Privacy
Privacy for the app and website.
The Kochab mobile app and kochab.io handle different data. This policy explains both.
Effective date and last updated: September 7, 2026.
This policy covers the Kochab mobile app and the kochab.io website. NDM Ventures, LLC, a South Dakota limited liability company doing business as Kochab, controls the data described in this policy. Our address is 4809 W 41st St, Ste 202, Sioux Falls, SD 57106.
The short version
The mobile app does not require a Kochab login or profile. Most app data stays on your device, and normal traffic between the app and a service you configure goes directly to that service. Limited app data leaves the device for purchases, push notifications, error reporting, software updates, and features you choose to use.
The website has its own data flows. Kochab uses cookieless PostHog pageview analytics on kochab.io, and Web3Forms processes support-form submissions. Website analytics is not connected to your app configuration, media stack, purchases, or notifications.
NDM Ventures does not sell personal information or share it for cross-context behavioral advertising. Kochab contains no advertising SDK.
The Kochab mobile app
Data stored on your device
Kochab stores the following data in the operating system keychain, app storage, or app cache:
- Service names, addresses, API keys, sign-in tokens, certificate pins, custom certificates, and other connection settings.
- Library, queue, activity, calendar, infrastructure, and artwork data fetched from services you configure.
- Saved home Wi-Fi network names, app settings, notification preferences, local diagnostic logs, and app-lock settings.
Kochab uses the operating system for biometric checks and receives only the result of a check. The app does not receive or store your fingerprint, face scan, or biometric template. The mobile app contains no advertising SDK and sends no product-analytics events to PostHog or another analytics service.
Normal requests to your configured services travel from your device to those services. They do not pass through Kochab servers. A configured service, reverse proxy, cloud connection, or third-party account such as Plex or Trakt handles those direct requests under its own terms and privacy practices. Any internet service you contact receives standard network information, including your IP address, to return a response.
Purchases and entitlements
Apple or Google processes your purchase and payment information. Kochab uses RevenueCat to retrieve products, complete purchases, restore purchases, and confirm whether the app is unlocked. RevenueCat creates an anonymous App User ID because Kochab does not provide it with your name or email address. RevenueCat may receive that identifier, device type, operating system, IP address, app activity timestamps, Apple receipt data or a Google purchase token, and purchase and entitlement history.
The notification relay sends the anonymous RevenueCat App User ID to RevenueCat when it verifies an entitlement. The relay stores a one-way hash of that identifier with a registered notification device; it does not store the raw identifier in its database.
Push notifications
Firebase Cloud Messaging and Apple Push Notification service may create and process app-installation and push tokens so Kochab can offer notifications. Kochab sends a push token to the Kochab notification relay after you register for push notifications.
The relay stores random account, device, and webhook identifiers; hashed authentication secrets; a hash of the RevenueCat identifier; the push token; platform; a device label; creation and disabled dates; and the last date each webhook fired. The device label may use the name assigned to your phone or its model. These technical relay accounts group notification devices and webhooks. They are not Kochab login accounts or user profiles.
Your configured service sends its webhook request to the relay. The request can contain a full service notification. The relay receives and reads the bounded request long enough to extract a coarse event type, then discards the request body. It does not store the notification body, media titles, file names, or service content. The relay sends a hook identifier and coarse event type through Firebase. Android receives a data message; iOS may receive a visible alert with the Kochab name and a coarse label such as "Download complete." The app then fetches any details directly from your service.
Trakt
If you connect Trakt, Kochab stores your Trakt access and refresh tokens in the device keychain. The sign-in token exchange and later token refreshes pass through the notification relay so Kochab does not ship the Trakt client secret in the app. The relay checks your RevenueCat entitlement, forwards the token request to Trakt, returns Trakt's response to your device, and does not store the Trakt code or tokens. After sign-in, your Trakt activity and content requests go directly from your device to Trakt. Trakt handles that data under its privacy policy.
Crash and error diagnostics
When Sentry is configured in a release build, Kochab uses it for crash and error diagnostics. Reports can include stack traces, app version, installed update number, operating-system and device-model information, error type, coarse operation breadcrumbs, and standard delivery metadata such as IP address. Kochab removes request data, user context, server names, device names, hostnames, network addresses from the report body, file paths, media titles, and credentials before sending a report. Kochab disables screenshots, attachments, and performance tracing.
Software updates and Kochab content
Shorebird checks for Dart-code updates when the app starts. Update requests can include Kochab's app ID, release version, patch number, platform, processor architecture, update channel, an anonymous per-app client ID, and standard network data such as an IP address. The app also requests public release notes and curated discovery content from Kochab services. Those requests include standard network information needed to return the requested content.
Backups and support bundles
If you create a backup, Kochab encrypts a .kbk file on your device with a passphrase that you control. You choose its destination, including a filesystem or cloud-drive provider. NDM Ventures does not receive or host that file. The destination provider handles it under its own policy.
If you choose to share an in-app support bundle, it can include the app version, device model, operating-system version, configured service types and versions, coarse health and notification states, selected settings, your description, and local diagnostic logs. Kochab scrubs hostnames, addresses, paths, media titles, and credentials on the device before opening the system share sheet. You choose the recipient and method.
Wi-Fi name and location permission
Kochab reads the name, or SSID, of the Wi-Fi network your device has joined. The app compares that name on your device with home-network names you saved for the active stack. Kochab does not read coordinates or send Wi-Fi names off your device.
Android and iOS restrict access to the connected Wi-Fi name through location-related permissions. On iOS, Kochab requests access only after you choose "Use my Wi-Fi name." On Android, Kochab explains the optional permission and directs you to system settings if you want to grant it.
A matching home Wi-Fi name makes Kochab try the internal address first. A readable non-home name makes Kochab try a configured external address first. If Kochab cannot read the Wi-Fi name, it cannot confirm whether you are home and tries the internal address first. A service with only an internal address still uses that address because no alternative exists.
The Wi-Fi name affects address order. It does not authenticate a server. Kochab verifies HTTPS connections with the system trust store or a certificate pin. A plain-HTTP address requires your prior consent; a consented internal HTTP address can still be used on a non-home network.
- Kochab calls no positioning API and does not read latitude, longitude, altitude, heading, or speed.
- Kochab stores saved Wi-Fi names in the device keychain and does not use them for advertising or analytics.
- Kochab does not request background location access or run a background location service.
You can decline or revoke the permission in system settings. The rest of the app continues to work.
The kochab.io website
Website requests and pageview analytics
Cloudflare hosts kochab.io and processes standard request information needed to deliver and protect the site, such as IP address, request time, requested URL, browser headers, and security signals.
Kochab uses PostHog to count pageviews and understand which website pages people use. A pageview can include the page URL, referrer, browser and device details, operating system, hostname, IP address, and user agent. PostHog can use request information to calculate a rotating pseudonymous audience identifier and may derive an approximate location from an IP address.
Kochab configures PostHog without analytics cookies, browser storage, session recording, automatic interaction capture, or person profiles. Kochab does not call PostHog's identification feature. PostHog requests pass through kochab.io, where the proxy removes cookies before forwarding them. Website analytics is not linked to mobile-app data.
Support form and email
The support form asks for a topic, email address, message, and optional name and subject. Web3Forms receives the submission, processes spam checks, and delivers it to the Kochab support inbox. Web3Forms and its infrastructure providers may also process IP address, browser information, request time, and security logs. If you email us instead, your email provider and ours process the message and addressing information.
We use support messages to answer requests, troubleshoot problems, and maintain a support history. Do not include passwords, API keys, private webhook URLs, or other credentials in a support form or email.
Why we process data
- Provide requested services: validate purchases, deliver notifications and updates, return website pages, connect optional services, and answer support requests.
- Maintain and protect Kochab: diagnose failures, prevent abuse, secure the website and relay, and measure website page use.
- Meet legal duties: keep records or disclose information when applicable law requires it, and establish or defend legal claims.
For users in the EEA, UK, or another jurisdiction that requires a legal basis, we rely on performance of a contract or steps you request before a contract for purchases and requested features; our legitimate interests in security, support, reliability, and privacy-minimized website measurement; compliance with legal obligations; and consent where applicable. You can withdraw consent without affecting processing that occurred before withdrawal.
Service providers and other recipients
NDM Ventures does not sell personal information. We require providers that process personal data for us to protect it in a manner consistent with this policy and applicable law. The providers and other recipients used by Kochab include:
- Cloudflare: website delivery and security, public Kochab content, the notification relay, its technical database, rate limiting, and operational logs. See Cloudflare's privacy policy.
- Apple and Google: app distribution, purchases, subscriptions, and platform push services. See Apple's privacy policy and Google's privacy policy.
- RevenueCat: product, purchase, restore, and entitlement processing. See RevenueCat's privacy policy.
- Firebase Cloud Messaging: app-installation and push-token services and notification delivery. See Firebase privacy information.
- Sentry: scrubbed mobile-app crash and error diagnostics. See Sentry's privacy policy.
- Shorebird: mobile-app update checks and Dart-code patch delivery. See Shorebird's privacy policy.
- PostHog: cookieless website pageview analytics. See PostHog's privacy policy.
- Web3Forms: website support-form processing, spam prevention, and email delivery. See Web3Forms' privacy policy.
- Services you choose: self-hosted services, Trakt, Plex, cloud-drive providers, external links, and other destinations that you configure or open receive the requests and data you direct to them.
We may also disclose information when law requires it, to protect legal rights or safety, or as part of a merger, financing, acquisition, or sale of assets. We will limit any disclosure to the information relevant to that purpose.
Retention and deletion
- On-device app data: connection records remain until you remove the service or stack. Cached data remains until you clear it, the app evicts it, or the operating system removes it. On iOS, Kochab stores configuration in the device keychain and intends it to survive deleting and reinstalling the app on the same device. Removing the relevant connection or erasing the device clears that data; uninstalling alone may not.
- Relay notification bodies and Trakt token exchanges: the relay processes them in memory and does not retain them after completing the request.
- Relay technical records: revoking a device deletes its device row. An invalid push token is deleted after a delivery attempt reports it invalid. A device with a lapsed entitlement can remain in a disabled state so restored access can reuse its notification setup. Webhook and random relay-account records can remain after the last device is removed because webhooks belong to the relay account. We retain them until you revoke the hooks, we remove inactive records, or we complete a verified deletion request.
- Purchases: Apple, Google, and RevenueCat retain transaction and entitlement records under their policies and legal obligations.
- Diagnostics and analytics: Sentry, PostHog, Cloudflare, and Shorebird retain technical records under our configured settings and their retention schedules. We retain them only while they help us secure, operate, and improve Kochab or meet legal duties.
- Support: we retain support messages for as long as needed to answer the request, keep useful support history, resolve disputes, and meet legal duties. Web3Forms can retain form-submission data and server logs under its published retention schedule.
- Files you control: you control retention for exported backups and support bundles at the destination you choose.
We may retain a record longer when law requires it, a dispute requires it, or we need it to prevent fraud or abuse. We delete or de-identify data when the applicable purpose ends.
Security
Kochab minimizes the data sent to NDM Ventures and its providers. The app uses operating-system secure storage for credentials, supports HTTPS certificate verification and pinning, encrypts exported backups with your passphrase, hashes relay authentication secrets and entitlement identifiers, limits relay request size, and scrubs off-device diagnostics. Our website and hosted services use HTTPS.
You control the security of the self-hosted services, addresses, reverse proxies, and storage destinations you configure. If you approve a plain-HTTP connection, its traffic does not receive transport encryption. No storage or transmission system can guarantee complete security.
Your choices and privacy rights
- Remove a service or stack in the app to delete its stored connection data. Clear cached data from Settings.
- Grant or revoke Wi-Fi-name access and notification permission in system settings.
- Remove a registered notification device in Kochab. Disable notifications for a configured service to remove its webhook when the service supports automatic deprovisioning.
- Manage or delete backup and support-bundle files at the destination where you saved or shared them.
- Manage or cancel a purchase or subscription through Apple or Google.
Depending on where you live, you may have rights to know whether we process your personal data; access, correct, or delete it; restrict or object to processing; receive a portable copy; withdraw consent; and appeal a denied request. You may also appoint an authorized agent where law permits. Kochab makes no decisions that produce legal or similarly significant effects through automated processing.
Relay records use random or hashed identifiers instead of a name or email address. We may need you to use an authenticated app control or provide the relevant technical identifier so we can verify a request without exposing another person's records.
Email hello@kochab.io to make a privacy request. We may ask for information needed to verify the request and will respond within the period required by applicable law. EEA and UK residents may also complain to their local data-protection authority. California residents have the rights that apply under California law. NDM Ventures does not sell personal information, share it for cross-context behavioral advertising, or use sensitive personal information to infer characteristics. We will not discriminate against you for exercising a privacy right.
Children
Kochab is a tool for managing self-hosted servers and is not directed to children under 13 or a higher minimum age where local law applies. We do not knowingly collect personal information from a child who cannot consent under applicable law. A parent or guardian who believes a child submitted information through the website, email, diagnostics, or the app can contact us at hello@kochab.io to request its deletion.
International transfers
NDM Ventures operates from the United States. The providers listed above may process data in the United States, India, and other countries where they or their infrastructure providers operate. Those countries may have different privacy laws from your country. Where law requires a transfer safeguard, we use an applicable contractual safeguard or another lawful transfer mechanism. Contact us if you need information about a safeguard relevant to your data.
Changes and contact
We may update this policy as Kochab, its providers, or applicable law changes. We will post the revised policy here and change the date above. We may also provide an in-app notice when a material change affects mobile-app data.
For a privacy question or request, contact:
NDM Ventures, LLC
4809 W 41st St, Ste 202
Sioux Falls, SD 57106
hello@kochab.io