Kana Privacy Notice

Last Updated: September 9, 2026

Before you enroll

Kana collects, per device:

  • FileVault (disk encryption) status
  • Firewall status
  • Gatekeeper status
  • System Integrity Protection status
  • Screen lock status
  • Automatic updates status
  • Whether Kana starts at login
  • Whether XProtect is present
  • Whether XProtect Remediator is present
  • Whether the Malware Removal Tool is present
  • Device hostname, platform, and OS version
  • The installed Kana version and the time of its last report
  • The team the device is enrolled in

Kana does not collect: no screen captures, no camera, no keystrokes, no browsing, no file contents, no location.

These states are shown to the manager of the team this device enrolls in, so they can tell whether the device meets that team's security policy.

We do not sell user or device data collected by Kana, and we do not use or disclose it to third parties for any purpose, including advertising, marketing, or analytics.

Read the Kana privacy notice

Who sees it

The posture states Kana collects are shown only to the manager of the team that device enrolled in, on that team's Kana console. They are used to decide whether the device meets that team's security policy. They are never shown to any other team, and they are never sold or disclosed to a third party for advertising, marketing, or analytics.

Retention

Individual posture reports are deleted automatically 30 days after they are received. A device's current enrollment record — its hostname, platform, OS version, Kana version, last report time, and the team it belongs to — is kept while the device is enrolled, and until your organization asks us to delete it or deletes its account.

Contact

For questions about this notice, contact us at:

Kana

Email: privacy@kana.io
Website: https://kana.io