Konfig

Privacy policy

Last updated 9 October 2026
01

Who we are and scope

This Privacy Policy explains how Konfig (“Konfig,” “we,” “us,” or “our”) collects, uses, discloses and retains information when you visit konfig.live, use the Konfig app for macOS, join the waitlist, contact support, or use the planning service the app relies on (together, the “Services”). Konfig is responsible for the personal information described here.

Applications and services that you choose to install, connect or use through Konfig are governed by their own terms and privacy policies.

02

Information we process

Information you give us: your waitlist email, your invite code, and any message you send with Tell support, including screenshots you add.

Your requests. To make a plan, the app sends our planner what you typed, the folder path and type of the project or app the task concerns, the name of the project's manifest file, the list of actions Konfig can take, and facts Konfig read on your Mac that the task needs. Those facts can include short values or excerpts taken from your files or apps, such as a version a project declares, an app's name or its download address. If a step fails, Konfig sends the step's outcome with an error code or short reason, not the command's full output. Anything that looks like a password, key or token is removed before the request reaches the model. Values you type into an approval (for example a project's API key) are written to that project on your Mac and are not sent to us.

Your screen, only when you allow it. For tasks done in a website (today, setting up a Stripe test key), Konfig asks first, then opens one browser window and takes screenshots of that window only, while you work in it. Each screenshot is checked on your Mac before anything is sent: if it shows a key or other secret, it is not sent and Konfig stops looking. Otherwise it is sent to the planner and the AI model to read what is on screen, and is not kept by Konfig, written to disk beyond a moment, or logged. Konfig stops looking before you press a button that creates a secret. A key you hand over goes from your clipboard into your Mac's Keychain; it is checked with the service it belongs to and is never sent to us or to the model.

Usage counts, per day and per tester name: how many requests, how many finished and how many succeeded, the kind of outcome (for example verified, declined or not supported), how many needed a retry and how many of those still succeeded, which of Konfig's built-in actions ran, how long they took, and app and macOS versions. Numbers, outcome kinds and action names only, never what you asked. The app reduces each event to these counts before sending it, and our server applies the same rule again.

Failure records: when a run fails or cannot be verified, the app sends one short record: app and macOS version and chip, which of Konfig's built-in steps stopped and at what stage, the kind of service involved (such as Google), an error category and code, step and retry counts, timings and how much of the AI model the run used. Never what you asked, file or account names, error text or contents. The app reduces it to these fields before sending, and our server applies the same rule again. Nothing is sent before you have seen this notice in the app, and you can turn it off on the app's This Mac page.

Connection information. Our server and the services that carry traffic to it process network addresses and connection details in order to deliver that traffic.

03

How we use information

We use information to provide and operate the Services: to make plans, to deliver updates, to keep the Services secure and prevent misuse, to diagnose failures, to answer support requests, to manage invites and the waitlist, to understand aggregate usage, and to comply with law.

We use aggregated counts that do not identify a person to understand reliability and improve the Services.

04

AI models and service providers

Planning currently uses Anthropic's Claude, reached through a model routing service and served by Amazon Bedrock or Google Cloud. Each request asks the routing service to use only those two providers, only endpoints it lists as zero data retention, and only endpoints that do not collect data. Before sending, our planner checks the routing service's current list of zero-data-retention endpoints and does not send the request if no approved endpoint is on it. After a response, it checks which provider served it and discards the result if it was not one of the two.

Screenshots you allow Konfig to read are sent the same way, under the same checks, and the model provider does not retain them under zero data retention. Zero data retention limits what is kept; it does not mean nothing is sent.

Konfig has no direct agreement with Amazon or Google. How the routing service and these providers handle a request is governed by their own terms and policies, which we do not control.

We do not use your requests, plans, files or support messages to train AI models.

05

What we keep, and for how long

Requests, plans and model responses: not stored by Konfig's server.

Usage counts: until we delete them. They contain no words you typed.

Failure records: 30 days, then deleted automatically (records are kept by day and deleted within a day after that).

Tell support messages: 30 days, then deleted automatically. This includes screenshots you add and, only if you tick Attach my last request, your last request and its plan.

Waitlist email: with the date you joined and whether you were invited, until you ask to be removed. Backup copies are kept on our Mac and in Apple iCloud Drive: a log of every signup, and recent spreadsheet copies of the waitlist, of which we keep the newest 14 and delete older ones periodically. When you ask to be removed, you are removed from the waitlist and from all of those copies; iCloud Drive may keep a deleted copy in its Recently Deleted folder for up to 30 days.

Your invite, this Mac's access token, and the name of the Mac that used the invite: until revoked.

Server logs: the status of each request, the tester name, the name of your Mac when it pairs, and event types, never what you asked. They are replaced when the server is restarted. A log of restarts and health checks, with no request content, is kept until we delete it.

On your Mac: the app keeps its run history, settings and access token in its own folder (the token is readable only by your user account). That history is never uploaded. You can read it, download it from any result, or delete it.

Apart from the waitlist backups described above, our server's data is not backed up. We may keep information longer where the law requires it, to establish or defend legal claims, or to deal with a security incident.

06

Sharing and disclosure

Service providers handle data on our behalf only to run Konfig: hosting the website and carrying its traffic and the app's, running the AI model that makes plans (described under AI models and service providers), measuring visits to the website (described under Website analytics and cookies), and storing the waitlist backups described under What we keep. Each receives only what its service needs. When Konfig installs something, your Mac downloads it directly from its publisher or package source, under their own policies.

We may also disclose information where required by law or legal process, to protect rights, safety or security, to investigate fraud or misuse, or in connection with a merger, acquisition, financing, reorganization or sale of all or part of our business, subject to applicable law.

We do not sell personal information, share it for cross-context behavioral advertising, or rent it to marketers.

07

Website analytics and cookies

konfig.live counts page views with Google Analytics, set up to collect as little as possible: no advertising features, and no cookies unless you allow them below. Without your permission, your browser sends Google only a cookieless signal that a page was viewed (which page, when, and the kind of device). Google uses your network address to estimate your country and does not keep it in Google Analytics. If you join the waitlist, your browser remembers that you did (a single local setting, so the page doesn't ask again); it is never sent to us. Your network address is used briefly in memory to limit abuse of the waitlist form and is not stored.

08

Security

Traffic between the app, the website and our server is encrypted (HTTPS).

Model credentials stay on our server and are never built into the app.

Invite codes work once; access tokens are per Mac and can be revoked.

Updates to Konfig's capabilities are cryptographically signed and checked by the app before use.

The operator tools that show usage counts and support messages are reachable only on the server itself.

No method of transmission or storage is completely secure. You are responsible for protecting your Mac and the run history stored on it. If a security incident affects information we are responsible for, we will respond and give notice as the law requires.

09

Your choices and rights

You can stop using the Services at any time, turn off failure records on the app's This Mac page, decline analytics cookies on konfig.live, and choose what to include in a Tell support message; the app shows you exactly what will be sent first.

You can ask us what we hold about you, to correct it, or to delete it: your waitlist entry, support messages or access. Because our server does not keep your requests, there is nothing about them to export or delete on our side; your history is on your Mac. Depending on where you live, you may have further rights, such as to object to or restrict processing, or to complain to a data-protection authority. We may need to confirm your identity before acting on a request.

10

Age and general audience

Konfig is made for a general audience of adults and is not intended for anyone under 16. We do not knowingly collect personal information from anyone under 16. If you believe someone under 16 has given us information, contact us and we will delete it.

11

International processing

Konfig and the providers named above may process information in countries other than the one where you live. Where the law requires it, we use appropriate safeguards for these transfers.

12

Changes to this policy

If this policy changes, the date at the top will change, and significant changes will be announced in the app. Where the law requires more notice or your consent, we will provide it.

13

Contact

For privacy questions or requests, use Contact on konfig.live or Tell support in the app.