This overview complements the documents in the 1-click installer and in Koryena.
The explicitly started data export for crafts as well as trade & freelancers generates portable, unencrypted JSON, CSV or SQLite files. This can contain business and personal data and must be protected accordingly. Access data and file attachments are excluded. Before a confirmed import, a local full backup is created. For full encrypted backups, the data backup function must still be used.
End User License Agreement
The provider is Sebastian Andreas Brost, Bonnstrasse 37, 45470 Mülheim an der Ruhr, Germany. Contact: service [at] koryena [dot] de.
Unless otherwise noted, the Koryena source code is licensed under the enclosed MIT license. Third-party models, durations, media, libraries, and content are subject to their own licenses and terms.
AI expenses may be incorrect or incomplete and are not a substitute for medical, legal, tax, financial, or other professional advice. Users are responsible for inputs, training data, recordings, prints, and the lawful use of generated content.
Business documents, draft legal and mandatory texts, offers, orders, work notes, invoices, XRechnungen and internal audit reports, reminders, tax overviews, balance sheet work overviews, calendar releases and e-mail drafts must be checked before they are used by a responsible person. Balance sheet overviews are not audited annual financial statements; Account assignment, inventory, valuation, depreciation and accrual remain subject to professional review. Without this check, automatically adopted new prices of tools and machines are neither book value nor current value or residual value for tax purposes. Changes to official sources are displayed, but not silently incorporated into documents that have already been issued. Koryena does not send documents unnoticed.
A limitation of liability does not apply in the event of intent, gross negligence, injury to life, limb or health or to the extent that mandatory law precludes it. German law applies to the extent that this is permissible vis-à-vis consumers.
Desktop Application Privacy
Chats, calendars, tax files, balance sheet items and work overviews, trade office, trade, freelancer, customer, project, working time, employee, vehicle, tool, machine, new price, inspection interval, inspection certificate, fitter appointment, construction site photo, material price, business paper and payment data, dealer profiles, document references and models are generally stored locally. Private long-term reminders, tax files, balance sheet and closing items, dealer access, office and company data, company logos, letterheads, construction site photos as well as scanned or textual inspection certificates are bound to the local user account via Windows-DPAPI, encrypted and part of the expressly set up module backups.
The optional wake-word readiness keeps the selected microphone open locally during the program runtime. Before a detected wake word, the installed local language model checks short sections only for the set wake words; they do not trigger any action or online connection and are immediately discarded. Only after the wake word is the following request passed to the local chat. A local pause detection automatically detects the end of the input. The function can be turned off under "Avatar and Language" and is suppressed during Koryena's own speech output.
A wholesaler connection established by the user transmits only the data required for the merchant account and the chosen official interface directly to that wholesaler via HTTPS. Access data is not in URLs or protocols. The official tax audit does not send any operating data to ELSTER; a direct tax levy is not included without an activated and verified ERiC connection.
Calendar approvals and exports, as well as business documents, are initially created locally as ICS, JSON, PDF, XML, and EML files. Calendar exports are not encrypted and must be protected in the selected location. Only a visible user action transfers drafts to the Windows standard program; Koryena does not send these business emails itself. Separately, the user can explicitly submit a support ticket in the global support center. An optional error pattern is limited, scaled down, and re-encoded without EXIF, camera, or location metadata. A sanitized system diagnostics are only attached in encrypted form after additional visible consent. Passwords, chat histories, and customer documents aren't automatically transferred. Koryena, XRechnung 3.0.2 only generates after an internal mandatory field, total, and release check and encloses a test report. This preliminary examination does not replace the current KoSIT examination tool, special recipient specifications or a tax and legal specialist examination.
The mobile companion app and customer portal use password-protected exchange packages. Koryena only compiles the expressly selected fitter or customer access; there is no automatic cloud sync. The decryption takes place in the browser of the end device. An encrypted offline version can remain stored locally there until it is locked or removed by browser data deletion. Only the visible re-import in the desktop program takes over permissible appointment statuses, working hours, construction site photos or feedback and logs the exchange. Customer feedback does not automatically change issued documents or payments. The package and password must be transmitted separately; a package expires after 30 days.
Online connections are made for updates, current sources, environmental and media catalogues, expressly selected tagesschau.de news feeds or the voluntary Koryena network search. A saved German zip code is sent to OpenPLZ for local messages only for location and state assignment; then Koryena loads the appropriate official regional feed from tagesschau.de without transferring the zip code to it. Without an active selection of interests, the message card remains hidden; a message archive is not saved. After activation, the Koryena network searches for instances every 30 minutes. It uses anonymous Koryena aliases instead of Windows device names, limits remote stations and packets, and rechecks received sources. Private data is not shared.
YouTube is only loaded after the user opens the YouTube section in the standalone media center. The search uses the official YouTube website; inserted video links will be reproduced via youtube-nocookie.com if possible. YouTube or Google can process connection data, search terms, video addresses and interactions. Their terms of use and privacy policy apply. Koryena doesn't store YouTube credentials and disables downloads in the embedded space.
The optional NINA/BBK warning display only transmits the stored five-digit zip code to OpenPLZAPI to determine the district and loads warning content from warnung.bund.de. Local content checksums and display times prevent warning windows with the same content for 24 hours, even after reboots. This history does not contain any warning texts or zip codes; old entries are cleaned up on the next successful retrieval. Previous notification identifiers are used for one-time transfers. The function is a supplementary comfort display and does not replace the warning app NINA or sirens, cell broadcast, broadcasting or instructions from the authorities. The technical interface is subject to change; in the event of a failure, Koryena does not generate a replacement warning.
During registration, the e-mail address, display name, password hash, desired profile, language as well as the status and time of the tester's decision are stored in the protected account database. The plaintext password is not saved. The decision will be automatically sent to the address provided. For a one-time three-day trial offer after a rejection, the server only stores the hash of a random activation token, its offer period, and the activation time. The three days begin only after the explicit activation; after expiration, a further program start with this test access is prevented without deleting local data.
An initial installation during the Closed Test requires you to log in with an accepted or valid trial account. The homepage password is only used for immediate protected verification and is not stored in the setup or in the desktop app. After that, the version message is active by default. At startup, and every 30 minutes thereafter, a derived installation check value, installed version number, time, and signature are reported via the non-publicly readable status channel. In addition, the installation retrieves the usage profile assigned to the account, its status, revision and optional term. The response is signed bound to installation and account token. A confirmed status is temporarily stored Windows-encrypted for a maximum of seven days. Profile changes only hide function modules; local content will not be transferred to the homepage or deleted. Without any special assignment, "Personal" remains active. Payment processing is not part of this feature. Chats, files, prompts, hardware data, Windows names, and business data are not included.
After the first successful admin password check, Koryena does not store the password, but only a Windows-DPAPI-encrypted share with the associated shared administrator identity for the current Windows user account. It is not transferable to other Windows accounts, activates the admin profile automatically every time it is started, and can be removed at any time under "Modules & Rights". Missing or corrupted shares do not open admin functions.
The two permanently stored protected administrator accounts can also receive the Admin profile in the homepage admin area via the same "Access profile" field. This selection is not displayed for other accounts and is also rejected on the server side. Koryena takes over the central admin share only as a validly signed authorization bound to the account and installation.
The separate administrator mode in the chat checks the password once on the protected forum page. After that, the server only stores the hash of a random device share and the associated shared administrator identity; the access token remains as an HttpOnly cookie in the protected WebView profile of the current Windows user. The password is not included. Device sharing can be revoked in the admin window.
Protected Administrator Chat stores messages, shared notes, and explicitly selected TXT, JPEG, PNG, or WebP files on the Koryena web server. This content is only available to activated administrators. Attachments are limited to three megabytes. Messages and attachments are retained after closing, can be removed individually and are automatically deleted after 365 days at the latest; Notes are retained until they are deliberately deleted.
The administrator voice chat only starts after a visible click and microphone sharing. Audio data is transmitted directly between administrators via an encrypted WebRTC connection, is not recorded on the server side, and is not stored after termination. Short-lived signaling data is removed after ten minutes at the latest. The Cloudflare STUN service used to establish a connection can obtain technically required IP and connection data.
Voluntary anonymous fault diagnosis is turned off by default. After deliberate activation, Koryena only transmits error group, random event identifier, hourly rounded time, Koryena and Windows version, runtime family, language, rough performance profile, error code and a non-calculable technical test value. Error messages, raw stack traces, names, email addresses, zip code, chat texts, prompts, files, file paths, device identifiers, account contents, and stable installation identifiers are not transferred. The server does not store a raw message, adds up the same errors for a maximum of 90 days, and uses a salted hash of the connection address only for the hourly transfer limit. Pending local reports can be deleted at any time.
Local reminders can be disabled and deleted. The size of the user interface, the simplified view, visible keyboard focus, reduced movement, the switch for the live map preview and the personal order of the main navigation are stored exclusively as local program settings. Supplementary updates receive settings and user data. For the forum and download account, the information displayed there also applies.