KBeat Suite
Privacy Policy
Effective September 22, 2026
In plain language: KBeat is local-first software. The website does not track you. The applications contact a provider only when you configure that integration. The optional Gmail indicator reads an aggregate unread count—not your messages.
1. Scope
This policy explains how KBeat Suite ("KBeat") handles information through its public website and desktop applications. KBeat consists of separately installable KDE Plasma applications and the optional KBeatDav server. Features you do not install or enable do not collect or process data on KBeat's behalf.
2. The public website
The KBeat website is a static information site. It does not use accounts, advertising, analytics, tracking pixels, behavioral profiling, or nonessential cookies. The web server or content-delivery provider may process ordinary connection information such as IP address, user agent, requested path, and timestamp for delivery, security, and short-lived operational logging.
3. Information handled by the applications
| Feature | Information | Purpose | Where it goes |
|---|---|---|---|
| Calendar and Tasks | Events, tasks, calendar names, server addresses, and account credentials you configure | Display, edit, notify, and synchronize your calendars and task lists | Stored locally and exchanged directly with the CalDAV or KBeatDav server you chose |
| Weather and pollen | Location and provider credentials you configure | Retrieve forecasts, conditions, and pollen information | Sent directly to the selected weather provider |
| Journal | Your entries, templates, search index, mood and health selections, and profile settings | Provide private daily writing, search, reminders, and optional synchronization | Encrypted before local storage; optional KBeatDav sync receives encrypted objects and associated synchronization metadata |
| Scraps | The Markdown notes and metadata you create | Capture, search, organize, and optionally synchronize quick notes | Stored locally; optional KBeatDav sync stores plaintext notes, which the server operator can read |
| Mail indicator | Google account email address, OAuth authorization, and the Inbox label's aggregate unread count | Show whether a connected Gmail Inbox contains unread mail | Authorization is stored locally; requests go directly to Google |
4. Google user data
The optional KBeat Mail indicator requests the minimum Google access used by the feature: OpenID identity, email address, and Gmail label access. It calls the Gmail API only to retrieve the aggregate unread-message count for the INBOX label.
KBeat Mail does not request, list, download, display, or store message subjects, senders, recipients, headers, bodies, attachments, or message identifiers. It cannot compose, send, modify, move, or delete mail.
How Google data is stored
- The connected email address and OAuth client identifier are stored in KBeat's local settings.
- The OAuth refresh token is stored in the desktop system's Secret Service, such as KeePassXC.
- Short-lived access tokens exist only in the background checker's process memory and are discarded when that process exits.
- The last aggregate unread count, check time, and connection state are stored in a private local cache so the desktop indicator can remain responsive.
How Google data is shared
KBeat does not sell, rent, advertise against, or share Google user data with data brokers or unrelated third parties. Data is exchanged with Google only to authorize the account, identify the connected email address, and read the Inbox label count requested by the user.
KBeat's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Local storage and credentials
KBeat stores application data under the operating system account running it. Private provider addresses, passwords, API keys, and OAuth refresh tokens use the desktop Secret Service where supported. KBeat does not provide a plaintext credential fallback. Anyone who controls your desktop account, Secret Service, KBeatDav host, reverse proxy, or backups may be able to access information available to that system.
6. Optional synchronization
You choose whether to connect third-party CalDAV services or KBeatDav. A self-hosted KBeatDav instance is operated by you or your chosen administrator, not by a centralized KBeat service. Calendar, Tasks, and remotely synchronized Scraps data are not end-to-end encrypted by KBeatDav. Journal content is encrypted before synchronization, although synchronization metadata is still required to operate the service.
7. Retention and deletion
Local information remains until you remove it through KBeat, delete the corresponding application data, or uninstall and clean up the relevant user data. Disconnecting a Google account from KBeat removes its locally saved account registration and refresh authorization. You may also revoke KBeat's authorization from your Google Account. Provider-side data remains subject to that provider's controls and retention practices.
Backups, filesystem snapshots, Secret Service backups, and independently operated KBeatDav servers may retain copies until their own retention periods expire. KBeat does not control those systems.
8. Security
KBeat uses bounded network requests, provider-scoped authorization, operating-system credential storage, encrypted Journal files, and explicit trust boundaries. No software can guarantee absolute security. Keep your operating system, KBeat packages, Secret Service, reverse proxy, and server backups protected and current.
9. Children
KBeat is general-purpose productivity software and is not directed to children. The project does not knowingly collect children's personal information through its website.
10. Changes to this policy
This policy may change when KBeat adds or materially changes a data-handling feature. The effective date above will be updated, and material changes will be described with the corresponding software release.
11. Contact
Questions about this policy or KBeat's handling of data may be sent to uglyegg@entropy.quest.