KELVINCodeby entropy
click to cross the forms

FAQ

Frequently asked questions.

Short answers. Tap a question to open it.

The basics

What is Kelvin Code?
A developer tool: a native macOS app that spins up disposable iOS simulator capsules and lets your agents — Claude, Codex, Cursor — drive the app inside them while you watch. Every session becomes reproducible evidence: the captures, the step by step of the run and the verdict, sealed and ready to run again. “Kelvin” is what we call the product day to day; the full name is Kelvin Code.
Do I need Xcode installed?
Yes. The iOS runtimes come from Xcode and Kelvin does not replace it. What Kelvin does is run the simulator out of your way: no simulator window ever opens, only Kelvin's.
Does it work with no account and no cloud?
It does. The Kelvin you download today runs entirely on your machine, with no login and no server of ours in the path.

Installing and using it

Which Macs run Kelvin?
macOS 14 or newer, Apple Silicon, with Xcode installed. To touch the screen, type and stream the session: macOS 15 and idb-companion installed via Homebrew.
What does it cost today?
Nothing. The beta is free and asks for no card. If there is a price, it will be announced before it applies.
How do updates work?
The app updates itself from the feed published on this site. Every version shows up in the changelog, with the binary on the public releases page.
Where does the official binary come from?
Only from github.com/andermelo/kelvin-releases and this site. We distribute Kelvin through no other channel.

Security and data

What does the Google sign-in access in my account?
Name, profile picture and verified e-mail — the openid, email and profile scopes, and nothing beyond. Kelvin Code neither requests nor receives access to Google Drive, Gmail, Calendar, contacts, repositories or any other data in your account. The sign-in exists at app.kelvincode.com only to say who is in the session; a person's identity here is their verified work e-mail, and the provider is only how you prove it — which is why GitHub (read:user, user:email) sits right beside it, with no hierarchy. The app you download and run on your Mac asks for no sign-in at all.
What leaves my machine?
In Kelvin Local, nothing: sessions, screens and apps never leave your Mac. Kelvin Code Cloud is optional, and in it your Mac connects outbound only — Kelvin opens no inbound port on your machine.
How do I know the right app ran?
The app you send is checked by two hashes — the received bytes and the extracted app tree — before any simulator is touched. And everything is bound to an organization: asking for another organization's object answers “not found”, without confirming that it exists. Negative tests cover that path.
What gets recorded?
Every critical action enters an audit trail: membership and role changes, machine enrollment and revocation, approval of the app that was sent, run transitions, control granted and handed back, accepted input, approvals and publication. Live control belongs to one person at a time and the handover is explicit — and the text you type never enters logs or the audit trail.
Do you delete the evidence after a while?
Today the evidence stays. The windows we intend to apply are written in the privacy policy — 30 days for a run that completed, 7 days for one that failed, 90 days for the audit trail — and while they are intentions this site says they are intentions: nothing is deleted on a schedule, and no date here is a promise. What does get deleted is a room's state when it ends: chat, proposals, tickets and seats.

The retention windows and the sub-processors are in the privacy policy. Found a vulnerability? Write to security@kelvincode.com.

Still missing something?

What Kelvin does today, feature by feature, lives on the features page.

See features