not, the two switches in Settings, Privacy stop the whole stream: Product analytics for what you do in the app, Health reports for what the backend counts.

What gets counted: crashes and quarantines, whether the backend came up, that a part of the app failed to start or had to restart, whether an install or an update failed, that the app was opened and which version on which operating system, that a tool ran and which one, that a turn finished and how it ended, that a message was sent and a reply came back, that a reply or a scheduled task failed, that something you wrote could not be saved, that a model was downloaded or loaded and that a request went to it, how far you got through setup, and that a trial or licence changed.

Also counted: whether the checks Kernl runs before its first start passed, with rough free disk space and graphics memory rather than exact figures, and how many of those checks failed; that Kernl asked your permission and what kind of action it was for; whether you allowed it, refused it, or never answered; that Kernl blocked or paused a tool on its own, which tool it was, and which rule stopped it; that the backend went away while you were working, and whether it came back; that a model was found, brought in from a file, or failed to load, and which model from the built-in list it was, or just the word custom for a file of your own; that you left setup part way through, which step you stopped at, and roughly how long before you came back; which setup option Kernl offered you and which one you picked, and why it was offered, without any detail of your machine beyond whether it found a graphics card; whether signing in to that service finished, and which service it was, never anything you typed there; whether you opened one of the explanations on the setup screen, and which one; which of the example ideas on an empty chat you picked, by its position in the list rather than anything it says; that a file Kernl made was opened or exported, its extension, roughly how big it was, and whether that worked; that you pressed the same button several times and nothing happened, and which part of the app you were in; that a scheduled task ran and how it ended, how it was started, and roughly how long it took; how a message ended, including one that answered nothing or hung, how long before the first words appeared, how long the whole thing took, how many updates arrived, and whether it was a retry; and that the key for a cloud provider started failing, ran out of quota, or began working again, naming the provider but never the key; and that a skill you asked to run would not start, naming the skill pack and the reason it gave, from a fixed list of nine; and how often an answer cites a link it did not open, or credits a folder on your computer that nothing read from, kept as a count next to how many sources it did read, never the links or the folder names themselves. One click turns all of it off.

The detailed set (off until you turn it on, and the app asks once)

Also counters, and we do not collect them unless you say yes: which individual features and settings you touch, which theme you picked, when a session started, the detail behind a turn beyond its outcome, the rating when you press thumbs up or down, which known programs Kernl started while working, which integrations you connected, and the exact tool a permission prompt was for rather than only the kind of action. This list is the full one.

What both sets carry: which operating system and which version of Kernl, your screen size, your language setting, and what kind of graphics card you have including its model name and roughly how much memory it has. Kernl's hardest failures are graphics failures, and without knowing the card we cannot tell whether a crash is one machine or ten thousand.

Neither one ever includes: what you typed, what Kernl replied, the names, paths, or contents of your files, what you passed to a tool, your keys, error text, or anything that names you.

The one place you can send us what you wrote is the feedback box, and only when you open it and press send. That message goes to us word for word, along with your email address if you fill that field in, and the same machine details listed above so we can tell what you were running. Nothing about it is automatic. If you would rather not use it, the box also offers to open your own mail program instead.

How you are identified: by a random string of characters generated on your machine when you install the app. It is not calculated from your computer's name, your hardware, or anything else about you, so it cannot be worked backwards into your identity. Deleting the app's data folder replaces it.

Your licence is identified differently, and only if you buy one. Checking a licence sends the key and a fingerprint of the machine to Keygen, our licensing provider, so the same key cannot run on unlimited computers. That fingerprint is derived from an installation identifier your operating system already keeps. It is deliberately not the same number as the one above and the two cannot be matched to each other, but it is calculated from your machine, so we say so plainly here rather than let the paragraph above imply otherwise. The free version never contacts Keygen.

Who processes it: PostHog (posthog.com), whose servers are in the United States. We only ever look at these as totals, to see which features matter and where the app is failing people.

When you connect an account of your own

If you connect your own account with Claude, GPT, Gemini, or another provider, what you type goes from your machine to that company directly, under their privacy policy. It does not pass through anything of ours, which means we could not log or store it even if we wanted to.

Using the built-in AI with reporting and the version check both switched off, Kernl makes no network requests at all. You can confirm that yourself with a firewall or any tool that shows you what your computer is connecting to.

One exception, and it is one you switch on: approving actions from another device you own. That works by keeping a connection open so the other device can find this computer, so while it is on, Kernl is talking to the network even when you are not using it. Turning it off in Settings stops that immediately. Windows will ask permission the first time, because a program listening for an incoming connection is exactly the thing your firewall is meant to ask about.

Finding your computer from another device uses public infrastructure run by n0, the makers of the connection library we use. The two computers hold the keys, so n0 cannot read what passes between them, but they do see that two devices are talking and roughly where from. That is the price of reaching your machine from outside your own network, and it is why the feature is off until you turn it on. With it off, none of that happens.

This website

  • Server logs: Standard Cloudflare CDN logs (retention per their policy)
  • No tracking cookies
  • No account required
  • Anonymous, cookieless analytics (PostHog, hosted in the US): page views, clicks, and performance timings only, with nothing that identifies you unless you hand us your email address yourself through the form below, and no cross-site tracking. State is kept in your browser's local storage, not cookies. We honor your browser's Do Not Track setting: with it on, the site sends no analytics at all.

If you give us your email address

The only place this site asks for your email is the form that tells you when a new build ships. If you use it, the address is stored in PostHog, the same service that counts page views, as a record with your address on it. We would rather it sat in a dedicated mailing list and it will, but naming the wrong place here would be worse than naming an unglamorous one. We keep it for that purpose and no other. We do not sell it, we do not share it with anyone else, and we do not use it to advertise to you. Every message has an unsubscribe link, and asking us to delete your address removes it.

Every company that can see any of this

This is the complete list. If a company is not on it, nothing of yours reaches it. Most people will only ever touch the first two.

  • Cloudflare serves this website and the download files, so it sees the same request logs any web host sees.
  • PostHog holds the usage counts described above, on servers in the United States, and holds your email address if you gave us one for build announcements.
  • Keygen checks paid licences. It sees the licence key and a fingerprint of the machine using it. The free version never reaches it.
  • Stripe takes the payment if you buy a licence. Your card details go to Stripe and never to us.
  • Clerk signs you in to the account page where you manage a licence you bought. It holds the email address you signed in with.
  • Resend sends the one email that carries your licence key after a purchase.
  • n0 runs the infrastructure that lets another device find your computer, and only while you have approvals from another device switched on.

None of them receive what you type into Kernl, what it replies, or anything from your files, because none of that leaves your machine to begin with.

How long we keep things

Anonymous analytics data is kept for up to 24 months and then deleted. An email address you gave us for build announcements is kept until you unsubscribe or ask us to remove it, whichever comes first. A message you send through the feedback box is kept alongside the analytics data and deleted on the same 24-month schedule, or sooner if you ask. Records tied to a licence you bought are kept as long as the licence is active and for as long afterwards as tax rules require us to.

Data Deletion

  1. Uninstall Kernl
  2. Delete the Kernl data directory

To request deletion of any analytics data associated with your anonymous visitor ID, contact privacy@getkernl.ai.

Your Rights

Disable analytics anytime in Settings. To request deletion of analytics data associated with your visitor ID, email privacy@getkernl.ai. We do not sell or share personal information.

Your California Privacy Rights (CCPA)

If you are a California resident, you have the right to: (1) know what personal information we collect about you, (2) request deletion of your personal information, (3) opt out of the sale or sharing of your personal information. We do not sell or share personal information. To exercise your rights, email privacy@getkernl.ai.

European Privacy Rights (GDPR)

If you are located in the European Economic Area, United Kingdom, or Switzerland, the lawful basis for processing your analytics data is legitimate interest (understanding product usage to improve the service). You have the right to: access your data, rectify inaccuracies, erase your data, restrict processing, data portability, and object to processing. To exercise any of these rights, contact privacy@getkernl.ai. Analytics data is processed by PostHog in the United States under their Data Processing Agreement.

Kernl Labs LLC is in the United States, so any data that does leave your machine is handled there. Where a company on the list above holds data belonging to someone in the EEA, the UK, or Switzerland, that transfer runs on the European Commission's Standard Contractual Clauses, which each of them publishes as part of its own data processing terms.

Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be reflected in the "Last updated" date above. Continued use of Kernl after changes constitutes acceptance.


Questions? privacy@getkernl.ai

Kernl

AI that works on your computer. Independent software, built in New York.

Download for Windows
Community

Product

  • Features
  • Integrations
  • Skills
  • Use cases
  • Pricing
  • Download

Learn

  • Benchmarks
  • Comparisons
  • FAQ
  • About

Trust

  • Security
  • Contact
  • Manage your license

© 2026 Kernl Labs LLC. All rights reserved.

Provided "as is", without warranty. See Terms and Privacy. Trademarks belong to their respective owners.