Kolibri(蜂鸟)是一款面向开发者的终端 / SSH 客户端,支持 iPhone、iPad、Mac、Android 与 Windows。本政策说明这款 app 会处理哪些数据、这些数据去了哪里,以及哪些数据我们根本拿不到。
一句话总结:你连接的是你自己的服务器。我们只收集运行跨设备功能所必需的最少数据——一个账号(邮箱或用 Apple 登录)、推送令牌、以及购买记录。app 里没有任何分析、埋点、广告或崩溃上报 SDK。你的保险库(SSH 密钥、凭据、主机簿)端到端加密,我们只见密文;终端内容要么直连你的服务器,要么经我们中转但端到端加密——两种情况我们都无法解读。
下面四类是会离开你的设备、并且我们的服务器能读到的数据。逐项写清用途、保留多久、能不能删。除此之外的数据要么只留在你设备本地(第二节),要么端到端加密、我们读不到(第三节)。
基础的单机使用(连你自己的 SSH 主机、SFTP、端口转发、本机终端)不需要账号。只有当你使用跨设备功能——配对电脑、跨设备同步保险库、异地接续会话、AI agent 远程审批推送——时,才需要一个 Kolibri 账号。账号可以用邮箱 + 密码注册,也可以用 Sign in with Apple。
| 数据 | 用途 | 保留期 | 能否删除 |
|---|---|---|---|
| 邮箱地址(用 Apple 登录时,可能是 Apple 的私有转发地址) | 作为账号身份,用于登录、找回密码、发送与账号安全有关的邮件 | 到你删除账号为止 | 能:删除账号即从服务器移除 |
| 密码(仅邮箱账号) | 验证登录身份 | 到你删除账号为止 | 能:我们只存 scrypt 散列,绝不存明文;删除账号即移除 |
| 两步验证信息(可选,你主动开启才有) | 用 authenticator app 的 TOTP 保护你的账号;同时生成一组恢复码 | 到你关闭两步验证或删除账号为止 | 能:恢复码以散列形式保存,不走短信、不收集手机号 |
账号 / 设备标识:设备首次运行本地随机生成的匿名标识(形如 dev_),以及登录后账号自身的 id |
作为权益归属主体、配对身份,实现跨设备解锁 | 到你删除账号 / 解除设备为止 | 能:解除设备或删除账号即移除 |
| 登录设备标签:一个固定的平台名(如「iPhone / iPad」「Mac」「Android」「Windows」) | 在你的「登录设备 / 会话」列表里区分设备 | 到该会话失效或你删除账号为止 | 能:登出该设备即移除。不含你的电脑名 / 机器名(那走的是第三节的端到端加密路径) |
删除账号时,我们会移除你的邮箱与上述个人数据,只保留一条最小墓碑记录(一个匿名账号 id 加两个时间戳),用于防止标识被复用与满足审计需要;同时撤销该账号名下的权益。若你用 Apple 登录并在「设置 → Apple 账户」里对 Kolibri 停用了 Apple 登录,Apple 也会通知我们,我们据此删除对应账号。
只有当你为某台主机主动打开推送(agent 完成 / 待审批的通知)时,才会用到这一类。
| 数据 | 用途 | 保留期 | 能否删除 |
|---|---|---|---|
| 推送令牌:Apple 设备是 APNs token,Android 设备是 Google FCM token | 让我们的中转服务能把「有一条待审批 / agent 完成」的通知投递到你这台设备 | 跟着这条配对走;配对超过 7 天无活动被清理时,或你关闭推送 / 解除配对时一并清除 | 能:关闭推送或解除配对即移除 |
桌面端(Mac / Windows)当前不接推送,靠一条常驻连接接收通知,因此桌面端不涉及推送令牌。
购买 Pro 后,为确认订单真实有效,app 会把下列信息发给我们的购买校验服务。支付全程由应用商店(Apple / Google)处理,我们收不到、也看不到你的银行卡号、账单地址或商店账号。
| 发送的字段 | 用途 |
|---|---|
| 平台标识(App Store / Google Play / 沙盒) | 选择正确的校验通道 |
| 商品 ID | 判定应授予哪一档权益 |
| 商店签名的交易凭据(收据) | 向 Apple / Google 验证订单真伪 |
| 交易号 | 去重与排障 |
| 账号 / 匿名设备标识(见 1.1) | 作为权益主体,并落实一份购买的「恢复购买」名额上限(未登录时每台设备各占一格;登录着账号恢复时,同一账号下的 iPhone / iPad 共用账号那一格) |
校验通过后,服务端保存一条权益记录:权益主体、权益档位、来源、商品 ID、到期时间、该主体兑换过的交易号及其首次绑定时间。保留期:为让你换设备 / 重装后能恢复购买而保留;删除账号会撤销并清理与该账号绑定的权益。这些记录里没有你的支付信息,也没有姓名。
以下数据由 app 保存在你的设备本地,不上传到我们的服务器:
删除 app 会一并删除 app 沙盒内的这些数据。保存在系统安全存储中的凭据,可在 app 内的凭据管理里逐条删除。
下面这些数据即便离开了你的设备,也是端到端加密的:密钥只在你自己的设备上,我们的中转服务只见密文,无法解密。据此,这些数据不属于我们「收集」的范畴。
关于 SSH 私钥:开启跨设备同步后,SSH 私钥材料会以密文形式离开设备、同步到你自己的其它设备——这是设计使然,不是泄露。本地明文私钥只存在系统安全存储里;离开设备的永远是密文,解密的密钥始终在你手里。我们从未、也无法看到你的明文私钥。
当你用 Kolibri 连接自己的服务器时,连接是从你的设备直接到那台主机的标准 SSH 连接。终端内容、命令、文件传输(SFTP)与端口转发流量都不经过我们的任何服务器,我们看不到、也无法记录。
Kolibri 的部分功能——手机与电脑配对、AI 编码 agent 的远程审批、跨设备接续会话、保险库同步——需要在你的两台设备之间传消息。两端不一定能直连,因此消息经由我们运营的中转服务(地址 relay.kolibri.work)转发。
中转与校验服务会记录安全审计日志,用于排障与防滥用。日志的设计红线是:
与任何联网服务一样,你的设备在连接我们的服务器时,网络层面必然会有 IP 地址参与通信;我们对它的处理如上。
如果你主动启用 Tailscale 集成,app 会用你自己提供的 Tailscale 凭据,从你的设备直接访问 Tailscale 的官方 API 来列出你的设备。该凭据保存在本机安全存储中,不会发给我们,相关请求也不经过我们的服务器。这部分数据的处理适用 Tailscale 的隐私政策。不启用则完全不涉及。
| 第三方 | 涉及场景 | 它拿到什么 |
|---|---|---|
| Apple | App 分发、TestFlight、应用内购买、Sign in with Apple、系统语音识别、Apple 推送(APNs) | 支付与登录信息由 Apple 直接处理;用 Apple 登录时向我们回传一个邮箱(可为私有转发地址);语音识别按 Apple 的机制处理;APNs 承载的通知内容为密文 |
| Android 端的 App 分发(Google Play)、应用内购买(Play 结算)、推送(Firebase Cloud Messaging)、系统语音识别 | 支付信息由 Google 直接处理;FCM 用于向 Android 设备投递通知(内容为密文);语音识别按 Android 系统机制处理 | |
| 我们的云基础设施(境外云服务器 + Cloudflare 边缘网络) | 中转与购买校验 | 承载上述加密流量;会话内容为密文 |
| Tailscale | 仅在你主动启用该集成时 | 你自己的 Tailscale 凭据与设备列表,直接在你的设备与 Tailscale 之间交换 |
除此之外没有第三方接收你的数据。我们不使用广告网络,也没有数据分析服务商。
在提供语音识别的平台上(iPhone / iPad / Mac 用 Apple 的服务,Android 用系统的语音识别服务),app 可以把语音转成文字填进输入框。仅在你主动开启这一次语音输入时才会使用麦克风,其余时间不录音。
在 Mac / Windows 上使用远程审批或会话宿主时,会有一个协同组件运行在你自己的电脑上。它的运行日志与审批审计记录(谁在什么时候放行了哪次改动)保存在你自己电脑的用户目录下(例如 ~/.kolibri,权限收紧到仅本人可读),不会上传给我们。
Kolibri 是开发者工具,不面向 13 岁以下儿童,也不会有意收集儿童的个人信息。
我们的账号、中转与购买校验服务运行在位于中国大陆境外的云服务器上,并经由一家全球内容分发 / 边缘网络(Cloudflare)接入。因此,第一节所列会离开设备的数据,会在境外被处理与存储。使用本 app 即表示你了解并同意这一跨境处理。无论数据在何处处理,本政策所述的加密与最小化原则始终适用。
凭据存放在系统安全存储;跨设备消息与保险库端到端加密;密码只以 scrypt 散列保存;与我们服务器之间的所有通信走 TLS 加密;服务端日志按 4.3 节脱敏。没有任何系统能保证绝对安全,但我们的设计原则是让服务端尽可能少地持有数据——拿不到的东西,就不会泄露。
本政策适用于 Kolibri 的全部客户端:iPhone、iPad、Mac、Android、Windows。各平台的数据行为一致;平台相关的差异(如推送在桌面端不涉及令牌、语音识别由各系统提供)已在上文对应处写明。
政策更新时,我们会修改本页内容并更新顶部的生效日期与版本号。涉及重大变更时,会在 app 内提示。
对隐私有任何疑问,或要行使上述权利,请联系:support@kolibri.work
Kolibri is a terminal / SSH client for developers, available on iPhone, iPad, Mac, Android and Windows. This policy explains what data the app handles, where it goes, and what we cannot receive at all.
In one paragraph: You connect to your own servers. We collect only the minimum needed to run cross-device features — an account (email, or Sign in with Apple), push tokens, and purchase records. The app contains no analytics, tracking, advertising or crash-reporting SDKs. Your vault (SSH keys, credentials, host book) is end-to-end encrypted and we only ever hold ciphertext; terminal content either goes directly to your servers or is relayed by us end-to-end encrypted — in both cases we cannot read it.
The four categories below are data that leaves your device and that our servers can read. For each we state the purpose, how long we keep it, and whether it can be deleted. Everything else either stays local to your device (section 2) or is end-to-end encrypted and unreadable by us (section 3).
Basic single-device use (connecting to your own SSH hosts, SFTP, port forwarding, a local terminal) requires no account. Only when you use cross-device features — pairing a computer, syncing the vault across devices, resuming a session on another device, remote approval for an AI agent — do you create a Kolibri account. You can register with email + password, or use Sign in with Apple.
| Data | Purpose | Retention | Deletable |
|---|---|---|---|
| Email address (may be Apple's private relay address when you use Sign in with Apple) | Your account identity — login, password recovery, and account-security email | Until you delete your account | Yes — removed from our servers when you delete your account |
| Password (email accounts only) | Authenticate you | Until you delete your account | Yes — stored only as a scrypt hash, never in cleartext; removed on account deletion |
| Two-factor data (optional; only if you turn it on) | Protect your account with an authenticator-app TOTP; a set of recovery codes is also generated | Until you disable 2FA or delete your account | Yes — recovery codes are stored hashed; no SMS, no phone number collected |
Account / device identifier: a random anonymous identifier generated on the device at first launch (prefixed dev_), plus your account's own id once signed in |
Subject of your entitlement, pairing identity, cross-device unlock | Until you delete your account / release the device | Yes — removed when you release the device or delete your account |
| Login-device label: a fixed platform name (e.g. "iPhone / iPad", "Mac", "Android", "Windows") | Distinguish devices in your login-device / session list | Until the session ends or you delete your account | Yes — removed when you log the device out. It contains no computer name / machine name (that travels only over the end-to-end-encrypted path in section 3) |
When you delete your account we remove your email and the personal data above, keeping only a minimal tombstone (an anonymous account id and two timestamps) to prevent reuse of the identifier and for audit, and we revoke the entitlements under that account. If you use Sign in with Apple and later turn off Apple sign-in for Kolibri in Settings → Apple Account, Apple notifies us and we delete the corresponding account.
This category applies only when you turn on push for a host (notifications for "approval pending" / "agent finished").
| Data | Purpose | Retention | Deletable |
|---|---|---|---|
| Push token: APNs token on Apple devices, Google FCM token on Android devices | Lets our relay deliver a "pending approval / agent finished" notification to this device | Tied to the pairing; cleared when the pairing is deleted after 7 days of inactivity, or when you turn off push / unpair | Yes — removed when you turn off push or unpair |
Desktop apps (Mac / Windows) do not currently use push; they receive notifications over a persistent connection, so no push token is involved on desktop.
After a Pro purchase, to confirm the order is genuine, the app sends the following to our verification service. Payment is handled end to end by the app store (Apple / Google); we never receive and cannot see your card number, billing address or store account.
| Field sent | Purpose |
|---|---|
| Platform (App Store / Google Play / sandbox) | Select the correct verification channel |
| Product ID | Determine which tier to grant |
| Store-signed transaction receipt | Validate the order with Apple / Google |
| Transaction ID | Deduplication and troubleshooting |
| Account / anonymous device identifier (section 1.1) | Subject of the entitlement; enforces the per-purchase "Restore purchases" slot limit (without sign-in each device takes one slot; when restoring while signed in, the iPhones / iPads on the same account share the account's single slot) |
On success the server stores one entitlement record: the subject, the tier, its source, the product ID, the expiry date, the transaction IDs redeemed by that subject, and when each was first bound. Retention: kept so you can restore your purchase after changing or reinstalling on a device; deleting your account revokes and clears entitlements bound to it. These records contain no payment information and no name.
The following is stored locally on your device and is never uploaded to our servers:
Deleting the app removes this data from the app sandbox. Credentials held in the system's secure storage can be deleted individually inside the app.
Even when the following leaves your device it is end-to-end encrypted: the keys live only on your own devices, and our relay holds only ciphertext and cannot decrypt. Accordingly, this data is not something we "collect."
About SSH private keys: with cross-device sync on, SSH private-key material does leave the device — as ciphertext — to sync to your own other devices. This is by design, not a leak. The cleartext private key exists only in the system's secure storage; what leaves the device is always ciphertext, and the key to decrypt it is always in your hands. We have never, and can never, see your cleartext private keys.
When you connect to your own server, Kolibri opens a standard SSH connection directly from your device to that host. Terminal content, commands, file transfers (SFTP) and port-forwarding traffic do not pass through any server of ours. We cannot see or log them.
Some features — pairing a phone with a computer, remote approval for AI coding agents, resuming a session on another device, and syncing the vault — require passing messages between two of your devices. Those devices cannot always reach each other directly, so messages are forwarded by a relay service we operate (at relay.kolibri.work).
The relay and verification services keep security audit logs for troubleshooting and abuse prevention, under these hard rules:
As with any networked service, your IP address is necessarily involved at the network layer when your device connects to our servers; it is handled as described above.
If you choose to enable the Tailscale integration, the app uses credentials you supply yourself to call Tailscale's official API directly from your device in order to list your machines. Those credentials are kept in local secure storage, are never sent to us, and the requests do not pass through our servers. Tailscale's own privacy policy applies to that processing. If you do not enable it, none of this occurs.
| Third party | When involved | What they receive |
|---|---|---|
| Apple | App distribution, TestFlight, in-app purchases, Sign in with Apple, system speech recognition, Apple push (APNs) | Payment and sign-in data handled directly by Apple; Sign in with Apple returns an email to us (possibly a private relay address); speech handled per Apple's mechanism; notification payloads over APNs are ciphertext |
| Android app distribution (Google Play), in-app purchases (Play Billing), push (Firebase Cloud Messaging), system speech recognition | Payment handled directly by Google; FCM is used to deliver notifications to Android devices (payloads are ciphertext); speech handled per the Android system mechanism | |
| Our cloud infrastructure (overseas cloud servers + Cloudflare edge network) | Relay and purchase verification | Carries the encrypted traffic described above; session content is ciphertext |
| Tailscale | Only if you enable that integration | Your own Tailscale credentials and device list, exchanged directly between your device and Tailscale |
No other third party receives your data. We use no advertising networks and no analytics vendors.
On platforms that provide speech recognition (Apple's service on iPhone / iPad / Mac; the system service on Android), the app can turn speech into text in the input field. The microphone is used only while you explicitly start a dictation; at all other times nothing is recorded.
Remote approval and session hosting on a Mac / Windows PC involve a companion component running on your own computer. Its runtime logs and approval audit records (who approved which change and when) are stored in your own home directory (e.g. ~/.kolibri, with permissions restricted to your user) and are never uploaded to us.
Kolibri is a developer tool. It is not directed at children under 13, and we do not knowingly collect personal information from children.
Our account, relay and purchase-verification services run on cloud servers located outside mainland China, reached through a global content-delivery / edge network (Cloudflare). The data listed in section 1 that leaves your device is therefore processed and stored outside mainland China. By using the app you understand and agree to this cross-border processing. Wherever data is processed, the encryption and minimisation principles described in this policy always apply.
Credentials live in the system's secure storage; cross-device messages and the vault are end-to-end encrypted; passwords are stored only as scrypt hashes; all communication with our servers uses TLS; server logs are redacted as described in section 4.3. No system can promise absolute security, so our design principle is to have the server hold as little as possible — what we never receive cannot leak.
This policy applies to all Kolibri clients: iPhone, iPad, Mac, Android and Windows. Data behaviour is consistent across platforms; platform-specific differences (e.g. desktop push involves no token, speech recognition is provided by each operating system) are noted where relevant above.
When this policy changes we will update this page and the effective date and version at the top. Material changes will also be surfaced in the app.
For any privacy question, or to exercise the rights above, contact support@kolibri.work.