Stays on your device
Your full portfolio records, original documents, and chat history remain local unless you choose an action that sends specific content.
Last updated: July 30, 2026
KlarFort is private by design. Your core portfolio records, original documents, and chat history live on your device. KlarFort does not persist your full portfolio tables on its servers. There are no ads, and your data is never sold.
When you choose an AI feature, KlarFort sends the request, files you attach, and the relevant portfolio context needed to answer it. KlarFort does not write chat messages, attachments, or portfolio snapshots to its persistent server storage. KlarFort does keep limited pseudonymous service and security records, optional notification data, selected AI outputs and rules, submitted reports, and deletion-recovery records. The policy below explains exactly what is stored, why it is needed, and how long it is retained.
Your full portfolio records, original documents, and chat history remain local unless you choose an action that sends specific content.
AI prompts, attachments, and relevant portfolio context are processed only after you consent and use or enable the feature. A portable backup goes only to the destination you choose.
Limited pseudonymous security records, hashed trial and purchase anchors, optional push data, selected AI outputs and rules, and submitted reports.
No advertising, no data sale, and no tracking across other companies' apps and websites.
Export and import happen on your device. A current version 7 portable JSON backup can include your core financial records; custom rules, including their prompts; saved risks; dashboard-milestone and import-history summaries, including attachment-derived source filenames or labels and saved share-card metadata such as headlines, subtitles, asset or entity names, dates, and in-app destination or attribution fields; compatibility fields used by sharing privacy and document import; and notification settings. KlarFort then hands the file to the save and share controls provided by iOS or Android. KlarFort's servers do not receive, route, or store the backup file.
You decide where the file goes. After you share or save it, the destination's privacy and security terms apply. The backup is not separately encrypted by KlarFort, so protect it like a financial document.
Compatible KlarFort versions on iOS and Android can import the backup. Each imported file can be up to 50 MB. Original document and attachment contents, chat history, authentication information, and net-worth snapshot history are not included. An attachment-derived source filename or label and its saved share-card metadata can still appear in an import-history summary.
Import combines data according to its type. Core financial records with matching IDs are updated, new core financial records are added, and core financial records that exist only on the destination remain there. Custom rules and import history from the backup replace those destination lists. Current compatible versions restore notification settings from the backup. A recognized last document kind is preserved, while the preferred document source and reuse choice reset to current defaults. Sharing-privacy choices also reset to current defaults rather than being restored.
AI is separate and optional. When you choose an AI feature, KlarFort sends the request, any attachment, and relevant portfolio context through its backend for processing. KlarFort does not save those inputs as a persistent portfolio copy. Selected AI outputs and limited pseudonymous service and security records are retained as described in this policy.
This summary is provided to align with the disclosure formats used by Apple's App Privacy Details and Google Play's Data Safety section. The detailed sections below are authoritative.
KlarFort does not use an email address, name, or social-login identity as your account. The backend operates a pseudonymous service profile derived from a trial or verified store purchase. It stores the following records:
Your complete portfolio tables (assets, liabilities, cash flows, projects, and obligations) are not persisted on KlarFort servers. KlarFort does not collect advertising identifiers, precise or coarse location, contact lists, microphone data, health or fitness data, biometric data, or financial-account credentials. Content sent for consent-gated AI processing is not written to persistent KlarFort storage; selected outputs and user-submitted reports are the exceptions described above.
KlarFort offers optional AI assistance: chat with the in-app assistant, daily insight notes, document import, and periodic background monitoring on paid tiers. These features are off until you agree to use them. The first time you open an AI feature, the app presents a consent screen that explains what will be shared and with whom; nothing is sent to any AI provider until you tap Agree and Continue. You can withdraw this consent at any time in the app under Settings > AI Data Sharing. Withdrawing consent immediately blocks any new AI request from the app and cancels an assistant response that is still streaming; a request already submitted to our servers finishes processing, and nothing further is sent.
When you use an AI feature, the app transmits a payload through our backend to our AI providers for processing, and the response is returned to you. The payload may contain:
KlarFort does not automatically add a name, email address, raw trial UUID, store purchase credential, or access token to the AI payload. Text and files you choose to submit may themselves contain personal information, so review them before sending. Requests are made by our servers on your behalf, so your device identifier and network address are not supplied to the AI provider as request identity fields.
Who receives it. Conversational and analysis requests are processed by the AI providers we may use: Anthropic PBC, Google LLC, or OpenAI, L.L.C. Documents and images you attach may also be processed by Google LLC to read their contents before your request is answered. Whichever providers process a request act as service providers under enterprise data-processing terms that restrict processing to delivering the service to us, impose confidentiality and security obligations consistent with the protections in this policy, and prohibit using your data to train their models. When a request needs current market information, the model may issue generic web-search queries that are instructed to contain no personal or portfolio details.
Retention. Your messages, attachments, and portfolio snapshots are forwarded for the lifetime of the request and are not written to persistent KlarFort server storage; a short-lived in-memory cache is used only to avoid processing an identical retried request twice. What KlarFort does keep are the outputs listed in What we store: daily insight notes (up to 90 days), your latest monitoring analysis (replaced by each newer one), and custom rules. These are removed when you delete your account.
Reporting is optional. When you use the in-app report action, KlarFort sends and stores the reported message UUID, a fixed report category, and a short excerpt under your pseudonymous service profile for safety review. The report does not transmit your full conversation unless that content is part of the excerpt shown by the app. Up to 100 reports are retained per profile; each is removed within 365 days under scheduled cleanup or earlier with the deletable data when you delete your account. Use the contact channel below for a support request or a reply.
Service providers involved in delivering KlarFort include:
The app contains no advertising SDKs and no social-login SDKs.
If you subscribe, billing is handled by Apple App Store or Google Play. Their terms govern your purchase, including auto-renewal, billing cycles, family sharing, and any price changes. KlarFort processes the store receipt or purchase credential to confirm your tier and stores the hashed verification and anti-replay record described above. KlarFort does not see, store, or process your payment-card details. Cancellation is performed in the same store account that originated the purchase, not by deleting your KlarFort profile. Unless you cancel in that store, billing continues on the store's normal schedule after KlarFort account deletion.
You can delete your account at any time:
Reset App Data is not account deletion. Reset clears local app data and disconnects the current device, but it does not request server erasure or remove stored AI outputs and reports. To erase active server data, use Delete Account first and wait for it to succeed before resetting or uninstalling.
The hashed anti-abuse trial record, bound subscription anti-replay record, generation-independent daily AI rate-limit rows, and durable authorization lifecycle and deletion-recovery records described in Data retention are not erased with active profile data. Historical backup images may retain prior row bytes until their seven-day expiry, but the external deletion history is reapplied before a restored database can serve, so those rows are purged again and old tokens stay invalid. Active store subscriptions must be cancelled separately in the App Store or Google Play account that originated the purchase. Deleting KlarFort does not cancel billing. A later verified recreation does not restore erased active profile or local data.
KlarFort is not directed at children under 13 and we do not knowingly retain account information for anyone under 13. If you are a parent or guardian and believe a minor has created an account, please contact us and we will delete it. KlarFort does not knowingly collect personal information in violation of the Children's Online Privacy Protection Act (COPPA).
Our infrastructure operates from facilities that may be located outside your country of residence. By using KlarFort you consent to your account information being processed in those jurisdictions, subject to the protections in this policy. Where required, transfers from the European Economic Area, the United Kingdom, or Switzerland are made under appropriate safeguards such as the Standard Contractual Clauses.
If you are in the European Economic Area, the United Kingdom, or Switzerland, you may have rights to access, correct, restrict, port, and erase personal data, and to object to processing or withdraw consent. Our lawful bases are: contract to deliver a subscription; consent for consent-gated AI features and notifications; legitimate interests to secure the service, enforce limits, prevent replay of the same trial identifier or store purchase, and investigate reported AI responses; and legal obligation where applicable. AI consent can be withdrawn directly in the app under Settings > AI Data Sharing. To exercise a right, use the in-app deletion action or email [email protected]. Because no account email is stored, support must securely verify the pseudonymous profile before acting on a profile-specific request. You also have the right to lodge a complaint with your local supervisory authority.
If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you the right to know what personal information we collect, the right to delete it, the right to correct it, the right to limit the use of sensitive personal information, the right to opt out of "sale" or "sharing", and the right not to be discriminated against for exercising these rights.
Notice at collection. The categories of personal information involved in KlarFort, the purposes for which they are used, whether they are stored on our servers or transmitted ephemerally, and the retention period for each are:
Sale and sharing. KlarFort does not sell personal information and does not share personal information for cross-context behavioural advertising, as those terms are defined in the CCPA and CPRA. The third parties listed in Third-party services act as service providers processing data on our behalf for the limited purposes listed; that is not "sale" or "sharing".
Sensitive personal information. AI content you choose to send may contain financial or other sensitive information. KlarFort uses it only to fulfil the request you initiated and does not use it to infer characteristics for advertising, sale, or unrelated profiling. You do not need to file a request to limit those unrelated uses; KlarFort does not perform them.
Right of non-discrimination. We will not deny you the Service, charge you a different price, or provide a different level of quality for exercising any of these rights.
To exercise your CCPA rights, use the deletion-request page or email [email protected]. We respond to verifiable requests within 45 days, with a single 45-day extension where reasonably necessary, in line with the timelines set by California law.
Residents of other US states with comprehensive consumer-privacy laws (including but not limited to Colorado, Connecticut, Delaware, Indiana, Iowa, Montana, Oregon, Tennessee, Texas, Utah, and Virginia) may have rights similar to those described in the GDPR and CCPA sections above. The same email and deletion-request channels apply.
We apply current industry-standard practices to protect the pseudonymous service data we hold and communication between the app, our servers, and consent-gated AI providers. Data is transmitted over TLS, stable store identifiers are persisted as one-way hashes, signed access tokens are stored on the device, and production access is restricted. No system is perfectly secure. To report a security concern, use the responsible-disclosure channel.
If we materially change how we handle your data, we will update this page, revise the Last updated date, and surface a notice in the app on next launch. Your continued use of the Service after a change becomes effective constitutes acceptance of the revised policy. We will not retroactively make material changes that reduce your privacy rights without your consent. Editorial clarifications and fuller disclosures that do not change how KlarFort handles data do not trigger a new in-app acceptance notice.
Questions, requests, or concerns about this policy:
We respond to every message we receive.
[email protected]