Klyko logo Klyko / Legal Open Klyko

Privacy Policy

Last updated: July 21, 2026

This policy explains what data Klyko ("Klyko", "we", "us") collects when you use our web app, browser extension, and desktop app, why we collect it, who we share it with, and the choices and rights you have over it. We built Klyko as a local-first tool: your workspace data lives on your own device first, and only syncs to our servers once you sign in. This policy describes both sides of that.

1. Information we collect

Account information

To create an account we need an email address. If you sign in with Google, we also receive your name and avatar image from Google (limited to your basic profile and email — we never request access to your Google Drive, Contacts, or anything beyond that). We don't use passwords: sign-in happens via a one-time 6-digit code sent to your email (valid for 15 minutes) or Google sign-in. Your session is represented by a token; on our servers we only ever store a one-way hash of that token, never the token itself.

Content you create

Workspaces, collections, sections, saved items (links, notes, checklists, and any titles or text you type), Launch Modes, and the list of devices you've signed into. This is the actual substance of what you use Klyko for, and it's yours — we treat it as confidential and don't read it except as needed to operate the service or respond to a support request you've sent us.

Billing information

Payments are processed by Stripe. Klyko never receives or stores your card number — we only keep what Stripe tells us afterward: your subscription plan and status, seat count, billing period, invoice amounts, and payment history, so we can show you your billing details and keep your plan entitlements accurate.

Support communications

If you contact support, we collect your email, your message, and your name if you choose to give it. To prevent abuse of the contact form, we apply rate limits keyed to a one-way hash of your IP address (or your email) — we don't retain your raw IP address for this purpose.

Cookies and local storage

We use one cookie, klyko_session, to keep you signed in (expires after 30 days). Your browser's local storage holds a copy of that session token, your theme and language preference, and a cache of your plan usage so the interface loads instantly. Separately, your browser keeps a full offline copy of your own workspace data (via IndexedDB) so Klyko keeps working without a network connection — this copy stays on your device and only ever syncs with your own account.

What we don't collect

We don't run any third-party analytics, advertising, or tracking scripts — no Google Analytics, no ad pixels, no session-recording tools. We keep a small first-party log of in-product events (like "workspace created") purely to power features such as your usage bar against plan limits; it is never shared with or sold to anyone outside Klyko.

2. How we use your information

  • Operate the service: authenticate you, sync your data across your devices, and enforce your plan's limits.
  • Process payments and manage your subscription through Stripe.
  • Send transactional email only — sign-in codes, team invitations, replies to your support requests, and notifications when someone shares a workspace with you. We do not send marketing or promotional email campaigns.
  • Detect and prevent abuse (e.g. repeated failed sign-in attempts, spam through the contact form).
  • Comply with legal obligations, such as retaining invoice records for tax and accounting purposes.

3. Who we share data with

We use a small number of service providers to run Klyko. None of them are permitted to use your data for their own purposes.

ProviderPurposeData involved
StripePayment processing, subscription billingPayment details, billing email, subscription status
ResendDelivering transactional emailYour email address, the content of that one email
CloudflareHosting, database, and file storage infrastructureAll account and workspace data described above
GoogleSign-in, only if you choose "Continue with Google"Name, email, avatar (via OAuth)

We do not sell your personal information, and we do not share it with third parties for their own advertising or marketing purposes.

4. Team collaboration and share links

Klyko is built around sharing workspaces with people you choose to share them with, which necessarily means some of your information becomes visible to others:

  • Teams. Every member of a team can see the name, email, and avatar of every other member — this is inherent to managing a shared team and its billing seats, and can't be hidden from teammates.
  • Public share links. If you turn on a public link for a workspace, anyone who has that link can view the workspace's content along with your display name and avatar (not your email address). You can turn a link off at any time, which disables access immediately.
  • Invitations. Inviting someone to a team or a shared workspace stores their email address until they accept (or you cancel the invite).

5. Browser extension

The Klyko browser extension reads the URL, title, and favicon of your open tabs so you can save and organize them into workspaces — it does not read the content of any page, and it does not use your browser's history API. It only stores a short-lived queue of items you're in the process of saving and your theme preference, locally on your device via chrome.storage.local.

6. Desktop app

The desktop app stores your session and device identifier locally so you stay signed in. Launch Modes that open local files, folders, or applications rely on a device-only index that maps them to your machine — this mapping is never sent to our servers and is different on every device you use. When you configure a Launch Mode to open a local app or run a local action, that action happens entirely on your own machine.

7. International data transfers

Our service providers (Section 3) operate globally, so your data may be processed in countries other than the one you live in, including the United States. We rely on our providers' own contractual and technical safeguards for these transfers.

8. Data retention

  • We keep your account and content for as long as your account is active.
  • Deleting a workspace or a piece of content removes it from your view immediately; the underlying record is then permanently purged shortly after.
  • A data export file we prepare for you expires and is deleted 7 days after it's generated.
  • Security and activity logs (e.g. sign-in and sync history) are kept to protect the service and investigate abuse; we don't yet enforce one fixed maximum retention window for these logs, but we don't use them for anything beyond security and support purposes.
  • Invoice and payment records may be kept longer where required by tax and accounting law.

9. Your rights and choices

You have a few different tools depending on what you're trying to do:

  • Export your content anytime. Settings → Backup lets you download a full copy of your workspaces as a .klyko file whenever you want, without needing to ask us.
  • Clear your content, keep your account. "Delete all data" in Settings removes your workspaces and their content but keeps you signed in with your existing account — useful for a fresh start.
  • Delete your account entirely. Email us (Section 12) to request full account deletion. We apply a 30-day grace period in case the request was made in error, after which we anonymize your profile (email, name, avatar) and permanently delete your sessions and connected devices. Invoice records tied to completed payments may be retained separately as required by law even after this.
  • Access, correct, or request a full copy of your personal data. Email us and we'll respond within 30 days.

If you're in the EEA, UK, or Switzerland, these map onto your rights under GDPR (access, rectification, erasure, restriction, portability, and objection), and you also have the right to lodge a complaint with your local data protection authority. If you're a California resident, we do not sell your personal information, and the choices above cover the requests CCPA gives you.

10. Children's privacy

Klyko is not directed at children under 16, and we don't knowingly collect data from them. If you believe a child has created an account, contact us and we'll remove it.

11. Security

All traffic to Klyko is encrypted (HTTPS). We never store your session token itself on our servers, only a one-way hash of it. Sign-in has no password to leak, and repeated failed sign-in attempts trigger a temporary lockout. No method of transmission or storage is 100% secure, but this is how we work to protect your data.

12. Changes to this policy

If we make material changes to this policy, we'll update the date at the top and let you know by email or an in-app notice before the change takes effect.

13. Contact us

Questions about this policy, or a request under any of the rights above, can go to [email protected].

© 2026 Klyko — Save your work context. Reopen it anywhere.