Legal
Privacy Policy
Last updated: August 15, 2026
koko VR Theater (“koko,” the “App”) is a media player for Meta Quest published by Krafti SASU(“we,” “us”). This policy explains what data the App, this website, and the koko Companion PC app handle and why. The guiding principle is simple: koko is local-first. Your media, your servers, and your credentials stay on your device and talk directly to the services you choose. We operate no account system and collect no advertising or behavioural-analytics data.
There are four limited exceptions, each described below:
- Buying and licensing koko: either through the Meta Horizon Store, or directly on this website via Stripe. Both involve data about your purchase.
- Activating your licence: the App tells our server which device it is running on so a purchase can be capped at 3 devices.
- Watch Together: a user-initiated peer-to-peer session brokered by a server we operate.
- Diagnostics and support: sent only when you submit a report.
Who we are
Data controller: Krafti SASU, a Société par actions simplifiée unipersonnelle (SASU) registered in France (RCS Paris 852 598 572), with its registered office at 75 rue Manin, 75019 Paris, France. Contact: contact@krafti.io.
What stays on your device
The following never leaves your headset and is never transmitted to Krafti:
- Plex and Jellyfin credentials and tokens. When you sign in to a Plex or Jellyfin server, authentication happens directly between your headset and that server (and, for Plex sign-in, plex.tv). Tokens are stored locally on the device and used only to talk to your servers.
- Your media and file metadata. Browsing and playing local, USB, and network files (SMB, FTP, SFTP, WebDAV, DLNA) happens directly between your headset and those sources. Library organisation, tags, watch history, bookmarks, and preferences are stored in a local database on the device.
- App settings such as playback, image, and audio calibration.
Uninstalling the App removes this on-device data. You can also export or clear it from within the App’s settings.
Device permissions
- Storage / All-files access (
READ_MEDIA_VIDEO,MANAGE_EXTERNAL_STORAGE): to let you browse and play video files you already have on the headset or attached storage. The App reads the files you open; it does not scan or upload your storage. - Microphone (
RECORD_AUDIO): requested solely for optional Watch Together voice chat (see below). If you never use that feature, the microphone is never accessed, and koko does not record or store microphone audio in any case. A separate setting,MODIFY_AUDIO_SETTINGS, supports voice dictation in the Meta system keyboard, where the audio is captured by the system keyboard process rather than by koko. - Network and Wi-Fi multicast: to reach your servers and discover devices on your local network (DLNA/UPnP).
Buying koko: the direct purchase on this site
koko can be bought directly from us on this website. On that path Krafti is the seller, and payment is processed by Stripe Payments Europe, Ltd.on Stripe’s own hosted checkout page.
- What Stripe collects from you.Your email address, name, billing address and country, your card or other payment details, and technical data Stripe uses for fraud prevention. Your payment details are entered on Stripe’s page and never reach our servers. Stripe acts as our processor for the payment and as an independent controller for fraud prevention and its own legal obligations; see stripe.com/privacy.
- What we can see. Through our Stripe account we can read the purchase record: your email address, billing country and address, the amount and tax charged, and the Stripe identifiers for the session and payment. We keep no separate customer database: the record lives in Stripe, and your licence key is derived cryptographically from the checkout session rather than stored by us.
- Delivery of your licence. Your activation code and download link are emailed to the address Stripe collected, using Resend as our email provider. We use that address to deliver the purchase and to answer you if you contact us about it; we do not add you to a marketing list.
Legal bases: performing our contract with you (Art. 6(1)(b) GDPR) for the sale and delivery, and complying with French accounting and tax law (Art. 6(1)(c)) for the invoice record, which we must keep for 10 years.
Buying koko: the Meta Horizon Store and the Platform SDK
koko is also sold on the Meta Horizon Store, where the App is free to try with an optional one-time in-app purchase (the “full unlock”). To offer this, the App integrates the Meta Horizon Platform SDK, and through that integration it accesses and processes a limited amount of data that Meta makes available about your account:
- Your entitlement and purchase records for this App. The App asks the Meta platform whether your Meta account owns the “full unlock” add-on. Meta returns your ownership status for this App (and the associated purchase record for the add-on, such as its product identifier and type). This data is associated with your Meta account and is provided to the App by Meta. We use it solely to determine whether to enable the paid features.
- Product and price information. The App requests the localized, currency-correct price of the add-on from the store so that it can be shown to you before you buy.
How we handle this data: the ownership result is evaluated on your device and cached locally so that a previous purchase keeps the App unlocked, including offline. We (Krafti) do not combine it with other data, disclose it to anyone, or use it for advertising, analytics, or profiling. The purchase transaction itself, including your payment details, is processed entirely by Meta on the Meta Horizon Store; we never receive or store your payment information.
Redeeming a Meta purchase. If you ask us to honour a Meta purchase, by signing in with Meta or from inside the app, we receive your Meta user identifier and a proof of purchase, check the entitlement with Meta server-to-server, and use the result once, to issue your licence key. We do not store the identifier afterwards, and we do not request your Meta name, profile, or friends list.
Activating your licence and the device limit
A licence key verifies offline on your headset, so nothing in the App itself limits how often a key could be copied. The one control we have is at activation, and it works like this: one purchase may be activated on up to 3 devices.
- What the App sends. Your activation code and an opaque device identifier that the App derives locally on your headset (a hash of the Android device id, so a reinstall does not burn a slot). It is not your name, your Meta account, or your headset serial number, and it carries nothing about your media, libraries, or browsing.
- What we store. The set of device identifiers that have activated a given purchase, in a Redis database hosted in the EU (Frankfurt). It is used for one purpose only: refusing a 4th device. This store is deliberately non-persistent: if it is lost, the counter simply resets, and nobody is locked out.
- Clearing it. You can wipe the device list yourself using the reset link in your licence email, or by writing to support@krafti.io from the address you bought with. Legal basis: our legitimate interest (Art. 6(1)(f)) in preventing licence sharing, which we consider proportionate given the identifier is pseudonymous and single-purpose.
App updates
The sideloaded build periodically asks our server whether a newer version has been published, and downloads it if you accept. The request carries no identifier, only the ordinary information any web request carries, such as your IP address and the app version. The Meta store build does not do this; it updates through the store.
Watch Together (optional)
If you start or join a Watch Together session, the App uses a signaling server we operate to connect you with the other people in your room. To establish the connection it exchanges an ephemeral room code, short-lived session and peer identifiers, and WebRTC connection details (SDP and ICE candidates).
WebRTC connection details include IP addresses, and the voice and playback-sync streams travel peer-to-peer. This means the other participants in your room may be able to see your IP address. If you enable the “Hide my IP” option, traffic is routed through a relay (TURN) server so your address is not exposed to peers. Voice audio is transmitted directly between peers while a session is active and is not recorded by us.
Server-side room and identity data is minimised and ephemeral: it exists only to broker the connection and is discarded when the session ends. If you mute, block, or report another participant, a report may be written to an abuse log keyed to ephemeral, session-scoped identifiers so we can address misuse; we keep these abuse logs for up to 90 days and then delete them. We rely on our legitimate interest in preventing abuse and keeping the feature safe.
Diagnostics, bug reports, and support (opt-in)
If you choose to send a bug report or feedback from Settings → Diagnostics, the App sends a scrubbed snapshot (recent application logs, your device model and OS version, and your app settings) to our reporting endpoint so we can diagnose the problem. This is sent only when you submit a report.
The support form on this site sends the same way: your message, the problem category, your email address if you supply one so we can reply, and basic browser context (user agent, referring page, language). Emailing us directly reaches the same inbox.
We rely on our legitimate interest in operating, securing, and improving the App, and use reports solely for that purpose. Reports are retained for up to 90 days and then deleted, except where an ongoing conversation with you requires keeping the thread.
The in-app web browser
koko includes an optional web browser for sites you choose to visit. Browsing happens between your headset and those websites; their own privacy policies apply. Browsing data is stored locally and can be cleared from the browser settings.
To reduce ads and trackers, the browser includes a filter-based ad blocker that is on by default and can be turned off in the browser settings. While it is enabled, koko periodically (about every three days) downloads the public EasyList and EasyPrivacy filter lists from easylist.to to keep its rules current. Those lists are generic and contain no information about you.
The koko Companion PC app
koko Companion is a free application for Windows, macOS, and Linux that shares folders you pick with your headset over your own local network. It has no account and no telemetry: pairing happens directly between your computer and your headset (by QR code or PIN), your files are served straight off your machine, and nothing is uploaded to us or to anyone else. The only contact with our servers is downloading the installer from this site.
This website
We run no analytics, no advertising, and no trackingon this site. The site itself sets no cookies; the only thing stored in your browser is a small local-storage entry remembering that you dismissed the storage notice. Stripe’s hosted checkout page runs on Stripe’s own domain under Stripe’s policy and does set cookies necessary for payment and fraud prevention.
Like any web host, our host keeps short-lived server logs (including IP addresses) for security and abuse prevention, and we rate-limit sensitive endpoints (checkout, activation, device reset, and the support form) by IP address, holding a counter keyed to your address for a matter of minutes.
What we do not do
- No advertising and no third-party advertising or tracking SDKs.
- No behavioural analytics or profiling.
- No sale of personal data.
- No user accounts hosted by Krafti.
- No marketing email unless you ask us for it.
Third parties and service providers
The services you connect to handle data under their own policies, including Plex, Jellyfin, your own servers and NAS, any websites you visit in the browser, and Meta (which operates the headset platform and the store through which you may have obtained the App).
For the limited data that does reach us, we rely on the following providers:
- Stripe: payment processing, invoicing, and tax calculation for direct purchases.
- Resend: delivering your licence email.
- Redis Cloud (via Vercel, Frankfurt): the per-purchase device list and endpoint rate limiting.
- Vercel: hosts this website, its API endpoints, and the application and companion downloads.
- Google Cloud: hosts our Watch Together signaling, relay (TURN), and bug-report endpoints.
- Google public STUN servers: when you use Watch Together, your device contacts these servers to discover its own network address so the peer-to-peer connection can be set up.
Some of these providers are established in, or transfer data to, the United States. Where that happens we rely on the European Commission’s Standard Contractual Clauses, or on the provider’s certification under the EU–US Data Privacy Framework, as applicable.
How long we keep things
- Purchase and invoice records(in Stripe): 10 years, as French tax law requires.
- Activated-device lists: until you reset them, or until the store is cleared.
- Bug and abuse reports: up to 90 days.
- Support email: as long as needed to resolve your request, then archived and deleted.
- Server logs and rate-limit counters: days and minutes respectively.
Your rights
Because koko stores your data on your own device, you remain in direct control of it. Where the GDPR or comparable laws apply, you have rights of access, rectification, erasure, restriction, portability, and objection regarding any personal data we process, for example your purchase record, the device list attached to your licence, an abuse report you are named in, or a bug report you submitted. Contact us at contact@krafti.io to exercise them. Note that we may have to keep an invoice record even after an erasure request, because tax law requires it.
If you are in the EU/EEA and believe we have not handled your personal data lawfully, you also have the right to lodge a complaint with your local data-protection authority. In France this is the Commission Nationale de l’Informatique et des Libertés (CNIL), cnil.fr.
Children
koko is not directed at children and we do not knowingly collect data from them.
Changes
We may update this policy as the App evolves. Material changes will be reflected here with a new “last updated” date.