Legal

Privacy policy

Last updated: June 2026

This is a plain-language summary of how Kliently handles data. It is written to be readable, not to obscure — but it is not a substitute for legal review of your own obligations.

Overview

Kliently is a client operating system for independent professionals. Running your business means trusting us with sensitive information — your clients, your contracts, and the money path between them. This policy explains, in plain language, exactly what we collect, why, and the control you keep. It applies to the Kliently marketing site, web app, and client portal.

The short version: your data is yours. We don't sell it, we don't use it to train AI, and you can export or delete it whenever you want.

What we collect

  • Account data: your name, email, password hash, and workspace details. We never store your password in plaintext.
  • Business data you enter: clients, projects, proposals, contracts, invoices, time entries, expenses, and payment records. This is your content; you own it.
  • Signature evidence: for e-signed documents we record IP address, user agent, timestamps, view and scroll milestones, and approximate location. This is the audit trail that makes a signature defensible — see our e-signature compliance page.
  • Payment metadata: when you connect a payment gateway, we store the transaction records and statuses needed to reconcile invoices. Card numbers and bank credentials are handled by the gateway, never by us.
  • Technical data: basic logs, device/browser type, and aggregate, privacy-respecting usage analytics used to keep the service reliable and secure.

How we use your data

We use the data above only to:

  • provide, maintain, and secure the service;
  • process the actions you take — sending a proposal, collecting a payment, generating an invoice PDF;
  • send essential service email (receipts, reminders, security notices) through our email provider;
  • provide support when you contact us, and detect fraud or abuse;
  • meet our legal and tax obligations.

We do not run advertising, and we do not build advertising profiles.

What we never do

  • We never sell your data or your clients' data.
  • We never use your content to train AI models. AI features run on your own API key, and prompts are not retained for training.
  • We never see your payment-provider secrets in plaintext — they're encrypted with AES-256-GCM at rest and only decrypted in memory to make a call you initiated.
  • We never share data with advertisers or data brokers.

Cookies & tracking

We use a small number of first-party cookies that are strictly necessary: a session cookie to keep you signed in, a cookie that remembers your language choice, and a cookie that remembers your light/dark theme. The live-chat widget sets a first-party identifier so a visitor's conversation persists across pages.

We do not use third-party advertising or cross-site tracking cookies.

Subprocessors

Your core data lives in Kliently's own database. We rely on a short list of vetted providers to deliver specific functions:

  • Stripe — subscription billing for Kliently itself.
  • Resend — transactional email delivery.
  • Inngest — background jobs (reminders, scheduled invoices).
  • Payment gateways you enable — SSLCommerz, Razorpay, and PayPal process payments under their own terms when you turn them on.

Each subprocessor receives only the minimum data needed for its task.

Data location & retention

We retain your data for as long as your workspace is active. When you delete content, it is removed from active systems promptly and from encrypted backups on a rolling cycle. Append-only audit and signature records are retained for their evidentiary value and to meet legal obligations, even after related content is deleted. If you close your account, we delete or anonymize your data within 30 days, except where we must retain records for tax or legal reasons.

Security

Workspaces are isolated at the database level, secrets are encrypted with AES-256-GCM, access tokens are unguessable and revocable, and every sensitive action is written to an append-only audit log. For the full picture, see our security page. No system is perfectly secure, but security is an architecture decision we take seriously.

Your rights

Depending on where you live (for example, under the GDPR or California's CCPA), you have the right to access, correct, export, and delete your personal data, and to object to certain processing. We extend these rights to all users regardless of location:

  • Export: download all workspace data as JSON from Settings → Danger zone, at any time.
  • Deletion: delete content in-app, or request full account deletion via support@kliently.app.
  • Access & correction: view and edit your data directly in the app, or ask us for help.

We respond to verified requests within 30 days. International transfers of data, where they occur, are protected by appropriate safeguards.

Children

Kliently is a business tool intended for users aged 18 and over. We do not knowingly collect data from children. If you believe a minor has provided us data, contact us and we will remove it.

Changes & contact

We may update this policy as the product evolves; material changes will be announced in-app or by email. Questions about privacy, or a data request? Email support@kliently.app and we'll help.

This policy is provided for transparency and does not constitute legal advice.