Privacy Policy
Last updated: March 9, 2026
1. Introduction
Klyra ("we", "us", "our") is committed to protecting the privacy of our users and their customers. This Privacy Policy explains how we collect, use, store, and protect information when you use our platform.
2. Information We Collect
2.1 Account Information
When you sign up, we collect your name, email address, and organization details through our authentication provider (Clerk). This information is necessary to create and manage your account.
2.2 Customer Data
You may submit data about your customers through the Service, including:
- Contact information (names, email addresses, phone numbers)
- Conversation messages and attachments
- Account details and custom attributes
- Product usage events (if you integrate usage tracking)
- Help center content and knowledge base articles
You are the data controller for your Customer Data. We process it solely as a data processor on your behalf.
2.3 Usage Data
We automatically collect information about how you interact with the Service, including pages visited, features used, browser type, and device information. This data is used to improve the Service and is processed via PostHog (self-hosted or cloud).
2.4 AI Processing
When AI features are enabled, conversation content and customer data may be processed by AI models to generate responses, health scores, predictions, and other insights. AI processing is performed through third-party model providers (via OpenRouter). We do not use your data to train AI models.
3. How We Use Information
- Providing the Service: Processing conversations, generating AI insights, calculating health scores, and delivering notifications.
- Improving the Service: Analyzing usage patterns to improve features, fix bugs, and optimize performance.
- Communication: Sending transactional emails (scheduled reports, SLA alerts, notifications) and occasional product updates.
- Security: Detecting and preventing fraud, abuse, and unauthorized access via audit logging and rate limiting.
4. Data Storage and Security
4.1 Infrastructure
Customer Data is stored in PostgreSQL databases hosted on Supabase with encryption at rest. Background job data is temporarily stored in Redis. Search indexes are maintained in MeiliSearch.
4.2 Multi-Tenant Isolation
Every database query is scoped to your organization. We implement triple-layered tenant isolation: session-level authentication, middleware-level organization scoping, and query-level filtering to ensure your data is never accessible to other organizations.
4.3 Security Measures
- HTTPS/TLS encryption for all data in transit
- Security headers (HSTS, X-Frame-Options, Content Security Policy)
- API key authentication with SHA-256 hashing
- Webhook signature verification for all inbound integrations
- Rate limiting on public endpoints
- Audit logging of all administrative actions
- Role-based access control (viewer, member, admin, owner)
5. Data Sharing
We do not sell your data. We share data only with:
- Infrastructure providers: Supabase (database), Clerk (authentication), and hosting providers — to operate the Service.
- AI model providers: Via OpenRouter — to process AI features you enable. These providers do not retain your data for training purposes.
- Email delivery: Resend or Postmark — to send transactional emails and scheduled reports.
- Integrations you enable: Slack, Discord, CRM systems — only when you explicitly configure these integrations.
- Legal requirements: When required by law, court order, or governmental request.
6. Data Retention
- Active accounts: Customer Data is retained for the duration of your subscription.
- After cancellation: Data is retained for 30 days to allow for export, then permanently deleted.
- Audit logs: Retained for 1 year from creation for compliance purposes.
- AI usage logs: Retained for 90 days for debugging and cost tracking.
7. Your Rights
You have the right to:
- Access: Request a copy of the data we hold about you.
- Correction: Update or correct inaccurate data.
- Deletion: Request deletion of your account and associated data.
- Export: Export your Customer Data in standard formats (CSV) at any time through the Service.
- Restriction: Request that we limit processing of your data in certain circumstances.
To exercise these rights, contact us at [email protected].
8. Cookies and Tracking
We use essential cookies for authentication and session management. We use PostHog for product analytics with the following settings:
- Page views and navigation are tracked automatically.
- Autocapture of clicks and form interactions is disabled.
- You can opt out of analytics tracking in your profile settings.
9. Children's Privacy
The Service is not directed at individuals under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
10. International Data Transfers
Your data may be processed in regions where our infrastructure providers operate. We ensure that appropriate safeguards are in place for any cross-border data transfers, including standard contractual clauses where required.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 30 days before taking effect. The "Last updated" date at the top of this page reflects the most recent revision.
12. Contact Us
For privacy-related questions or requests, contact us at [email protected].