Legal

Privacy Policy

Last updated: May 9, 2026

Heads-up

Klent is currently in private alpha. The data-handling principles below apply throughout — what changes during alpha is retention, which is best-effort while we iterate the schema. See §4 (Retention) for the specifics.

This Privacy Policy explains what data Klent collects, how we use it, and the rights you have over it. It applies to the Klent dashboard, the Klent API, the Klent SDKs, and the Klent MCP server (collectively, the “Service”), operated by Verbose Digital LLC (“Klent,” “we,” “us”).

1. Data we collect

We collect three categories of data:

Account data

  • Your name, email, and profile picture (provided by your identity provider through WorkOS during sign-up);
  • The projects you create and the team members you invite;
  • API keys you mint (we store a hash, never the plaintext).

Service usage data

  • Tool calls, decisions, and execution events your SDK or MCP server sends to the Klent API;
  • Policy definitions, alert rules, and pending-approval queues;
  • Webhook delivery logs and email-approval votes.

Operational telemetry

  • Anonymous request logs (timestamps, paths, response codes, latency) that we use to monitor uptime and debug issues;
  • Coarse-grained product analytics (page views, feature adoption) that never include the contents of tool calls or PII.

2. How we use your data

We use the data above strictly to:

  • Authenticate you and authorise your API requests;
  • Run the policy engine, route approvals, send alerts, and serve the dashboard;
  • Communicate with you about the Service (announcements, security notices, billing if and when paid plans launch);
  • Diagnose incidents, investigate abuse, and improve performance and reliability;
  • Comply with applicable legal obligations.

We do not sell your data, and we do not use the contents of your tool calls, policy definitions, or audit events to train any third-party AI models.

3. Sub-processors

We rely on a small set of vendors to operate the Service. Each is bound by a data-processing agreement and only handles the data it needs to perform its function:

  • Supabase (PostgreSQL hosting) — stores all structured Service data;
  • Railway (compute) — runs the API, dashboard, and docs services;
  • WorkOS (authentication) — handles login, organisation, and SSO flows;
  • Resend (transactional email) — delivers alerts and human-approval emails;
  • Cloudflare (DNS / CDN) — handles edge routing for our domain.

4. Data retention

Account data is retained for as long as your account is active. After you delete your account, we remove your data within 30 days, except where retention is required by law (e.g., invoices) or to resolve an open dispute.

Service-usage data (executions, events, decisions) is retained according to your project's retention policy, configurable in the dashboard. The default retention is 90 days.

During alpha: retention is best-effort and we may reset Service-usage data when a schema change requires it. Account data and audit trails are preserved across these changes whenever possible.

5. Your rights

Depending on your jurisdiction, you may have the right to access, correct, port, or delete the personal data we hold about you, and to object to or restrict our processing of it.

Most of these rights can be exercised directly from the dashboard. For anything else, email [email protected] and we will respond within 30 days.

If you are in the EEA, UK, or Switzerland, you have the right to lodge a complaint with your local data-protection authority.

6. Cookies

The Klent landing page does not set marketing or analytics cookies. The dashboard sets a session cookie issued by WorkOS for authentication and a small set of strictly-necessary cookies for the UI.

7. Security

Data is encrypted in transit (TLS 1.2+) and at rest (managed by Supabase). API keys are stored as bcrypt hashes; only the plaintext shown at mint time is ever returned to you.

If we become aware of a security incident affecting your data, we will notify you without undue delay and follow up with the scope, impact, and remediation steps.

8. International transfers

Klent is operated from the United States. By using the Service, you understand that your data may be transferred to and processed in the United States and any country where our sub-processors operate. Where required, transfers are governed by Standard Contractual Clauses.

9. Children

The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us and we will delete it.

10. Changes to this policy

We may update this policy from time to time. The “Last updated” date at the top reflects the most recent change. Material changes will be communicated in advance via email or the dashboard.

11. Contact

For privacy-related questions or to exercise any of the rights above, email [email protected].