Privacy

This page says what Kaho keeps about you, why, for how long, and how to have it deleted. It covers the Kaho app, the Kaho account you sign in to with Google, and Kaho Storage. Last changed 9 October 2026.

Your Kaho Account

When you sign in with Google, Kaho asks Google only for your identity (openid) and your email address (email). It never sees your Google password, contacts, files or anything else in your Google account.

Data Shape Purpose
Google account ID and email address The stable ID Google gives your account, and the email address it reports, updated when you sign in. Signs you in as the same person each time, and is where we write to you about your account, such as a notice that stored files will be deleted.
Sign-in times When your account was made and when you last signed in. Account administration and security.
Sessions and devices For each device signed in: its name (the computer's host name), its operating system family, and when its session began, was last used and ends. Each device keeps its refresh token in its operating system's credential store; the server keeps only a hash of it. Keeps you signed in, and lists your devices in the app so you can sign any of them out.

Kaho Storage

Kaho Storage keeps the files you upload so you can open them on any device you sign in on. Your files are yours: we do not read them, share them, sell them, or use them to train anything. Nobody can open them through a public link.

Data Shape Purpose
File contents The bytes of each file you upload, kept in Cloudflare R2 with a Western Europe location hint, under keys that name neither the file nor its contents. Stores your files and gives them back to you.
File and folder names Each file's and folder's name and place, size, modification time, SHA-256 digest, and when it was moved to the Trash. Shows your folders in the app, keeps your devices in step, and checks every download is the file you uploaded.
Copies on your devices The app keeps a list of your files' names and, for files you open, a cache of up to 5 GB, in its own folder on your device. Signing out removes both. Lists your folders quickly and opens files without downloading them again.
Corruption reports When a download fails its check, the app reports which file and which stored copy, never its contents. Lets us find and repair a damaged copy.

Billing

Stripe takes payments for Kaho Storage plans. Your card details go to Stripe, never to Kaho, and Stripe's own privacy policy covers what you give it. Kaho keeps your Stripe customer and subscription identifiers, which plan you have and between which dates, and the events Stripe sends about them, to know which plan your account has. Records of charges are kept as long as tax law requires.

How Long It Is Kept

When What happens
While you have a plan Your files are kept. Files you move to the Trash are deleted 30 days later.
When a plan ends You keep full access for 48 hours. Then your files are read-only for 90 days: you can open, download, move, rename and delete them, but not add to them. Buying a plan again restores everything.
Before files are deleted We email the account's owners, at least 30 days before deletion, the day the files will be deleted. Nothing is deleted until that email has been sent.
After deletion A deleted file can no longer be reached through Kaho at once, and its bytes leave Cloudflare R2 about a week later. One exception: small files are stored packed together, and a small file deleted from a pack whose other files you keep stays inside that pack, out of anyone's reach, until the pack is rewritten. When all of an account's files are deleted, everything leaves R2 within about a week. Database backups, which hold names and sizes but no file contents, keep deleted records for up to 30 days.
Your account Kept while you use it, until you ask us to delete it.

Asking Us To Delete It

To have your files and your account deleted, write to [email protected] from the email address you sign in with. We reply to confirm, then delete your stored files and close your account within 30 days, signing out every device. Backups age out 30 days after that. We keep records of charges as tax law requires. You can download your files first with Download To… in the app.

Who Processes It

Service What it does for Kaho
Google Sign-in; sending account email from a kaho.ai mailbox; encrypted database backups in its Paris region; service monitoring.
Cloudflare Stores file contents in R2; serves kaho.ai.
OVHcloud Runs Kaho's servers and database, in France.
Stripe Takes payments.
Sentry Crash reports, as described below.

Crash Reporting

Kaho uses Sentry for crash debugging. Sentry helps us see whether the app launched successfully and gives us native crash reports when the desktop app fails.

The Kaho crash reporting code is configured to avoid app content, opened document contents, prompts, screenshots, and precise location. Kaho sets an anonymous install ID for grouping reports from the same installation, but it does not set a user name, email address, or user IP address field.

Data Sent On App Startup

Data Shape Purpose
Anonymous install ID A locally generated UUID sent as Sentry user.id. No user name, email, or IP address is set by Kaho. Groups launch and crash data from one installation without asking for personal account details.
Release and build SENTRY_RELEASE plus tags for platform, arch, and build_config. Shows which Kaho version, operating system family, CPU architecture, and build produced the event.
Kaho telemetry tags app=kaho, privacy=light, and telemetry_schema=1. Separates Kaho events from other Sentry data and records the privacy schema used for the payload.
Privacy context anonymous_install_id=true, content=false, file_paths=false, precise_location=false, raw_ip=false, and country=server_aggregate_only. Makes the intended data limits explicit on the event scope.
Launch metric Metric kaho.app.launch with value 1 and attributes schema=1, event=launch, and privacy=light. Counts launches so we can tell whether a release is actually starting for users.
Sentry session tracking Sentry native session lifecycle data tied to the same release and build metadata. On app close, Kaho also sends metric kaho.app.session_duration_bucket with value 1, attributes schema=1, event=session_end, privacy=light, and bucketed duration <10s, 10s-1m, 1m-5m, 5m-30m, 30m-2h, or 2h+. Lets Sentry classify launches, clean exits, crashed sessions, and approximate session length without sending exact usage duration.

Data Sent On Crash Dumps

Data Shape Purpose
Native crash dump Crashpad minidump data such as exception or signal details, crashing thread state, thread stacks, CPU register state, loaded binary/module metadata, and debug identifiers. Lets Sentry symbolicate the crash and show the failing native code path.
Release, build, and anonymous install ID The same SENTRY_RELEASE, platform, arch, build_config, and anonymous user.id configured at startup. Groups crashes by app version and installation so repeated crashes can be diagnosed.
Privacy context The same privacy flags used at startup: no app content, no opened file paths from Kaho, no precise location, and no user IP address field set by Kaho. Keeps the crash event scoped to debugging metadata rather than user documents or work content.
GPU tags When graphics initialization succeeds: gpu_api, gpu_vendor, and gpu_device_type. Separates crashes by graphics backend and broad GPU class.
GPU context Vulkan reports device name/model, vendor and device IDs, device type, driver/API versions, and device-local memory. Metal reports device name/model, registry ID, Apple vendor IDs, device type, memory, unified memory, low-power, and removable flags. Helps diagnose renderer crashes that depend on a specific GPU, driver, or memory configuration.
Crashed session state Sentry native session tracking marks the active session as crashed. Shows crash-free session health for a release.