Kde
- The documents do not say whether your data trains AI.
- The policy rules out using your data for targeted ads.
- Data is shared only with the providers who run the service.
- The documents do not say who can read your content.
KDE collects account and log data for community sites; much of what you post is public and kept forever.
Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.
Collected
Account details, emails, IPs in logs, and optional extra profile info depending on the service.
Read the exact line
Privacy policy
“During this process, you'll be asked to provide your name and email address, along with a password, and be given the choice of a series of usernames.”
Training
They use it to run forums, bugs, git, wikis, donations, and to keep the sites working and secure.
Read the exact line
Privacy policy
“We collect personal information in order to provide you with services on our websites. This information is collected only where necessary to deliver those services as outlined below.”
Sharing
Admins see logs; many posts, names, and git commits are public; CDNs and PayPal may see traffic.
Read the exact line
Privacy policy
“As an open bug tracking system, your email address and your name, if you provided one, will be made publicly accessible to both logged in and users of the system.”
Kept
Server logs drop in 14 days; git, wiki, and Gitlab activity can be kept forever.
Read the exact line
Privacy policy
“These logs are only made accessible to system administrators who have responsibility for the smooth operation of our services, and are automatically removed from our systems after 14 days.”
Controls
You can often edit your profile yourself, or email sysadmin@kde.org about updates or removal.
Read the exact line
Privacy policy
“In most cases our services provide the ability for you to update your information on a self-service basis.”
Fine print
They say they will post a site announcement when the privacy policy changes in a real way.
Read the exact line
Privacy policy
“When this is done, except where the updates are minor (such as correcting typographical errors) we will post an announcement regarding the update on our website and detail the impact of the changes on you.”
Expand “Read the exact line” to see the source alongside the explanation.
What you can turn off
The controls and opt-outs their own documents describe, and where they say to find them.
Turn on Do Not Track or Matomo opt-out
Browser DNT setting or Piwik/Matomo opt-out cookie, as described in website statistics
Update your KDE Identity profile
KDE Identity site, self-service
Ask to update or remove information
Email sysadmin@kde.org or file a ticket (KDE Identity required)
Unsubscribe from mailing lists
Mailman's interface for the list
If a switch is not where they say, the deletion request above still applies.
Line by line
The lines that matter most, worst first.
Code you commit, including your name and email, becomes a public history they say they cannot rewrite.
Read the exact line
Privacy policy
“By entering commits into our repositories you acknowledge that the information contained in them will form part of the public record of open source development activity undertaken by the KDE Community”
For example, if you push a patch with your real email, that email can stay in git forever.
You generally cannot fix or erase old git or svn identity data.
Read the exact line
Privacy policy
“As a consequence of them being historical records, it is not possible to rectify them once they have been entered into our repositories as this would constitute a modification of the historical record”
For example, changing your name later will not remove it from old commits.
Bugzilla shows your email and name to anyone, even people who are not logged in.
Read the exact line
Privacy policy
“As an open bug tracking system, your email address and your name, if you provided one, will be made publicly accessible to both logged in and users of the system.”
For example, filing a bug can put your email on a public page.
List posts can go to other subscribers and public archives, including outside Europe.
Read the exact line
Privacy policy
“By sending an email to one of our mailing lists, you consent to us redistributing your message in this manner.”
For example, an email to a KDE list may show up on a third-party archive site.
Gitlab activity tied to your profile is kept with no end date.
Read the exact line
Privacy policy
“All these events will be associated with the respective Gitlab profile for the individual taking the action where this is possible, and this information will be retained indefinitely within Gitlab.”
For example, an old merge-request comment can stay on Gitlab forever.
Most Identity profiles stay private, but developers and e.V. members have name and email published.
Read the exact line
Privacy policy
“Profiles created on the KDE Identity platform are not made publicly accessible, with the exception of KDE Developers and Members of the KDE e.V., whose name and email address are made accessible to the public.”
For example, becoming a KDE developer can put your email on a public page.
Their own stats tool skips you if you send DNT or their opt-out cookie.
Read the exact line
Privacy policy
“Should your browser be configured to send either a Piwik/Matomo specific opt out cookie, or a standard Do Not Track (DNT) notice, then information on you will not be collected.”
For example, turning on Do Not Track in your browser means Matomo should not track you.
If you only browse without logging in, they mostly collect stats and short logs.
Read the exact line
Privacy policy
“With the exception of website statistics, donations and regular server logging, no information is collected from people accessing our services over the web who have not logged into them.”
For example, reading kde.org without an account should not create a named profile.
Full IP server logs are limited to admins and deleted after two weeks.
Read the exact line
Privacy policy
“These logs are only made accessible to system administrators who have responsibility for the smooth operation of our services, and are automatically removed from our systems after 14 days.”
For example, the IP from visiting a page should drop from logs after 14 days.
Bigger privacy-policy changes should be announced on the site with what they mean for you.
Read the exact line
Privacy policy
“When this is done, except where the updates are minor (such as correcting typographical errors) we will post an announcement regarding the update on our website and detail the impact of the changes on you.”
For example, a new service that collects more data should get a website announcement.
Words to know
Legal words from the lines above, in plain English.
- personal data
- Any information that is about you or can be linked to you, from your name to your phone's ID. For example, your email, your IP address and the list of apps on your phone are all personal data.
- de-identified
- Data with your name and obvious identifiers removed, though it can sometimes still be traced back to you. For example, your chats with names stripped out may still be kept and studied after you delete your account.
- consent
- Your clear agreement to something, given by an action like ticking a box or tapping Accept. For example, a pop-up asking if the app may use your location is asking for consent.
- opt out
- Something is on by default and stays on until you find the setting and turn it off. For example, your chats may be used for training unless you go into settings and switch it off.
- cookies
- Small files a website saves on your device so it can recognise you and remember what you did. For example, a cookie keeps you logged in and can also tell an ad company which sites you visited.
How we got here · grade C · score 46/100 · 15 of 15 policy answers backed by a verified quote · 8 not stated
What does the app collect beyond what it needs to work?
Besides account details, they log IPs, user agents, and Matomo stats, plus extra profile fields on some services.
Does it record your voice, face or body, and what happens to that?
The policy does not describe collecting voice, face, or body data.
Are your chats and uploads used to train AI models, and is that off by default?
Not stated in the documents.
Can employees or contractors read your conversations, and when?
Not stated in the documents.
Are you profiled or tracked for advertising?
They use self-hosted Matomo for stats with DNT opt-out, and do not describe ads or ad trackers.
Do they sell or share your data, and can you opt out?
They use CDNs, a firewall, DNS, and PayPal; they do not say they sell data. Public community posts are shared by design.
What rights do they take over what you type and what the AI makes?
Not stated in the documents.
How long do they keep your data after you delete it, and can you delete it in the app?
Some logs last 14–30 days, but git, wiki, Gitlab, and Phabricator records can be kept indefinitely.
Does it build a lasting memory or profile of you, and can you see, edit or turn it off?
Not stated in the documents.
Do they commit to basic security, and have they leaked data?
They describe limited admin access to logs and short log retention for security.
Is there a real age gate, and are teens protected?
Not stated in the documents.
Will they tell you when the rules change, and is the policy specific?
The policy text has no date; they say they will announce non-minor changes on the website.
Can they close your account without warning, and can you get your data out first?
Not stated in the documents.
If something goes wrong, who pays?
Not stated in the documents.
Do subscriptions renew on their own, and can you get a refund?
Not stated in the documents.
The privacy policy is 4,486 words at a professional or legal expert level (Flesch reading ease 23.1).