Data Privacy Policy
Last updated: July 5, 2026
1. Data We Collect
When you use Klarity, we collect the following information:
- Account information: Your name, email address, and profile picture provided by your Google or Microsoft account during sign-up.
- Billing information: A customer identifier and subscription status from our payment processor. We do not collect or store your card number, PayPal account, Apple Pay token, or other payment-method details ourselves.
- Usage data: Information about how you interact with the application, including tasks created, pages visited, and features used.
- Technical data: IP address, browser type, device information, and session data necessary for the service to function.
2. How We Use Your Data
We use your data to:
- Provide and maintain the Klarity service, including task management, scheduling, and collaboration features.
- Authenticate your identity and secure your account.
- Improve the application based on aggregated, anonymized usage patterns.
- Communicate important service updates or changes.
We do not sell your personal data to third parties.
3. Data Storage and Security
Your data is stored on secure servers within the European Union. We implement industry-standard security measures, including encryption in transit (TLS) and at rest, to protect your information.
Access to your data is restricted to authorized personnel who need it to operate and maintain the service.
4. Third-Party Services
Klarity integrates with the following third-party services:
- Google OAuth: Used for authentication. We receive your name, email, and profile picture from Google when you sign in.
- Microsoft OAuth: Used for authentication. We receive your name, email, and profile picture from Microsoft when you sign in.
- Google Calendar / Microsoft Calendar: If you enable calendar sync, we access your calendar data to provide scheduling features. This data is only used within Klarity and not shared further.
- Crisp (live chat support): We use Crisp (Crisp IM SARL) to provide in-app chat support. When you are signed in, your name and email address are shared with Crisp so we can identify you in support conversations, along with the messages you send us. Crisp's handling of your data is governed by their own privacy policy.
- Polar (payment processor): Subscription billing is handled by Polar (Polarsource, Inc.). When you start a paid plan, you enter payment details (credit/debit card, PayPal, Apple Pay, or other methods Polar supports) directly with Polar — we never see or store them. We only receive a customer identifier, subscription status, and billing period from Polar. Polar's handling of your data is governed by their own privacy policy.
5. Analytics
We measure how our website and application are used with a self-hosted instance of PostHog, an open-source analytics platform. It runs entirely on our own servers within the European Union — analytics data is never shared with, or accessible to, any third party.
- Cookieless by default: Unless you opt in below, analytics uses no cookies or fingerprinting. On our public website it collects aggregate technical data only: pages visited, referrer, campaign parameters, browser and device type, and coarse location derived from your IP address (the address itself is not stored).
- Pseudonymous product usage: When you are signed in, usage events (for example, which features you use) are linked to a pseudonymous internal user identifier. Your name and email address are never sent to the analytics system.
- Legal basis: We process this data on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in understanding and improving Klarity.
- Optional attribution identifier (consent): If you accept the banner on our website, we store a random identifier and the campaign parameters of your first visit in your browser's local storage and a first-party cookie. This lets us recognize your browser across visits — and connect your journey across our website and app — so we can understand which advertisement led to a signup. The legal basis is your consent (Art. 6(1)(a) GDPR); you can decline without any effect on the website, and withdraw at any time via "Cookie settings" in the footer or by clearing your browser data. Without consent, only the cookieless analytics described above run.
- On account deletion: The identifier linking analytics events to you is destroyed together with your account, after which the remaining data can no longer be associated with any person.
6. Your Rights
Under the GDPR and applicable data protection laws, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate personal data.
- Erasure: Request deletion of your personal data ("right to be forgotten").
- Portability: Request a machine-readable copy of your data.
- Objection: Object to processing of your personal data for specific purposes.
- Withdrawal of consent: Withdraw your consent at any time where processing is based on consent.
7. Data Retention
We retain your personal data for as long as your account is active. If you delete your account, your data will be permanently removed within 30 days, except where we are legally required to retain certain records.
8. Contact
If you have questions about this privacy policy or wish to exercise your data rights, please contact us at: