Privacy Policy
Last updated: July 21, 2026
This policy explains what data Klyko ("Klyko", "we", "us") collects when you use our web app, browser extension, and desktop app, why we collect it, who we share it with, and the choices and rights you have over it. We built Klyko as a local-first tool: your workspace data lives on your own device first, and only syncs to our servers once you sign in. This policy describes both sides of that.
1. Information we collect
Account information
To create an account we need an email address. If you sign in with Google, we also receive your name and avatar image from Google (limited to your basic profile and email — we never request access to your Google Drive, Contacts, or anything beyond that). We don't use passwords: sign-in happens via a one-time 6-digit code sent to your email (valid for 15 minutes) or Google sign-in. Your session is represented by a token; on our servers we only ever store a one-way hash of that token, never the token itself.
Content you create
Workspaces, collections, sections, saved items (links, notes, checklists, and any titles or text you type), Launch Modes, and the list of devices you've signed into. This is the actual substance of what you use Klyko for, and it's yours — we treat it as confidential and don't read it except as needed to operate the service or respond to a support request you've sent us.
Billing information
Payments are processed by Stripe. Klyko never receives or stores your card number — we only keep what Stripe tells us afterward: your subscription plan and status, seat count, billing period, invoice amounts, and payment history, so we can show you your billing details and keep your plan entitlements accurate.
Support communications
If you contact support, we collect your email, your message, and your name if you choose to give it. To prevent abuse of the contact form, we apply rate limits keyed to a one-way hash of your IP address (or your email) — we don't retain your raw IP address for this purpose.
Cookies and local storage
We use one cookie, klyko_session, to keep you signed in (expires after 30 days). Your browser's
local storage holds a copy of that session token, your theme and language preference, and a cache of your plan
usage so the interface loads instantly. Separately, your browser keeps a full offline copy of your own workspace
data (via IndexedDB) so Klyko keeps working without a network connection — this copy stays on your device and
only ever syncs with your own account.
What we don't collect
We don't run any third-party analytics, advertising, or tracking scripts — no Google Analytics, no ad pixels, no session-recording tools. We keep a small first-party log of in-product events (like "workspace created") purely to power features such as your usage bar against plan limits; it is never shared with or sold to anyone outside Klyko.
2. How we use your information
- Operate the service: authenticate you, sync your data across your devices, and enforce your plan's limits.
- Process payments and manage your subscription through Stripe.
- Send transactional email only — sign-in codes, team invitations, replies to your support requests, and notifications when someone shares a workspace with you. We do not send marketing or promotional email campaigns.
- Detect and prevent abuse (e.g. repeated failed sign-in attempts, spam through the contact form).
- Comply with legal obligations, such as retaining invoice records for tax and accounting purposes.
3. Who we share data with
We use a small number of service providers to run Klyko. None of them are permitted to use your data for their own purposes.
| Provider | Purpose | Data involved |
|---|---|---|
| Stripe | Payment processing, subscription billing | Payment details, billing email, subscription status |
| Resend | Delivering transactional email | Your email address, the content of that one email |
| Cloudflare | Hosting, database, and file storage infrastructure | All account and workspace data described above |
| Sign-in, only if you choose "Continue with Google" | Name, email, avatar (via OAuth) |
We do not sell your personal information, and we do not share it with third parties for their own advertising or marketing purposes.
4. Team collaboration and share links
Klyko is built around sharing workspaces with people you choose to share them with, which necessarily means some of your information becomes visible to others:
- Teams. Every member of a team can see the name, email, and avatar of every other member — this is inherent to managing a shared team and its billing seats, and can't be hidden from teammates.
- Public share links. If you turn on a public link for a workspace, anyone who has that link can view the workspace's content along with your display name and avatar (not your email address). You can turn a link off at any time, which disables access immediately.
- Invitations. Inviting someone to a team or a shared workspace stores their email address until they accept (or you cancel the invite).
5. Browser extension
The Klyko browser extension reads the URL, title, and favicon of your open tabs so you can save and organize
them into workspaces — it does not read the content of any page, and it does not use your browser's history API.
It only stores a short-lived queue of items you're in the process of saving and your theme preference, locally
on your device via chrome.storage.local.
6. Desktop app
The desktop app stores your session and device identifier locally so you stay signed in. Launch Modes that open local files, folders, or applications rely on a device-only index that maps them to your machine — this mapping is never sent to our servers and is different on every device you use. When you configure a Launch Mode to open a local app or run a local action, that action happens entirely on your own machine.
7. International data transfers
Our service providers (Section 3) operate globally, so your data may be processed in countries other than the one you live in, including the United States. We rely on our providers' own contractual and technical safeguards for these transfers.
8. Data retention
- We keep your account and content for as long as your account is active.
- Deleting a workspace or a piece of content removes it from your view immediately; the underlying record is then permanently purged shortly after.
- A data export file we prepare for you expires and is deleted 7 days after it's generated.
- Security and activity logs (e.g. sign-in and sync history) are kept to protect the service and investigate abuse; we don't yet enforce one fixed maximum retention window for these logs, but we don't use them for anything beyond security and support purposes.
- Invoice and payment records may be kept longer where required by tax and accounting law.
9. Your rights and choices
You have a few different tools depending on what you're trying to do:
- Export your content anytime. Settings → Backup lets you download a full copy of your
workspaces as a
.klykofile whenever you want, without needing to ask us. - Clear your content, keep your account. "Delete all data" in Settings removes your workspaces and their content but keeps you signed in with your existing account — useful for a fresh start.
- Delete your account entirely. Email us (Section 12) to request full account deletion. We apply a 30-day grace period in case the request was made in error, after which we anonymize your profile (email, name, avatar) and permanently delete your sessions and connected devices. Invoice records tied to completed payments may be retained separately as required by law even after this.
- Access, correct, or request a full copy of your personal data. Email us and we'll respond within 30 days.
If you're in the EEA, UK, or Switzerland, these map onto your rights under GDPR (access, rectification, erasure, restriction, portability, and objection), and you also have the right to lodge a complaint with your local data protection authority. If you're a California resident, we do not sell your personal information, and the choices above cover the requests CCPA gives you.
10. Children's privacy
Klyko is not directed at children under 16, and we don't knowingly collect data from them. If you believe a child has created an account, contact us and we'll remove it.
11. Security
All traffic to Klyko is encrypted (HTTPS). We never store your session token itself on our servers, only a one-way hash of it. Sign-in has no password to leak, and repeated failed sign-in attempts trigger a temporary lockout. No method of transmission or storage is 100% secure, but this is how we work to protect your data.
12. Changes to this policy
If we make material changes to this policy, we'll update the date at the top and let you know by email or an in-app notice before the change takes effect.
13. Contact us
Questions about this policy, or a request under any of the rights above, can go to [email protected].