Security & privacy

Your sessions touch on the intimate. The architecture accounts for it.

What a client says in a session should never serve any purpose other than supporting them. This page describes precisely where your data lives, who can access it, what is never done with it, and how you retrieve it or make it disappear.

Free trial, no credit card.
France

AWS hosting, Paris region, GDPR-compliant: storage stays within the European Union.

Never

No session ever trains an AI model.

AES-256

Session contents encrypted at rest, exchanges encrypted in transit (TLS).

On request

Export and deletion of your data, at any time.

The four commitments

What is not negotiable.

These four principles predate the features: they shaped how the product is built, and no evolution will call them into question.

01 · Consent

Nothing is captured without the client's agreement

Consent is collected and traceable in the product, and revocable at any time: capture stops, and deletion of already-recorded sessions can be requested from the client's record.

02 · No training

Your sessions feed no model

AI processing goes through APIs whose terms exclude training models on your content. And we train no model of our own on your sessions.

03 · Isolation

A client never sees another client

Each coach workspace is logically isolated, and within it, each client record is too. A memory-chat conversation in client mode cannot reach another record's sessions.

04 · Reversibility

Your data leaves when you decide

Export of your sessions, summaries and records, then deletion on request, associated memory included. No conditions.

The technical detail

Where your data lives, and how.

A session's journey, from capture to retention, with the measures that apply at each step.

01Hosting

In France, stored in the EU.

Your data at rest (client records, sessions, memory, imported files) is hosted on AWS infrastructure in region eu-west-3 (Paris) and does not leave the European Union for storage.

HostAmazon Web Services
Regioneu-west-3 · Paris
Session contentsEncrypted in the database (AES-256-GCM)
ExchangesEncrypted in transit (TLS / HTTPS)
PasswordsHashed (bcrypt), never in plain text
IsolationPer organization, on every request
02Control & retention

You stay in control, retention stays limited.

We keep your data only as long as needed for the purposes described in the privacy policy. Export and deletion remain in your hands, at any time.

Export of your dataAt any time, on request
Deleting a record or a sessionImmediate, associated memory included
Account deletionRemoves the associated data
Session contentsKept for the described purposes only
Security logs≈ 12 months
Support conversations3 years after the last exchange
03Subprocessors

Who is involved, and for what.

Each subprocessor is bound by a data processing agreement and only accesses the data needed for its service. Storage stays in the EU; processing involving a provider outside the EU is governed by Standard Contractual Clauses. The full, up-to-date list is public.

See the full list
RolePurposeSafeguards
HostingStorage and computeFrance (EU)
TranscriptionAudio to textDPA · SCCs
Generative AISummaries, briefings, chatDPA · SCCs
Email deliveryReminders and reportsDPA · SCCs
PaymentThe coach's subscriptionDPA

What we never do

Five things that will not happen.

Train a model on your sessions

Excluded by our AI providers' terms, and we train no model of our own.

Sell or hand over your data

Never sold nor shared for advertising or commercial purposes.

Read your sessions without cause

Internal access restricted to authorized staff, limited to what is strictly necessary, sensitive operations logged.

Send a transcript to the client

The raw material never leaves your space. You alone decide what is sent.

Hold your data hostage at cancellation

Export then deletion on request, associated memory included.

Get started for freeFree trial, no credit card.

The questions your clients ask, and your answers.

Will anyone else listen to our session?

No. Your space is isolated. Internally, access is restricted to authorized staff, limited to what support strictly requires, and sensitive operations are logged.

Is the recording kept for long?

It serves to produce the transcript and the summary. You can delete a session at any time, and retention stays limited to the purposes described in the privacy policy.

Can I withdraw my consent afterwards?

Yes, at any time. Capture stops, and the client can ask for already-recorded sessions to be deleted: you trigger it from their record.

Where is the data, and who can access it?

Stored in France (AWS Paris), encrypted. Providers are bound by a data processing agreement and, when outside the EU, governed by Standard Contractual Clauses. The list is public.

What happens if Klarity disappears?

Your data is exportable at any time, and account deletion removes the associated data, memory included. You remain the data controller: Klarity is only your processor.

A security question before you start?

Write to us: we answer precisely, and we provide the data processing agreement (DPA) on simple request.

contact@klarity.coachReply within 48 business hoursA vulnerability to report? Same address: every report is reviewed.