Privacy Policy
Last updated: 2026-04-26
KULVEX is built on a simple principle: your data lives on your server, not ours. The system is designed to run entirely on hardware you control. This policy explains what stays local, what leaves your machine when you opt into cloud features, and what rights you have over your data.
1. What KULVEX is
2. Data that stays on your server (always)
- Chat history with all agents (channels: web, Signal, WhatsApp, Telegram, etc.)
- Agent definitions, custom prompts, learned rules, style profiles
- Long-term memory contents (mempalace database)
- Voice recordings, image outputs, file uploads
- Smart-home state, camera footage, sensor data
- Mempalace embeddings, vector indexes, tool call logs
- Local model weights and inference state
3. Data sent to third parties (strictly limited)
3.1 License validation (required for paid licenses)
- Your license key
- A hardware fingerprint (CPU/MAC-derived hash, not personally identifying)
- The KULVEX version installed
3.2 Payments (Stripe)
3.3 External Learning (the Correction Engine — opt-in)
This feature is OFF by default for every agent. You enable it per agent in the Agent Builder. Before the first time you turn it on, KULVEX shows a confirmation dialog that summarises this section.
When External Learning is ON for an agent, the following data leaves your server and is sent to the external provider you configured:
- Excerpts of recent chat history for that agent (up to ~30 turns at a time)
- The agent's system prompt and instructions
- The agent's name and ID
- Filter-event metadata (samples of leaked text caught by the runtime sanitiser)
The external provider then receives, processes, and (per their own retention policy) may store this data on their infrastructure. KULVEX has no control over what the provider does with the content — that's governed by their privacy policy:
If you have conversations containing sensitive information — personal identifiable data, financial records, medical details, trade secrets, third parties' personal data without their consent, or anything covered by GDPR/HIPAA-style regulations — we strongly recommend you do NOT enable External Learning for those agents. Use it only for casual or public-facing agents.
Toggling External Learning OFF stops all outbound transmission for that agent immediately. Past data already sent to the provider remains subject to their retention policy.
4. Channel integrations (Signal, WhatsApp, Telegram, etc.)
5. Cookies, telemetry, analytics
6. Your rights
- Access: all data is in MongoDB / SQLite on your server. You can query, export, or inspect it directly.
- Deletion: uninstalling KULVEX or wiping the database removes everything. Per-conversation deletion is available in the chat UI.
- Portability: agent definitions and chat logs are plain JSON / SQLite — no proprietary formats.
- Opt-out of cloud features: any toggle you flipped ON can be flipped back OFF at any time.
- License/account data: contact KULVEX support to delete your license record from the licensing server. Note this revokes future updates and re-activation rights.
7. Children
8. Changes to this policy
9. Contact
Note: This is a v1 of the privacy policy. It will be revised by legal review before the v1.0 commercial release. If you spot inaccuracies or have questions about how a specific feature handles data, please reach out at the contact above.