Privacy Policy
Last updated: July 15, 2026
KlarFort is local-first: your core portfolio records are stored on your device. Optional AI features transmit the request and relevant portfolio context through KlarFort's backend to AI providers only after you consent. KlarFort also stores limited pseudonymous service data, anti-abuse trial and subscription records, temporary abuse and cost-control records, optional notification data, selected AI feature outputs, and AI response reports as described below. KlarFort has no advertising and does not sell your data.
Summary of data practices
This summary is provided to align with the disclosure formats used by Apple's App Privacy Details and Google Play's Data Safety section. The detailed sections below are authoritative.
- Data stored and linked to a pseudonymous service profile: a pseudonymous User ID; a full one-way deduplication hash derived from the client-generated trial Device ID; a one-way hash of a stable store transaction or purchase identifier together with product, tier, expiration, and verification information (Purchase History); an optional push delivery token; service and rate-limit records; selected AI feature outputs; and, when you report an AI response, the reported message UUID, fixed report category, and excerpt.
- Data transmitted for consent-gated AI processing: your request, attached documents or images, and relevant portfolio context may be sent through our backend to Anthropic, Google, or OpenAI. KlarFort does not persist chat messages or attachments on its servers. The selected outputs it does store are listed in What we store.
- Data kept on your device: your full portfolio records, documents, and chat history remain local unless you choose an action that transmits some of that content, such as an AI request or an AI response report.
- Data not linked to you: none.
- Data used to track you across other companies' apps and websites: none.
- Data shared for sale, advertising, or cross-context behavioural advertising: none. KlarFort does not sell or share user data in the senses defined by the CCPA, the CPRA, or comparable laws.
- Service providers we use to deliver the product: Apple App Store and Google Play for subscription billing; the AI providers we may use (Anthropic, Google, and OpenAI) for consent-gated AI processing; Apple Push Notification service and Firebase Cloud Messaging for opted-in notification delivery; Hetzner for backend hosting; and Cloudflare for the public website.
What we store
KlarFort does not use an email address, name, or social-login identity as your account. The backend operates a pseudonymous service profile derived from a trial or verified store purchase. It stores the following records:
- Pseudonymous access profile. The backend issues a signed access token whose subject is a derived pseudonymous User ID. The token is stored on your device, not as an account-password record on our servers.
- Trial anti-abuse record. On first install, the app creates a random UUID and sends it with the device platform to request the seven-day preview. The server normalizes the UUID and immediately derives a full SHA-256 deduplication hash. Only that one-way hash, the platform, trial start and expiration, and a derived pseudonymous User ID are persisted; the raw UUID is not stored. The UUID is not an advertising identifier or device fingerprint. The hashed record is retained indefinitely to prevent replay or regrant for the same installation identifier. Reset or uninstall may generate a new identifier, so this record does not identify a physical device across installations.
- Subscription verification and anti-replay record. A store receipt or purchase credential is processed to verify entitlement. KlarFort persists a one-way SHA-256 hash of the stable store transaction or purchase identifier, not the raw Play purchase token, together with product ID, tier, expiration, verification time, and the first pseudonymous User ID that verified it. Once bound, this record is retained indefinitely to prevent the same purchase from being replayed against another profile.
- Notification delivery token (optional). If you enable push notifications, KlarFort stores the operating-system token needed for delivery. It is removed on account deletion and stale registrations are cleaned after 30 days without an update.
- Daily AI rate-limit anchor. KlarFort stores an internal database row ID, an opaque pseudonymous User ID, the UTC date, and an integer request count to enforce the daily AI cap. The row is generation-independent and retained across account deletion and verified recreation so the same receipt or lifecycle subject cannot reset that cap. It is kept for up to 30 days under the existing startup and daily cleanup policy. It contains no prompt, portfolio record, attachment, AI output, or report excerpt.
- AI outputs generated for you (only if you consent to AI features). The daily insight notes generated for your account (kept for up to 90 days), your latest background-monitoring analysis (one snapshot, replaced by each newer analysis), and the custom rules you create or accept from the assistant (kept until you delete them). All of these are removed when you delete your account.
- AI response reports (only when you submit one). KlarFort stores the reported AI message UUID, a fixed report category, and a short excerpt under your pseudonymous service profile so the report can be reviewed for safety. A report is not a support ticket and does not guarantee an individual reply. Up to 100 reports are retained per profile; each is removed within 365 days under scheduled cleanup or earlier when you delete your account.
- Authorization lifecycle record and deletion-recovery ledger. Account deletion durably records the pseudonymous User ID, deletion time, and authorization generation needed to reject every pre-deletion access token. Before active data is erased from the database, an append-only recovery ledger outside that database also records the pseudonymous User ID, the authenticated token generation, the target deleted generation, and the deletion time. These narrow records are retained so deletion can be reapplied after database recovery. An explicit recreation after verified store-purchase restoration marks the profile active under the current token generation. The records remain; erased user content is not made active again and pre-deletion tokens remain invalid.
- Security and operational records. Service logs may contain a pseudonymous User ID, request ID, timestamp, outcome, connection metadata, and security or error event. Raw trial UUIDs and raw store purchase credentials are not written to persistent application storage or application audit logs. Logs are used to operate and protect the service and may be retained where necessary for security, fraud prevention, incident response, or legal obligations.
Your complete portfolio tables (assets, liabilities, cash flows, projects, and obligations) are not persisted on KlarFort servers. KlarFort does not collect advertising identifiers, precise or coarse location, contact lists, microphone data, health or fitness data, biometric data, or financial-account credentials. Content sent for consent-gated AI processing is not written to persistent KlarFort storage; selected outputs and user-submitted reports are the exceptions described above.
AI features require your consent
KlarFort offers optional AI assistance: chat with the in-app assistant, daily insight notes, document import, and periodic background monitoring on paid tiers. These features are off until you agree to use them. The first time you open an AI feature, the app presents a consent screen that explains what will be shared and with whom; nothing is sent to any AI provider until you tap Agree and Continue. You can withdraw this consent at any time in the app under Settings > AI Data Sharing. Withdrawing consent immediately blocks any new AI request from the app and cancels an assistant response that is still streaming; a request already submitted to our servers finishes processing, and nothing further is sent.
When you use an AI feature, the app transmits a payload through our backend to our AI providers for processing, and the response is returned to you. The payload may contain:
- The text of the question or prompt you wrote.
- Any document, image, or other file you yourself attach to the request.
- A snapshot of the portfolio records you entered in the app (asset, liability, cash-flow, obligation, and project entries with their names, amounts, dates, and notes), together with derived metrics such as net worth, runway, and risk signals, your custom rules, and your default currency.
KlarFort does not automatically add a name, email address, raw trial UUID, store purchase credential, or access token to the AI payload. Text and files you choose to submit may themselves contain personal information, so review them before sending. Requests are made by our servers on your behalf, so your device identifier and network address are not supplied to the AI provider as request identity fields.
Who receives it. Conversational and analysis requests are processed by the AI providers we may use: Anthropic PBC, Google LLC, or OpenAI, L.L.C. Documents and images you attach may also be processed by Google LLC to read their contents before your request is answered. Whichever providers process a request act as service providers under enterprise data-processing terms that restrict processing to delivering the service to us, impose confidentiality and security obligations consistent with the protections in this policy, and prohibit using your data to train their models. When a request needs current market information, the model may issue generic web-search queries that are instructed to contain no personal or portfolio details.
Retention. Your messages, attachments, and portfolio snapshots are forwarded for the lifetime of the request and are not written to persistent KlarFort server storage; a short-lived in-memory cache is used only to avoid processing an identical retried request twice. What KlarFort does keep are the outputs listed in What we store: daily insight notes (up to 90 days), your latest monitoring analysis (replaced by each newer one), and custom rules. These are removed when you delete your account.
Reporting an AI response
Reporting is optional. When you use the in-app report action, KlarFort sends and stores the reported message UUID, a fixed report category, and a short excerpt under your pseudonymous service profile for safety review. The report does not transmit your full conversation unless that content is part of the excerpt shown by the app. Up to 100 reports are retained per profile; each is removed within 365 days under scheduled cleanup or earlier with the deletable data when you delete your account. Use the contact channel below for a support request or a reply.
Third-party services
Service providers involved in delivering KlarFort include:
- Apple App Store and Google Play, which handle the payment flow for paid subscriptions and provide receipt or purchase information used to verify your tier. KlarFort does not see your payment-card details.
- Anthropic, Google, and OpenAI, the AI providers we may use for consent-gated AI features, which receive the payload described in AI features require your consent only after you agree and only when you use those features.
- Apple Push Notification service (APNs) and Firebase Cloud Messaging (FCM), used only as transport for the notifications you opted into.
- Hetzner Online GmbH, which hosts KlarFort's backend and database infrastructure.
- Cloudflare, Inc., which hosts and protects the public klarfort.com website. The public site does not contain your in-app portfolio.
The app contains no advertising SDKs and no social-login SDKs.
What we do not do
- No advertising. The product has no ad surfaces and no advertising integrations.
- No social sign-in providers. We do not request access to third-party identity profiles.
- No data selling. Your information is not for sale and never will be.
Subscriptions and in-app purchases
If you subscribe, billing is handled by Apple App Store or Google Play. Their terms govern your purchase, including auto-renewal, billing cycles, family sharing, and any price changes. KlarFort processes the store receipt or purchase credential to confirm your tier and stores the hashed verification and anti-replay record described above. KlarFort does not see, store, or process your payment-card details. Cancellation is performed in the same store account that originated the purchase, not by deleting your KlarFort profile. Unless you cancel in that store, billing continues on the store's normal schedule after KlarFort account deletion.
Data retention
- Daily insight notes are kept for up to 90 days. The latest monitoring analysis replaces the previous analysis. Custom rules remain until you delete them where the app provides that action or delete your account. Up to 100 AI response reports are retained per profile, each for no more than 365 days under scheduled cleanup or until earlier account deletion.
- Optional push-token rows are removed on account deletion and stale registrations are routinely cleaned. Generation-independent daily AI rate-limit rows remain across deletion and verified recreation for up to 30 days so the same subject cannot reset the current daily cap.
- The full one-way trial deduplication hash, platform, trial dates, and pseudonymous subject are retained indefinitely to prevent replay or regrant for the same installation identifier. The raw client UUID is transmitted for grant verification but is not persisted; reset or uninstall may generate a new identifier.
- The hashed, bound subscription verification record is retained indefinitely to prevent receipt or purchase replay against another pseudonymous profile.
- The durable authorization lifecycle and append-only deletion-recovery records are retained across deletion and any later verified recreation. Recreation marks the profile active under the current token generation; it does not restore erased content, and every pre-deletion access token remains invalid.
- Hourly database recovery images and their matching deletion-ledger snapshots are kept under scheduled cleanup for no more than seven days. A historical image may physically contain user-scoped rows that were deleted after the image was captured. It is not an active service database: before any restored image can serve requests, KlarFort requires the same externally recorded deletion history and reapplies each deletion, purging those rows and preserving token invalidation. Startup fails rather than serve if the recovery ledger is missing, incomplete, malformed, or bound to a different database lineage.
- Security, operational, support, and legally required records are retained only as needed for their stated security, incident-response, request-handling, fraud-prevention, or legal purpose. KlarFort does not promise a fixed deletion date where the applicable obligation or security need determines the period.
Data deletion
You can delete your account at any time:
- From inside the app: open Settings, choose Delete Account, and confirm. After the server confirms deletion, KlarFort removes local app data and the access token. The backend deletes the active user-scoped push token, daily insights, latest monitoring analysis, custom rules, and AI response reports.
- Without the app: follow the public request process at klarfort.com/delete-account. KlarFort accounts do not have an email address on file, so the address you email from does not identify a profile. Support will request secure purchase or device-context verification sufficient to locate the pseudonymous profile without exposing or deleting another person's data.
Reset App Data is not account deletion. Reset clears local app data and disconnects the current device, but it does not request server erasure or remove stored AI outputs and reports. To erase active server data, use Delete Account first and wait for it to succeed before resetting or uninstalling.
The hashed anti-abuse trial record, bound subscription anti-replay record, generation-independent daily AI rate-limit rows, and durable authorization lifecycle and deletion-recovery records described in Data retention are not erased with active profile data. Historical backup images may retain prior row bytes until their seven-day expiry, but the external deletion history is reapplied before a restored database can serve, so those rows are purged again and old tokens stay invalid. Active store subscriptions must be cancelled separately in the App Store or Google Play account that originated the purchase. Deleting KlarFort does not cancel billing. A later verified recreation does not restore erased active profile or local data.
Children
KlarFort is not directed at children under 13 and we do not knowingly retain account information for anyone under 13. If you are a parent or guardian and believe a minor has created an account, please contact us and we will delete it. KlarFort does not knowingly collect personal information in violation of the Children's Online Privacy Protection Act (COPPA).
International transfers
Our infrastructure operates from facilities that may be located outside your country of residence. By using KlarFort you consent to your account information being processed in those jurisdictions, subject to the protections in this policy. Where required, transfers from the European Economic Area, the United Kingdom, or Switzerland are made under appropriate safeguards such as the Standard Contractual Clauses.
Your rights (GDPR, UK GDPR, EEA, Switzerland)
If you are in the European Economic Area, the United Kingdom, or Switzerland, you may have rights to access, correct, restrict, port, and erase personal data, and to object to processing or withdraw consent. Our lawful bases are: contract to deliver a subscription; consent for consent-gated AI features and notifications; legitimate interests to secure the service, enforce limits, prevent replay of the same trial identifier or store purchase, and investigate reported AI responses; and legal obligation where applicable. AI consent can be withdrawn directly in the app under Settings > AI Data Sharing. To exercise a right, use the in-app deletion action or email [email protected]. Because no account email is stored, support must securely verify the pseudonymous profile before acting on a profile-specific request. You also have the right to lodge a complaint with your local supervisory authority.
California residents (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you the right to know what personal information we collect, the right to delete it, the right to correct it, the right to limit the use of sensitive personal information, the right to opt out of "sale" or "sharing", and the right not to be discriminated against for exercising these rights.
Notice at collection. The categories of personal information involved in KlarFort, the purposes for which they are used, whether they are stored on our servers or transmitted ephemerally, and the retention period for each are:
- Identifiers (pseudonymous User ID, client-generated trial Device ID, hashed stable store identifier, optional push token, request ID, and connection metadata): used for access, service delivery, security, notification delivery, and fraud prevention; retained as described in What we store and Data retention.
- Commercial information / Purchase History (product ID, tier, expiration, verification time, and a hash of the stable store transaction or purchase identifier): used for entitlement verification and anti-replay protection; the bound record is retained indefinitely as described above.
- Internet or other electronic network activity information (service requests, request counts, UTC dates, and optional push delivery data): used to operate, protect, and deliver the service. The opaque daily AI count rows remain across account deletion and verified recreation for up to 30 days solely to enforce the same subject's daily cap.
- User-attached content for consent-gated AI features (your prompt text, the portfolio snapshot described in AI features require your consent, and any document, image, or other file you yourself attach to a request, which may include financial information, files, photos, or images): used solely to fulfil the AI request you sent; not written to KlarFort server storage; processed by Anthropic, Google, or OpenAI as service providers under contractual data-processing terms.
- AI outputs generated for you (daily insight notes, your latest monitoring analysis, and custom rules): used to show you your own insights without regenerating them; retained as described in What we store and Data retention; deleted with your account.
- Reported AI response content (message UUID, fixed report category, and excerpt): submitted only when you report a response; up to 100 reports are stored under the pseudonymous service profile for safety review, each for no more than 365 days under scheduled cleanup or until earlier account deletion.
Sale and sharing. KlarFort does not sell personal information and does not share personal information for cross-context behavioural advertising, as those terms are defined in the CCPA and CPRA. The third parties listed in Third-party services act as service providers processing data on our behalf for the limited purposes listed; that is not "sale" or "sharing".
Sensitive personal information. AI content you choose to send may contain financial or other sensitive information. KlarFort uses it only to fulfil the request you initiated and does not use it to infer characteristics for advertising, sale, or unrelated profiling. You do not need to file a request to limit those unrelated uses; KlarFort does not perform them.
Right of non-discrimination. We will not deny you the Service, charge you a different price, or provide a different level of quality for exercising any of these rights.
To exercise your CCPA rights, use the deletion-request page or email [email protected]. We respond to verifiable requests within 45 days, with a single 45-day extension where reasonably necessary, in line with the timelines set by California law.
Other US state privacy rights
Residents of other US states with comprehensive consumer-privacy laws (including but not limited to Colorado, Connecticut, Delaware, Indiana, Iowa, Montana, Oregon, Tennessee, Texas, Utah, and Virginia) may have rights similar to those described in the GDPR and CCPA sections above. The same email and deletion-request channels apply.
Security
We apply current industry-standard practices to protect the pseudonymous service data we hold and communication between the app, our servers, and consent-gated AI providers. Data is transmitted over TLS, stable store identifiers are persisted as one-way hashes, signed access tokens are stored on the device, and production access is restricted. No system is perfectly secure. To report a security concern, use the responsible-disclosure channel.
Changes to this policy
If we materially change how we handle your data, we will update this page, revise the Last updated date, and surface a notice in the app on next launch. Your continued use of the Service after a change becomes effective constitutes acceptance of the revised policy. We will not retroactively make material changes that reduce your privacy rights without your consent.
Contact
Questions, requests, or concerns about this policy:
We respond to every message we receive.
[email protected]