Klaro

Legal

Privacy

Last updated August 2026

Summary

Klaro stores your job-search materials and outreach history so you can generate drafts in your voice. We don't sell your data. AI runs on our server with a shared key — you never paste one. Gmail drafts live in your Gmail; Klaro never sends mail for you.

What we collect

Account info from Google sign-in (name, email, profile image). Content you paste or upload for outreach, resume, writing samples, LinkedIn text, job descriptions, and generated drafts. A Gmail draft id after you save, so edits can update the same draft. A Gmail refresh token is kept in an httpOnly cookie on your device so you stay connected. It is not stored in Klaro's database. Access tokens stay on the server and are never sent to your browser.

How we use it

To run Klaro for you: build a voice profile, generate email drafts, save them to Gmail Drafts, and power your tracker. We use a shared AI provider to process prompts that include your materials. Klaro does not send email on your behalf.

How long we keep it

  • Profile & tracker data — kept while your account is active. Deleted when you request account deletion (see below).
  • Sign-in session — until you sign out or the session expires (Auth.js session cookies).
  • Gmail connection cookie — up to 180 days on your device, or until you disconnect Gmail in Klaro or revoke access in your Google account.
  • Daily AI usage & rate limits — rolling counters (per day or per hour) used to enforce fair use; not kept as a long-term history.
  • Server & security logs — short-lived operational logs (e.g. sign-in events, rate-limit hits). No resume text, prompts, or tokens. Retention follows our hosting provider (typically up to ~30 days).
  • Gmail drafts— stay in your Gmail account under Google's retention; Klaro does not delete them when you delete your Klaro account.

Subprocessors

We use the services below to run Klaro. Each receives only what it needs for its role. We don't sell personal data to them or anyone else.

  • Google

    Sign-in (OAuth), Gmail Drafts API

    Account name, email, profile image; draft content you save to Gmail

  • Google Gemini (AI)

    Voice profiles and email generation

    Prompts that include your pasted materials and job context (processed to return drafts; not used to train models per Google’s API terms)

  • Hosting provider (Vercel)

    App hosting and serverless functions

    Request metadata, security logs (no resume text or API keys in logs)

  • Database provider (Appwrite)

    Account and app data storage

    Profile, outreach tracker, usage counters, rate-limit buckets

  • Plausible Analytics

    Optional, privacy-friendly page stats

    Page views only if you opt in via cookie settings; no cross-site tracking

  • Stripe

    Payments (when billing is enabled)

    Billing email, payment method, purchase history — only if you buy credits or enable metering

Deleting your data

You can limit or remove data in several ways:

  1. Clear materials in the app — edit or empty resume, writing samples, and voice rules on Profile anytime. Delete individual tracker rows from Tracker.
  2. Disconnect Gmail— use Reconnect Gmail → revoke in Google, or remove Klaro's access under your Google Account → Security → Third-party access. This clears the httpOnly refresh cookie on your next disconnect.
  3. Delete your Klaro account — email klaro.outreach@gmail.com from the address on your Google account. We verify ownership, then delete your user record and cascaded data (profile, outreach entries, usage counters). Self-serve delete in the app is coming; email works today.
  4. Optional analytics — turn off anytime via Cookie settings in the footer.

Account deletion does not remove drafts already saved in Gmail. Remove those in Gmail if you want them gone.

Your choices

You can update or clear profile materials in the app, and revoke Gmail draft access in your Google account settings at any time.

Cookies

Klaro uses a small number of cookies and similar browser storage:

  • Essential:sign-in session cookies (Auth.js / Google OAuth), Gmail connection (httpOnly, device-only; tokens are not stored in Klaro's database), and a saved record of your cookie preferences. These are required to use the app.
  • Analytics (optional): privacy-friendly page stats (Plausible when configured). Off by default; loaded only after you opt in via the cookie banner or footer settings. We remove analytics cookies and storage if you opt out later.

You can change optional cookies anytime from Cookie settings in the site footer. Essential cookies cannot be disabled while you are signed in.

Privacy questions

Data requests, subprocessors, or deletion help: klaro.outreach@gmail.com

Terms · FAQ · Accessibility