Legal information
Cookie policy
Last updated:
This policy explains how Klarity ("Klarity"), published by Boostage, uses cookies and other trackers on the https://klarity.coach website and the https://app.klarity.coach application. It complies with Directive 2002/58/EC ("ePrivacy"), Article 82 of the French Data Protection Act, and the CNIL (the French data protection authority) guidelines and recommendation on "cookies and other trackers".
Klarity is an online software (SaaS) that assists the practice of coaching, intended for independent Professionals. It enables client and session management, note-taking, the generation of session reports and briefings, as well as an AI-assisted session memory (automatic summaries, briefings, search and chat over the longitudinal memory). Navigating the application involves potentially sensitive data relating to the clients supported by the Professional: we therefore deliberately limit trackers to what is strictly necessary for the operation and security of the service, and we do not activate any consent-based tracker without your prior agreement.
1. What is a cookie / tracker?
A cookie is a small text file placed on and read from your device (computer, tablet, smartphone) by the browser, when you visit a site or use an application. The term "tracker" is broader: it refers to any technology that allows information to be read or written on your device, or accessed on it — HTTP cookies, but also local storage (localStorage, sessionStorage), invisible pixels, device identifiers, fingerprinting, etc.
A tracker may be:
- internal ("first party"): placed by Klarity itself, on its own domain;
- third-party: placed by a provider distinct from Klarity (for example an anti-bot or payment service), which can then access the information it has placed.
Some trackers are exempt from consent (strictly necessary for the service you request, or intended exclusively for its security). The others (non-exempt audience measurement, marketing) are subject to your prior consent and are only placed after it has been obtained.
2. Cookies and trackers used by Klarity
By default, only strictly necessary and security trackers are placed. Functional (support) and marketing trackers are placed only after your consent via the banner (§ 4). Audience measurement is performed without any tracker (§ 2.4). The technical names below are those actually used by the current architecture; some remain subject to slight change.
2.1 Strictly necessary (exempt from consent)
| Name / identifier | Purpose | Type | Consent required | Duration |
|---|---|---|---|---|
JWT access token (kept mainly in the browser's localStorage) | Maintain the Professional's authenticated session, avoid re-login at each action | Internal | No | Session duration |
auth_token (companion cookie) | Let the app guard access to protected pages | Internal | No | Session duration |
refresh_token (httpOnly cookie) | Renew the session without re-entering credentials | Internal | No | ≈ 30 days |
klarity_cookie_consent (cookie + localStorage) and kl_consent (cross-subdomain cookie, value 1/0) | Store your cookie choices and honor them across https://klarity.coach and https://app.klarity.coach | Internal | No | ≈ 13 months |
NEXT_LOCALE / locale | Remember the chosen language | Internal | No | ≈ 12 months |
Interface preferences: theme (theme_preset, theme_radius, theme_content_layout, theme_scale), sidebar state (sidebar_state_*), a non-sensitive logged-in identifier (cm_uid), localStorage flags for dismissed banners / one-time intros | Store display comfort choices; store no tracking data | Internal | No | Persistent / for the comfort item concerned |
There is no CSRF cookie: the API authenticates with
Bearertokens, without a shared session cookie.
2.2 Security — reCAPTCHA (exempt from consent)
| Name / identifier | Purpose | Type | Consent required | Duration |
|---|---|---|---|---|
Google reCAPTCHA v3 (_GRECAPTCHA cookie set by Google on google.com) | Protect public forms (signup, password reset, public booking, public consent / check-in pages) against bots and abuse | Third-party (Google) | No — security tracker strictly necessary for the requested service | Duration set by Google |
reCAPTCHA v3 is used exclusively for security purposes (bot detection and fraud prevention) and only on public / non-authenticated pages: signup, password reset, public booking, and public consent / check-in pages. On this basis, the CNIL allows the consent exemption for trackers strictly necessary to provide an online communication service expressly requested and proportionate to that purpose. The scope is limited to the pages where protection is required. A transfer to the United States may occur, governed by SCCs / DPF (see transfers in § 6).
2.3 Functional — Crisp customer support (consent required)
| Name / identifier | Purpose | Type | Consent required | Duration |
|---|---|---|---|---|
Crisp support chat widget (crisp-client/* cookies + local/session storage) | Operate the customer support chat and recognize a returning visitor's conversation, to ensure continuity of the exchange | Third-party (Crisp) | Yes (functional tracker, not essential to the service) | Duration set by Crisp |
The Crisp widget is loaded only after your consent to the "functional" category. It places third-party
crisp-client/*cookies and uses local/session storage to operate the conversation and recognize an ongoing conversation. If you withdraw your consent, these trackers are purged. Crisp is hosted in the European Union (Amsterdam and Frankfurt), with no transfer outside the EU (see transfers in § 6).
2.4 Audience measurement — PostHog (trackerless, EU-hosted)
We measure the site's audience with PostHog, hosted in the European Union (eu.i.posthog.com). PostHog is configured in "cookieless" mode: its persistence is memory-only, so it sets no cookie and no localStorage on your device, and session recording is disabled. Because it stores nothing on your terminal and keeps data within the EU, this tool measures traffic without placing any tracker — it is therefore not subject to consent and does not appear as a banner category.
2.5 Marketing — attribution cookies (consent required)
| Name / identifier | Purpose | Type | Consent required | Duration |
|---|---|---|---|---|
kl_attr ("last-touch" attribution) | Store acquisition parameters (UTM tags, ad click identifiers gclid / fbclid, landing page, referrer) to attribute a signup | Internal (set at the root domain .klarity.coach) | Yes (prior marketing consent) | ≈ 30 days |
kl_attr_ft ("first-touch" attribution) | Same purpose, retained on the first touch | Internal (root domain .klarity.coach) | Yes (prior marketing consent) | ≈ 90 days |
Affonso affiliate-tracking pixel (affonso_data cookie set by Affonso) | Attribute a conversion to the affiliate who referred you to the Service (to calculate their commission) and expose the possible welcome-discount coupon (affiliate programme, Article 20 ter of the Terms) | Third-party (Affonso) | Yes (marketing tracker) | ≈ 60 days |
These attribution trackers are placed only after your marketing consent has been obtained, and are purged on withdrawal. The internal cookies (
kl_attr,kl_attr_ft) are set at the root domain (.klarity.coach) so that the signup flow on https://app.klarity.coach can attribute the acquisition. No ad-network advertising pixel (no Meta Pixel, no Google Ads tag) is used; the only third-party marketing tracker is the Affonso affiliate-tracking pixel (see § 6), loaded only after consent and used to remunerate affiliate partners and expose their possible discount coupon (Article 20 ter of the Terms).
2.6 Payment (Stripe)
The payment provider Stripe (Stripe) is not embedded in the site or the application (Stripe.js is not loaded). Payment and subscription management happen on Stripe-hosted pages reached by redirection. Any Stripe cookies (__stripe_mid / __stripe_sid, anti-fraud) are set by Stripe on its own hosted pages, during the payment journey — not by https://klarity.coach or https://app.klarity.coach. When strictly necessary for the security of the transaction you request, they fall under the exemption. A transfer to the United States may occur, governed by SCCs / DPF (see transfers in § 6).
2.7 Technical monitoring (Sentry)
We use Sentry for technical error monitoring. Sentry captures an error context and, only when an error occurs, a session snapshot (no continuous session recording), with personal data minimized. This is a security / reliability measure, generally without advertising cookies. Sentry is hosted in the European Union (Frankfurt region), with no transfer outside the EU (see transfers in § 6).
2.8 Mapping — Google Maps (address autocomplete)
In the application, address autocomplete (for example to fill in your organization's address) relies on the Google Maps / Places API. The script is loaded only when you use that address field; on that occasion, Google may set a cookie (e.g. NID) on its own domains. Loading is limited to the feature you request. A transfer to the United States may occur, governed by SCCs / DPF (see transfers in § 6).
3. Legal bases
| Tracker category | Legal basis | Grounds |
|---|---|---|
| Strictly necessary (session/auth, essential preferences, consent record) | Consent exemption (Art. 82 French Data Protection Act) | Trackers strictly necessary to provide the online communication service expressly requested by the user |
| Security — reCAPTCHA | Consent exemption (Art. 82 French Data Protection Act) | Tracker intended exclusively for security (anti-bot / anti-fraud), proportionate to that purpose |
| Payment — strictly necessary anti-fraud trackers (Stripe-hosted pages) | Consent exemption (Art. 82 French Data Protection Act) | Necessary for the security of the requested transaction |
| Functional — Crisp support | Consent (Art. 82 French Data Protection Act) | Tracker not essential to the service |
| Marketing — attribution cookies and affiliate tracking (Affonso) | Consent (Art. 82 French Data Protection Act) | Prior, free, specific, informed, and unambiguous consent |
| Mapping — Google Maps (address autocomplete) | Exemption (Art. 82 French Data Protection Act) | Tracker loaded at your request, necessary for the address-entry feature expressly requested |
The processing of any personal data resulting from consent-based trackers relies, under the GDPR, on Article 6(1)(a) (consent). Processing linked to exempt trackers relies on the publisher's legitimate interest (Art. 6(1)(f) GDPR) in providing a functional and secure service, or on the performance of the contract (Art. 6(1)(b)) for authentication and payment.
4. Consent management
On your first visit, and when the retention period of your choices expires, our consent manager (a first-party module, self-built and self-hosted) presents you with a banner. It allows you, in an equivalent manner and without dark patterns:
- to Accept all consent-based trackers;
- to Reject all (refusal is as simple as acceptance, via a button of the same level);
- to Customize your choices, category by category.
The categories presented are: strictly necessary, functional, and marketing. Audience measurement does not appear as a separate category because our measurement tool operates without any tracker (§ 2.4). Your choice is versioned and stored for ≈ 13 months (CNIL recommendation); at expiry, the banner is presented to you again.
Until you have made a choice, no consent-based tracker is placed. Only strictly necessary and security trackers (including reCAPTCHA) are active, as they are exempt.
Withdrawal of consent. You may modify or withdraw your consent at any time, as easily as you gave it, via the "Manage my cookies" / "Cookie preferences" link accessible at all times (for example in the footer of the site and the application). Withdrawal does not affect the lawfulness of placements made before it.
5. Configuration via your browser
Independently of the banner, you can configure your browser to accept, refuse, or delete cookies. Please note: blocking strictly necessary cookies may degrade or prevent access to Klarity (in particular maintaining the authenticated session). Help links for the main browsers:
- Google Chrome: Settings → Privacy and security → Cookies and other site data.
- Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data.
- Safari: Settings → Privacy.
- Microsoft Edge: Settings → Cookies and site permissions.
The browser setting does not replace the consent module: it acts at the device/browser level, whereas the banner records your choices per purpose for Klarity.
6. Third-party cookies and transfers outside the European Union
Some trackers are issued by third-party providers, which act as controllers or processors depending on the case:
- Google reCAPTCHA v3 (provided by Google Ireland Ltd / Google LLC) — anti-bot security on public pages. Google may transfer data to the United States. These transfers are governed by the European Commission's Standard Contractual Clauses (SCCs) and/or by Google's membership of the EU-U.S. Data Privacy Framework (DPF). The use of reCAPTCHA is subject to Google's privacy policy and terms.
- Affonso (affiliate-tracking platform) — a marketing tracker set only after consent, used to attribute a conversion to the affiliate partner who referred you to the Service and to calculate their commission (affiliate programme, Article 20 ter of the Terms). Affonso may transfer data to the United States; these transfers are governed by the Standard Contractual Clauses (SCCs) and, where applicable, by membership of the EU-U.S. Data Privacy Framework (DPF). The use of Affonso is subject to its own privacy policy.
- Stripe (Stripe) — payment processing and fraud prevention, on its hosted pages. Stripe (Stripe Payments Europe Ltd / Stripe, Inc.) may carry out transfers to the United States, governed by the SCCs and/or the Data Privacy Framework.
- Crisp (provided by Crisp IM SAS) — customer support chat, loaded only after functional consent. Crisp is hosted in the European Union (Amsterdam and Frankfurt): operating the widget involves no transfer outside the EU.
- Sentry — technical error monitoring, hosted in the European Union (Frankfurt region), with no transfer outside the EU. The Sentry DPA and SCCs apply as a general contractual safeguard (the publisher, Functional Software, Inc., being established in the United States).
- Google Maps / Places (provided by Google Ireland Ltd / Google LLC) — address autocomplete in the application, loaded only when you use the address field. Google may set a cookie and carry out transfers to the United States, governed by the SCCs and/or the Data Privacy Framework.
PostHog, our audience-measurement tool, is hosted in the European Union (eu.i.posthog.com) and configured without any tracker: it involves no transfer outside the EU and stores nothing on your device (§ 2.4).
Transfers outside the EU present appropriate safeguards within the meaning of Articles 44 et seq. of the GDPR (SCCs, DPF, additional measures). You can obtain a copy or details of these safeguards from our GDPR referent (§ 8).
7. Retention of your consent choices
In accordance with the CNIL recommendation:
- The proof of consent (or refusal) and your preferences are retained for 13 months. At the end of this period, the banner is presented to you again.
- The trackers themselves have their own lifetime, indicated in § 2 (CNIL recommendation: ≤ 13 months for consent-based trackers, with no automatic renewal by a mere new visit).
Data collected via trackers is not retained beyond the period strictly necessary for its purpose.
8. Contact and updates
For any question relating to this policy or to exercise your rights (access, rectification, erasure, objection, withdrawal of consent):
- GDPR referent / DPO: Anthony Desbois — support@klarity.coach
- Postal address: 200 rue de la Croix Nivert, 75015, Paris, France
- General contact: support@klarity.coach
You also have the right to lodge a complaint with the CNIL (www.cnil.fr).
Updates. This policy may be amended to take account of legal, regulatory, case-law, or technical developments (addition or removal of trackers). The applicable version is the one published on https://klarity.coach.
