Privacy policy
Kunai is a fun open-source project — a bet on how far a terminal and a hobby codebase can actually go. Nobody here wants to know what you watch, and the architecture is built so nobody can.
Last updated October 2, 2026. Effective October 2, 2026.
1.The deal
Kunai is a hobby open-source terminal client. It finds a stream someone else is already hosting and hands it to mpv. The CLI and this docs website are both covered here, as two separate things.
2.Scope
This policy covers:
- — The CLI: setup, playback, history, lists, the queue, downloads, diagnostics, and the optional usage ping.
- — The docs website, including ordinary pages and share links under
/w/.
mpv, stream providers, Discord, npm, GitHub, and Vercel are other people's services. Section 7 says what they receive from you.
3.Controller
Kunai has no legal entity. No company, no registered office, no data-protection officer. The maintainer of this hobby project is the controller: the person who decides what the CLI and the website do with data. Reach them through GitHub issues and discussions on KitsuneKode/kunai. A street address would be fiction, so none is printed here.
4.What never leaves
The CLI is local-first. Watch history, lists, the queue, downloads, searches, stream URLs, and file paths stay on your machine. No accounts. No sync. Kunai does not upload them.
Diagnostics stay local. An exported bundle is redacted on the way out: no stream URLs, no cookies, no authorization headers, no private paths.
A search or a play press goes from your machine to a provider. The maintainer does not get a copy. The provider does.
5.The one thing you can turn on
Usage analytics are opt-in only. No code path can enable them without an explicit action from you. Skipping setup leaves them off. On, current builds send at most one ping a day:
- — sha256 of a local install id (the id itself stays on the machine)
- — version
- — operating system
- — architecture
- — timestamp
No titles, queries, providers, stream URLs, or file paths. The hash can tie one day to the next until you rotate the id or turn this off.
Pings go to analytics.kunai.kitsunekode.in. You can point them at a self-hosted https endpoint instead. The ingest server has no code path that reads a client IP address. Raw rows are deleted after 35 days. The lifetime figure outlives those rows — it is a cumulative count of observations, not of unique people, and reinstalls, rotated ids, and invented ids all move it.
Turning it off deletes the local install id. Rotate id is available while it stays on; older pings do not follow the new id. DO_NOT_TRACK=1 or CI=true hard-block sends, even if the setting is on. Everything we publish sits on the public analytics page; the full contract is Reliability and privacy.
6.What this website sends
The docs website, not the app, sends page views to Vercel Analytics and web-vitals to Vercel Speed Insights. Cookieless. No cross-site tracking. URLs under /w/ are share links that name a watched title — they are filtered out before the send.
Kanna wanders this site; she does not take notes.
7.Third parties
- — Stream providers receive your request directly — search, playback, and downloads included — and they see your IP address. No proxy and no relay in front of the video. That is the design.
- — Discord Rich Presence is off by default. On, it uses local IPC to the Discord app on your machine. Full presence includes the title. Private mode leaves the title out.
- — npm and GitHub see a download the way they see any other package or release.
8.Your rights
Where a GDPR-style law applies, you can seek access, correction, erasure, and a stop. Where the CCPA applies, you can seek to know, to delete, and to opt out of sale. We cannot identify you, so access and erasure mostly resolve themselves.
Your library is on your computer; we have no copy to show, correct, or return. The opt-out is the erasure: turning analytics off deletes the local id and new pings stop, raw rows already stored are deleted after 35 days, and the lifetime count that remains has no name on it. “Delete me” has no row to find. We do not sell personal information, we do not share it for cross-context advertising, and the website sets no analytics cookie.
9.Children's privacy
Kunai is not directed at children. We do not knowingly collect personal information from them.
10.International processing
CLI library data stays on the machine you installed it on. An opt-in ping is processed at analytics.kunai.kitsunekode.in, or at the https endpoint you configured. Page views and web-vitals from this website are processed by Vercel in the United States and in the other regions where Vercel runs Analytics and Speed Insights.
11.Disclaimer
Kunai is a client-side playback tool. It does not host, upload, mirror, seed, or distribute content. Streams come from non-affiliated third-party providers. There is no guarantee of provider uptime, catalog, legal availability, or subtitle accuracy. Copyright belongs to the providers. Beta software, hobby project, no warranty — the full text lives at the disclaimer.
12.Changes to this policy
This policy lives in a public git repository. The commit history is the changelog; when the words change, the diff is the notice. Kanna does not run a mailing list.
13.Governing law
There is no legal entity, so this policy picks no country, no court, and no venue. It does not remove a privacy right you already have where you live.
14.Contact
Something here that reads wrong — or worse, a claim the code does not keep — is a bug report, not a support ticket: GitHub issues and discussions on KitsuneKode/kunai.