Kolibri

隐私政策 · Privacy Policy

生效日期 / Effective date: 2026-08-15  ·  版本 / Version: 1.0

中文版

Kolibri(蜂鸟)是一款面向开发者的终端 / SSH 客户端,支持 iPhone、iPad 与 Mac。本政策说明这款 app 会处理哪些数据、这些数据去了哪里,以及哪些数据我们根本不会拿到

一句话总结:Kolibri 没有账号体系,不含任何分析、埋点、广告或崩溃上报 SDK,也不会把你的终端内容、主机地址、密码或密钥上传给我们。你连接的是你自己的服务器;我们的服务器只在两种场景下出现:设备间配对中转(内容端到端加密,我们只见密文)与购买校验。

一、我们不收集的数据

二、只存在你设备上的数据

以下数据由 app 保存在你的设备本地,不会上传到我们的服务器:

删除 app 会一并删除 app 沙盒内的这些数据。保存在系统钥匙串中的凭据,可在 app 内的凭据管理里逐条删除。

三、匿名设备标识

app 首次运行时会在本地生成一个随机的匿名设备标识(形如 dev_ 开头的一串随机字符),保存在设备的安全存储里。它:

四、连接与传输

4.1 SSH 直连(不经过我们)

当你用 Kolibri 连接自己的服务器时,连接是从你的设备直接到那台主机的标准 SSH 连接。终端内容、命令、文件传输(SFTP)与端口转发流量都不经过我们的任何服务器,我们看不到、也无法记录。

4.2 官方中转服务(relay)

Kolibri 的部分功能——手机与电脑配对、AI 编码 agent 的远程审批、跨设备接续会话——需要在两台设备之间传消息。两端不一定能直连,因此消息经由我们运营的中转服务(地址 relay.kolibri.work)转发。

4.3 服务端日志

中转与校验服务会记录安全审计日志,用于排障与防滥用。日志的设计红线是:

与任何联网服务一样,你的设备在连接我们的服务器时,网络层面必然会有 IP 地址参与通信;我们对它的处理如上。

4.4 Tailscale(可选功能)

如果你主动启用 Tailscale 集成,app 会用你自己提供的 Tailscale 凭据,从你的设备直接访问 Tailscale 的官方 API 来列出你的设备。该凭据保存在本机安全存储中,不会发给我们,相关请求也不经过我们的服务器。这部分数据的处理适用 Tailscale 的隐私政策。不启用则完全不涉及。

五、购买与订阅

Kolibri 的 Pro 功能通过 Apple 的应用内购买销售。支付全程由 Apple 处理:我们收不到、也无法看到你的银行卡号、账单地址或 Apple ID。

购买完成后,为了确认这笔订单真实有效,app 会把下列信息发送到我们的购买校验服务:

发送的字段用途
平台标识(App Store / 沙盒)选择正确的校验通道
商品 ID判定应授予哪一档权益
商店签名的交易凭据(收据)向 Apple 验证订单真伪
交易号去重与排障
匿名设备标识(见第三节)作为权益主体,并统计设备数量上限

校验通过后,服务端保存一条权益记录:权益主体(即上述匿名设备标识)、权益档位、来源、商品 ID、到期时间、该主体兑换过的交易号及其首次绑定时间。

保存这些的唯一目的是:让你换设备、重装后能恢复购买,并落实「一份订阅最多在 5 台设备上启用」的限制。这些记录里没有你的姓名、邮箱或支付信息。

六、语音输入

app 提供把语音转成文字填进输入框的功能。仅在你主动开启这一次语音输入时才会使用麦克风,其余时间不录音。

七、桌面协同组件(companion)

在 Mac 上使用远程审批时,会有一个协同组件运行在你自己的电脑上。它的运行日志与审批审计记录(谁在什么时候放行了哪次改动)保存在你自己电脑的用户目录下(~/.kolibri,权限收紧到仅本人可读),不会上传给我们。

八、第三方

第三方涉及场景它拿到什么
Apple应用分发、TestFlight、应用内购买、系统语音识别支付与账号信息由 Apple 直接处理;语音识别按 Apple 的机制处理
我们的服务器基础设施(云主机 + CDN / 边缘网络)中转与购买校验承载上述加密流量;内容为密文
Tailscale仅在你主动启用该集成时你自己的 Tailscale 凭据与设备列表,直接在你的设备与 Tailscale 之间

除此之外没有第三方接收你的数据。我们不使用广告网络,也没有数据分析服务商。

九、儿童

Kolibri 是开发者工具,不面向 13 岁以下儿童,也不会有意收集儿童的个人信息。

十、你的权利

十一、数据安全

凭据存放在系统安全存储;跨设备消息端到端加密;与我们服务器之间的所有通信走 TLS 加密;服务端日志按第 4.3 节脱敏。没有任何系统能保证绝对安全,但我们的设计原则是让服务端尽可能少地持有数据——拿不到的东西,就不会泄露。

十二、本政策的变更

政策更新时,我们会修改本页内容并更新顶部的生效日期。涉及重大变更时,会在 app 内提示。

十三、联系我们

对隐私有任何疑问,或要行使上述权利,请联系:departurenull@gmail.com


English Version

Kolibri is a terminal / SSH client for developers, available on iPhone, iPad and Mac. This policy explains what data the app handles, where it goes, and what we never receive at all.

In one paragraph: Kolibri has no user accounts. It contains no analytics, tracking, advertising or crash-reporting SDKs. We do not upload your terminal content, host addresses, passwords or keys. You connect to your own servers; our servers are involved in only two cases: relaying messages between your devices (end-to-end encrypted — we only ever hold ciphertext) and verifying purchases.

1. What we do not collect

2. Data that stays on your device

The following is stored locally on your device and is never uploaded to our servers:

Deleting the app removes this data from the app sandbox. Credentials held in the system Keychain can be deleted individually inside the app.

3. Anonymous device identifier

On first launch the app generates a random, anonymous device identifier locally (a random string prefixed with dev_) and stores it in the device's secure storage. It:

4. Connections and transmission

4.1 Direct SSH connections (never touch us)

When you connect to your own server, Kolibri opens a standard SSH connection directly from your device to that host. Terminal content, commands, file transfers (SFTP) and port-forwarding traffic do not pass through any server of ours. We cannot see or log them.

4.2 The official relay service

Some features — pairing a phone with a computer, remote approval for AI coding agents, and resuming a session on another device — require passing messages between two of your devices. Those devices cannot always reach each other directly, so messages are forwarded by a relay service we operate (at relay.kolibri.work).

4.3 Server-side logs

The relay and verification services keep security audit logs for troubleshooting and abuse prevention, under these hard rules:

As with any networked service, your IP address is necessarily involved at the network layer when your device connects to our servers; it is handled as described above.

4.4 Tailscale (optional)

If you choose to enable the Tailscale integration, the app uses credentials you supply yourself to call Tailscale's official API directly from your device in order to list your machines. Those credentials are kept in local secure storage, are never sent to us, and the requests do not pass through our servers. Tailscale's own privacy policy applies to that processing. If you do not enable it, none of this occurs.

5. Purchases and subscriptions

Kolibri's Pro features are sold through Apple's in-app purchase system. Apple handles payment end to end: we never receive and cannot see your card number, billing address or Apple ID.

After a purchase, in order to confirm the order is genuine, the app sends the following to our purchase-verification service:

Field sentPurpose
Platform (App Store / sandbox)Select the correct verification channel
Product IDDetermine which tier to grant
Store-signed transaction receiptValidate the order with Apple
Transaction IDDeduplication and troubleshooting
Anonymous device identifier (section 3)Subject of the entitlement; enforces the device limit

On success the server stores one entitlement record: the subject (that anonymous device identifier), the tier, its source, the product ID, the expiry date, the transaction IDs redeemed by that subject, and when each was first bound.

The sole purpose is to let you restore your purchase after changing or reinstalling on a device, and to enforce the limit of 5 devices per subscription. These records contain no name, email address or payment information.

6. Voice input

The app can turn speech into text in the input field. The microphone is used only while you explicitly start a dictation; at all other times nothing is recorded.

7. The desktop companion component

Remote approval on a Mac involves a companion component running on your own computer. Its runtime logs and approval audit records (who approved which change and when) are stored in your own home directory (~/.kolibri, with permissions restricted to your user) and are never uploaded to us.

8. Third parties

Third partyWhen involvedWhat they receive
AppleApp distribution, TestFlight, in-app purchases, system speech recognitionPayment and account data handled directly by Apple; speech handled per Apple's mechanism
Our hosting infrastructure (cloud server + CDN / edge network)Relay and purchase verificationCarries the encrypted traffic described above; content is ciphertext
TailscaleOnly if you enable that integrationYour own Tailscale credentials and device list, exchanged directly between your device and Tailscale

No other third party receives your data. We use no advertising networks and no analytics vendors.

9. Children

Kolibri is a developer tool. It is not directed at children under 13, and we do not knowingly collect personal information from children.

10. Your rights

11. Security

Credentials live in the system's secure storage; cross-device messages are end-to-end encrypted; all communication with our servers uses TLS; server logs are redacted as described in section 4.3. No system can promise absolute security, so our design principle is to have the server hold as little as possible — what we never receive cannot leak.

12. Changes to this policy

When this policy changes we will update this page and the effective date at the top. Material changes will also be surfaced in the app.

13. Contact

For any privacy question, or to exercise the rights above, contact departurenull@gmail.com.