Kwnx Privacy Notice

This notice explains what Kwnx keeps on your device, what may be processed by DeepAstra, and the choices and rights available to you.

Effective August 9, 2026Last updated August 10, 2026
01

Scope and controller

This notice applies to the Kwnx desktop application, website, console, CLI when released, device services, and related support. DeepAstra LLC, registered in the Sultanate of Oman, is the controller for personal data described here. The wider DeepAstra Privacy Policy also applies.

02

The local-first boundary

Kwnx is designed so that file access, terminal commands, Git operations, browser actions, and tool execution happen through the runtime on your device. The cloud control plane does not execute shell commands and is not a backup or file-hosting service for your project.

Local-first does not mean that nothing leaves your device. Prompts, model context selected for a task, model responses, account data, usage records, and content you intentionally send to a connected service must be transmitted to provide those features. Review permission prompts and connected-service settings carefully.

03

Information we process

  • Account and profile data, such as name, email, organization, role, preferences, and consent choices.
  • Device and session data, such as install and device identifiers, operating system, app version, registered runtime state, authentication events, and security status.
  • Service and usage data, such as model selection, token or credit usage, feature activity, update checks, download/install outcomes, and diagnostic events.
  • Anonymous product telemetry sent to PostHog, including a random installation-scoped identifier, event name, app version, operating system, device architecture, client type, project and thread counts, selected provider or model, and high-level task outcomes. Telemetry events are configured not to create a PostHog person profile and do not include prompt text or project file contents as event properties.
  • Support and feedback data that you choose to submit.
  • Basic website data, such as browser type, requested pages, and security logs. The approximate-country feature works from a coarse country code and does not store your raw IP address.
  • Payment and entitlement records handled through DeepAstra Account and its payment providers when paid services are used.
04

Prompts, model context, and connected tools

To perform an AI task, Kwnx sends the prompt and the context selected or produced for that task through DeepAstra Orchestration and applicable model infrastructure. Context can include source text, command output, diffs, or other project information when needed for the task and permitted by the runtime mode.

In the DeepAstra cloud deployment, if you connect an MCP server, Git provider, Google or Microsoft service, or another app, data needed for the action is sent to that provider under your instruction. Third-party terms and privacy notices apply to their processing. Private on-premises and air-gapped deployments are designed to work without third-party cloud services for full sovereignty.

05

Google and Microsoft cloud connections

These connections apply only to the DeepAstra cloud deployment. Private on-premises and air-gapped deployments are designed to operate without Google, Microsoft, or other third-party cloud services, keeping identity, models, tools, and data inside the customer-controlled environment for full sovereignty.

If you use Google or Microsoft to sign in to the cloud service, the identity flow may provide DeepAstra with your account identifier, name, email address, and profile image so we can authenticate you, create or link your DeepAstra account, secure the session, and provide account support. Kwnx does not receive your provider password.

If you separately connect Google Workspace or a Microsoft service, Kwnx requests only the permissions shown on that provider's consent screen. Depending on the connector and permissions you approve, Kwnx can read, create, edit, organize, or otherwise act on connected content only when you request a visible feature or enable a workflow that requires it.

OAuth tokens for cloud connections are kept server-side in encrypted storage and are not placed in the desktop application. Data returned by a connector can pass through DeepAstra Orchestration and selected model infrastructure to complete your request, and can appear in your Kwnx conversation or other output. That content is then handled under the chat, sync, retention, and deletion terms in this notice.

DeepAstra's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not sell Google user data or use it for advertising, surveillance, credit decisions, or unrelated profiling. Human access is prohibited except with your affirmative permission for specific data, when necessary for security or support, when required by law, or when data is aggregated for permitted internal operations.

06

Chat and device sync

When chat sync or remote viewing is enabled, Kwnx may store a redacted projection of project titles, conversation messages, status, model choice, and activity metadata so you can view work across your devices. Kwnx is designed not to automatically upload project file trees, file bodies, raw commands, tool arguments, sealed reasoning, or artifact bytes for this feature.

Conversation text is an important exception: if you or the assistant includes code, a path, or other project information in a message, that text can sync as part of the conversation. Secret redaction reduces risk but cannot guarantee that ordinary source text or paths are removed.

07

How we use information

  • Provide authentication, device registration, model access, sync, updates, console features, and support.
  • Measure entitlements and usage, process billing, and enforce plan limits.
  • Secure accounts and devices, prevent abuse, investigate incidents, and maintain append-only audit records for security-relevant events.
  • Operate, debug, and improve Kwnx and DeepAstra services.
  • Comply with legal obligations and enforce applicable terms.
08

How information is shared

We do not sell personal data. We share information only as needed with DeepAstra affiliates and vetted service providers; model and orchestration infrastructure; payment, support, security, and analytics providers, including PostHog for product telemetry; connected services you instruct Kwnx to use; competent authorities when legally required; and parties to a business transaction with appropriate safeguards.

Deployment and infrastructure providers depend on the option selected. DeepAstra cloud uses vetted infrastructure and optional third-party services, including connected Google and Microsoft services when you authorize them. Private on-premises and air-gapped deployments are designed without third-party cloud services so identity, models, tools, and data remain inside the customer-controlled boundary. Those deployments are governed by the applicable enterprise agreement.

09

Data location and international transfers

Data location depends on the selected deployment. DeepAstra cloud may process and store data in service regions chosen for availability, security, and compliance. Government and enterprise customers may select a customer-controlled on-premises or air-gapped deployment without third-party cloud services, with agreed residency and full-sovereignty controls. Where an international transfer is necessary for the cloud service, we apply safeguards required by applicable law and agreements.

10

Retention, disconnection, and deletion

We keep personal data only as long as needed for the service, security, legal, tax, audit, and dispute purposes described here. Account data is generally retained for the life of the account and a reasonable period afterward; usage and log data may be retained for up to 24 months; support communications may be retained for up to 36 months; transaction records follow applicable commercial and tax requirements.

Synced Kwnx product data is retained while the feature and account require it or until deletion, subject to backups, security records, and legal obligations. Deleting local files does not automatically delete a message that already synced, and deleting a synced conversation does not delete your local project files.

Cloud users can disconnect Google, Microsoft, or another connected service from Kwnx settings and revoke Kwnx or DeepAstra access from the provider account. Disconnecting deletes or revokes the stored OAuth tokens, but content already copied into a conversation or output follows the normal Kwnx retention rules. To permanently delete your DeepAstra account and personal workspace, use the Data & Privacy controls at account.deepastra.ai/account or contact DeepAstra. On-premises and air-gapped customers manage retention and deletion inside their controlled environment under the applicable agreement.

11

Security

We use administrative, technical, and physical safeguards including encrypted transport, access controls, device-bound sessions, rotating credentials, audit logging, and signed update controls. No system is completely secure; you are responsible for device security, local backups, permission choices, and protecting credentials and secrets.

12

Your choices and rights

  • Manage theme, product preferences, model choices, connected services, runtime permissions, and available consent settings.
  • Disconnect or sign out devices and stop using Kwnx at any time.
  • Request access, correction, erasure, restriction, portability, withdrawal of consent, or objection where provided by Oman's Personal Data Protection Law and other applicable law.
  • Contact DeepAstra to exercise a right. We may verify your identity and retain information where legally required.
13

Children

Kwnx is not directed to people under 18, and we do not knowingly collect their personal data. Contact us if you believe a minor has provided personal data through Kwnx.

14

Changes and contact

We may update this notice as Kwnx evolves. Material changes will be communicated through the product, website, or account contact channel as required by law. For privacy questions or rights requests, use the contact channel at deepastra.ai/contact.