Skip to content
Kestrellocal work agentBack to product

Privacy boundary

Your context is not the product.

Kestrel keeps work local by default, identifies every deliberate external route, and gives you controls to disconnect and delete.

Last updated July 23, 2026
01

What stays on your device

Kestrel is designed around local storage. Project context, conversations, approvals, event-application drafts, configuration, and remembered context are stored on the device running Kestrel unless you deliberately connect an external service.

Sensitive stored fields are encrypted. Managed credentials use the operating system’s protected credential storage and are not exposed to the desktop renderer.

02

When data leaves the device

Data leaves the device only when a feature needs a service you selected. The destination and purpose depend on that connection.

  • A cloud model provider receives the prompt context needed to answer the request.
  • OAuth-connected services receive only the requests made through their approved scopes.
  • An optional memory or observability provider receives only the categories enabled in its settings.
  • An optional operator-supplied paired-node extension exchanges authenticated commands, bounded results, and privacy-preserving presence with your configured gateway.
  • An event or hackathon website receives information only when you approve browser-assisted submission.
03

Credentials and account access

Kestrel does not ask you to paste browser cookies or OAuth refresh tokens into chat. API keys are write-only after entry. OAuth uses the provider’s external authorization page, and access can be disconnected from Kestrel or revoked with the provider.

The local model path can operate without a cloud-model account. Installing it requires an explicit automatic-setup action or the separate manual setup path.

04

Paired-node extensions

Kestrel does not ship a mobile application. Its authenticated gateway exposes a bounded protocol that separately developed paired-node extensions may use for Talk, wake phrases, or permission-gated location.

The protocol's presence record excludes coordinates, foreground applications, window titles, input events, and IP addresses. The operator of an external node is responsible for its platform permissions and privacy disclosures.

05

Diagnostics and analytics

Kestrel does not enable product analytics or advertising tracking by default. Optional OTLP or Prometheus diagnostics are operator-configured and exclude prompt content, credentials, and personal memory by design.

The marketing website does not need an agent endpoint and does not run the desktop application in the browser.

06

Your controls

  • Inspect, correct, or delete remembered context from the application.
  • Disconnect providers and paired-node extensions and revoke their credentials.
  • Remove individual event-application drafts and local artifacts through their product controls.
  • Reset local application data using the documented recovery path.
  • Revoke OAuth access directly with the connected provider.
07

Retention, transfers, and children

Local data remains until you delete it or remove the application data. External providers apply their own retention and transfer terms; review those terms before connecting them.

Kestrel is a general work tool and is not directed to children. It does not sell personal information or use personal information for cross-context behavioral advertising.

08

Policy changes and contact

Material changes will be reflected on this page with a new date. Kestrel publishes Kestrel and receives privacy and deletion requests at arnavsri993@gmail.com.

Kestrel

Local-first by architecture. Consequential actions stay visible.

PrivacySupport