Privacy Policy

Koru, a terminal-first workspace for macOS

Last updated: August 12, 2026

1. Introduction

This Privacy Policy explains how Fly-by-wire AB (“Company”, “we”, “us”), a company registered in Sweden, collects, uses, and protects information in connection with the Koru application, its CLI, and the optional Koru Cloud sync service (together, the “Software”).

Koru is built to keep your data on your device. Everything in your vault is encrypted before it is written to disk, and the optional cloud sync is end-to-end encrypted so that we only ever store data we cannot read.

2. Data Controller

The data controller for the purposes of GDPR and other applicable data protection laws is:

Fly-by-wire AB
Email: support@flybywire.se
Website: https://flybywire.se

3. What Data We Collect

3.1 Data on Your Device (We Do NOT Have Access)

The following is stored on your device and, unless you turn on cloud sync, is never transmitted to us:

  • Secrets: API keys, tokens, credentials, and their descriptions.
  • Context and notes: Markdown and text content and embedded images.
  • Project configuration: project names, descriptions, repositories, and worktrees.
  • Terminal sessions and preferences: your local settings and session state.

Secret values and content are encrypted at rest using AES-256-GCM. The encryption key is generated on your device and stored in the macOS Keychain, tied to your device and user account.

We cannot access, read, or recover this data. If you lose access to your device, or if your macOS Keychain or your cloud passphrase is lost or becomes inaccessible (for example due to OS reinstallation, device migration, or hardware failure), your encrypted data will become permanently unrecoverable. We do not hold your encryption keys or passphrase and cannot assist with recovery. Please refer to our Terms of Service for your data responsibility obligations.

3.2 Koru Cloud (Optional, End-to-End Encrypted)

If you enable Koru Cloud sync, your projects, secrets, and notes are encrypted on your device before they are uploaded. Your data is unlocked only by a passphrase that you choose and that we never receive. Our servers store only encrypted ciphertext that we cannot read. To operate the service we store:

DataPurpose
Email addressTo identify your account and send sign-in links
Encrypted vault data (ciphertext)To sync your projects across your devices
Wrapped encryption keys and a verification blobTo let your passphrase unlock your data on each device (we cannot derive your passphrase from them)
A device machine identifierTo manage your synced devices and sessions

3.3 Anonymous Usage Data (Opt-In)

Analytics are off by default. If you opt in, Koru sends anonymous, non-identifying usage data tied to a random per-install identifier, never to your account. Specifically:

  • Environment: app version, macOS version, and CPU architecture.
  • Lifecycle: app launches, session length, and update installations.
  • Feature usage (counts and flags only): terminals opened, worktrees created, notes and context files created, whether cloud sync is on, active theme, and which integrations are connected.
  • Health: error and sync-failure counts by category.

We never collect the contents of your vault, your notes, context or terminal output, project or file names, anything you type, or your email through analytics. You can turn this off at any time in Settings.

3.4 Feedback

If you send feedback from within Koru, we receive the message you write, the app version, and a device machine identifier so we can follow up on issues. Do not include sensitive information in feedback.

3.5 Payments (Koru Cloud Subscription)

Koru Cloud is billed through Stripe, Inc. Stripe may collect your name, email address, billing address, payment card details, and transaction information. We do not store your payment card details. Stripe processes payments under its own privacy policy: https://stripe.com/privacy. We may receive from Stripe your email address, subscription status, and transaction details for billing and support.

3.6 Data We Do NOT Collect

  • No advertising identifiers.
  • No location data.
  • No behavioral profiling.
  • No cookies in the application (Koru is a native app, not a web service).
  • No readable copy of your vault, ever. Cloud data is stored only as ciphertext.

4. How We Use Your Data

We use the limited data above to operate your account and the cloud sync service, to bill and support your subscription, to fix bugs and improve Koru (only if you opt in to analytics), and to respond to feedback. We do not use your data for marketing, profiling, or automated decision-making unless you explicitly opt in. We do not sell, rent, or trade your personal data.

5. Data Sharing

We share data only with:

  • Stripe, Inc. (payment processing), under Stripe's Privacy Policy.
  • Infrastructure providers that host our servers, which only ever process encrypted ciphertext for cloud sync.
  • Law enforcement or regulatory authorities, only when required by applicable law. Because cloud data is end-to-end encrypted, we can only ever provide ciphertext we cannot read.

6. Data Retention

  • Cloud data: retained while your account is active. You may delete your cloud data or account at any time by contacting us; local copies remain on your devices until you remove them.
  • Payment data: retained by Stripe under its policies and applicable financial regulations.
  • Analytics: stored in aggregate against a random per-install id, with no way to tie it back to you.

7. Data Security

  • On device: encrypted with AES-256-GCM; keys held in the macOS Keychain.
  • Cloud sync: end-to-end encrypted; the master key is wrapped with a key derived from your passphrase (PBKDF2-SHA-256), which never leaves your device.
  • In transit: all communication with our servers uses HTTPS/TLS.
  • Payments: handled by Stripe, a PCI DSS Level 1 certified processor.

While we use industry-standard measures, no method of electronic storage or transmission is completely secure.

8. Your Rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or port your personal data, to object to processing, and to withdraw consent. EU/EEA users have these rights under GDPR and may lodge a complaint with a supervisory authority (in Sweden, Integritetsskyddsmyndigheten, https://www.imy.se). California residents have rights under the CCPA, including to know, delete, and opt out of sale (we do not sell personal information). To exercise any right, email support@flybywire.se and we will respond within 30 days or as required by law.

9. International Transfers and Children

Our servers may process data outside the EU/EEA; where they do, we rely on appropriate safeguards such as Standard Contractual Clauses. Koru is not directed at individuals under 16, and we do not knowingly collect data from children.

10. Changes and Contact

We may update this Privacy Policy from time to time; updated versions are posted here with a revised date, and we will make reasonable efforts to notify users of material changes. For any question about this policy or your data, contact support@flybywire.se.