Privacy policy
Last updated : 26 juillet 2026
This is a translation provided for convenience. The French version is the legally binding one.
In one sentence: Kestro runs entirely on your machine, with no account and no measurement of what you do with it. We keep the email address linked to your purchase, so that you can recover your key, and the operating system of each installed machine, so that we know which ones to keep supporting.
Who processes your data
The publisher of Kestro, identified in the legal notice, is the controller for the processing described below. For any question, write to [email protected].
The application
Kestro is a desktop application that runs locally. In practice, this means that:
- Your tunnels, projects, services and commands are saved in a file in your user folder. They are not sent anywhere.
- Your credentials and keys are kept in your operating system’s keychain. Kestro only reads them to open a connection from your machine.
- Health checks run from your machine to the addresses you have designated yourself. We know neither the list of them nor their results.
- Tunnels open directly between your machine and your server. No traffic passes through our infrastructure.
- No usage statistics are sent. We do not know what you open, nor when, nor how often.
- Your machine says three things about itself: its operating system and version, its architecture, and the installed version of Kestro. Nothing more, and nothing that points to you. They travel with the licence check, which happens anyway: they add no connection of their own. We use them to know which versions of macOS and Windows to keep supporting, and whether a published update actually gets installed.
- Error reports are on by default: when Kestro breaks, we receive the stack trace, the version and the operating system. That is all, and it is described in detail below. A switch in Settings › Behaviour turns them off, and nothing leaves your machine from that moment on.
The update check, for its part, sends us nothing at all: it downloads the list of published versions, like any other file. It can be turned off in the settings.
The kestro.dev website
This site counts its visits, and nothing else. The measurement is ours (no data goes to any third party, not Google, not anyone) and it sets no identifier that would follow you: your IP address is never stored. It is used to compute an irreversible fingerprint, mixed with a random salt that changes every night and which we delete after two days. By the next day, nothing links your visit yesterday to your visit today: not even us, with the database in front of us.
What we get out of it fits in one sentence: which pages are read, for how long, how far down, and which ones lead to a download. Nothing identifies you, nothing follows you from one site to another, nothing is cross-referenced with your licence. That is why you still see no consent banner here: there is nothing to consent to.
If your browser asks not to be tracked (the “Do Not Track” setting, or the Global Privacy Control signal) nothing at all is measured. No obligation requires this of us for measurement of this kind; we do it because a product that promises to know nothing about your work would lose more by ignoring that setting than it could ever gain by counting a few visits.
A single cookie exists on this site, and it measures nothing: the currency of the pricing page, kept for one day, so that the amount shows in euros or dollars without flickering.
These measurements are kept for thirteen months, then deleted.
What Kestro sends
Three calls go out unasked, and three only:
- On first launch, to start your trial period. We receive a fingerprint of your machine, a computed, irreversible value that can neither identify you nor trace your computer. It exists solely so that reinstalling does not restart the trial indefinitely.
- When you activate your key, to check that it is valid and to link it to that machine.
- Every six hours, to renew this machine’s right to run. That is what makes releasing a computer from kestro.dev take effect, and what lets a revoked licence stop working. This call carries the machine fingerprint and the three items described above, never anything else. Without a network, Kestro keeps working: the right to run lasts twenty days.
A third one exists, and you can close it: the error report, sent when Kestro breaks, unless you have turned it off in Settings › Behaviour. It contains the stack trace, the version and the operating system. Paths are shortened (your home folder becomes ~) and we explicitly disable memory snapshots, which could carry a passphrase or a token. These reports are processed on our behalf by Sentry, on its European Union servers, and kept for ninety days. Turning the setting off stops everything, at once.
There is no account, so no password, no session, and no way for us to know who uses Kestro or how.
Our hosting provider keeps technical connection logs (IP address, date, page requested) for security and proper operation, in accordance with its own legal obligations.
Buying a licence
When you buy a licence, the payment is processed by Stripe Payments Europe, Ltd., which collects the data needed for the transaction and for invoicing. We neither see nor store your bank details.
On our side, we keep:
| Data | Why | How long |
|---|---|---|
| Email address | To send you your key, and to send it again if you lose it | Until you ask us to delete it |
| Key and related purchase | Support, refunds, accounting obligations | 10 years (legal obligation) |
| Fingerprint of the activated machine | Linking a key to a machine, managing the trial | As long as the key is active |
| Machine’s operating system, version and architecture | Knowing which versions of macOS and Windows to support | As long as the machine checks in |
The renewal tells us that a machine is still there, and nothing more: no usage statistics, no list of your tunnels or your projects ever reaches us. We know an installation exists and which system it runs on; we have no idea what you do with it.
Your rights
Under the General Data Protection Regulation, you have a right of access, rectification, erasure, restriction of processing, objection and data portability in respect of your personal data. A request to [email protected] is enough, and we answer it within 30 days.
To have your address erased, write to us: we remove it, keeping only the invoices the law requires us to hold for ten years. Note that your key will keep working (it lives on your machine), but we will no longer be able to send it to you again if you lose it.
You may also lodge a complaint with the CNIL (cnil.fr).
Changes
If this policy changes, the update date at the top of the page is changed. A change that would affect your rights would be notified to you by email if we have your address.