Security & privacy
Your sessions touch on the intimate. The architecture accounts for it.
What a client says in a session should never serve any purpose other than supporting them. This page describes precisely where your data lives, who can access it, what is never done with it, and how you retrieve it or make it disappear.
AWS hosting, Paris region, GDPR-compliant: storage stays within the European Union.
No session ever trains an AI model.
Session contents encrypted at rest, exchanges encrypted in transit (TLS).
Export and deletion of your data, at any time.
The four commitments
What is not negotiable.
These four principles predate the features: they shaped how the product is built, and no evolution will call them into question.
Nothing is captured without the client's agreement
Consent is collected and traceable in the product, and revocable at any time: capture stops, and deletion of already-recorded sessions can be requested from the client's record.
Your sessions feed no model
AI processing goes through APIs whose terms exclude training models on your content. And we train no model of our own on your sessions.
A client never sees another client
Each coach workspace is logically isolated, and within it, each client record is too. A memory-chat conversation in client mode cannot reach another record's sessions.
Your data leaves when you decide
Export of your sessions, summaries and records, then deletion on request, associated memory included. No conditions.
The technical detail
Where your data lives, and how.
A session's journey, from capture to retention, with the measures that apply at each step.
In France, stored in the EU.
Your data at rest (client records, sessions, memory, imported files) is hosted on AWS infrastructure in region eu-west-3 (Paris) and does not leave the European Union for storage.
You stay in control, retention stays limited.
We keep your data only as long as needed for the purposes described in the privacy policy. Export and deletion remain in your hands, at any time.
Who is involved, and for what.
Each subprocessor is bound by a data processing agreement and only accesses the data needed for its service. Storage stays in the EU; processing involving a provider outside the EU is governed by Standard Contractual Clauses. The full, up-to-date list is public.
See the full listWhat we never do
Five things that will not happen.
Excluded by our AI providers' terms, and we train no model of our own.
Never sold nor shared for advertising or commercial purposes.
Internal access restricted to authorized staff, limited to what is strictly necessary, sensitive operations logged.
The raw material never leaves your space. You alone decide what is sent.
Export then deletion on request, associated memory included.
The questions your clients ask, and your answers.
Will anyone else listen to our session?
No. Your space is isolated. Internally, access is restricted to authorized staff, limited to what support strictly requires, and sensitive operations are logged.
Is the recording kept for long?
It serves to produce the transcript and the summary. You can delete a session at any time, and retention stays limited to the purposes described in the privacy policy.
Can I withdraw my consent afterwards?
Yes, at any time. Capture stops, and the client can ask for already-recorded sessions to be deleted: you trigger it from their record.
Where is the data, and who can access it?
Stored in France (AWS Paris), encrypted. Providers are bound by a data processing agreement and, when outside the EU, governed by Standard Contractual Clauses. The list is public.
What happens if Klarity disappears?
Your data is exportable at any time, and account deletion removes the associated data, memory included. You remain the data controller: Klarity is only your processor.
A security question before you start?
Write to us: we answer precisely, and we provide the data processing agreement (DPA) on simple request.
