Effective 22 July 2026
kimi web server that you run on your own computer — your data
never passes through us, because there is no “us” in the middle.
This policy explains how the Kay Remote mobile app (“Kay Remote”, “the app”, “we”) handles information. It applies to the iOS and Android versions of the app.
Kay Remote is an independently developed app. It is a remote control for the Kimi Code command-line tool and is not affiliated with, endorsed by, or operated by Moonshot AI. We do not run any backend service for the app.
Nothing. We do not collect, receive, store, sell, or share any personal data. The app has no analytics, no advertising, no crash-reporting SDKs, no cookies, and no account system. You do not create an account and you do not give us any information.
To connect to your server, the app saves two things locally on your device, using the operating system’s standard app storage:
http://100.x.y.z:58627), andThis information stays on your device. It is never transmitted to us and we have no way to access it. Removing it is covered under “Deleting your data” below.
Kay Remote communicates only with the server address you configure —
the kimi web server running on your own computer, reached over your local
network or your private Tailscale network. Everything you see in the app (sessions,
chat, tool output, files) is served live by your machine and travels directly
between the app and your server. It does not pass through any server operated by us or
any third party. There is no middleman service and no telemetry.
The app can use your device camera for a single purpose: scanning the pairing QR code so the server URL and token can be filled in automatically. The camera image is processed on-device to read the code and is never stored or transmitted. You can decline the camera permission and enter the connection details manually instead.
The app includes no third-party analytics, advertising, or tracking services, and it does not share data with anyone. The only network destination is the server you choose.
Kay Remote is a developer tool intended for a general, professional audience. It is not directed to children, and because it collects no data, it collects no data from children.
Because we hold no data about you, there is nothing for us to delete. To remove the
connection details stored on your device, disconnect within the app or delete the app —
this clears the stored server URL and token. To invalidate a token on the server side,
run kimi web rotate-token on the computer running the server.
Your server URL and token grant access to your sessions and files, so treat the token like a password. Keep your server reachable only over your private network or Tailscale, as recommended in the app’s setup instructions. Kay Remote does not weaken or bypass any of your server’s authentication.
If this policy changes, we will update the page and the “Effective” date above. Material changes will be reflected here before they take effect.
Questions about this policy? Email 92combo@gmail.com.