Legal · Privacy Policy
Privacy Policy
Effective 9 September 2026 · Version 1.0-beta · English original
1. Controller
Data controller: Samuel Ján Mucha, sole individual operating as Klunq Labs, Brno, Czech Republic, contact admin@klunqlabs.com. No data protection officer is designated. EU supervisory authority: Úřad pro ochranu osobních údajů (Czech DPA) — you may complain to them or to your local EU authority.
2. What we process and why
| Data | Purpose | Lawful basis (Art. 6 GDPR) |
|---|---|---|
| Account email, password hash | Registration, login, contract notices | Contract (b) / legitimate interest (f) |
| Encrypted team key, v-key aliases, budgets, spend aggregates | Providing and metering the Service | Contract (b) |
| Security/abuse signals, support correspondence | Security, abuse enforcement (§5 ToS), support | Legitimate interest (f) |
| Turnstile challenge data | Bot protection at signup/login | Legitimate interest (f) |
Prompts are not stored. Chat content passes through to model providers for inference only; we persist spend aggregates, never prompt bodies (store_prompts_in_spend_logs: false).
3. Recipients and transfers
- Supabase (EU) — auth, database, encrypted key storage (processor).
- Oracle Cloud (Frankfurt, EU) — proxy hosting (processor).
- Cloudflare (global edge, incl. US) — hosting, security, captcha. Third-country transfer safeguard: EU Standard Contractual Clauses; copy available on request.
- Model providers (e.g. OpenRouter and downstream providers, incl. US) — inference only; provider terms apply to content you send.
- Lemon Squeezy (future, when payments launch) — merchant of record for billing, under its own terms and privacy notice.
No sale of personal data, no advertising profiling. IP addresses are processed by Cloudflare and Supabase for delivery and security; we store none ourselves.
4. Retention — what deletes your data
Nothing expires on a clock today. Deletion is event-driven — this table is the whole schedule. A time-based purge job is planned before monetization.
- Login deleted (request to the email above) → Supabase Auth user removed → your encrypted team-key row is deleted with it in the same transaction (database cascade).
- Virtual keys and spend logs (proxy database): persist until you delete them in the dashboard, or we delete them under abuse enforcement — otherwise indefinitely.
- Support correspondence: 90 days after the ticket closes.
5. Your rights
Access, rectification, erasure, restriction, objection, portability (Art. 15–21 GDPR): write to admin@klunqlabs.com — we answer within one month (EU) and within 45 days for US requests. Providing account data is a contractual requirement: without an email we cannot create your account. No automated decision-making with legal effect takes place; abuse reviews are human.
6. United States privacy note
We meet the higher bar voluntarily, regardless of thresholds. We do not sell or share personal data and run no advertising profiling. California residents hold rights to know, delete and correct their data and to opt out of any sale/sharing (none occurs) — exercise them at the email above. The Service is not directed at children under 13 and we do not knowingly collect their data; accounts require legal capacity to contract.
7. Cookies
Strictly-necessary storage only — see the Cookie Policy . No analytics today.
8. Future analytics (reserved)
We plan optional conversation analytics (Langfuse) so Clients can analyse their own End-User interactions. It is not active: activation requires a prior update of this policy with notice, and Client-side controls before any conversation content is retained.