1. Scope and contact
Klause AI operates the Klause document Review service. This policy applies to klauseai.com and the product features available through it.
Privacy questions and deletion requests can be sent to privacy@klauseai.com.
2. Data we process
Account data
Email address, authentication identifiers, and account status. Authentication credentials are handled by Supabase Auth; Klause does not receive your plain-text password.
Document Review data
Submitted text or extracted file text, document metadata, selected Review type and jurisdiction, validated ReviewResult, saved Review sessions, and owner-authorized follow-up questions and answers.
Provider and diagnostic data
Configured AI provider and model identifiers, Review state, duration, limited telemetry, errors, and temporarily retained raw provider output used to diagnose failures and validate the Review pipeline.
Usage and security data
A server-issued anonymous browser identifier, Review counters, timestamps, request metadata available to our hosting platform, and security or abuse-prevention records.
Billing data
Paddle customer and subscription identifiers, subscription status, billing-period information, and webhook-processing records. Paddle processes payment-card and transaction data as merchant of record; Klause does not store full card numbers.
Communications and analytics
Support messages, transactional-email delivery information, and limited site analytics when those services are enabled.
3. How document Review works
- 1. Submission. You paste document text or upload a supported file. Klause extracts the text on the server.
- 2. AI processing. The document text and Review instructions are sent through OpenRouter to the configured AI model so the Review can be produced. Provider handling is also subject to the applicable provider terms and settings.
- 3. Validation. Klause validates and normalizes the provider response into the canonical ReviewResult format.
- 4. Storage. Klause stores Review session data. For authenticated saved Reviews, document text is retained so owner-authorized follow-up questions can be grounded in the original document. Temporary anonymous and diagnostic data is removed according to Section 4.
4. Retention and deletion
| Data | Current retention rule |
|---|---|
| Anonymous Review sessions | Deleted after 24 hours, including submitted document text, Review result, and associated telemetry. |
| Authenticated saved Reviews | Retained until you delete the Review or the associated account is deleted, subject to limited legal or security exceptions. |
| Follow-up questions | Retained with the parent Review and deleted when that Review is deleted. |
| Raw AI provider output | Redacted after 7 days. The validated ReviewResult may remain under the rule for the Review session. |
| Failed authenticated Review sessions | Deleted after 30 days. |
| Anonymous identifier and usage ledger | Deleted after 13 months without activity. The browser cookie is configured for up to one year. |
| Paddle webhook-processing records | Deleted after 13 months. Paddle may retain transaction records under its own legal and operational obligations. |
Signed-in users can delete individual saved Reviews through the product. Deleting a Review also removes its stored document context, telemetry, and follow-up conversation through database cascade rules. Account-level deletion requests can be sent to the privacy email above until self-service account deletion is available.
5. Service providers
- Vercel: application hosting and server execution.
- Supabase: authentication and database services.
- OpenRouter and configured model providers: AI inference for document Reviews and follow-up answers.
- Paddle: subscription checkout, payment processing, tax handling, and customer billing portal.
- Resend: transactional email when email delivery is used.
- Analytics providers: limited traffic and product analytics when enabled.
6. Security
Klause uses server-side ownership checks, restricted service-role database access, row-level security, private no-store responses for sensitive routes, webhook signature verification, and protected internal maintenance endpoints. No online service can guarantee absolute security, so users should avoid submitting unnecessary secrets or highly sensitive personal information.
7. Your choices and rights
- Delete individual saved Reviews from the Review interface.
- Cancel or manage a paid subscription through the Paddle billing portal.
- Request access, correction, export, restriction, objection, or deletion where applicable to you.
- Unsubscribe from optional marketing messages through the link in the message.
- Contact a relevant data-protection authority where local law provides that right.
We may need to verify identity before completing a request. Some records may be retained when required for security, dispute resolution, fraud prevention, or legal obligations.
8. International processing
Klause and its providers may process data in countries other than your own. The locations and transfer safeguards depend on the providers, model route, account configuration, and applicable law. Contact us for questions about a particular processing arrangement.
10. Changes to this policy
We may update this policy when the product, providers, retention periods, or legal requirements change. The effective date at the top identifies the current version. Material changes may also be communicated through the product or by email where appropriate.