Stays on your device
Your full portfolio records, original documents, and chat history remain local unless you choose an action that sends specific content.
Last updated: August 28, 2026
This Privacy Policy explains how EFMC DIGITAL FOR WEB-DESIGN CO. L.L.C S.O.C, referred to on this site as EFMC Digital LLC ("EFMC", "we", "us", or "our"), provides KlarFort and handles information. Where applicable, EFMC is the data controller for the personal data processed as described in this Policy. KlarFort is the product and brand name.
KlarFort is private by design. Your core portfolio records, original documents, and chat history live on your device. KlarFort does not persist your full portfolio tables on its servers. There are no ads, and your data is never sold.
When you choose an AI feature, KlarFort sends the request, files you attach, and the relevant portfolio context needed to answer it. KlarFort does not write chat messages, attachments, or portfolio snapshots to its persistent server storage. Selected AI outputs and rules are kept as described below. Personalized Insights reports, evidence links, snooze state, and resolution state stay on your device; KlarFort does not keep a durable server copy of those personalized reports or portfolio records. KlarFort still keeps the limited pseudonymous service, security, reporting, and deletion-safeguard records required to operate the wider service.
Your full portfolio records, original documents, and chat history remain local unless you choose an action that sends specific content.
AI prompts, attachments, and relevant portfolio context are processed only after you consent and use or enable the feature. A portable backup goes only to the destination you choose.
Limited pseudonymous access, security, purchase-verification, and service records; optional push data; selected AI outputs and rules; and reports you submit.
KlarFort shows no ads and never sells your data. Optional user-level ad measurement is off unless you choose Accept & Allow Measurement on the single Terms & Privacy screen; on iOS it also requires Apple's tracking permission. iOS may still register an install for Apple's delayed aggregate attribution without starting user-level measurement.
Export and import happen on your device. A portable backup can include your core financial records, supported settings, custom rules, saved risks, and other user-created content. KlarFort then hands the file to the save and share controls provided by iOS or Android. KlarFort's servers do not receive, route, or store the backup file.
You decide where the file goes. After you share or save it, the destination's privacy and security terms apply. The backup is not separately encrypted by KlarFort, so protect it like a financial document.
KlarFort on iOS and Android can import the backup. Each imported file can be up to 50 MB. Original document and attachment contents, chat history, authentication information, net-worth snapshot history, and generated Insights reports are not included.
Import combines data according to its type. Core financial records with matching IDs are updated, new core financial records are added, and core financial records that exist only on the destination remain there. Custom rules and import history from the backup replace those destination lists. Current compatible versions restore notification settings from the backup. A recognized last document kind is preserved, while the preferred document source and reuse choice reset to current defaults. Sharing-privacy choices also reset to current defaults rather than being restored.
AI is separate and optional. When you choose an AI feature, KlarFort sends the request, any attachment, and relevant portfolio context through its backend for processing. KlarFort does not save those inputs as a persistent portfolio copy. Selected AI outputs and the limited pseudonymous service and security records are retained as described below; personalized Insights reports remain local.
This summary is provided to align with the disclosure formats used by Apple's App Privacy Details and Google Play's Data Safety section. The detailed sections below are authoritative.
KlarFort does not use an email address, name, or social-login identity as your account. The service operates a pseudonymous profile for access and verified subscriptions. It stores the following records:
Your complete portfolio tables (assets, liabilities, cash flows, projects, and obligations) are not persisted on KlarFort servers. Outside optional ad measurement, KlarFort does not collect advertising identifiers. KlarFort does not collect precise location, contact lists, microphone data, health or fitness data, biometric data, or financial-account credentials. Content sent for consent-gated AI processing is not written to persistent KlarFort storage. The exceptions are the selected AI outputs and user-submitted reports described above; personalized Insights outputs are not an exception because they remain on the device.
Both klarfort.com and www.klarfort.com use Cloudflare Web Analytics to measure aggregate website traffic and page performance. The metrics may include page paths, referring sites, country, general browser, device, and operating-system categories, navigation type, and page-performance timings. We use these reports to understand how the public website is used and improve its reliability and performance.
Cloudflare Web Analytics does not use cookies or local storage to collect these usage metrics, does not fingerprint individuals, and does not track individual visitors across Cloudflare customers' sites. KlarFort does not use it to build advertising profiles. This website analytics is separate from the optional in-app advertising measurement described below and does not receive any KlarFort portfolio records, documents, chat messages, or AI content.
KlarFort has no in-app ads. After the opening subscription screen, the app presents one Terms & Privacy screen with two clear actions. Accept & Allow Measurement accepts the Terms, Privacy Policy, and Disclaimer and opts in to the optional measurement described here. Accept Without Measurement accepts the same legal documents while keeping user-level measurement off. Both actions confirm that the user is at least 18, and both provide the same app access. The measurement choice is independent of the separate just-in-time AI consent and does not affect the seven-day Premium preview, purchasing, restoring purchases, or subscription benefits.
User-level measurement. If you allow it, KlarFort starts a measurement provider's SDK, which may automatically report the app install and app launches or sessions and, at most once, the first verified paid-subscription event. The provider may create or access a provider-generated device identifier and process an IP address, IP-derived approximate location, network information, app version, operating-system version, device model, and other standard app and device metadata. On iOS, this path starts only after Apple's App Tracking Transparency status is authorized and may use IDFV and the IDFA Apple then permits. On Android, it may use the Google Advertising ID (GAID), App Set ID, and Google Play Install Referrer data where available and permitted. The provider may share these limited events, identifiers, and attribution data with advertising partners to measure KlarFort campaigns and distinguish paid from organic acquisition. KlarFort does not set a custom measurement user ID or provide a backend measurement event ID to Apple or measurement and advertising partners. It does not send a name, email address, phone number, KlarFort account identifier, portfolio record, holding, balance, cash-flow amount, AI content, file, receipt, order or transaction identifier, price, revenue, currency, product, tier, or billing cadence.
Apple aggregate attribution. Before the app's interactive screens, iOS calls a registration-only bridge to register the install with Apple's privacy-preserving ad-attribution framework. That call does not start a user-level measurement session, emit an SDK event, select a conversion value, or store an Apple-attribution marker. After a user chooses Accept & Allow Measurement and authorizes Apple's separate tracking prompt, KlarFort starts user-level measurement with provider-managed conversion values; the configured provider model is then the sole conversion-value manager. KlarFort does not directly update an AdAttributionKit or SKAdNetwork conversion value. Apple controls delayed, signed postbacks and may send copies to the measurement provider and the relevant ad network. These aggregate postbacks do not expose an advertising identifier or identify a particular user or device to KlarFort or its measurement and advertising partners.
Choice, delayed consent, and withdrawal. The opening subscription screen appears before the unified Terms & Privacy choice. If a first paid subscription is verified there, the app may keep only an opaque measurement event identifier briefly on the device while you make that choice. That identifier is local authorization and deduplication state: it is never forwarded to Apple or measurement and advertising partners. The first-paid event is reported only if you choose to allow measurement and, on iOS, authorize tracking; otherwise the identifier is deleted. KlarFort does not backfill other events. If you choose Accept Without Measurement or Apple's tracking status is denied or restricted, iOS performs only the registration-only aggregate install path, with no provider-managed subscription conversion. You can turn Ad Measurement off in Settings to stop future user-level sharing and managed subscription conversions and clear pending local measurement state. Changing this setting cannot prevent or recall an aggregate install registration or data already received by Apple or measurement and advertising partners; their retention and rights-request procedures apply to that data.
KlarFort offers optional AI assistance: chat with the in-app assistant, daily insight notes, document import, and periodic background monitoring on paid tiers. These features are off until you agree to use them. The first time you open an AI feature, the app presents a consent screen that explains what will be shared and with whom; nothing is sent to any AI provider until you tap Agree and Continue. You can withdraw this consent at any time in the app under Settings > AI Data Sharing. Withdrawing consent immediately blocks any new AI request from the app and cancels an assistant response that is still streaming; a request already submitted to our servers finishes processing, and nothing further is sent.
When you use an AI feature, the app transmits a payload through our backend to our AI providers for processing, and the response is returned to you. The payload may contain:
KlarFort does not automatically add your name, email address, service-access credentials, or purchase credentials to the AI payload. Text and files you choose to submit may themselves contain personal information, so review them before sending. Requests are made by our servers on your behalf, so your device identifier and network address are not supplied to the AI provider as request identity fields.
Who receives it. Conversational and analysis requests are processed by the AI providers we may use: Anthropic PBC, Google LLC, or OpenAI, L.L.C. Documents and images you attach may also be processed by Google LLC to read their contents before your request is answered. Whichever providers process a request act as service providers under enterprise data-processing terms that restrict processing to delivering the service to us, impose confidentiality and security obligations consistent with the protections in this policy, and prohibit using your data to train their models.
Search and research separation. Some AI features may use public web search or public market and economic reference sources. When you use chat search, the search provider may receive a query derived from your request. KlarFort directs the assistant not to include private portfolio details in that query. Personalized Insights research sends public-research services only generic research requests or public reference values, not your raw question, rules, names, notes, amounts, portfolio rows, scores, or identifiers.
Retention. Your messages, attachments, and portfolio snapshots are used only to process your request and a short retry window; they are not written to persistent KlarFort server storage. KlarFort keeps the selected outputs listed in What we store: daily recommendations (up to 90 days), the latest monitoring analysis (replaced by each newer one), and custom rules. Personalized Insights reports and actions remain on your device.
Reporting is optional. When you use the in-app report action, KlarFort sends and stores a reference to the reported response and a short excerpt under your pseudonymous service profile for safety review. The report does not transmit your full conversation unless that content is part of the excerpt shown by the app. Up to 100 reports are retained per profile; each is removed within 365 days under scheduled cleanup or earlier with the deletable data when you delete your account. Use the contact channel below for a support request or a reply.
Service providers involved in delivering KlarFort include:
The app contains a measurement SDK but contains no ad-serving or social-login SDK. KlarFort does not display ads in the app.
If you subscribe, billing is handled by Apple App Store or Google Play. Their terms and native purchase sheet govern your purchase, including the price and billing period, auto-renewal, billing cycles, family sharing, and price changes. KlarFort subscriptions carry no store trial period; the optional app-managed preview requires no payment method and is never billed by any store. KlarFort processes the purchase information needed to confirm your tier and protect against misuse. KlarFort does not see, store, or process your payment-card details. Cancellation is performed in the same store account that originated the purchase, not by deleting your KlarFort profile. Unless you cancel in that store, billing continues on the store's normal schedule after KlarFort account deletion.
You can delete your account at any time:
Reset App Data is not account deletion. Reset clears local app data, including the Ad Measurement choice and pending measurement events, and disconnects the current device, but it does not request server erasure, recall data already sent to attribution providers, or remove stored AI outputs and reports. To erase active server data, use Delete Account first and wait for it to succeed before resetting or uninstalling.
The limited access, purchase-verification, abuse-prevention, service-limit, and deletion-safeguard records described in Data retention are not all erased with active profile data. Historical recovery copies may retain prior data for up to seven days, but completed deletion requests are reapplied before a recovered copy can serve. Active store subscriptions must be cancelled separately in the App Store or Google Play account that originated the purchase. Deleting KlarFort does not cancel billing. A later verified recreation does not restore erased active profile or local data.
KlarFort is for adults age 18 or older and is not offered to minors, including with parent or guardian consent. We do not knowingly retain account information for anyone under 18. If you are a parent or guardian and believe a minor has created an account, please contact us and we will delete it. KlarFort does not knowingly collect personal information in violation of the Children's Online Privacy Protection Act (COPPA).
Our infrastructure operates from facilities that may be located outside your country of residence. By using KlarFort you consent to your account information being processed in those jurisdictions, subject to the protections in this policy. Where required, transfers from the European Economic Area, the United Kingdom, or Switzerland are made under appropriate safeguards such as the Standard Contractual Clauses.
If you are in the European Economic Area, the United Kingdom, or Switzerland, you may have rights to access, correct, restrict, port, and erase personal data, and to object to processing or withdraw consent. Our lawful bases are: contract to deliver a subscription; consent for consent-gated AI features, notifications, and user-level advertising measurement; legitimate interests, where permitted, for privacy-preserving aggregate campaign measurement, privacy-preserving aggregate website traffic and page-performance measurement, service security, limit enforcement, fraud prevention, repeated-misuse prevention, and investigation of reported AI responses; and legal obligation where applicable. AI consent can be withdrawn under Settings > AI Data Sharing, and advertising-measurement consent can be withdrawn under Settings > Ad Measurement. To exercise a right, use the in-app deletion action or email contact@klarfort.com. Because no account email is stored, support must securely verify the pseudonymous profile before acting on a profile-specific request. You also have the right to lodge a complaint with your local supervisory authority.
If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you the right to know what personal information we collect, the right to delete it, the right to correct it, the right to limit the use of sensitive personal information, the right to opt out of "sale" or "sharing", and the right not to be discriminated against for exercising these rights.
Notice at collection. The categories of personal information involved in KlarFort, the purposes for which they are used, whether they are stored on our servers or transmitted ephemerally, and the retention period for each are:
Sale and sharing. KlarFort does not sell personal information. If you choose Accept & Allow Measurement, limited identifier, install, session, and first-paid-subscription data may be disclosed to measurement and advertising partners; this may be considered "sharing" or targeted advertising under California or other state law. KlarFort obtains an affirmative opt-in before user-level measurement and provides an in-app control to stop future sharing. Apple aggregate attribution does not identify a particular user or device.
Sensitive personal information. AI content you choose to send may contain financial or other sensitive information. KlarFort uses it only to fulfil the request you initiated and does not use it to infer characteristics for advertising, sale, or unrelated profiling. You do not need to file a request to limit those unrelated uses; KlarFort does not perform them.
Right of non-discrimination. We will not deny you the Service, charge you a different price, or provide a different level of quality for exercising any of these rights.
To exercise your CCPA rights, use the deletion-request page or email contact@klarfort.com. We respond to verifiable requests within 45 days, with a single 45-day extension where reasonably necessary, in line with the timelines set by California law.
Residents of other US states with comprehensive consumer-privacy laws (including but not limited to Colorado, Connecticut, Delaware, Indiana, Iowa, Montana, Oregon, Tennessee, Texas, Utah, and Virginia) may have rights similar to those described in the GDPR and CCPA sections above. The same email and deletion-request channels apply.
We apply current industry-standard practices, including encrypted transport, restricted production access, monitoring, and data minimization, to protect the pseudonymous service data we hold and communication between the app, our servers, and consent-gated AI providers. No system is perfectly secure. To report a security concern, use the responsible-disclosure channel.
If we materially change how we handle your data, we will update this page, revise the Last updated date, and surface a notice in the app on next launch. Your continued use of the Service after a change becomes effective constitutes acceptance of the revised policy. We will not retroactively make material changes that reduce your privacy rights without your consent. Editorial clarifications and fuller disclosures that do not change how KlarFort handles data do not trigger a new in-app acceptance notice.
Questions, requests, or concerns about this policy may be sent to the privacy-support address below. Full provider, licence, address, telephone, and corporate-contact details are available on the Contact page.
We respond to every message we receive.
contact@klarfort.com