Kun

KUN · PRIVACY

Privacy policy

How the Kun website and unified account service handle your sign-in details, sessions, and request data.

Last updated

Operator: Kun 项目维护者

1. Scope

This policy describes personal information processing by the Kun website (www.kun-agent.com), the Kun unified account service (api-kun-server.com), and Kun sign-in features in web applications that integrate these services. The website provides product information, documentation, downloads, and release information; the unified account service provides email-code and Google sign-in, profiles, and application authorization.

Model requests, workspace files, plugins, and other third-party services in the Kun desktop application depend on the features and settings you use. The description of Google sign-in here does not mean that every desktop feature only processes sign-in information. Consult the relevant feature documentation and the privacy policies of your chosen providers.

2. Information accessed through Google sign-in

When you choose Google sign-in, Google verifies your identity. Through Google’s basic identity permissions, Kun and its authentication provider Supabase receive your Google account identifier, name, email address and verification status, profile picture URL, and other basic profile information to create or recognize your Kun account.

The current sign-in flow requests basic identity, email, and profile permissions (openid, email, and profile). These permissions do not allow Kun to read your Gmail messages, Google Drive files, calendar, or contacts. Google handles your Google password; it is not submitted to Kun as sign-in form data.

2.1 Email verification code sign-in

When you choose email-code sign-in, the email address you provide is used to deliver a one-time code, verify mailbox ownership, and create or recognize your Kun account. Supabase Auth generates and verifies the code. A sign-in session is established only after successful verification; a business profile is created when the profile endpoint is first accessed.

Cloudflare Email Sending processes the recipient address, message content, and delivery results to deliver authentication codes. These messages are for account authentication, not marketing. A code expires after 10 minutes and cannot be reused after successful verification.

The sign-in page uses Cloudflare Turnstile to reduce automated abuse. Your browser may retain the pending email address and send time in tab-scoped session storage to restore the form and countdown; the code you enter is not written to that storage. Email-code and Google sign-in follow the account storage, data use, application authorization, and sign-out practices described in this policy.

3. How information is used

Account information is used to sign you in, identify the current user, display your name, email, and avatar, and establish sessions in applications you authorize. Changes you make in the website’s personal center, such as your display name, are saved to your Kun profile.

When an independent application requests Kun sign-in, the consent page identifies the application and requested permissions. If you approve, the application receives the corresponding identity information and its own sign-in tokens. Applications using the Kun sign-in component manage sessions separately from the account center; signing out of an application does not also sign you out of the account center.

4. How information is stored

Supabase Auth manages account identities, authentication sessions, and authorization records. Kun’s Supabase database stores profile information such as an account ID, display name, avatar URL, and creation and update timestamps. The server reads and updates profiles using verified user identities.

Web applications using the Kun sign-in component, including versions of the official website with sign-in enabled, use browser sessionStorage for their application access token, refresh token, and sign-in validation state. The unified account center stores a separate session in browser storage on its own domain to maintain sign-in and refresh tokens. The website also uses localStorage for your language preference and sessionStorage to cache the public GitHub star count.

Clearing browser storage may sign you out or reset preferences, but does not automatically delete your server-side account, profile, or existing operational records.

5. Downloads, updates, and operational data

Cloudflare serves the website and account service. Hosting and authentication services process operational data such as IP addresses and browser request information when handling requests. Service logs support operations and troubleshooting.

The website also enables Cloudflare Web Analytics, which collects page views, referring sites, device and browser types, country, and page-load and performance metrics in the browser to understand visits and improve website performance.

When the website accesses the release-update endpoint, downloads an installer, or accesses the model-catalog endpoint, the existing analytics implementation writes an event date, hashes of the IP address and User-Agent, and Cloudflare-provided country, region, city, timezone, and data-center information to Supabase. Depending on the endpoint, records also include request paths, release versions or channels, installer names and formats, download ranges, response statuses, and error categories. Hashing does not make this information fully anonymous.

These records support download and update statistics and analysis of endpoint operation. The public statistics endpoint provides aggregate counts. To retrieve the GitHub star count or load avatars hosted by Google or other providers, your browser sends requests to those services, which receive normal network request information.

6. Information provided to services and applications

Google provides identity verification. Supabase provides authentication, application authorization, profile storage, and analytics storage. Cloudflare provides hosting and network services for the website, account endpoints, and downloads. These providers process information needed for their respective functions and have their own privacy policies.

Independent applications you authorize can receive the identity information requested for their sign-in features and approved by you. Whether an application deletes previously received information after you revoke access depends on its policy. Review the privacy information of third-party sites you visit through links on this website.

7. Your choices and account information

You can browse public product information and documentation without signing in. When using a web application with the Kun sign-in component, you can sign out of that application. You can also change your display name in the website’s personal center and revoke Kun’s access in your Google Account third-party connections settings. To revoke an authorized application’s access, contact us at the email address on this page.

Signing out or revoking authorization does not automatically delete stored account information. There is currently no automatic account-deletion function on this page. To request access, correction, or deletion, use the contact email provided on this page.

8. Changes to this policy

This page will be updated as sign-in and website features change, with a revised update date. Review the relevant information before using new account features or granting additional permissions.

Contact us

For privacy questions or requests to access, correct, or delete account information, contact the email address below. Do not include passwords, access tokens, or other secrets in your message.

zhongxingyuemail@gmail.com

Related services and account controls

Kun account center Google Account third-party connections Google · Privacy policy Supabase · Privacy policy Cloudflare · Privacy policy GitHub · Privacy policy