KBeat Suite

Privacy Policy

Effective September 22, 2026

1. Scope

This policy explains how KBeat Suite ("KBeat") handles information through its public website and desktop applications. KBeat consists of separately installable KDE Plasma applications and the optional KBeatDav server. Features you do not install or enable do not collect or process data on KBeat's behalf.

2. The public website

The KBeat website is a static information site. It does not use accounts, advertising, analytics, tracking pixels, behavioral profiling, or nonessential cookies. The web server or content-delivery provider may process ordinary connection information such as IP address, user agent, requested path, and timestamp for delivery, security, and short-lived operational logging.

3. Information handled by the applications

FeatureInformationPurposeWhere it goes
Calendar and TasksEvents, tasks, calendar names, server addresses, and account credentials you configureDisplay, edit, notify, and synchronize your calendars and task listsStored locally and exchanged directly with the CalDAV or KBeatDav server you chose
Weather and pollenLocation and provider credentials you configureRetrieve forecasts, conditions, and pollen informationSent directly to the selected weather provider
JournalYour entries, templates, search index, mood and health selections, and profile settingsProvide private daily writing, search, reminders, and optional synchronizationEncrypted before local storage; optional KBeatDav sync receives encrypted objects and associated synchronization metadata
ScrapsThe Markdown notes and metadata you createCapture, search, organize, and optionally synchronize quick notesStored locally; optional KBeatDav sync stores plaintext notes, which the server operator can read
Mail indicatorGoogle account email address, OAuth authorization, and the Inbox label's aggregate unread countShow whether a connected Gmail Inbox contains unread mailAuthorization is stored locally; requests go directly to Google

4. Google user data

The optional KBeat Mail indicator requests the minimum Google access used by the feature: OpenID identity, email address, and Gmail label access. It calls the Gmail API only to retrieve the aggregate unread-message count for the INBOX label.

KBeat Mail does not request, list, download, display, or store message subjects, senders, recipients, headers, bodies, attachments, or message identifiers. It cannot compose, send, modify, move, or delete mail.

How Google data is stored

How Google data is shared

KBeat does not sell, rent, advertise against, or share Google user data with data brokers or unrelated third parties. Data is exchanged with Google only to authorize the account, identify the connected email address, and read the Inbox label count requested by the user.

KBeat's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. Local storage and credentials

KBeat stores application data under the operating system account running it. Private provider addresses, passwords, API keys, and OAuth refresh tokens use the desktop Secret Service where supported. KBeat does not provide a plaintext credential fallback. Anyone who controls your desktop account, Secret Service, KBeatDav host, reverse proxy, or backups may be able to access information available to that system.

6. Optional synchronization

You choose whether to connect third-party CalDAV services or KBeatDav. A self-hosted KBeatDav instance is operated by you or your chosen administrator, not by a centralized KBeat service. Calendar, Tasks, and remotely synchronized Scraps data are not end-to-end encrypted by KBeatDav. Journal content is encrypted before synchronization, although synchronization metadata is still required to operate the service.

7. Retention and deletion

Local information remains until you remove it through KBeat, delete the corresponding application data, or uninstall and clean up the relevant user data. Disconnecting a Google account from KBeat removes its locally saved account registration and refresh authorization. You may also revoke KBeat's authorization from your Google Account. Provider-side data remains subject to that provider's controls and retention practices.

Backups, filesystem snapshots, Secret Service backups, and independently operated KBeatDav servers may retain copies until their own retention periods expire. KBeat does not control those systems.

8. Security

KBeat uses bounded network requests, provider-scoped authorization, operating-system credential storage, encrypted Journal files, and explicit trust boundaries. No software can guarantee absolute security. Keep your operating system, KBeat packages, Secret Service, reverse proxy, and server backups protected and current.

9. Children

KBeat is general-purpose productivity software and is not directed to children. The project does not knowingly collect children's personal information through its website.

10. Changes to this policy

This policy may change when KBeat adds or materially changes a data-handling feature. The effective date above will be updated, and material changes will be described with the corresponding software release.

11. Contact

Questions about this policy or KBeat's handling of data may be sent to uglyegg@entropy.quest.