Privacy
Privacy policy
Your library and settings stay on your computer. Optional integrations, downloads, updates, and beta usage counts make the direct requests explained below.
Draft policy. This plain-language summary reflects how Kioku works today and has not yet been legally reviewed.
No Kioku account or cloud library
Kioku does not have user accounts or a hosted copy of your library. The app does not send your library, watch history, provider account data, or settings to us.
Local storage
Your library, watch progress, settings, and backups are stored in a local SQLite database and local files on your computer. Kioku has no remote copy to restore, so back up your data before deleting the app's data folder.
Metadata and airing information
Kioku requests anime metadata from the tracking service you search or connect. Its weekly schedule uses AniList's public airing metadata even when another service is active. Requests can include provider IDs or titles needed to find a match, and results are cached on your computer.
Third-party sync services
If you connect AniList, Kitsu, or MyAnimeList, you choose one connected service for two-way library sync. Other connected services can still be used for search and read-only list previews.
Saved OAuth app credentials and connection tokens are encrypted with your operating system's secure storage and kept on your device. Tokens are sent to the service that issued them when Kioku makes an authenticated request. On Linux this needs a working secret service such as GNOME Keyring or KWallet; without one, Kioku will not save credentials at all.
Each service's own privacy policy applies to the data you share with it. You can disconnect a service at any time.
Feeds and downloads
If you add an RSS feed or Torznab source, Kioku connects directly to the address you configure. API keys are stored in the encrypted credential vault.
If you enable Kioku's built-in WebTorrent client, downloads use private peer discovery through the distributed hash table (DHT) by default and do not announce to trackers. Two optional features announce to public trackers instead: a discovery setting you can turn on for regular downloads, and streaming a release you choose. Kioku blocks each until you accept a one-time in-app privacy disclosure. Torrent peers can see your IP address, as with other torrent software.
If you choose qBittorrent instead, Kioku connects to the Web API address you configure and stores that username and password in the same encrypted vault. The signed-in session stays in Kioku's main process and is never exposed to the interface. qBittorrent itself owns its own trackers, peers, and seeding behavior.
Updates
Eligible packaged builds ask once whether Kioku may check for updates automatically; if you decline, manual checks stay available in Settings. Update checks and downloads go to downloads.kioku.moe, Kioku's release host on Cloudflare R2. Cloudflare may process your IP address and request metadata transiently to serve those files. Development, test, and unpacked local builds do not check for updates.
Optional aggregate product-improvement data
Beta builds can share optional aggregate product-improvement counters after you explicitly turn the setting on. It is off by default, beta access does not depend on it, and activity before consent is not saved for later upload.
The payload is limited to a UTC day, Kioku version, operating-system family, beta channel, and counts of allowlisted setup, playback, franchise-continuation, and upgrade-report actions. Some counters include a coarse success, failure, or reason category. Kioku does not include anime titles, provider content, filenames, paths, release names, URLs, torrent identifiers, playback history, free-form text, logs, crash dumps, or a stable installation, account, device, or advertising identifier.
Counters are aggregated on your computer before they are sent to telemetry.kioku.moe. Aggregate rows are retained for up to 90 days, and random retry batch IDs are retained for up to seven days to prevent duplicate counting. Turning the setting off immediately deletes counters still waiting on your computer. Already accepted aggregates cannot be separated or deleted by device because no stable device identity is collected.
The collector runs on Cloudflare Workers and D1. Cloudflare may process IP addresses and request metadata transiently to deliver and protect the endpoint, including rate limiting. Kioku does not store IP addresses, user agents, or request headers in the product-learning database, and the Worker does not log request bodies.
These aggregate counts are directional and can be spoofed. Kioku does not use them for person-level tracking or join them to a beta tester roster.
Feedback, diagnostics, and crashes
Feedback email is separate from product-improvement counters. Kioku shows the exact subject and body before it opens your mail app, and it never attaches diagnostics automatically.
Diagnostics are saved locally for you to review. Runtime details, aggregate health checks, and crash-file counts and timestamps are included by default. Application logs are optional and off by default because even sanitized logs may contain anime titles, filenames, paths, or release names. Native crash dump files are never attached automatically.
Logs and native crash dumps otherwise stay on your device and only leave it if you choose to share them.
This website
This site is static. It sets no cookies and runs no analytics scripts. The download page requests the release manifest from downloads.kioku.moe, the same Cloudflare-hosted release host the app uses for updates, to check whether a public release exists; Cloudflare may process your IP address and request metadata transiently to serve it. Our hosting provider may keep standard access logs to operate the site.
Contact
Questions about privacy? Email [email protected].
Draft last updated September 4, 2026.