LEGAL
Klos Privacy Policy
Version: 2026-08-29
Effective date: August 29, 2026
Last updated: August 29, 2026
1. Who we are
Klos is operated by Klos LLC, a Florida limited liability company. Klos LLC is wholly owned by GrayMoon Holdings LLC, also a Florida LLC. Our mailing address is on file with the Florida Division of Corporations (entity number L26000244944) and is available on request.
This Privacy Policy explains what information Klos collects, how we use it, and the rights you have over it. It covers the Klos iOS application (“the App”), the Klos web viewer at view.getklos.com (“the Viewer”), and the Supabase-backed services that support both (“the Backend”) — together, “Klos.”
Contact for privacy questions: privacy@getklos.com
2. What information we collect
2.1 Information you provide directly
When you create a Klos account, we collect your email address and a password (which we never store in clear text — we store only a one-way hash that cannot be reversed). Klos does not offer third-party social sign-in (there is no “Sign in with Apple” or “Sign in with Google”).
When you use Klos, you upload encrypted documents. Document names, your notes, and pouch names are encrypted on your device before they leave it. Other information remains visible to Klos so the service can operate, including document type, relevant dates, tags, and the operational metadata described in Section 4.
You may also add persons and contacts so you can share documents or invite people to a Family Vault. Person and contact names, email addresses, phone numbers, and relationship labels are encrypted on your device before storage. Record identifiers and ownership, linked-user identifiers when present, timestamps, and Family Vault membership remain visible operational metadata.
When you share a document or invite someone to a Family Vault, we store the share configuration — who you shared with, what permissions you granted, when the share expires, and when it has been opened, revoked, or has expired.
2.2 Information we collect automatically when you use Klos
Usage events. Klos keeps a small, fixed-taxonomy product-event log in our own database to understand how the product is used. We do not use any third-party analytics service. The taxonomy covers events such as account creation and activation, document import, share creation/opening/revocation, pouch creation, and subscription changes — plus a small number of operational and error events we use to detect failures.
For each event we record your user ID, the event type, a timestamp, a session identifier, and an optional numeric value (such as a document count). Any structured context attached to an event is limited to non-identifying operational data: it does not include free text you have typed, document or message content, document or contact identifiers, or raw error messages that could contain such data.
Crash reports. Klos uses Sentry to receive crash and error reports so we can fix bugs. We configure Sentry to strip personal information. Sentry receives: device model, OS version, app version, stack trace, and a hashed user identifier. Sentry does not receive: your email address, document content, document filenames, encryption keys, share tokens, or anything you have typed.
Session and device metadata. We log basic technical information (app version, OS version, IP address at the time of an authenticated request) for security, fraud prevention, and diagnostics. We do not build advertising profiles. We do not track you across other apps or websites.
3. How we use your information
We use the information described above to:
- Operate the App, Backend, and Viewer — store and retrieve your encrypted documents, deliver shares, authenticate sign-ins.
- Send you freshness reminders about documents you’ve asked us to track (passport expiring soon, insurance card needing renewal, etc.).
- Enforce share permissions — view-only shares don’t offer a download control, expired shares can no longer be opened, and revoked shares stop working on the next attempt (a link someone already opened may stay viewable until its short-lived access window expires).
- Security and fraud prevention — investigate suspicious sign-in patterns, prevent abuse, respond to attacks.
- Send account communications — account verification, share notifications, password reset emails, important service announcements.
- Improve Klos — understand which features are used and which aren’t, find and fix bugs, decide what to build next.
We do not use your information for advertising. We do not sell, rent, or trade your information to anyone.
4. The End-to-End Encryption Story
Klos encrypts your document content on your device, before it reaches our servers, using AES-256-GCM.
Your keys. Every account has a content key that encrypts your documents. That content key is itself wrapped by a key derived from your account password using Argon2id, and the wrapped result is what we store. We never receive your password, the key derived from it, or your content key in usable form.
Klos also caches keys in your device’s secure storage so the app can open without re-entering your password every time. That storage is local to your device. It is not synced to iCloud or to any other cloud service.
Family Vault. Documents you move into a Family Vault are encrypted under separate shared-vault key material, wrapped individually to each member’s registered active X25519 public key. Klos trusts its authenticated backend mapping from each account to its registered active X25519 public key. We do not independently verify the human recipient outside Klos. An actively malicious or compromised backend could substitute a public key for a future Family Vault or Klos-to-Klos delivery. Leaving or being removed from a Family Vault removes your access to its key material.
What our servers hold. Encrypted document content, encrypted key material, public keys, and the metadata below. Our servers never hold your plaintext documents, your usable encryption keys, or your password. A storage-layer incident at our infrastructure provider would expose encrypted blobs and stored key material. Stored backend data alone cannot decrypt existing Private Vault ciphertext.
What is hidden, and what is not. Document names, your notes, and pouch names are encrypted on your device — we cannot read them.
Running the service does require us to see other information: your email address and account status; how many documents you have; when they were created and updated; the type of each document (for example, that it is a passport rather than an insurance policy); its issue and expiry dates, statement dates, and any tags you add; its freshness status and whether you pin it; whether it is in your Private or Family Vault; file size, page count, format, and storage path; that person and contact records exist, their record and linked-user identifiers and timestamps; Family Vault membership; and share events. The names, email addresses, phone numbers, and relationship labels inside those person and contact records are encrypted and unreadable to Klos.
Each file also has a server-visible integrity checksum derived deterministically from its plaintext. It helps detect corruption, but it can also be used to test whether your account contains a file whose contents are already known.
In plain terms: we can see that you hold a passport expiring in March. We cannot see the passport, what you called it, or what you wrote about it.
Recovery — please read this part.
Your password is the only portable key to your vault. Because we never see it, we cannot reset it for you and then hand your documents back.
The keys cached on your device let Klos open on a phone you have already set up — including after deleting and reinstalling the app, and across an encrypted device backup or a direct device-to-device transfer. They do not exist on a device you have never set up.
If you forget your password and no longer have a device where Klos is already set up, your documents cannot be recovered — not by you, and not by us. This is true on iPhone and on Android.
This is the honest trade-off of end-to-end encryption: exposure of stored backend data alone does not reveal your existing Private Vault plaintext, and Klos cannot decrypt your vault on your behalf — including when you would very much like us to. Future Family Vault and Klos-to-Klos deliveries have the server-trusted recipient-key boundary described above.
5. Third-party processors we use
We rely on a small number of third-party services to operate Klos. Each is a data processor acting on our behalf under standard data-processing terms. None of them is permitted to use your data for their own purposes.
| Processor | What we use it for | What it receives | Privacy policy |
|---|---|---|---|
| Supabase | Backend database, authenticated storage of encrypted blobs, authentication | Encrypted document blobs and encrypted document, pouch, and person/contact fields; account and operational metadata; share metadata; usage events. Region: United States. | supabase.com/privacy |
| Sentry | Crash and error reporting | Device model, OS version, app version, stack trace, hashed user ID. No PII. | sentry.io/privacy |
| Resend | Transactional email delivery (share notifications and Family Vault invitations) | Recipient email address, email subject and body, and the share or invitation link | resend.com/legal/privacy-policy |
| Apple (Apple Push Notification Service) | Push notifications | Push notification payloads (text only — never document content or keys) | apple.com/legal/privacy |
We do not use third-party analytics services (no Google Analytics, no Mixpanel, no Amplitude, no Segment, no Facebook Pixel). We do not use advertising networks.
6. Data sharing and disclosure
We never sell, rent, or trade your information. This is a hard commitment. There is no opt-out you need to set — we simply don’t do it.
We disclose information only in the limited cases below:
- To the processors listed in Section 5, as needed to operate Klos.
- To people you choose to share with. When you create a share or invite someone to a Family Vault, the recipient (or the Vault member) receives the content you chose to share, on the terms you set.
- For legal reasons, if we receive a valid subpoena, court order, or similar legal demand. When the law permits, we will notify you before disclosing your information so you have an opportunity to object. We will challenge demands that appear overbroad or improper.
- To protect Klos, our users, and the public, in cases of fraud, abuse, or imminent harm — narrowly and only when necessary.
- In a business transaction. If Klos is ever acquired or merged, your information would transfer to the successor entity, subject to this Privacy Policy. We would notify you before any such transfer.
7. Data retention and deletion
You can delete your Klos account at any time from the App’s Settings.
Deletion is immediate and permanent. When you confirm account deletion, Klos removes your data right away — there is no grace period and no undo. The deletion cascade permanently removes your account record, all encrypted document blobs in storage, all share records, all person and contact records, and all usage-event entries. Because your documents are end-to-end encrypted and Klos holds no master key, once they are deleted no one — including us — can recover them. If you want to keep any document, export it before you delete your account.
If you do not delete your account, we retain your information for as long as your account is active. Inactive accounts may be subject to additional deletion policies in the future; we will notify you before such a policy takes effect.
Specific retention windows:
- Encrypted documents, share records, person and contact records, and usage events: until you delete them, or until you delete your account — at which point removal is immediate and permanent.
- Crash reports (Sentry): per Sentry’s default retention (currently 90 days).
- Share/invitation email-delivery logs (Resend): per Resend’s default retention (currently 30 days).
8. Your rights
You have the following rights over your information, regardless of where you live:
- Access. Get a copy of the information we hold about you. Where the data is encrypted (document content, names, notes, pouch names, and person/contact details), we can return the ciphertext; you decrypt with your key. Where it is plaintext (account and operational metadata, document types and dates, tags, record and linked-user identifiers, and events), we provide it directly.
- Correction. Update or correct information that’s wrong.
- Deletion. Delete your account, or specific documents and persons, at any time.
- Portability. Export your data in a machine-readable format.
- Restriction or objection. Ask us to stop processing your information for a specific purpose (for example, to stop sending freshness reminders). Sign-in and basic service delivery cannot be restricted without effectively suspending the account.
California residents (CCPA / CPRA). You have the rights above. You also have the right to opt out of the “sale” or “sharing” of personal information — Klos does not sell or share personal information for advertising purposes, so the opt-out is moot in our case, but the right is acknowledged. You may designate an authorized agent to exercise these rights on your behalf. Klos will not discriminate against you for exercising any CCPA right.
EU and UK residents (GDPR / UK GDPR). Our legal bases for processing are: (a) contract — to provide the service you signed up for; (b) legitimate interest — to keep Klos secure and prevent fraud; (c) consent — for any optional processing you’ve turned on (such as push notifications). You have the rights above plus the right to lodge a complaint with your national data protection authority. We do not currently designate an Article 27 representative; if EU usage of Klos grows materially, we will appoint one and update this policy.
To exercise any right, email privacy@getklos.com from the address on your Klos account. We respond within 30 days for most requests (45 days for complex requests, with notice).
9. Children
Klos is intended for adults aged 18 and over. The App Store age rating reflects this. We do not knowingly collect personal information from children under 13 (COPPA). If we discover that we have collected such information, we delete it as soon as we become aware. If you are a parent or guardian and believe your child has used Klos, contact privacy@getklos.com and we will act promptly.
10. Security
Beyond the end-to-end encryption story described in Section 4, Klos takes the following security measures:
- In transit: all communication between the App, Viewer, and Backend is encrypted with TLS (currently TLS 1.3 where the platform supports it).
- On your device: your encryption keys are held in the iOS Keychain via
expo-secure-store, protected by the device’s hardware security and your passcode or biometric. Your documents and metadata are stored locally in encrypted form. - In storage: documents are stored as ciphertext that we cannot decrypt. Storage URLs are signed and short-lived. View-only shares don’t offer a download, though no app can stop a recipient from screenshotting what they’re allowed to see — we say so plainly rather than over-promise.
- Biometric gate: you can require Face ID or Touch ID before the App will unlock your vault. This is an additional gate on top of your password — not a replacement for it.
- Account hygiene: sign-in attempts are rate-limited, and sensitive account flows use email verification links.
No system is perfectly secure. If a security incident affects your information, we will notify you in the manner and timeframe required by applicable law.
11. International data transfers
Klos’s Backend is hosted in the United States. If you use Klos from outside the United States — including from the European Union, United Kingdom, or other jurisdictions with data-transfer rules — your information will be transferred to and stored in the United States. By creating an account, you consent to this transfer.
For EU and UK residents: we rely on the Standard Contractual Clauses (SCCs) for any onward transfer to processors that need them, and we evaluate each processor’s data-handling practices before engaging them.
12. Changes to this Privacy Policy
If we change this Privacy Policy in a way that affects your rights or how we handle your information, we will notify you in-app and by email at least 30 days before the change takes effect. For minor wording updates that don’t affect your rights, we will update the “Last updated” date at the top of this page without separate notice.
The current version, with its effective date, is always linked from the footer of getklos.com and from Settings → About in the Klos app.
13. Governing law and disputes
This Privacy Policy is governed by the laws of the State of Florida, United States, without regard to its conflict-of-laws principles. Any dispute arising from this Policy or your use of Klos that is not resolved through good-faith discussion will be brought in a state or federal court of competent jurisdiction located in Palm Beach County, Florida, and you and Klos agree to that venue.
If you are an EU or UK resident, nothing in this section limits your right to bring a complaint to your national data protection authority or to seek the protection of mandatory consumer-protection laws in your country of residence.
14. Contact us
For privacy questions, requests to exercise your rights, or any concern about how Klos handles your information:
Email: privacy@getklos.com
Operator: Klos LLC, a Florida limited liability company
Mailing address: Available on request from privacy@getklos.com or via the Florida Division of Corporations record for entity L26000244944.
We aim to respond within 5 business days for general questions and within 30 days for formal rights requests (45 days for complex requests, with notice).
This Privacy Policy is written in plain language to be readable. If anything in it is unclear, please email us — we’d rather explain than have you guess.