Privacy

What Kato reads, what stays, what leaves.

Kato is an app that reads the text on your screen, so this page errs on the side of saying too much. It is written to match what the code does. Where the app can prove a claim mechanically — the egress ledger, the export command — we say so and prefer that you check.

On your Mac (the app)

What Kato reads. With your permission, Kato reads on-screen text through the macOS Accessibility API and, if you grant it, call audio for on-device transcription (whisper.cpp on Metal). The audio never leaves this Mac. The transcript text does go to the brain, like any other text Kato reads, so it can write the recap and the follow-up: secret-scrubbed for keys, cards and emails, logged in the egress ledger, and blocked entirely for a sealed space. Names and business detail go as written — sealing a space is what keeps a call's content on this Mac. Secure text fields — passwords and the like — are excluded by the OS and additionally skipped by Kato. By default Kato takes no screenshots and runs no OCR: it reads the same text a screen reader gets. There is an optional per-app deep read, off unless you enable it from Terminal, and every use of it is logged.

Where it lives. The day journal is encrypted at rest on your Mac. Your memory is plain local files you own, under ~/kato. kato export ~/kato writes the whole thing out as a plain-file bundle you own — a SHA-256 manifest and a copy of the on-disk format doc included. The journal lines stay encrypted in it, and your Mac's key opens them. We never hold a copy; if you cancel, everything stays with you.

What leaves, and how you can tell. Kato keeps an egress ledger: every cloud call the brain makes is logged with provider, size and hash, and shown to you in the app. The brain's calls are:

Four things sit outside the ledger: the one-time model download from huggingface.co, the one-request key check against api.anthropic.com when you paste your own key, and — only if you pick those hands — a draft you send to WhatsApp, which travels inside the wa.me link Kato opens for you, and a hand-off to a coding agent, where the pack goes to that agent on your Mac and whatever it sends next is its own. The first two carry nothing from your memory; the last two are work you chose to hand over.

Spaces you seal never leave the Mac — their content is excluded from every AI call. The Blind Kato switch in the menu bar stops capture instantly. These aren't policy promises: only four listed files in the brain library may make an HTTP request, and CI checks that.

On this website

We use PostHog for page analytics with autocapture and session recording off, and Do Not Track respected. Anonymous events only — a person profile is created solely if you submit your email, and then only to send you the download link. The email goes to our sending provider (Resend) for that purpose.

Payments run through Stripe; we never see your card number. Billing runs on Kato's own Stripe account, so the name on your statement is INSTALLKATO.COM.

What we don't do

Questions or deletions

Email a human: iam@armando.mx. If you gave us your email and want it gone, one message and it's deleted from our contact list.

Last updated September 11, 2026. If this page and the app's behavior ever disagree, that's a bug — tell us and we'll fix whichever one is wrong.