Karnex Privacy Policy
Karnex is a remote support and device management service operated by Karnytine Labs LLC ("Karnytine Labs", "we", "us"). This policy explains what information Karnex collects, why, who it is shared with, and the choices you have. It covers karnex.org, the Karnex console, the Karnex Agent installed on managed computers, the Karnex Viewer (the desktop app for Windows and Linux, and any later macOS build, and the Karnex Viewer app for Android), KarnexDesk (support ticketing, including karnexdesk.com, organizations' support portals such as yourcompany.karnexdesk.com, and the "Get help" window on managed computers), and Kara, our AI assistant. The Android app stores your sign-in token and display preferences on your device; it does not collect location, contacts, photos, advertising identifiers or analytics.
1. Who this applies to
Karnex is used by organizations (our customers) to support and manage computers. There are two groups of people whose information we handle:
- Account holders and their teammates who sign in to the console.
- People who use computers managed through Karnex. The organization that installed the Karnex Agent decides how it is used on those computers and is responsible for telling its own users about it. If you are using a computer that is managed with Karnex, please direct questions about that management to your organization or IT provider.
- People who ask an organization for help through KarnexDesk — by email, on the organization's support portal, or with "Get help" on a managed computer. We handle this information on behalf of that organization, which decides how it is used; questions about a request should go to the organization you contacted.
2. Information we collect
| Category | What | Why |
|---|---|---|
| Account | Name, email address, job title, password (stored only as a salted hash), two-factor authentication secret and backup codes (stored protected), and for any security key you add, the name you give it and the key's public credential (never a secret; used only to check your sign-ins), and for any Microsoft or Google account you connect for sign-in, that provider's identifier for you and the account's email address, the date you accepted our policies, and whether your email is verified. | To create and secure your account and to contact you about the service. |
| Organization | Organization name, team members and their roles and permissions, plan and subscription status, optional logo and subdomain. | To provide the console, access control and billing. |
| Managed computers | From the Karnex Agent: computer name, operating system and version, manufacturer, model, serial number, processor, memory, boot time, the signed-in username, network address, MAC address, agent version and last-seen time; free disk space and processor load; and, on Linux, the desktop type (Wayland, Xorg or text console). The name you give the machine, its site and notes your team writes about it. | To show your fleet, let you connect to the right computer, keep the agent up to date, and raise the monitoring alerts you set up (low disk, high processor load, offline). |
| Monitoring | The alert rules your Org Admin sets, the alerts raised, and the email address alerts are sent to. For service and event-log monitors (RMM Automation add-on), a check runs on the computer every 5 minutes and returns whether each watched service is running and how many matching events appeared, with the newest matching event's ID, source and the first 160 characters of its message (which can include names the computer logged, such as a username); these checks are kept for a day, and alert details as long as the alert. Script monitors run a script your team saved on each covered computer on the schedule it sets; we keep each run's exit code and output for a day, and the last line of a failing run's output as the alert's detail. Disk-health and battery-wear monitors use the daily hardware inventory (below). If a rule is set to open a KarnexDesk ticket, the ticket holds the alert's details and the computer it is about. Scheduled reports your admins set up (which report, when, and the email addresses it goes to); each one is emailed through our email provider to those addresses with the report's data (machine details, patch status or alerts) attached. | To tell you when a computer needs attention. |
| Remote sessions | Who connected to which computer, when, and for how long. We do not record or store the live content of a remote session: it is end-to-end encrypted between the computer and the operator's viewer (see section 5). The one exception is a recording an operator chooses to make (next row). | To operate sessions, enforce plan limits and keep an audit trail. |
| Session recordings (optional, Karnex Elevate) | If an operator uses "Record video" in the Karnex Viewer, a silent video of the remote screen as the operator saw it is uploaded from their viewer over TLS, converted to a compressed video, and stored for the organization, together with the computer, operator, date, length, resolution and size. If your organization has set a recording passphrase, the recording is encrypted on the operator's device before upload and we store it without being able to read it; only people who know the passphrase can watch it. Otherwise, unlike a live session, a recording is not end-to-end encrypted to our servers, because they must process and play it back. Who viewed, downloaded or deleted a recording is logged. The operator's own viewer also keeps a copy on their device. | To give the organization a reviewable record of support sessions for compliance and quality. Nothing is recorded unless an operator starts it. |
| Local admin passwords (optional, Endpoint Security add-on) | If an Org Admin turns on local admin password rotation, the name of the managed local admin account on each computer and its current and previous password. Each computer creates its own password and sends it encrypted; we store it encrypted and show it only to the organization's Org Admins and Admins, recording each time it is revealed. It is deleted with the computer or the organization. | |
| BitLocker recovery keys (optional, Endpoint Security add-on) | If an Org Admin turns on BitLocker key backup, each Windows computer's BitLocker recovery passwords, their key IDs, which drive they belong to and whether each drive is protected. Each computer sends its keys encrypted; we store them encrypted and show them only to the organization's Org Admins and Admins, recording each time one is revealed. They are deleted with the computer or the organization. | |
| Compliance checks (optional, Endpoint Security add-on) | If an Org Admin turns on compliance checks (or runs one), each computer's operating system and version, antivirus products and whether they are on and up to date, firewall and User Account Control state, disk-encryption state, whether a restart is pending, and the names of its local administrator accounts. Shown only to the organization's Org Admins and Admins; the newest result per computer is kept and deleted with the computer or the organization. | |
| Software and hardware inventory (RMM Automation add-on) | Once a day, the name, version and publisher of the programs installed on each covered computer, and its hardware facts: disks (model, size, health), battery capacity, make, model and firmware date. Shown to your organization in reports and monitors; the newest collection per computer is kept and deleted with the computer or the organization. | |
| Network discovery (optional) | When your team scans a network: the addresses that answered, their MAC addresses and names, which common ports were open and, if a community was given, their SNMP names. Kept for 30 days in the console list, deleted with the organization. | |
| Network devices (optional) | For devices and sites your team monitors: their name, address (or website link) and type; for SNMP devices the community (stored encrypted) and what they report (name, description, uptime, printer toner); for ping, TCP-port and website checks the latest response time; and the up/down history of each. The checks are run by a computer with Karnex on the same network. Deleted when your team removes the device or with the organization. | |
| IT documentation and password vault (optional) | Notes your team writes about clients and machines, and the credentials it stores in the password vault (name, username, link, notes and the secret). Vault secrets are stored encrypted and shown only to the people the entry is shared with, recording each time one is revealed. Documents and vault notes are stored as written (not encrypted beyond our normal storage). Deleted when your team deletes them or with the organization. | |
| Commands and scripts | Commands and scripts your team sends to a computer, who sent them, when, and the output returned — including the installed-software list, Windows Update status and security status (antivirus, firewall, BitLocker; on Linux, the installed packages, pending package updates, firewall, disk encryption, AppArmor/SELinux, automatic updates, ClamAV and SSH sign-in settings) a technician looks up from a machine's Software, Updates and Security tabs. Uploaded script files. Automation tasks, patch policies, software deployments and app-update policies your admins set up (including installer links and the installed-app lists and versions they report) (what runs or which updates are approved, on which machines, and when or on which monitor alert), their run history, and patch-compliance results (updates still missing, last install result, restart pending). | To deliver and run them, show results, and keep an audit trail. |
| Support tickets (KarnexDesk) | For organizations that use KarnexDesk: the requester's email address and name, the email addresses of other people copied on a request (from the email's To and Cc lines, or added by the organization's team), who then receive copies of its public replies, the messages, notes and replies on each request, answers to the organization's request forms, the computer and client a request is about, who worked on it and what changed, and the requester's satisfaction rating and comment, the time team members log on it (how long, billable or not, and a note), the values of the organization's own custom fields on it, and which of its requests are linked to each other. If an organization shows its logo in its ticket emails, the logo is loaded from karnex.org when the email is displayed, so our servers receive that request like any other web request; we don't use it to track whether emails were read. Email sent to an organization's KarnexDesk address arrives through our email provider and becomes a ticket. An organization can block senders; email from a blocked address or domain is discarded and not kept. People an organization invites to its support portal sign in with emailed links; we keep their email, name and which client they belong to. | To let the organization receive, answer and track requests, and to email the people involved. |
| "Get help" requests | When someone uses "Get help" on a managed computer: what they typed, the email and name they choose to give, the signed-in Windows user, and computer details (operating system, memory, uptime, free disk space, network addresses and agent version). A screenshot of their screen is included only if they tick the box; it is stored with the ticket (encrypted at rest) and only the organization's technicians can open it. | So the organization knows which computer needs help and what state it is in. |
| Help articles (KarnexDesk) | Articles an organization writes. Articles it marks public are shown on its support portal to anyone who visits; we count views and "Was this helpful?" answers. | To let organizations publish self-help for their users. |
| Kara (AI assistant) | What you type to Kara in the chat on karnex.org, and, if you choose "Talk to a person", the email, name and note you give; that conversation then becomes a request to the Karnex team. When a technician chooses "Draft with Kara" or "Improve with Kara" on a ticket, the ticket's content is used to write a suggested reply (see section 4). | To answer questions about Karnex and to help technicians write replies. Kara's replies are suggestions: a person reviews a draft before it is sent. |
| Billing | Handled by Stripe. We keep the Stripe customer and subscription identifiers, plan, and payment status. We do not receive or store full card numbers. | To charge for the service and handle non-payment. |
| Technical data | IP address and request details in server logs, and security events such as failed sign-ins. | To operate, secure and troubleshoot the service and prevent abuse. |
| Sign-up records | A one-way record of the email address used for a free trial (with any "+tag" removed) that remains after an account is deleted. | To prevent repeated free trials. |
Karnex does not use advertising or third-party analytics trackers. The console keeps your sign-in token in your browser's local storage so you stay signed in; it does not use advertising cookies.
3. How we use information
- To provide, maintain and secure Karnex, including sign-in, sessions, scripts, support ticketing, billing and support.
- To run Kara, our AI assistant, when you chat with her or when a technician asks her to draft a reply.
- To send service emails: email verification, password resets, payment and account notices, and quotes you request. We do not send marketing email without your consent.
- To detect and prevent fraud, abuse and violations of our Acceptable Use Policy (linked from the footer of the Karnex console).
- To meet legal obligations.
We do not sell personal information, and we do not share it for advertising.
4. Who we share information with
We use a small number of service providers who process information on our behalf, only to provide their part of the service:
- DigitalOcean — hosts our servers and database.
- Backblaze — stores session recordings and files attached to support tickets, such as "Get help" screenshots (encrypted at rest), only for organizations that make them. It also holds backups of our database, which we encrypt before upload so Backblaze can't read them; they are kept for about three days.
- Cloudflare — DNS and network proxying for karnex.org and karnexdesk.com, so it sees the network-level details of requests, and it receives email sent to KarnexDesk addresses and passes it to us. Its Turnstile check on our sign-up form, KarnexDesk portal sign-in and Kara’s “Talk to a person” looks at signals from your browser to tell people from bots. Cloudflare cannot read the content of end-to-end encrypted sessions.
- Stripe — payments and subscription billing.
- Zoho ZeptoMail — sending service emails, including KarnexDesk ticket emails.
- Microsoft and Google — only if you choose to sign in with them: you sign in on their page, and they tell us which of their accounts you used. We receive no password from them.
- Anthropic — provides the AI model behind Kara. It receives what you type in the Kara chat, and, only when a technician chooses "Draft with Kara" or "Improve with Kara", that ticket's content: its subject and messages, the team's internal notes (used as background, never quoted to the requester), request form answers, the computer and client names, and the organization's matching help articles. Nothing is sent to Anthropic unless you chat with Kara or a technician asks for a draft. Anthropic processes this data under its commercial terms, which do not permit it to use the data to train its models.
Within an organization, information about its computers, sessions, commands, tickets and team is visible to the people the organization has given access. A person who contacts an organization through KarnexDesk sees only their own requests and the organization's public replies, never its internal notes. We may also disclose information when required by law or to protect the rights, safety and security of our users or the service. If Karnytine Labs is involved in a merger or sale, information may transfer as part of it, and we would tell you.
5. End-to-end encryption
The screen, keystrokes, clipboard, chat, files (including file names) and audio of a Karnex remote session are encrypted on the managed computer and decrypted only in the operator's viewer. Our servers relay this data but do not hold the keys and cannot read it, and we do not record it ourselves. The exception is a recording that an operator in your organization deliberately starts in the Karnex Viewer: it is captured on the operator's device from what they see, uploaded over TLS and stored so your team can review it (see "Session recordings" in section 2). Commands, scripts and their output, and account and machine details, are protected by TLS in transit but are processed by our servers as described above. More detail is on the Security page inside the Karnex console.
The Karnex Viewer keeps a few things on the operator’s own computer, not on our servers: for each machine it has connected to, the machine’s ID and its identity public key (so it can warn if that machine’s identity ever changes), and its own settings. The Linux and macOS Viewer stores these in the user’s configuration folder; its sign-in is kept only in memory while the app is open.
6. Security
Connections to Karnex use TLS. Passwords are hashed; two-factor authentication is available; roles and permissions restrict access within each organization. No system is perfectly secure, but we work to protect your information and will notify affected customers of a confirmed breach as required by law.
7. Retention and deletion
We keep information for as long as the account is active. When an organization is disbanded, its people, computers, sessions, session recordings, scripts, notes, keys, webhooks, support tickets, ticket files, help articles and portal contacts are permanently deleted and installed agents are told to uninstall. Support tickets are otherwise kept for as long as the organization uses Karnex. We do not keep Kara chat conversations on our servers unless you choose "Talk to a person", which turns the conversation into a support request. Session recordings are otherwise kept until an Org Admin deletes them; deleting one removes the stored file. Backups are retained on a rolling basis and age out. We may keep limited records where the law requires it, for billing and tax, or to prevent abuse (for example the trial record in section 2).
8. Your choices and rights
You can view and update your account details in the console. You can turn on two-factor authentication and change your password at any time. Depending on where you live, you may have the right to access, correct, delete or export your personal information, or to object to certain processing. To make a request, email [email protected]. If your information is held on behalf of an organization that uses Karnex, we may refer your request to that organization.
9. International use
Karnex is operated from the United States and information is processed there and in other countries where our providers operate. By using Karnex you understand that your information may be transferred to and processed in the United States.
10. Children
Karnex is a business service and is not directed to children under 16. We do not knowingly collect personal information from children.
11. Changes
We may update this policy. If the changes are material we will notify account holders, for example by email or a notice in the console, and update the effective date above.
12. Contact
Karnytine Labs LLC
[email protected]