Klara
Legal NoticePrivacy PolicyData Processing AgreementTechnical and Organizational Measures

Legal document

Privacy Policy

How Klara handles personal data, encrypted content, retention, and user rights.

Last updated: 2026-07-25Updated to disclose transactional account-verification email and the recipients of Google user data, and to affirm compliance with the Google Workspace Limited Use requirements. German/EU counsel review remains recommended; the production backup-retention schedule must still be confirmed.

Controller and Contact

Controller: Jasper Zimmerling, Leubnitzer Straße 28, 01069 Dresden, Germany.

Privacy contact: jasper@zimmerl.ing.

No data protection officer or EU representative is currently listed. Whether an appointment is legally required must be reassessed before launch and whenever Klara's processing scale, risk profile, or establishment changes. Privacy questions can be sent to the contact above.

What Klara Stores

Account data: email address, Klara user ID, authentication session metadata, sign-in metadata, and profile metadata.

Workspace data: projects, tasks, calendar events, calendar day highlights, calendar templates, objectives, key results, task/key-result links, focus preferences, recurrence settings, timestamps, and relationships between records.

Optional integration data: Google account email, calendar identifiers and metadata, event content and recurrence data, encrypted Google refresh tokens, sync mappings, sync status, and operational error information when Google Calendar is connected.

Optional feature data: audio submitted for transcription, goal descriptions and selected project names submitted for AI-assisted goal drafting, account-verification and password-reset email addresses and links, and feedback or mailing-list content submitted by the user.

Encryption metadata: whether an encryption-key backup exists, KDF type, iteration count, and creation/update timestamps. Raw encryption key material, wrapped_key, salt, and iv are not included in user data exports.

Purposes and Legal Bases

Klara processes account and workspace data to provide the planning service, authenticate users, sync data across devices, secure the service, provide data export and deletion functions, and maintain reliability.

The legal basis for providing the Klara service, account management, synchronization, export, deletion, user-requested Google Calendar sync, user-requested AI assistance, and transactional account-verification and password-reset email is Article 6(1)(b) GDPR, performance of a contract or steps requested before entering into a contract.

The legal basis for security logging, abuse prevention, service integrity, operational diagnostics, reliability monitoring, and debugging necessary to operate Klara is Article 6(1)(f) GDPR, legitimate interests in operating and protecting Klara and its users.

Mailing-list updates are sent only after an affirmative opt-in and rely on Article 6(1)(a) GDPR. Consent can be withdrawn at any time. Feedback content is processed when a user chooses to submit it; optional contact details and attachments are included only as provided by the user.

If Klara later adds optional analytics, performance measurement, marketing analytics, advertising tracking, heatmaps, session replay, or similar technologies that require consent or an additional provider, those processing activities will be documented separately before activation and loaded only where legally permitted.

Authentication Sessions and Technical Storage

Klara uses authentication sessions to keep users signed in and to protect account access. These sessions are required for secure operation of the service.

Session tokens and related technical storage are used to authenticate requests, enforce user-specific access, and prevent unauthorized access to account data.

Klara does not use these required authentication sessions for advertising tracking.

Operational Diagnostics

Klara does not currently load a third-party web analytics or performance-measurement provider.

Operational diagnostics are limited to data needed to operate, secure, debug, and improve the service. Configured Discord webhooks can receive aggregate usage counts, pseudonymous security-event summaries, route and error information, and sync-health results. Raw passwords, session tokens, encryption keys, and decrypted workspace content are not intentionally included.

Klara does not use operational diagnostics to build advertising profiles.

Google Calendar Integration

Google Calendar connection is optional and starts only after the user completes Google OAuth. Klara requests the calendar scopes needed to list calendars and to read, create, update, move, and delete calendar events for the user-facing synchronization feature.

Klara receives the connected Google account email, calendar metadata, event data, recurrence and cancellation information, and OAuth credentials. The Google refresh token is encrypted before database storage. Access tokens are obtained when synchronization runs and are used to call Google Calendar APIs.

Depending on the selected synchronization mode, Klara imports Google events into Klara and exports Klara events to the selected Google calendar. This can create, update, move, or delete events in Google on the user's behalf. Google Calendar data is not used for advertising, credit decisions, or unrelated analytics and is not sent to OpenAI for the AI goal features.

Users can disable a calendar mapping or disconnect the Google account in Settings. Disconnecting the account disables watches and removes the stored refresh token. Users may separately choose whether imported Klara event copies are removed; events already written to Google are managed in Google Calendar.

Google User Data Sharing and Limited Use

Klara processes information received from Google Workspace APIs only to provide and operate the user-controlled Google Calendar connection, including the synchronization mode, calendar, and Klara project selected by the user.

Google user data is transferred only to the recipients necessary for this feature: Google Ireland Limited / Google LLC to authenticate the account and exchange events with the selected Google Calendar; and Levo Studio together with the named infrastructure providers Hetzner Online GmbH, DataLix, and Wordbase / SkyLink Data Center, acting as hosting, database, backup, maintenance, security, and troubleshooting processors for Klara. Klara may also disclose information to competent authorities or affected parties only where required by law or necessary to investigate or respond to a security incident.

Klara does not sell Google user data or disclose it to advertisers, data brokers, OpenAI, other AI or machine-learning providers, or unrelated third parties. Klara's separate optional AI features process only content that the user submits specifically to those features; Google Calendar data is not submitted to them.

Klara does not use or transfer Google user data, including data derived from Google user data, to develop, improve, or train generalized or foundational artificial-intelligence or machine-learning models.

Klara's use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

AI-Assisted Goals and Transcription

When the user requests goal transcription, the submitted audio file is sent to the OpenAI API for transcription. When the user requests AI-assisted goal drafting, the entered goal description, selected project identifiers and names, and the current date are sent to the OpenAI API to generate editable goal and key-result drafts.

The features use OpenAI only after a user action. OpenAI API inputs and outputs are not used to train OpenAI models by default unless the Klara API account explicitly opts in. Klara does not intentionally send unrelated workspace content, Google Calendar content, account passwords, encryption keys, or session tokens to OpenAI.

AI output may be inaccurate. Users review and edit generated drafts before saving them. If the OpenAI API is unavailable, Klara can return local fallback suggestions for goal drafting; transcription requires the configured API.

Email, Feedback, and Mailing List

Resend is used for transactional account-verification and password-reset email when the service is configured. The recipient email address, verification or reset URL, subject, and message content are transmitted to Resend for delivery.

When Discord feedback webhooks are configured and a user submits feedback, Klara sends the feedback text or interview responses, optional contact information, account email or identifier, page URL, browser information, timestamp, and any attachments selected by the user to a restricted Discord channel.

When the optional launch mailing-list webhook is configured, the subscriber email address, page URL, browser information, source, and timestamp can be sent to Discord in addition to being stored in Klara. Mailing-list consent is recorded with the subscription.

Encryption Transparency

Klara encrypts the following content fields in the browser before storing them in the application database: project names, task titles, task descriptions, event titles, event locations, event notes, event attendee placeholders, calendar day highlight labels, calendar template names, calendar template item titles, locations, notes, and attendee placeholders, goal titles and descriptions, and key result titles and descriptions.

The following metadata remains unencrypted because it is needed to operate the product: account identifiers, row IDs, timestamps, calendar start and end times, due dates, recurrence settings, record relationships such as project_id and task_id, task status, priorities, calendar day highlight dates and colors, calendar template item timing, project/task relations, recurring-source metadata, and focus preference structure.

Klara stores encrypted content as ciphertext and does not store the user account encryption key in the application database as plaintext. Without the user account encryption key, Klara cannot read encrypted content from the server-side database values alone. This protection depends on the security of the user device, browser storage, user credentials, and recovery-key handling.

Metadata such as event times and project relationships remains plaintext so Klara can display calendars, sort tasks, connect records, sync across devices, and provide reminders and planning views.

Export, Deletion, and Retention

Klara provides a self-service data export in Settings and a self-service account deletion flow. The export contains an operator-visible view of stored server data and, when the account encryption key is available on the device, a user-readable view decrypted locally in the browser. Account deletion deletes the application account and associated app data, including projects, tasks, events, calendar day highlights, calendar templates, objectives, key results, focus preferences, and encryption-key backup metadata.

Active account data is retained while the account exists. Deleted tasks are retained for up to 30 days for recovery and system consistency and are then purged during normal cleanup. Infrastructure backups follow the documented Levo Studio backup cycle and are used only for continuity, recovery, and security. The signed infrastructure DPA requires protected EU/EEA backups, restore testing, and deletion or return after the service ends, but does not state a fixed retention period; Klara will publish the specific production period once it is operationally confirmed.

When account deletion is completed, the user loses access immediately. Residual copies expire through the documented infrastructure-backup cycle. Data held by optional external providers is subject to the provider-specific retention rules and deletion mechanisms described in their agreements.

User Rights

Users can request access, correction, deletion, restriction, data portability, objection, and withdrawal of consent for consent-based processing.

Users can download their data export and delete their account directly in Settings.

Users can contact jasper@zimmerl.ing for privacy requests. Users in the EU/EEA also have the right to lodge a complaint with their competent supervisory authority.

Subprocessors

Levo Studio, operated by Julius Grimm in Germany, processes data for Klara under a signed Article 28 GDPR agreement and provides deployment, Docker Swarm and Dokploy administration, server and PostgreSQL operation, backups, monitoring, maintenance, security support, and technical troubleshooting.

The documented production infrastructure uses four EU/EEA nodes: one Hetzner Online GmbH node in Falkenstein, Germany; one DataLix node in Frankfurt am Main, Germany; and two Wordbase / SkyLink Data Center nodes in the Netherlands. The application runs as a containerized Next.js service with a PostgreSQL database. Vercel and Supabase are not part of the current production runtime.

Google Ireland Limited / Google LLC: optional Google OAuth, account-profile lookup, and Google Calendar synchronization. Google processes the connected calendar data under the user's Google relationship and the applicable Google API terms.

OpenAI Ireland Ltd. and OpenAI affiliates: optional API transcription and AI-assisted goal drafting. Processing can occur in the EU and other documented OpenAI processing locations, including the United States, subject to the OpenAI data-processing terms and applicable transfer safeguards.

Plus Five Five, Inc. (Resend), United States: transactional account-verification and password-reset email delivery when configured. Resend documents EU Standard Contractual Clauses and EU-US Data Privacy Framework coverage for applicable transfers.

Discord Netherlands B.V. / Discord Inc.: user-submitted feedback, launch-list notifications, and limited operational or security webhook messages when the corresponding webhook is configured. Processing can occur in the Netherlands, United States, and other documented locations, using applicable adequacy decisions, the EU-US Data Privacy Framework, or Standard Contractual Clauses.

GitHub is used for source control, CI/CD, and the private container-image registry. Klara does not intentionally send production account or workspace data to GitHub through the application.

Klara will provide advance notice of material additions or replacements where required by the applicable DPA. Optional providers are used only when their feature is configured and invoked.

International Transfers

Where personal data is transferred outside the EU/EEA, Klara relies on an applicable transfer mechanism, such as an adequacy decision, Standard Contractual Clauses, and supplementary measures where required.

Core application and database infrastructure is documented in Germany and the Netherlands. Optional OpenAI, Resend, Discord, and Google services can involve processing outside the EU/EEA. Klara limits the data sent to each service to the relevant feature and relies on the provider's documented DPA, adequacy or Data Privacy Framework coverage, and/or EU Standard Contractual Clauses as applicable.

Security and Breach Process

Klara uses client-side encryption for the content fields listed above, authenticated access, user-scoped server-side data access, and server-only secret keys for administrative actions such as account deletion.

Potential personal-data breaches are triaged, contained, documented, and assessed for notification duties. Klara notifies the competent supervisory authority within 72 hours after becoming aware of a notifiable breach, unless the breach is unlikely to result in a risk to user rights and freedoms. Klara notifies affected users when required by GDPR.

Reference Framework

Drafted against GDPR transparency, processor, security, and breach-notification concepts including GDPR Articles 13, 14, 28, 32, 33, and 34.