Khint privacy policy
This document describes what data Khint ("we", "us", "Khint") collects when you use the Khint desktop app (macOS and Windows) and this marketing site, why we collect it, where it lives, and how you can ask us to delete it. It is written to be readable, not to cover us legally. See the working-draft notice at the bottom.
1. Who we are
Khint is operated by KAZOUINI MOHAMED-AMINE, entrepreneur individuel registered in France (SIREN 102 311 560, R.C.S. Paris), based in Paris, France. We act as the data controller for the data described below. Contact: [email protected]. See also our legal notice.
2. What Khint actually does on your machine
Khint is a desktop app: a menu-bar app on macOS and a system-tray app on Windows. It reacts to three keyboard shortcuts:
- ⌘⇧K opens the action palette. Khint reads the text you have selected in the foreground app and sends it, with the prompt of the action you pick, to our inference provider (Anthropic or OpenAI, see §6). The result is pasted back into the same app and logged in a local SQLite database for your action history.
- Palette OCR captures the screen region on-device, then sends the image to our inference provider for text extraction. The extracted text is pasted. The screenshot is not stored beyond that single call.
- Your dictation shortcut is opt-in and has no default binding: nothing listens until you set one in Settings. While you hold or latch that key, the microphone records, and the clip is sent through our backend to Groq for transcription (see §6). The audio is not stored on our side.
Khint does not record your screen, log your keystrokes, or monitor your apps in the background. The only network calls it makes are: (a) the inference call when you trigger an action or a dictation, (b) optional cloud sync when you sign in (see §7), (c) calls to work tools you have explicitly connected (see §6), and (d) auto-update checks.
3. What we collect, and why
From the desktop app, when you trigger an AI action: the selected text and (if a Memory session is active) its compact context summary, sent to our backend, which forwards them to our inference provider to generate the rewrite. We need this to run the action you asked for.
From the desktop app, in your local SQLite database: your action history (input, output, timestamp, action used), your saved agents / Packs / workflows, and your Memory sessions. This stays on your device unless you sign in.
From the desktop app, if you sign in: your Clerk-authenticated identity (email, user id), and your action history, agents, Packs, and workflows are mirrored to our Supabase database so they sync across machines. Memory sessions stay local: they are never synced to our servers.
From the desktop app, usage counts:the app reports which of its features get used, as event names only: that the palette was opened, that an agent or a workflow ran, which screen of the first-launch tour was reached. Never the text you work on, never an agent's name, never a file path. These land in our own database in the EU, through our own API, and no analytics vendor is involved. The tour counters carry no account identifier at all. The rest is on by default and can be switched off in Settings, under General.
From the marketing site: standard hosting logs (IP, user agent, request path) at the DigitalOcean platform layer, plus the ChatGPT Ads measurement pixel. The pixel tells us whether someone who saw a Khint ad went on to download the app, create an account, or subscribe. It records the pages visited on this site and which of those three things happened, along with the identifiers OpenAI uses to match a visit back to an ad click. It runs on this website only: it is not in the Khint app, and it never sees the text you work on. We run no other analytics or marketing tracker.
If you upgrade to a paid plan: Stripe collects your payment details directly. We never see your card number; we only see the resulting subscription status linked to your account.
4. What we do not collect
- We do not capture, screenshot, or record your screen continuously. OCR only runs when you trigger it from the palette.
- We do not log keystrokes, monitor clipboard contents, or introspect what app you are in.
- We do not collect anything from text you have not selected, even when an action is triggered.
- We do not sell, rent, trade, or share your data with anyone outside the sub-processors listed below.
- We do not train any models on your inputs or outputs. Our inference providers do not either (per their API terms).
5. Sub-processors
Khint relies on the following third-party services to operate. Each one only sees the data it needs.
- Anthropic (Claude API, USA) and OpenAI(API, USA): both are inference sub-processors. They receive the selected text, the active session context when an action opts in, and the screenshot when you use Capture; they return the transformed text. In the app the picker shows modes, not vendors: which provider serves Instant or Quality is a routing decision we may change, and the PowerPoint diagram feature runs on Claude. Both providers' commercial API terms forbid training on inputs and outputs.
- Your own AI provider (Lifetime plan): on the Lifetime plan you bring your own API key (Anthropic or OpenAI). Your selected text goes to that provider under your own account and their terms. The key is attached per call, used in memory only, and never stored or logged on our servers. Those calls also produce no usage records on our side.
- Groq(speech-to-text API, USA): only when you use voice dictation (opt-in: it does nothing until you bind a dictation shortcut). The microphone records between the press that starts a dictation and the press that ends it, or for as long as you hold the key if you prefer to hold it. Then the audio clip and a short vocabulary hint (names of your agents and workflows, used to spell technical terms correctly) are sent through Khint's backend to Groq, which returns the transcript. Zero Data Retention is enabled on our Groq account: audio and transcripts are not stored and not used for training. The microphone is never open outside a dictation you started, an on-screen indicator is up for every second it is open, and Khint keeps no server-side copy of the audio.
- OpenAI (advertising measurement, USA): a second, separate role from the inference one above. The measurement pixel on khint.app reports back which of our ads led to a download, a sign-up, or a subscription. It receives the pages you visit on this website, the conversion events listed in section 3, and the identifiers needed to attribute them to an ad click. It receives nothing from the app.
- Clerk (authentication, USA): handles sign-up, sign-in, and session tokens for accounts that opt in to cloud sync. Clerk receives your email and authentication metadata.
- Supabase (Postgres database, EU region): stores the cloud-synced copy of your agents, Packs, and Workflows, plus action-history metadata (action name, timestamp, duration, never the text in or out, which stays on your device). Memory sessions are never synced. Encrypted at rest and accessed only by our backend service key.
- Stripe (billing, USA / Ireland): processes paid subscriptions. Stores card and billing data; we do not.
- DigitalOcean (hosting, USA): serves this marketing site and the Khint backend API. Standard request logs.
6. Work integrations & Google user data (Gmail)
Khint can connect to work tools you already use: Jira, Confluence, Linear, Notion, Slack, and Gmail. Every integration is opt-in: you connect it yourself from the MCP page in the app, and its credentials (API tokens or OAuth tokens) are stored in your operating system's keychain, on your device, never on our servers. Content you pull from a connected tool lands in your local Memory session (local SQLite, never synced to our cloud). Writes (creating an issue, posting a message, drafting an email) go directly from your device to the tool's API. If you switch a tool on under Memory's Knowledge section, Khint builds a full-text index of that tool's content in local SQLite on your device: the index itself never reaches our servers, and switching the source off (or forgetting the integration's credentials) deletes it. When an agent run opts in to Search Knowledge, only the few excerpts matching that run's text are sent along with the AI request, exactly like the session context described above.
Gmail specifically.Connecting Gmail runs Google's OAuth consent flow on your device. Khint requests two scopes: gmail.readonly, used only to pull an email thread or search results into a Memory session when you explicitly ask for it, and gmail.compose, used to create drafts and to send email: every send shows you the recipient, subject, and body and requires your explicit confirmation first. Your Google tokens live in your device keychain; our servers never see or store your tokens or your mailbox content.
Gmail content you pull is stored only in the local database on your device. It is never synced to our cloud, never used for advertising, never sold, and never used to train AI models. If a Memory session is active, pulled content can be reflected in the session's compact summary, which is computed transiently through our backend and our inference provider (see §5) and is not stored server-side. No human at Khint can read your Gmail data.
Khint's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect Gmail at any time with "Forget credentials" on the Gmail card in the app (deletes the tokens from your keychain), or revoke Khint's access from your Google account permissions page. Uninstalling Khint removes the locally stored content.
7. Cloud sync is opt-in
Cloud sync only runs once you sign in inside the desktop app. If you never sign in, none of the data described in §3 leaves your device (with the exception of the per-action call to our inference provider, which is required for the AI action itself). When you sign out, local data stays; only the sync stops.
8. Data retention
Local SQLite data lives on your device until you uninstall Khint or delete the app's storage directory. Cloud-synced data lives in Supabase until you ask us to delete it. Anthropic retains API request data per their commercial policy (typically 30 days of operational logs, no training); the same applies to OpenAI if you selected an OpenAI model.
9. Your rights
If you are in the EU/UK, you have rights under GDPR/UK GDPR: access, rectification, erasure, restriction, portability, and objection. To exercise any of them, email [email protected]. We aim to reply within 30 days. We will not require a special process or fee. You can also lodge a complaint with your local supervisory authority.
You can also: uninstall Khint to wipe the local database; delete cloud-synced data by emailing us (we will automate this once we have more users).
10. International transfers
Anthropic, OpenAI (if selected), Clerk, Stripe, and DigitalOcean are USA-based. Supabase hosts our database in the EU. Where data is transferred outside the EU/UK, we rely on the providers' Standard Contractual Clauses (SCCs) and equivalent safeguards.
11. Children
Khint is not directed at people under 16. We do not knowingly collect personal data from minors.
12. Changes to this policy
We will update the "Last updated" date below when this policy materially changes. For significant changes (new sub-processor categories, data uses), we will also post a notice on our changelog page before the change takes effect, and surface an in-app notice the next time you open Khint.
13. Contact
Questions, concerns, or rights requests: [email protected].
Last updated: 2026-07-22