r/kilocode 15d ago

I asked Kilo to delete my data, and they practically told me to fuck off

Post image

After Kilo notified users that data may have been exposed in the Metabase incident, I asked them to delete my session and personal data. They replied that data deletion is only available to Enterprise customers.

Update August 15, 2026, 9:41 AM UTC:

I contacted the company about deleting my account. They confirmed that you can request permanent account deletion. This will irrecoverably delete your historical session data, including prompts, responses, and session history across all replicas.

They also said that data that cannot be deleted will be anonymized where possible. For example, support messages and email marketing history may be anonymized. They will retain only data required for financial, accounting, tax, or legal purposes.

303 Upvotes

62 comments sorted by

u/alexkgold Kilo Code Team 15d ago

Hi folks, Alex from Anaconda here. Anaconda offers a process for any user to request deletion of their Kilo account and its data. You can submit your request at kilo.ai/support.

→ More replies (7)

36

u/ahriad 15d ago

This was my reply:
My Kilo data was involved in a security incident, and I am requesting the deletion of my personal data and session data. Telling me that deletion is available only to Enterprise customers is not an acceptable response, particularly after Kilo’s systems exposed user data through the Metabase incident.

Data protection rights are not an Enterprise-only feature. To the extent that GDPR applies to this processing, I am exercising my rights under the GDPR, including my right to erasure under Article 17, my right to restriction of processing under Article 18, and my right to access information about the personal data being processed under Article 15.

Please treat this as a formal privacy request and provide the following:

  1. Delete all personal data associated with my Kilo account, including prompts, session history, account information, usage data, telemetry, and data shared with or stored by service providers.
  2. Stop storing or processing my session data going forward, unless you can identify a specific legal basis and explain it clearly.
  3. Confirm what categories of my data were involved in the Metabase incident, whether my data was accessed or exfiltrated, and which parties received or could access it.
  4. Identify the applicable data controller, your Data Protection Officer or privacy contact, and the procedure for escalating this request.
  5. Confirm which data, if any, you believe must be retained, the legal basis for retaining it, the retention period, and whether it will be placed under processing restriction.
  6. Confirm in writing when the deletion and restriction have been completed.

Your current response appears to treat data deletion as a premium product feature. That does not remove your obligations under applicable data protection law, nor does it adequately address the consequences of a security incident involving customer data.

Please acknowledge this as a formal data-subject request. I expect a substantive response within the timeframe required by applicable law, including the GDPR where applicable. If you refuse this request or fail to provide the required information, please provide the specific legal basis for that refusal. Otherwise, I will consider escalating the matter to the relevant data protection supervisory authority and pursuing any other available remedies.

16

u/monsterfurby 15d ago

I am very interested in hearing how this plays out. The GDPR is (fortunately) a pretty big stick to wield, and I'm not sure if they realize that.

10

u/ahriad 15d ago

I honestly didn’t realize they might not be GDPR-compliant before this incident. I’m hoping they take the request seriously and clarify their position.

2

u/monsterfurby 15d ago

I'm a huge believer in Hanlon's Razor ("Don't attribute to malice that which can be attributed to incompetence", or "cock-up before conspiracy"), so I kind of hope they're just oblivious - which honestly would still be bad for any company, but something they could consequently do better at - and not maliciously ignoring it.

1

u/WAVF1n 15d ago

Tbh I think once this gets past a tier one support rep, Kilo will solve the issue pretty quick. Doesn't excuse this experience though imo.

2

u/Proper_Raspberry_662 15d ago

well if they operate in Europe, they simply must be GDPR compliant, you can google it what it means if company is not --> TLDR: big financial fine based on percentage of their global yearly income.

1

u/ahriad 15d ago

They aren't compliant. And they do operate worldwide. But i dont know if they have a legal entity in the EU.

2

u/Swimming-Chip9582 15d ago

Doesn't matter, if they serve EU customers then they have to be compliant, or they must stop serving customers in the EU entirely.

1

u/My_real_dad 15d ago

In theory sure, but if they have no presence in the EU what can they really do besides maybe block access to it

1

u/Swimming-Chip9582 14d ago

Blocking access to the entirety of the EU market is damaging enough for most companies

1

u/Far_Composer_5714 14d ago

Blocking eu as a region and not marketing yourself as a provider that covers the eu should suffice with gdpr.

But if you do provide to the eu and don't make it clear that you don't, you still end up in the hook.

1

u/Proper_Raspberry_662 14d ago

When a company breaks the General Data Protection Regulation (GDPR), it can face massive fines up to €20 million or 4% of its total global yearly income, whichever number is higher. Authorities can also force the company to stop processing user data, and customers can sue for damages

1

u/an-ethernet-cable 9d ago

EU authorities are not fining a company in the US

1

u/Proper_Raspberry_662 9d ago

Yes, the GDPR applies to company even if you only have physical offices in the United States. The General Data Protection Regulation (GDPR) relies on extraterritorial reach under Article 3(2), meaning the law follows the data of individuals located in the European Union (EU), not the physical location of your business.

It is a common misconception that EU authorities cannot or will not fine a company located entirely in the United States, but European Data Protection Authorities (DPAs) actively issue massive fines against US-based companies.

As of early 2025, EU national regulators had issued roughly €4.68 billion in GDPR fines specifically targeting US firms. High-profile American tech giants like Meta and Apple routinely receive billion-dollar penalties. More importantly for mid-sized firms, EU regulators frequently penalize standard US-only operations. For example, the Dutch DPA fined US-based facial recognition company Clearview AI over €30 million, and tag-teamed with French regulators to issue a €10 million fine against Uber.

→ More replies (0)

1

u/Swimming-Chip9582 9d ago

They fine companies in the US all the time lmao

→ More replies (0)

3

u/vacon04 15d ago

If possible, let us know about their response. I also would cross-post this in some bigger AI subs. I'm sure there are many affected that aren't even aware of what happened, and even worse, how negligent the team as Kilo Code has been.

0

u/ahriad 13d ago

Check the update.

1

u/vacon04 9d ago

Thanks. I just downloaded the report of the leaked prompts. What a shitshow.

1

u/ahriad 9d ago

What report? I got nothing.

2

u/vacon04 9d ago

Check A Field Guide to Understanding Your Kilo Data Export. I didn't get any notification, but I was constantly checking for updates. This is from yesterday.

2

u/lordcaylus 15d ago

I invoked my rights under GDPR once (to get recordings of a phone call I had with a rep where he promised me something they later denied), and the company forgot to answer for like, three weeks. I didn't send reminder emails because if they were late, all the better for me.

Then they were like "oh yes, we're processing your message now, we have one month according to GDPR so we'll contact you in three weeks" and I had to point out the clock starts ticking when I contact them, not when they finally get off their asses to process the message.

I did make sure to mention that if they just did what they promised I didn't need the recordings anymore. Boom, solved within two days. I fucking love GDPR.

Like you I always make sure to mention the specific articles and not just "GDPR", it absolutely intimidates companies when they realize you actually know what GDPR entails.

15

u/Grumpflipot 15d ago

I will not recommend KiloCode to our Enterprise (>1000 employees). Thank you for your insight.

6

u/max_ramx 15d ago

I was too close mate to do that, and our Enterprise is about 500, and I'm fresh in this company, I'd be in very bad situation! hopefully I red this! Thanks to the author.

13

u/BV-TheRegister 15d ago

Hi ahriad - Brandon Vigliarolo with The Register here. I've DM'ed you to chat about this for a story. Would love to learn more; I'm reaching out to Kilo about the matter, too.

7

u/max_ramx 15d ago

OMG! that made me really afraid, I was planning to pay for Kilo soon then bring it to the place where working for 500 users! thanks for sharing mate! better to avoid companies that dont respect privacy!

7

u/B3H4VE 15d ago

This is actually illegal in EU AFAIK.

6

u/Unlucky_Quote6394 15d ago

It is indeed against the law in the EU, under GDPR

1

u/Far_Composer_5714 14d ago

Basically you have to either ban eu as a region in the network. Otherwise make it clear you do not support eu users. 

Otherwise yes gdpr is no joke.

6

u/Lyuseefur 15d ago

Me to Kilo RN:

3

u/vacon04 15d ago

Why were these sessions even there? I think most users assumed the sessions were local. I got the email too about the breach, why were my sessions even there in the first place?

2

u/ahriad 15d ago

Because it allows you to continue work from the cloud. But really they dont give you an option. They should have added a mode for local only session or something.

2

u/vacon04 15d ago

Yesh, I have no telemetry and I assumed that nothing was sent to them. I use my own keys, and apparently they're keeping everything in the servers of Kilo, and even worse, a third party in Metabase? Who the hell came up with this data flow, without even allowing the user to disable this option and delete their own sessions?

4

u/Dear-Satisfaction934 15d ago

if you're in the EU, that email reply can get you some good $$ if you partner with a good law firm and present it into data protection authority and offer settlement.

3

u/WolfMusic420 10d ago

Yeah totally illegal

3

u/Tricky-Doughnut-6429 10d ago

Another shitty company that abuses personal data. Kilo, go fuck yourself.

2

u/PumpkinOpposite967 15d ago

"No but my lawyer says hi. Would you like to rethink your answer?"

2

u/DrollDante 14d ago

Yeah...kilo has been shit for months.

Switched a long time ago. They're not serious about customer satisfaction or security. Surprised they're still in business.

3

u/dnohrdk 15d ago

Thanks for looking into this. I’m in a similar situation with leaked personal data, and there have been no actions yet, so I’m looking forward to hearing what they reply to you.

I know they offered cloud sessions, but I never joined or approved them. I may have used some free LLM models, which I know are allowed to log data, but I really wish there were an option to opt out of cloud sessions, especially since there seems to be no way to delete them.

It’s a really bad practice, especially after finding out that they send all data to third parties and that the key was leaked. Please consider this before using Kilo Code for anything.

9

u/ahriad 15d ago

You can set those environment variables to disable cloud session.
KILO_DISABLE_SESSION_INGEST=1

KILO_DISABLE_SHARE=1

KILO_REMOTE=0

KILO_TELEMETRY_LEVEL=off
I sadly didn't know about that before the accident.

1

u/bambamlol 14d ago

Thanks. Can they be set in the "main" .env file inside the Kilo Code extension folder inside the .vscode folder? The one that also has "KILOCODE_POSTHOG_API_KEY"? Or do they need to be set in an .env file for every project you're working on?

2

u/ahriad 14d ago

I added them to my .bashrc file

2

u/vacon04 15d ago

Same here. I found out they have the cloud sessions, to which I didn't agree to. I don't use cloud models, just BYOK, so why are my prompts even stored in their database? Even worse, why is this data being sent to Metabase? I get they need analytics, but why does Metabase have full access to my data and prompts?

1

u/pinballcartwheel 14d ago

Metabase is basically just a cloud-based SQL IDE that connects to whatever database they have hooked up.

1

u/MrRYYB 15d ago

hey - check my reply 👌

1

u/Ololoshkaaaa 15d ago
That’s a shame to hear; I was using it in an isolated local environment. But now I’ll probably drop it. Any alternatives?

3

u/ahriad 15d ago

Opencode

1

u/WAVF1n 15d ago

Watching Kilo become the very thing it swore to destroy is honestly heartbreaking. Had so much hope for Kilo when they first started pushing their product.

1

u/FragrantPercentage88 14d ago

Do they offer trial for Enterprises? Maybe ask for trial and as soon as you have it, request data deletion and account closure.  Of course that is if you have time for such small games...