Privacy Policy
Last updated:
This policy explains what data Klorr (klorr.io) collects, why we collect it, and the choices you have. Klorr is operated by a sole founder; we keep data collection deliberately small and this policy deliberately plain.
1. Data we collect
- Account data — your email address and, if you provide it, your name. Used to create and secure your account and to contact you about the service.
- Projects and generated code — the projects, prompts, brand context, and Shopify section code you create in Klorr, stored so your work persists across sessions and devices.
- Usage metrics — operational counters such as generation counts and AI token usage, used to enforce plan budgets, prevent abuse, and understand aggregate service load.
- Newsletter sign-ups — if you subscribe, your email address, the language of the page you signed up on, and the currency you were shown, so that what we send you is in your language.
- Payment data — payments are handled by Stripe. Your card details go directly to Stripe; Klorr does not store card numbers. We keep only subscription status and billing records (plan, invoices, payout state for sellers).
We do not collect data for advertising, and we do not sell your data.
2. Processors we use
- Supabase — hosts our database and authentication (Postgres, hostable in the EU). Your account, projects, and marketplace data live here.
- Anthropic — when you generate or edit a section, your prompt and the relevant section code are sent to Anthropic's Claude API to produce the result. We send only what is needed for the generation.
- Stripe — payment processing for subscriptions and marketplace sales.
3. Cookies
Klorr uses cookies only to keep you signed in (authentication session cookies). We do not use advertising or cross-site tracking cookies, and there are no third-party ad trackers on the site.
4. Retention
We keep your account data and projects for as long as your account exists. If you delete your account, we delete your account data and projects within a reasonable period, except where we must keep records for legal, tax, or fraud-prevention reasons (for example, marketplace sale records). Newsletter sign-ups are kept until you unsubscribe. Operational logs are kept for a limited time and then deleted or aggregated.
5. Your rights
You can, at any time:
- Access and export your data — your projects and generated code are visible and downloadable in the app, and you can manage your profile from the account page;
- Correct your account details from the account page;
- Delete your account and associated data from the account page, or by emailing us;
- Unsubscribe from the newsletter using the link in any email we send;
- Object or complain — contact us with any privacy concern, and if you are in the EU/EEA or UK you may also lodge a complaint with your local data-protection authority.
If you are in the EU/EEA or UK, you have rights under the GDPR (and UK GDPR) including access, rectification, erasure, restriction, portability, and objection. We honour these rights for all users regardless of location.
6. Security
Data is transmitted over HTTPS and stored with access controls in Supabase. No system is perfectly secure; if we learn of a breach affecting your data, we will notify you as required by law.
7. Children
Klorr is not directed at children under 13 (or under 16 where local law sets a higher threshold), and we do not knowingly collect their data.
8. Changes
We may update this policy as the service evolves. Material changes will be announced by email or in-app before they take effect.
9. Contact
Privacy questions or requests: support@klorr.io.