Privacy policy
Last updated : 26 juillet 2026
This is a translation provided for convenience. The French version is the legally binding one.
In one sentence: Kestro runs entirely on your machine, with no account and no measurement of what you do with it. We keep the email address linked to your purchase, so that you can recover your key, and the operating system of each installed machine, so that we know which ones to keep supporting.
Who processes your data
The publisher of Kestro, identified in the legal notice, is the controller for the processing described below. For any question, write to [email protected].
The application
Kestro is a desktop application that runs locally. In practice, this means that:
- Your tunnels, projects, services and commands are saved in a file in your user folder. They are not sent anywhere.
- Your credentials and keys are kept in your operating system’s keychain. Kestro only reads them to open a connection from your machine.
- Health checks run from your machine to the addresses you have designated yourself. We know neither the list of them nor their results.
- Tunnels open directly between your machine and your server. No traffic passes through our infrastructure.
- Usage statistics are anonymous: we count how many tunnels are opened, not who opens them. Nothing is written on your machine for this, and no identifier survives closing Kestro — two sessions of yours are, to us, two strangers. What is sent is detailed below.
- Your machine says three things about itself: its operating system and version, its architecture, and the installed version of Kestro. Nothing more, and nothing that points to you. They travel with the licence check, which happens anyway: they add no connection of their own. We use them to know which versions of macOS and Windows to keep supporting, and whether a published update actually gets installed.
- Error reports are on by default: when Kestro breaks, we receive the stack trace, the version and the operating system. That is all, and it is described in detail below. A switch in Settings › Behaviour turns them off, and nothing leaves your machine from that moment on.
The update check, for its part, sends us nothing at all: it downloads the list of published versions, like any other file. It can be turned off in the settings.
The kestro.dev website
This site counts its visits, and nothing else. The measurement is ours and it sets no identifier that would follow you: your IP address is never stored. It is used to compute an irreversible fingerprint, mixed with a random salt that changes every night and which we delete after two days. By the next day, nothing links your visit yesterday to your visit today: not even us, with the database in front of us.
Part of this measurement does go to a third party, and it must be said: we record some visits in order to replay them, so we can see where pages lose their readers. That service is called PostHog, its servers are in the European Union, and it never receives your IP address: recordings travel through this domain, which does not pass it on. Nothing is written in your browser — which is why you still see no banner — so nothing links two visits together. Anything you type into a field is masked, and three pages are never recorded: the thank-you page, the renewal page, and the one that displays your licence key.
What we get out of it fits in one sentence: which pages are read, for how long, how far down, and which ones lead to a download. Nothing identifies you, nothing follows you from one site to another, nothing is cross-referenced with your licence. That is why you still see no consent banner here: there is nothing to consent to.
If your browser asks not to be tracked (the “Do Not Track” setting, or the Global Privacy Control signal) nothing at all is measured. No obligation requires this of us for measurement of this kind; we do it because a product that promises to know nothing about your work would lose more by ignoring that setting than it could ever gain by counting a few visits.
A single cookie exists on this site, and it measures nothing: the currency of the pricing page, kept for one day, so that the amount shows in euros or dollars without flickering.
Some links to this site belong to someone: a person who talks about Kestro gets an address of their own, and we count how many visits come through it. If you download the application from such a link, a short code is copied to your clipboard. The application reads it once, on its very first launch, to know who introduced you to the product — then it clears it. It recognises nothing but that code: anything else in your clipboard is discarded on the spot and never reaches us. For those visits only, we compute a second fingerprint from your IP address, with the same daily salt as above: it exists to recognise the installation that follows the download, and stops being computable after two days.
These measurements are kept for thirteen months, then deleted. Session recordings are kept for thirty days: they exist to fix a page, not to build an archive.
What Kestro sends
Three calls go out unasked, and three only:
- On first launch, to start your trial period. We receive a fingerprint of your machine, a computed, irreversible value that can neither identify you nor trace your computer. It exists solely so that reinstalling does not restart the trial indefinitely.
- When you activate your key, to check that it is valid and to link it to that machine.
- Every six hours, to renew this machine’s right to run. That is what makes releasing a computer from kestro.dev take effect, and what lets a revoked licence stop working. This call carries the machine fingerprint and the three items described above, never anything else. Without a network, Kestro keeps working: the right to run lasts twenty days.
A third one exists, and you can close it: the error report, sent when Kestro breaks, unless you have turned it off in Settings › Behaviour. It contains the stack trace, the version and the operating system. Paths are shortened (your home folder becomes ~) and we explicitly disable memory snapshots, which could carry a passphrase or a token. These reports are processed on our behalf by Sentry, on its European Union servers, and kept for ninety days. Turning the setting off stops everything, at once.
One last one exists, and it is the only one that speaks of what you do: usage statistics. Six events may be sent, and six only: a session opened, a tunnel opened, a project launched, a service added, a share created, a licence activated. Without the name of the host, the project, the service, the file or the command — the list of what may be sent is closed in the code, and the compiler refuses to let free text into it.
What makes them anonymous, and this is not a figure of speech: the identifier that carries them is drawn at random every time Kestro opens, it lives in memory, and it disappears when you close the application. Nothing is written on your machine, nothing links two sessions together, and nothing can be brought near your licence or your machine fingerprint. That is why there is no checkbox and no setting to go looking for: there is nothing to refuse when nothing follows you. These events are processed on our behalf by PostHog, on its European Union servers, which does not receive your IP address.
There is no account, so no password, no session. We know how many sessions open a tunnel, never who, nor towards what, nor what becomes of anyone from one time to the next.
Our hosting provider keeps technical connection logs (IP address, date, page requested) for security and proper operation, in accordance with its own legal obligations.
Buying a licence
When you buy a licence, the payment is processed by Stripe Payments Europe, Ltd., which collects the data needed for the transaction and for invoicing. We neither see nor store your bank details.
On our side, we keep:
| Data | Why | How long |
|---|---|---|
| Email address | To send you your key, and to send it again if you lose it | Until you ask us to delete it |
| Key and related purchase | Support, refunds, accounting obligations | 10 years (legal obligation) |
| Fingerprint of the activated machine | Linking a key to a machine, managing the trial | As long as the key is active |
| Machine’s operating system, version and architecture | Knowing which versions of macOS and Windows to support | As long as the machine checks in |
| Session recordings on this website | Seeing where a page loses its readers | 30 days |
| Anonymous usage events | Knowing which features are used, without knowing by whom | 12 months |
The renewal tells us that a machine is still there, and nothing more: no usage statistics, no list of your tunnels or your projects travels with it. We know an installation exists and which system it runs on. What you do with it arrives by an entirely separate route, as counts, with nothing that would let the two be brought together — it is precisely to keep that impossible that the two share no identifier.
Your rights
Under the General Data Protection Regulation, you have a right of access, rectification, erasure, restriction of processing, objection and data portability in respect of your personal data. A request to [email protected] is enough, and we answer it within 30 days.
To have your address erased, write to us: we remove it, keeping only the invoices the law requires us to hold for ten years. Note that your key will keep working (it lives on your machine), but we will no longer be able to send it to you again if you lose it.
You may also lodge a complaint with the CNIL (cnil.fr).
Changes
If this policy changes, the update date at the top of the page is changed. A change that would affect your rights would be notified to you by email if we have your address.