Source + posture
Kanade is self-hosted. The desktop app runs on the operator’s Windows machine, the daemon binds loopback by default, and public web properties do not host the workstation.
The default privacy model is local:
- hooks append to local JSONL,
- the daemon stores local SQLite and markdown memory,
- provider credentials stay in local config or environment,
- bug-report links are opt-in through
KANADE_BUG_REPORT_URL, - no product telemetry is sent by default.
Private alpha means distribution is intentionally narrow. There is no public installer surface, signup form, invite path, or tester onboarding flow in these docs. The maintainer update channel exists so releases can be verified on the real installed target.