Klor.

Privacy

Last updated 17 September 2026

Klor evaluates flags on your users' devices. Their attributes, ids and locations are never sent to us, because the architecture has nowhere to put them.

The short version

  • We hold your account details and your configuration. We do not hold your users.
  • Flag evaluation happens inside your app. User context is never transmitted to Klor.
  • Usage counters record which flag keys were read and what value was served. They carry no user or device identifier, and can be switched off entirely.
  • You can delete your account and everything it owns from your settings page, at any time, without asking us.

What we collect

Account information. Your name, email address, and either a hashed password or an identifier from the provider you signed in with. We never store a password in a form we can read.

Configuration. The workspaces, projects, environments, flags, targeting rules and update gates you create, and the published snapshots compiled from them. This is your data; it is what the service exists to store.

An audit trail. Who changed what, and when, for each project. Visible to you in the dashboard.

API keys. Stored only as a SHA-256 hash, alongside a short display prefix. A leak of our database does not hand anyone a working key.

Usage counters. When telemetry is enabled, the SDK reports a flag key, which value was served, why, and a count. There is no user id, device id, IP-derived identifier or session in that payload. It exists so you can find config nothing reads any more.

Ordinary request logs. Our infrastructure provider records requests to our servers, including IP address, for operational and abuse-prevention purposes.

What we do not collect

Klor sends your application a ruleset and your application decides. The user id, country, app version, custom attributes and anything else you target on stay on the device and are never transmitted to us. This is not a promise about our intentions; it is a property of how the SDK works, and you can verify it by reading the network traffic your app produces.

There are no advertising or analytics scripts on this site, and no third-party cookies. The only cookie we set is the one that keeps you signed in.

Who else touches it

Cloudflare is our sole subprocessor. The service runs entirely on Cloudflare Workers, D1, Workers KV, Analytics Engine and Email Sending, on their global network. We do not sell data, and we do not share it with anyone else except where the law requires it.

How long we keep it

  • Account and configuration data: until you delete it, or delete your account.
  • Published snapshots: for as long as the environment exists, because rolling back to an old one depends on it still being there.
  • Usage counters: coarse marks that are overwritten as they are refreshed, and evaluation data points retained by our analytics provider on their standard schedule.
  • Audit entries: for the life of the project they belong to.

Your rights

You can read, correct and export your data yourself. Account details are editable in settings; configuration is readable through the dashboard and, in full, through the management API, which returns exactly what we hold.

Deletion is self-serve and immediate. Deleting your account removes it, along with every workspace where you are the only member, including projects, flags, published snapshots and API keys. Apps still reading those keys stop receiving config at once. Where a workspace has other members, we ask you to hand it over or empty it first, because it is not solely yours to destroy.

Depending on where you live you may have further rights over your personal data, including access, rectification, restriction, portability and objection. Write to us at privacy@klor.dev and we will act on it.

Children

Klor is a tool for software teams and is not directed at children. We do not knowingly collect information from anyone under 16.

Changes

If we change this policy in a way that matters, we will say so on this page and update the date at the top. Continuing to use Klor after that means the new version applies.

Contact

Questions, requests, or a complaint: privacy@klor.dev.