Note: This privacy policy applies exclusively to the Mac App Store version of Kobel. For the Windows version (distributed via Paddle) please refer to our general privacy policy.

Kobel does not store any of your files. Everything runs locally on your Mac. We collect as little data as possible. Payments are handled exclusively via Apple’s App Store. Exception: if you use the optional social media integration, the one-time sign-in and token-renewal step for Facebook, Instagram, Reddit, TikTok and LinkedIn runs briefly through a connection server (see the “Social media integration” section).

1. Controller

Amoria · Owner: Lara Möller · Lucia-Pogwisch-Ring 5 · 24253 Probsteierhagen · hello@kobel.app

2. Data we collect

When you visit our website

When you access our website, the web host stores technical access data (IP address, browser type and version, operating system, referrer URL, date/time of the request, data volume transferred, HTTP status code) in the server log. These data serve solely for the technical provision, error analysis, and IT security of the website and are not combined with any other data sources.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a technically sound and secure website).
Retention: a maximum of 14 days, then automatic deletion or anonymisation. Longer retention occurs only in the case of concretely documented security-relevant incidents.
Host: The website is hosted by 1&1 IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. A data processing agreement under Art. 28 GDPR has been concluded with the host.

When you purchase via the Mac App Store

Purchases and subscriptions for the Mac version are processed exclusively via Apple’s App Store (StoreKit 2). Apple acts as Merchant of Record — meaning the purchase contract is concluded between you and Apple, not between you and us.

Data Apple processes: Apple receives your payment details (credit card, Apple ID, bank account — depending on the payment method you choose). Apple’s own privacy policy applies: apple.com/legal/privacy/en-ww/.

Data we receive: We receive from Apple exclusively an anonymised transaction identifier and an entitlement status (e.g. “Pro licence active” or “subscription active until [date]”). There is no direct payment channel between Kobel and you.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract — provision of the purchased licence).

Kobel app on your Mac (local)

The Kobel app stores data exclusively and locally on your Mac, typically under ~/Library/Application Support/Kobel/:

• List of folders you have shared
• List of managed AI applications
• Audit log: which app accessed what and when
• Settings (language, theme, etc.)

This data never leaves your Mac. Kobel does not send usage data, telemetry, or file contents to us or to any third party.

Licence and receipt validation

To verify whether an in-app purchase is valid, Kobel contacts exclusively Apple’s servers (StoreKit receipt validation) as well as our own licence API at kobel.app. Only the anonymised transaction identifier is transmitted. No personal data, no profile, no IP address storage.

For purchases made via the Mac App Store, the provider stores server-side the transaction identifier assigned by Apple (original_transaction_id) together with the product ID and licence status, in order to validate the purchase and enable cross-platform activation. Payment data (payment method, billing address) remains with Apple.

Note: the Mac App Store version does not collect or transmit a device hash. The licence is bound via the Mac App Store receipt (Apple) or via the email sign-in (see the section “Email sign-in with one-time code”).

Email sign-in with one-time code (licence restore)

To restore an already purchased licence on a (further) device — in particular across platforms between Windows and Mac — Kobel offers a sign-in via email and one-time code. No password-based user account is created.

How it works: You enter the email address used at purchase in the Kobel app. The app transmits the email address and your display language over HTTPS to a server operated by the provider (kobel.app/api). If an active licence exists for that address, the server sends a six-digit one-time code to it via the provider’s own email service (hosted by 1&1 IONOS SE, Germany; an Art. 28 GDPR data-processing agreement is in place). After you enter the code in the app, the associated licence is activated on the device.

Stored server-side — exclusively: a non-reversible hash of the email address (SHA-256 with a server-side secret) — not the address itself; a hash of the one-time code — never the code in plain text; creation and expiry timestamps and a failed-attempt counter.

Safeguards: the code is valid for 10 minutes, works only once, and is discarded after four failed attempts. Requests are rate-limited per IP address and per email address. The server’s response is identical whether or not a licence exists for an address, so it cannot be used to probe which email addresses are customers. Logs contain at most a truncated hash of the email address.
Legal basis: Art. 6(1)(b) GDPR (performance of contract — restoring the purchased licence). The code email is a purely transactional message without any advertising.
Retention: one-time-code records (hashes only) are deleted automatically no later than 24 hours after the code expires.

What Kobel does NOT do on Mac

The following functions are technically disabled in the Mac App Store build:

• Auto-updater (updates are delivered exclusively via the Mac App Store)
• Cloud OAuth for Google Drive / Dropbox (on Mac these are accessed via the system file picker rather than external OAuth servers)
• Incoming HTTP server (prohibited by Apple’s Sandbox)
• Paddle payment system (replaced by StoreKit 2)
• Cloudflared tunnel and ChatGPT tunnel (prohibited by Apple’s Sandbox)

Team policy (IT-administrator configuration) – optional

This feature is disabled by default and applies only if an IT administrator of your organisation enters a policy source in the Kobel settings — either an HTTPS URL or a local/UNC path. Kobel loads the JSON file at start-up and periodically thereafter, enforcing the rules it contains (path block-lists, allowed file types, disabling of the app proxy, write/delete restrictions, AI whitelist, pre-installed app-proxy entries).

When using an HTTPS URL, Kobel transmits your IP address, user agent, and possibly cookies to the policy server when fetching the file; this server is operated by your organisation or its provider — Amoria has no influence over it. The most recently loaded policy is cached locally in box-state.json.
Notice to employees: if you use Kobel within your employment relationship and your employer has set a policy source, your employer can centrally restrict Kobel’s functionality on the workplace device. The employer is an independent controller and fulfils its own information obligations under Art. 13 GDPR / § 26 BDSG. Kobel itself does not transmit the contents of your shared files to the policy server as part of the synchronisation.
Legal basis: Art. 6(1)(f) GDPR; in the employment context additionally § 26(1) BDSG / Art. 88 GDPR with the applicable national rules.

App proxy (external MCP servers) – optional

At your explicit request, Kobel can launch external MCP-compatible applications as subprocesses. For each entry, box-state.json stores the display name, executable path, launch parameters, and any environment variables (env) you provide. The latter often contain third-party credentials (e.g. API keys for GitHub, Notion, Slack, databases, in-house systems). They are stored in plain text in the local app-data folder, protected by your operating-system file permissions, and do not leave the device toward Amoria or Apple.

What the MCP servers you start actually do lies outside Kobel’s control. Due to Apple’s Sandbox requirements, some subprocess functions may be restricted. The provider of the relevant MCP server is the controller for those processings; please consult its privacy policy.
Legal basis: Art. 6(1)(b) GDPR; for the local storage of the env variables Art. 6(1)(f) GDPR. Recommendation: use API keys with the minimum required scope (“least privilege”) and revoke tokens with the relevant third party when no longer needed.

Social media integration – optional

At your explicit request, Kobel can connect social network accounts (Facebook, Instagram/Threads, Reddit, TikTok, LinkedIn, Telegram, Bluesky) so that a connected AI application can perform limited actions on your behalf (e.g. publishing posts, reading and replying to comments or messages). Nothing is set up by default.

Facebook, Instagram/Threads, Reddit, TikTok, LinkedIn: Sign-in uses OAuth 2.0. So that the secret app credential never has to reside on your Mac, the sign-in and token-renewal process is handled through a connection server operated by the provider at kobel.app/api/connect/ (hosted by 1&1 IONOS SE, Germany; Art. 28 GDPR data-processing agreement in place). In doing so, the access token and any refresh token and basic account details (name, account ID, page token, Instagram account ID where applicable) are processed temporarily: held briefly in a server file (sign-in max. 15 minutes, result max. 3 minutes), handed to your local app exactly once, and then deleted automaticallyno permanent storage and no database logging. The app secret never leaves the server.

Telegram and Bluesky: here you enter the bot token or app password directly in Kobel. These are stored locally only and sent directly to the platform – without involving our connection server.

Stored locally: after connecting, the tokens/bot token/app password and the account name (for display) are stored locally on your Mac. The actual content (posts, comments, messages) flows through the local connector directly to the platform – not via our server, not to Amoria, and not to Apple.

Independent controllers: Meta Platforms Ireland Limited (Facebook, Instagram, Threads); Reddit, Inc. (USA); TikTok Technology Limited (Ireland); LinkedIn Ireland Unlimited Company; Bluesky Social, PBC (USA); Telegram Messenger Inc. Where processing takes place in the USA, the transfer relies on your explicit consent (Art. 49(1)(a) GDPR) and, where certified, on the EU-US Data Privacy Framework or EU Standard Contractual Clauses. Privacy policies: Meta · Reddit · TikTok · LinkedIn · Bluesky · Telegram.
Legal basis: Art. 6(1)(a) GDPR (consent by connecting) and Art. 6(1)(b) GDPR (providing the function). Revocable at any time via “Disconnect” in the Kobel settings and in your platform account.

Data deletion – connected social media accounts

(1) In Kobel: Settings → Social Media → “Disconnect” for the relevant platform (removes the locally stored credentials). (2) In the platform: additionally revoke Kobel in your account’s app/permission settings. (3) Server-side, Kobel stores no permanent account or token data; data used briefly during the connection is deleted automatically (within 15 minutes at the latest). For Meta accounts, removing the app in your Meta account automatically triggers our deletion endpoint. Questions: hello@kobel.app.

3. Contact by email

If you contact us by email, the data you provide will be used to process your request and then deleted. We do not pass this data on to third parties.

4. Security vulnerability reports

Anyone who reports a security vulnerability to us at security@kobel.app will typically transmit their name, email address, technical evidence (screenshots, logs, proof of concept), and possibly IP addresses. Details of the reporting process are set out in our security policy.

Purpose and legal basis

Processing serves the maintenance and restoration of IT security in our products and the fulfilment of statutory reporting obligations under the EU Cyber Resilience Act (CRA), in particular Arts. 13 and 14. Legal basis: Art. 6(1)(c) GDPR (legal obligation) in conjunction with Art. 6(1)(f) GDPR (legitimate interest in product security).

Disclosure to third parties

In cases required by law, we may share data with the EU Agency for Cybersecurity (ENISA), the BSI, or other competent authorities. Where necessary for clarification or documentation, data may also be shared with our legal advisors.

Retention

Reports are retained for seven years. This is due to CRA documentation obligations, the need to provide evidence in product liability cases (§ 15 ProdHaftG), and statutory commercial retention periods.

Data subject rights

You may at any time request access (Art. 15 GDPR), rectification (Art. 16 GDPR), and restriction of processing (Art. 18 GDPR). Erasure (Art. 17 GDPR) may be excluded during the statutory retention period pursuant to Art. 17(3)(b) GDPR; in that case processing will be restricted.

5. Cookies

Our website uses only technically necessary cookies required for the operation and security of the site. No tracking, analytics, or advertising cookies are used. Legal basis: § 25(2) no. 2 TDDDG and Art. 6(1)(f) GDPR. The Kobel app itself does not set any cookies.

6. Fonts

For a consistent appearance, fonts are embedded locally on this website. When the page loads, no connection to Google servers is established and no IP addresses or other personal data are transmitted to Google.

7. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), and objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR). Any consent given may be withdrawn with effect for the future at any time (Art. 7(3) GDPR). To exercise your rights, please contact hello@kobel.app.

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority for us is the Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD), Holstenstraße 98, 24103 Kiel, Germany — datenschutzzentrum.de.

8. Deleting your local Kobel data

If you want to remove your local Kobel data from your Mac:

1. Uninstall Kobel via Launchpad (hold down the icon, then click the × button).
2. Optionally delete the folder ~/Library/Application Support/Kobel/.

Apart from the licence data described in this policy (the Apple transaction identifier, product ID, and licence status, and — where the email sign-in is used — non-reversible hash values), the provider stores no personal data outside your Mac.

9. International privacy information

Kobel is available worldwide via the Apple Mac App Store. The country-specific notes below supplement the information above.

9.1 California, USA (CCPA/CPRA)

California residents have the right to know about, delete, and correct personal information concerning them, and to opt out of its “sale” or “sharing”. Amoria does not sell or share personal information as defined by the CCPA/CPRA. Requests: hello@kobel.app.

9.2 United Kingdom (UK GDPR)

For UK users the principles of the UK GDPR apply as described above. Complaints to the Information Commissioner’s Office (ICO): ico.org.uk.

9.3 Canada (PIPEDA)

For Canadian users the principles of PIPEDA apply to the processing described above. Payment data are processed by Apple in the Mac App Store.

9.3a Québec, Canada (Law 25 / Bill 64)

Users resident in Québec also benefit from the Loi modernisant des dispositions législatives en matière de protection des renseignements personnels (Law 25, formerly Bill 64) read together with the Loi sur la protection des renseignements personnels dans le secteur privé. You have, in particular, the right to access, rectify, port (since September 2024), and restrict the processing of your personal information. A privacy impact assessment is conducted before any transfer of personal information outside Québec. Payment processing takes place via Apple (US/Ireland); where licence validation occurs, only an anonymised transaction identifier is processed. Requests under Law 25: hello@kobel.app. Supervisory authority: Commission d’accès à l’information du Québec (CAI), cai.gouv.qc.ca.

9.4 Brazil (LGPD), Australia (Privacy Act), other countries

Applicable national data-protection laws apply correspondingly to the processing described above. Data-subject rights: hello@kobel.app.

9.5 Note on AI applications

The AI applications you connect may transmit conversation content (including file paths and file contents) to their servers according to their own privacy policies. This processing is not controlled by Kobel or Amoria. Please review the privacy policies of the AI applications you use.

10. Children

Kobel is a paid productivity tool aimed at adults and businesses; paid licences may only be purchased by persons who are at least 18 years old. Amoria does not knowingly collect personal data from children under 16. If we become aware that personal data of a minor has been processed without the required parental consent, we will delete the record without undue delay. Please send any related notice to hello@kobel.app.

11. Changes

We reserve the right to update this privacy policy as needed. The current version is always available on this page. Material changes will be displayed in Kobel via a notice dialog on the next launch.