Sign in

Privacy Policy

Last updated: October 8, 2026 · Effective: October 8, 2026

This Privacy Policy explains what personal data Krot collects, why, how we use and protect it, who we share it with, how long we keep it, and the rights you have. It applies to getkrot.com, the Krot web app (including when installed on your phone), your Krot cloud computer, and our emails and support. Please read it together with our Terms of Service.

Contents

  1. Who we are
  2. The short version
  3. Two kinds of data: account data and your cloud computer
  4. What we collect
  5. How we use it, and our legal bases
  6. Your coding agents and their vendors
  7. Voice dictation
  8. Notifications
  9. Sharing a session with guests
  10. Service providers we use
  11. Other disclosures
  12. When people at Krot can see your data
  13. Where your data is stored and international transfers
  14. How long we keep data
  15. Security
  16. Cookies and similar technologies
  17. Your rights
  18. Additional information for US residents
  19. Additional information for the EEA, UK and Switzerland
  20. Additional information for Israel
  21. Children
  22. No selling, no advertising, no training on your content
  23. Changes to this policy
  24. Contact us

1. Who we are

Krot is operated by Krotapp ("Krot", "we", "us" or "our"). For personal data described in this policy as account data, we are the data controller. You can reach us about anything in this policy at privacy@getkrot.com. Our postal address is available on request at the same address.

Krot is in a private alpha, open by invitation. Some features described here may change as the service develops; when that changes how we handle personal data, we will update this policy as described in section 23.

2. The short version

  • Krot gives you your own always-on cloud computer where coding agents you choose (for example Claude Code, Codex, Cursor or GitHub Copilot) run under your own accounts with their vendors.
  • We collect only what we need to run Krot: your email address and basic account details, information about your cloud computer and sessions so the app can show them, and the minimum technical data needed to keep the service secure.
  • Your full code, files, conversations with agents and agent logins are stored on your cloud computer, not in Krot's account database. To make the session list useful, your cloud computer sends Krot a short plain-text preview of the latest message in each session, as described in section 4.2. Your agents send data to their vendors under your accounts and those vendors' own terms.
  • We never ask for, and our systems are designed never to hold, your Claude, OpenAI, Cursor or GitHub passwords or tokens. Each sign-in happens in the vendor's own flow, on your cloud computer.
  • We do not sell your personal data, we do not use it for advertising, we run no third-party analytics or tracking on getkrot.com, and we do not use your code, files or conversations to train AI models.
  • Our servers are in the European Union (Germany).
  • You can ask us at any time for a copy of your data, to correct it, or to delete your account and your cloud computer.

3. Two kinds of data: account data and your cloud computer

Account data is the information Krot itself needs to run the service: who you are, your invitation, your devices for notifications, and a status summary of your cloud computer, including the short session-list previews described in section 4.2. We decide how this data is used, and we are its controller.

Your cloud computer (sometimes called your "box") is a private, persistent computer we host for you. It holds what you and your agents put there: your projects and code, files you upload, your agents' conversations, files attached in chats, API keys you choose to save, and the logins your agents need. We host and secure this content for you and process it only to provide the service to you, on your instructions. You decide what goes there and what your agents do with it. If your cloud computer contains personal data about other people (for example, a customer list in a project), you are responsible for having a lawful basis to process it there. If you are a business and need a data processing agreement for content on your cloud computer, contact privacy@getkrot.com.

4. What we collect

4.1 Information you give us

  • Waitlist: your email address and when you joined. We use it only to invite you to Krot and to tell you about your invitation.
  • Account and sign-in: your email address; if you sign in with Google, the name and email address Google shares with us for that purpose; the date you joined; when you last signed in or opened the app. Sign-in is by a one-time email link or with Google. Krot is by invitation, so we also keep the list of invited addresses.
  • Your cloud computer's content: everything described in section 3, which you or your agents create or upload.
  • Messages and voice: messages you type or dictate to your agents in Krot chat, and files or photos you attach. These go to your cloud computer and from there to the agent you are talking to (see section 6 and section 7).
  • Saved provider keys: if you save an API key for a model provider on your cloud computer, it is typed on your cloud computer's own page, sent from your browser to your cloud computer only, and stored there in a restricted folder. Krot's account systems record only which providers you have saved a key for, never the key itself.
  • Connected services (MCP): if you add a service in Connections, your cloud computer stores its name, server address, settings and any access tokens or OAuth credentials in a restricted folder on that computer. Krot’s account database does not store these credentials. Your browser sends connection settings and credentials directly to your cloud computer.
  • Communications: what you send us when you contact us for support, feedback or a privacy request.

4.2 Information created when you use Krot

  • Cloud computer status: to show your dashboard, your cloud computer regularly reports to Krot: which agents are installed and signed in (yes or no), the names and states of your sessions and which agent each uses, a plain-text preview of the latest person or agent message in each session (up to 100 characters; this can include personal data, code or paths written in the message), links to sessions in the vendors' own apps, your session settings (such as permissions, auto resume and auto handoff), any usage-limit message an agent showed, how much memory, processing and storage your cloud computer and each session use, how much of your agent plans' usage limits is used (as percentages), whether a chat is currently open, and the email address of each Claude account you have added. This status report does not include full transcripts, project files, tool output or message attachments; the preview can include an excerpt of code written in a message.
  • Activity events: a short history of events such as your cloud computer coming online or restarting, agents signing in or out, session state changes (with session names), and Claude accounts being added or removed (with their email address).
  • Time zone: your browser's time zone, so we can schedule updates to your cloud computer for your night.
  • Notification devices: if you turn on notifications, the push subscription your browser gives us (an address at your browser vendor's push service and encryption keys).
  • Session sharing: if you share a session, the share links you create, their access level and expiry, and the guests who accept them (see section 9).
  • Technical and security data: when your browser or device connects to Krot, our servers and our hosting provider necessarily process your IP address and basic request information. Krot uses IP addresses briefly, in memory, to limit abuse (for example, too many sign-in attempts), and does not store them in its database. Our server logs record errors and certain security events (for example, a refused sign-in attempt, which includes the email address used). Our hosting provider may keep its own technical logs as described in section 14.
  • Browser storage: see section 16.

4.3 Information from others

  • Google: if you choose to sign in with Google, your name and email address.
  • Session owners: if someone shares a session with you, the email address they invite.
  • Your agents' vendors: the vendor apps you connect (for example the Claude app or the ChatGPT app) exchange data with your agents directly. Krot does not receive data from these vendors about you, apart from what your agents show on your cloud computer.

4.4 What we do not collect

  • We do not ask for, and our account systems do not store, your passwords or login tokens for Claude, OpenAI, Cursor, GitHub or any model provider.
  • We do not use third-party analytics, advertising pixels, session recording or fingerprinting on getkrot.com or in the app.
  • We do not knowingly collect special categories of data (such as health or biometric data). Please do not upload such data unless you need it for your project and have a lawful basis to do so.
  • We do not use your voice to identify you.

5. How we use it, and our legal bases

If you are in the European Economic Area, the United Kingdom or Switzerland, data protection law requires us to state the legal basis for each use. We rely on the following:

PurposeDataLegal basis
Inviting you from the waitlistWaitlist emailTaking steps at your request before a contract; your consent, which you can withdraw at any time
Creating your account and signing you inAccount and sign-in dataPerformance of our contract with you
Providing your cloud computer, running your agents and sessions, and storing your contentCloud computer content and statusPerformance of our contract with you
Showing your dashboard, session states and resource useCloud computer status, eventsPerformance of our contract with you
Sending notifications you turned onNotification devices, session names and previewsPerformance of our contract with you
Session sharingShare links, guest emails, acceptancesPerformance of our contract with you (and, for guests, our legitimate interest in providing the feature the owner chose)
Updating your cloud computer at a convenient timeTime zone, activity statePerformance of our contract with you
Security, preventing abuse and fraud, enforcing our TermsTechnical and security data, account data, eventsOur legitimate interests in keeping Krot and its users safe
Support and communicating with you about the service, including important changesAccount data, communicationsPerformance of our contract; our legitimate interests
Improving and fixing Krot (using aggregate status and error information, never your content)Cloud computer status, error logsOur legitimate interests in improving the service
Billing, once paid plans are availablePlan, billing contact, transaction recordsPerformance of our contract; legal obligations (tax and accounting)
Complying with law and responding to lawful requests; establishing, exercising or defending legal claimsAny data, as necessaryLegal obligation; our legitimate interests

Where we rely on legitimate interests, we have balanced them against your rights and you can object (see section 17). Where we rely on consent, you can withdraw it at any time without affecting earlier processing. Providing your email address is necessary to create an account; without it we cannot provide Krot. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.

We will send you service emails (such as sign-in links and important notices). We will only send you marketing emails if you have agreed to receive them or where the law otherwise allows, and every marketing email will let you unsubscribe.

6. Your coding agents and their vendors

Krot hosts the coding agents you choose. It does not provide AI models. Each agent (such as Claude Code from Anthropic, Codex from OpenAI, Cursor from Anysphere, GitHub Copilot from GitHub, or an open-source agent connected to a model provider) runs unmodified on your cloud computer and signs in with your own account or API key, in the vendor's own sign-in flow.

  • When an agent works, it sends your prompts, the files it reads, its tool results and similar content directly from your cloud computer to its vendor, under your account. The vendor processes that data as its own controller, under its own terms and privacy policy, which you accepted when you created your account with it. Krot does not control, and is not responsible for, how vendors process data. We encourage you to read their policies.
  • Some vendors let you follow and drive the same session from their own apps (for example the Claude app's Remote Control, or the ChatGPT app for Codex). Data then flows between your cloud computer and that vendor directly.
  • If you hand off a session to another agent, or turn on auto handoff (which continues a session that stopped at a usage limit on another of your connected accounts or agents), Krot passes a summary of the earlier conversation (up to a fixed length) to the next agent as its first message, at your direction. That agent's vendor then receives it under your account with that vendor.
  • If you enable a connected service (MCP) for a session, your cloud computer sends the agent’s tool requests to that service and returns its replies to the agent. Those requests may contain content from your session or files, depending on the tool used. The service processes the data under your relationship with it and its own terms and privacy policy. Disconnecting a service removes its saved authentication credentials from your cloud computer; removing the connection removes its saved configuration.
  • If your agents use GitHub, they do so with your GitHub login on your cloud computer, and GitHub's terms and privacy statement apply.

7. Voice dictation

When you use the microphone in Krot chat:

  • Usually, your browser's own speech recognition turns your speech into text. Depending on your browser and device, your browser vendor may process the audio (for example, Google for Chrome or Apple for Safari) under its own terms. Krot receives only the resulting text.
  • Where your browser has no speech recognition, the recording (up to a few minutes) is sent from your browser to your cloud computer, which passes it to Krot's own speech-to-text service running on the same infrastructure in Germany. The service returns the text. Our software does not store the recording after transcription, and we do not use recordings to train any model or to identify you.

The resulting text is sent to your agent like any typed message. Dictation is not available to guests in shared sessions.

8. Notifications

If you turn on notifications, Krot sends them through your browser vendor's push service (for example Apple, Google or Mozilla). A notification may contain the session's name, a link to it, and, when an agent finishes, a short excerpt of its reply (up to 220 characters) and the names of up to three files it produced. Notification contents are encrypted end to end between Krot and your device; the push service delivers them but cannot read them. Krot does not store the notification-specific excerpt or file names. Separately, the shorter latest-message preview described in section 4.2 is stored with your cloud computer's status for the session list. You can turn notifications off at any time in the app or in your device settings.

9. Sharing a session with guests

You can share a session with people you choose by link. When you do:

  • We store the link (in a protected form), its access level (view or participate), its expiry, and, if you name one, the guest's email address.
  • Guests sign in to Krot with their email address. We store their account and when they accepted and last opened the share. You can see who has accepted your shares and revoke access at any time.
  • Guests can see the shared conversation, your name or email address as shown on the share, and, if you allow it, files in that conversation. Guests who participate can send messages, which run under your agent's account with its vendor. Guests cannot use your terminal, your workspace or your session controls.
  • If you explicitly allow participating guests to use a session’s connected services, their messages can cause the agent to call those services under your saved authorization.
  • Content a guest has already seen or downloaded cannot be recalled after you revoke access.

As a guest, the session owner controls the shared content and can see your email address and activity on the share.

10. Service providers we use

We use the following service providers (processors) to run Krot. They may process personal data only on our instructions and are bound by confidentiality and data protection obligations.

ProviderWhat they doLocation
Lathe, and its infrastructure provider Hetzner Online GmbHHosting of Krot's servers, database, speech-to-text service and your cloud computer; backupsGermany (Falkenstein)
Our sign-in service (an instance of the open-source Supabase Auth server, run on our hosting infrastructure)Email-link and Google sign-inGermany
ResendDelivery of sign-in emailsUnited States
GoogleSign in with Google, if you choose itUnited States and elsewhere
CloudflareDomain name system (DNS) for getkrot.com; Cloudflare does not proxy or see our web trafficGlobal
PorkbunDomain registration and email forwarding for our addresses at getkrot.comUnited States
Apple, Google, Mozilla push servicesDelivering notifications you turned on (encrypted end to end)Varies by your browser

When paid plans start, we will use a payment provider to process payments; we will name it here before it processes your data. We will update this list when we add or replace a provider that processes personal data. If you would like to be told of changes in advance, write to privacy@getkrot.com.

The AI vendors described in section 6 are not our service providers: you choose and contract with them directly.

11. Other disclosures

We share personal data with others only as described in this policy, or:

  • At your direction, for example when you share a session or connect an agent.
  • For legal reasons, if we believe in good faith that disclosure is required by law, regulation, legal process or an enforceable governmental request; or is necessary to protect the rights, property or safety of Krot, our users or the public, including to prevent fraud, abuse or security threats. Where the law allows, we will tell you about a request for your data before disclosing it, and we will challenge requests we believe are unlawful or overbroad.
  • In a business transaction, such as a merger, acquisition, financing, reorganization or sale of assets, to the parties involved, under confidentiality obligations. If control of your personal data changes, we will tell you and this policy (or one at least as protective) will continue to apply.
  • With your consent, in any other case.

12. When people at Krot can see your data

Krot's administrators can see account data (such as your email address, invitation and the status summary of your cloud computer) to operate the service. Because we host your cloud computer, our administrators and our hosting provider technically have the ability to access it. We access the content of your cloud computer (your code, files and conversations) only:

  • when you ask us to, for example for support;
  • when necessary to keep the service or other users secure, or to investigate a suspected breach of our Terms or of law;
  • to comply with law; or
  • to maintain or repair the service, limited to what is needed.

Access is limited to the people who need it for these purposes. Where we access your content for security or legal reasons, we will tell you unless the law, or a security investigation, prevents us from doing so.

13. Where your data is stored and international transfers

Krot's servers, database and your cloud computer are hosted in Germany, in the European Union. Our team works from outside the EU, including from Israel and the United States, and some of our service providers (listed in section 10) are in the United States. When personal data from the EEA, the UK or Switzerland is accessed from or transferred to another country, we rely on an adequacy decision where one exists (the European Commission has recognized Israel as providing adequate protection), or otherwise on appropriate safeguards such as the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant) or the recipient's certification under the EU-US Data Privacy Framework and its UK and Swiss extensions. You can ask us for more information about these safeguards at privacy@getkrot.com.

Data your agents send to their vendors is transferred by those vendors under their own terms.

14. How long we keep data

  • Account data, cloud computer status (including session-list previews) and activity events: while your account is open. After you ask us to delete your account, or your account is closed, we delete them within 30 days, unless we must keep certain records longer by law or to establish, exercise or defend legal claims.
  • Your cloud computer and its content: while your account is open. When your account ends, you have at least 30 days to retrieve your content (see our Terms); we then delete your cloud computer. Removing a session in the app does not delete its project folder; you can delete files yourself at any time.
  • Backups: our hosting provider keeps backups of our systems and of cloud computers for disaster recovery. Deleted data may remain in backups until they are overwritten in the normal cycle, up to 90 days, during which it is protected and not otherwise used.
  • Waitlist: until you are invited or ask us to remove you. If you are not invited, we will delete your address when the waitlist closes or within 24 months, whichever is earlier.
  • Sign-in links and one-time codes: deleted soon after they expire. Pending sign-ins for shared sessions expire after 24 hours.
  • Notification subscriptions: until you turn notifications off, the subscription stops working, or your account is deleted.
  • Share links and guest records: revocation or expiry ends access but does not automatically delete these records. We retain them while the owner’s account is open and delete them with account data as described above.
  • Server and security logs: for a limited period, generally no longer than 90 days, unless needed to investigate a security incident.
  • Support communications: for as long as needed to handle your request and for up to 24 months afterwards.
  • Billing records, once paid plans start: as long as tax and accounting law requires (typically up to 7 years).

15. Security

We use technical and organizational measures designed to protect personal data against loss, misuse and unauthorized access, including:

  • encryption in transit (HTTPS only, with HTTP Strict Transport Security) for getkrot.com and your cloud computer's addresses;
  • a separate cloud computer for each user, whose agents run as an unprivileged user and never see the secrets that connect your cloud computer to Krot;
  • signed, time-limited requests between Krot and each cloud computer, single-use entry links that expire within a minute, and encryption of the secret that links each cloud computer to Krot;
  • sign-in only through the vendors' own flows for your agents, so Krot's account systems never hold your vendor credentials;
  • access controls on shared sessions, checked on every request;
  • security headers that stop getkrot.com from being embedded by other sites; and
  • limiting the people who can access production systems.

No system is perfectly secure. Krot is a pre-release service, and coding agents can run any code and commands you or they choose on your cloud computer, including code that could expose or delete your data. Please keep backups of important work (for example in a GitHub repository), protect your accounts with strong, unique credentials and two-factor authentication where available, and review what your agents may do without asking. If we become aware of a personal data breach that affects you, we will notify you and the relevant authorities as required by law.

16. Cookies and similar technologies

Krot uses only cookies and browser storage that are strictly necessary to provide the service you ask for, so we do not show a cookie banner. We use no advertising, analytics or tracking cookies.

NameWherePurposeLasts
krotgetkrot.com (cookie)Keeps you signed in30 days, or until you sign out
krot-share-signingetkrot.com (cookie)Completes sign-in when you open a shared session10 minutes
gbxYour cloud computer's address (cookie)Lets your browser into your cloud computer's own pages after Krot hands you over12 hours
App preferences (for example krot.resume, krot.account, file view settings)Your browser's local storageRemembers where you were and your display choicesUntil you clear them
Message drafts (krot.composer.…)Your browser's local storageKeeps a message you have not sent yet, on your device onlyUntil sent or cleared
krot.tzYour browser's session storageYour time zone, sent once to your accountUntil you close the tab

The installed app's service worker only shows notifications; it stores no pages or data. You can delete cookies and site data in your browser settings; you will then be signed out. Because we do not track you, we do not respond differently to "Do Not Track" or Global Privacy Control signals, but we honor them in the sense that no tracking takes place.

17. Your rights

Depending on where you live, you may have the right to:

  • access your personal data and receive a copy;
  • correct inaccurate data;
  • delete your data, including your account and cloud computer;
  • restrict or object to our processing, including processing based on legitimate interests;
  • portability: receive data you gave us in a structured, machine-readable format, or have it sent to another provider (your project files can also be downloaded from the app or kept in your own GitHub repositories);
  • withdraw consent at any time, where we rely on consent; and
  • complain to a data protection authority (see sections 19 and 20).

To exercise any right, email privacy@getkrot.com from the address on your account, or tell us how to reach you. We may need to verify your identity before acting, and we will respond within the time the law requires (generally within one month, which may be extended where the law allows). We do not charge for requests unless they are manifestly unfounded or excessive. You may use an authorized agent where the law allows; we may ask for proof of their authority. We will not treat you differently for exercising your rights.

Some data can also be managed directly in the app: you can disconnect agents and GitHub, remove saved provider keys and added Claude accounts, delete files and sessions, revoke shares and turn off notifications.

18. Additional information for US residents

This section applies to residents of California and of other US states with comprehensive privacy laws, to the extent those laws apply to us.

  • Categories collected in the last 12 months: identifiers (such as email address, name and account identifiers); internet or electronic network activity (such as cloud computer status, events and technical logs); geolocation only at the level of time zone; audio information (dictation, processed as described in section 7); professional or employment-related information only if you put it in your content; and inferences, none. Content on your cloud computer may contain any category you choose to store there.
  • Sources: you, your devices, your cloud computer, Google (if you sign in with Google), and session owners who invite you.
  • Purposes: the business and commercial purposes in section 5.
  • Disclosures: to the service providers in section 10 for business purposes, and as described in section 11.
  • Sale and sharing: we do not sell personal information and do not share it for cross-context behavioral advertising, and have not done so in the last 12 months. We do not knowingly sell or share the personal information of consumers under 16.
  • Sensitive personal information: we do not use or disclose it for purposes that would give rise to a right to limit its use. Login credentials for your agents are kept on your cloud computer, not by Krot.
  • Retention: see section 14.
  • Your rights: to know, access, correct and delete your personal information, and not to be discriminated against for exercising these rights, as described in section 17. If we deny your request, you may appeal by replying to our decision; we will respond within the period the law requires. If we deny your appeal, you can contact your state attorney general.

19. Additional information for the EEA, UK and Switzerland

  • Controller: Krotapp, contactable at privacy@getkrot.com.
  • Representatives: where we are required to appoint a representative in the European Union or the United Kingdom, we will name them here. Until then, please contact us directly at privacy@getkrot.com, and we will respond to you in the same way.
  • Complaints: you have the right to lodge a complaint with the data protection authority in the country where you live or work, or where an alleged infringement took place. In the UK, this is the Information Commissioner's Office. We would appreciate the chance to address your concern first.
  • Legal bases and transfers: see sections 5 and 13.

20. Additional information for Israel

If you are in Israel, the Protection of Privacy Law, 5741-1981, and its regulations apply to our processing of your personal data. You are not legally required to provide personal data, but without an email address we cannot provide Krot. Your data is used for the purposes in section 5 and disclosed only as described in sections 10 and 11. You have the right to review your data and to ask us to correct or delete it, by writing to privacy@getkrot.com. You may also contact the Privacy Protection Authority.

21. Children

Krot is for adults. You must be at least 18 years old to use it, and it is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a person under 18 has given us personal data, contact privacy@getkrot.com and we will delete it and close the account.

22. No selling, no advertising, no training on your content

We do not sell your personal data or your content. We do not use them for advertising or to build advertising profiles. We do not use your code, files, conversations, prompts or voice recordings to train, fine-tune or evaluate AI models, and we do not give them to anyone else for that purpose. The vendors of the agents you use may have their own policies on training; check your settings with each of them.

23. Changes to this policy

We may update this policy as Krot develops or the law changes. We will post the new version on this page with a new "last updated" date. If a change is material, we will tell you in advance, by email or in the app, at least 30 days before it takes effect where reasonably possible. Where the law requires your consent to a change, we will ask for it.

24. Contact us

For privacy questions and requests: privacy@getkrot.com.
For other legal matters: legal@getkrot.com.

Krotapp
Postal address available on request.

Build anywhere with any coding agent.

Product

  • Features
  • How it works
  • Founders plan
  • FAQs

Get started

  • Join the waitlist
  • Sign in

For AI assistants

  • llms.txt
  • Sitemap

Legal

  • Privacy Policy
  • Terms of Service

© 2026 Krot

Your logins stay on your cloud computer. Krot never holds your Claude, OpenAI, Cursor or GitHub credentials.