Privacy Policy

Last updated: 2026

This policy explains what personal data Klyrentra AI ("Klyrentra", "we", "us") collects, how we use it, and the rights you have. Contact addresses on this page are placeholders while our production domain is being finalised.

1. Data we collect

  • Account data: email, name, company, and authentication provider (email/password or Google Sign-in).
  • Content you provide: AI receptionist configuration, knowledge base uploads, chat history, briefing history, and other data you enter into the product.
  • Google data (only if you connect Google): the read-only Gmail messages and Google Calendar events required to produce briefings and drafts you request. See section 4 for what we do with this data.
  • Usage data: pages accessed, feature usage, credit ledger entries, error logs.
  • Payment data: handled by Stripe; we store only your Stripe customer ID and subscription status. We never see or store card numbers.

2. How we use it

  • To provide the features you signed up for (briefings, chat, AI receptionist, email reply drafts).
  • To secure the platform and detect abuse.
  • To bill you and manage your subscription.
  • To communicate essential service updates.

3. Legal bases (UK / EU GDPR)

Performance of a contract (delivering the service), legitimate interests (security, product improvement), consent (marketing communications and connecting third-party accounts like Google), and legal obligation.

4. Google user data — Limited Use compliance

Klyrentra's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We request read-only scopes only: gmail.readonly, calendar.readonly, plus openid and your Google email address so you can tell which account is connected.
  • We access your Gmail and Google Calendar data only after you complete Google's OAuth consent flow, and only to produce the outputs you explicitly ask for (a daily briefing, or an AI-drafted reply to a specific email).
  • We do not transfer Google user data to third parties except (a) the AI provider that generates your requested output (Google Gemini via the Lovable AI Gateway), (b) the hosting and database provider that stores the encrypted content on our behalf, and (c) as required by law.
  • We do not use Google user data to serve advertising.
  • We do not allow humans to read Google user data except (i) with your explicit consent, (ii) for security purposes such as investigating an abuse report, (iii) to comply with applicable law, or (iv) in aggregated and anonymised form for internal operations, in each case as permitted by the Limited Use policy.
  • We do not use Google user data to train or improve generalised AI/ML models.
  • You can disconnect Google at any time from the Connections page. Disconnecting deletes our stored OAuth tokens and calls Google's revoke endpoint so the grant is invalidated on Google's side too.

5. AI processing

Content you submit for AI features may be sent to our AI provider (Google Gemini via the Lovable AI Gateway) for the sole purpose of producing your requested output. It is not used to train third-party foundation models. See our AI Disclaimer for accuracy limitations.

6. Sub-processors

We use the following sub-processors to run the service:

  • Supabase (managed PostgreSQL database and authentication).
  • Lovable (application hosting).
  • Google (Gemini via the Lovable AI Gateway for AI outputs; Gmail and Calendar APIs when you connect Google).
  • Stripe (payments).

7. International transfers

Where data is processed outside the UK / EEA, we rely on the sub-processors' Standard Contractual Clauses and adequacy decisions.

8. Retention

We retain account and content data while your account is active. You can delete individual briefings, disconnect Google, or delete your account at any time. On account deletion your rows are removed from the application database; backups roll off over the sub-processor's standard retention window.

9. Your rights

You can request access, correction, deletion, portability, and object to processing under UK / EU GDPR. Contact privacy@klyrentra.com.

10. Security

Row-level security in the database, HTTPS in transit, AES-256-GCM encryption at rest for OAuth tokens, and short-lived session tokens. Full detail on the Security page.

11. Changes

We will notify you of material changes by email or in-app notice.

12. Contact

Data protection queries: privacy@klyrentra.com.