Privacy policy
In short
- Your notes, todos, bookmarks and other content are stored as files in your own GitHub repositories. kaihuman has no server that stores your content.
- The apps talk directly to GitHub from your browser or computer, using your GitHub access token. The token stays on your device.
- There are no analytics, no tracking and no advertising, and nothing is sold.
Who is responsible
kaihuman is operated by Adam Urban, a private individual. For anything about privacy, write to [email protected].
What this policy covers
The website kaihuman.com, the web console at app.kaihuman.com, the kaihuman browser extension, the desktop palette and the command-line tool (CLI).
Signing in with GitHub
You sign in with GitHub. A small sign-in service exchanges the one-time code from GitHub for an access token and hands it straight back to your browser. It does not store the token or your content. GitHub shows you which access kaihuman asks for before you agree; the apps need read and write access to the repository you use with kaihuman.
You can revoke the access at any time in your GitHub settings under Applications.
What is stored where
In your GitHub repositories
Everything you create: notes, todos, logs, bookmarks, read-later items, knowledge-base entries and settings. GitHub stores it under GitHub's privacy statement. You can read, change, export or delete it directly on GitHub.
On your device
- Web console: the access token and your selected repository in the browser's local storage, and a cache of your GitHub profile and files in the browser's IndexedDB. Signing out removes the token.
- Browser extension: the access token, the selected repository and caches (bookmarks, usage counts, today view) in the extension's local storage. The extension receives the token only from the console at app.kaihuman.com.
- Desktop palette: the access token and an optional DeepL key in your operating system's keyring; settings and caches in your user configuration folders.
- CLI: the access token and a copy of your repository in your user configuration folder.
What the browser extension reads
The extension has no standing access to the websites you visit. It loads into a tab only when you act on it there — the keyboard shortcut, the toolbar button or the right-click menu — and it reads a page only then: when you save the page to read later or to your knowledge base, it takes the page's title, address, main text and, if you allow it, its images, and writes them to your repository. It does not collect your browsing history. Access to your browser bookmarks is requested only when you import them.
Services you can choose to use
- Translation: if you set your own DeepL API key, the text you translate is sent to DeepL under DeepL's terms.
- AI providers: the CLI can pass a prompt to an AI command-line tool you have installed yourself (for example Claude, Copilot or Gemini). That tool's provider handles the prompt under its own terms.
- Push reminders: if you turn on reminders, your browser's push subscription is stored in your repository, and a GitHub Actions workflow in your repository sends the reminders through your browser vendor's push service.
Hosting
kaihuman.com and app.kaihuman.com are static websites hosted by Cloudflare, which processes technical request data such as IP addresses to deliver and protect them. This website loads its fonts from Google Fonts, which receives your IP address when the page loads.
Your rights
Your content is in your repositories, so you control it fully. If you are in the EU or UK, you also have the right to access, correct, delete or export personal data, to restrict or object to its processing, and to complain to a data protection authority. Write to [email protected] to exercise them.
Changes
When this policy changes, the new version is published here with a new effective date. The history of this page is public in the kaihuman source repository.