Legal
Privacy Policy
Version 1
Effective 14 June 2026
Last updated: 14 June 2026
TL;DR: Klar stores your data on your device. Nothing is sent anywhere unless you opt in to cloud sync or AI features. We don't sell data. You can delete everything at any time.
1. Introduction
Klar ("we", "us", "our") is a personal finance management application that runs entirely in your web browser. This Privacy Policy explains how your personal and financial information is handled when you use Klar at klar.marcelmoyo.workers.dev or any associated domains.
Klar is built on a local-first principle: your data stays on your device unless you explicitly choose to enable optional cloud sync or AI features. We process your data only as described in this policy.
By using Klar, you agree to this Privacy Policy. If you do not agree, please stop using the app and clear your browser's localStorage for this site.
2. Data We Process
Klar processes information that you enter:
- Financial transactions (amounts, dates, categories, merchants, notes)
- Bank account names and balances you choose to record
- Budget limits and spending history
- Savings goals and progress
- Debt records and repayment plans
- Subscriptions and recurring bills
- Personal preferences (theme, currency, region)
- Receipt photo images you choose to attach (stored locally as base64)
Klar does not collect:
- Government ID numbers (NI, SARS, passport)
- Full bank account or card numbers
- Biometric data
- HMRC or SARS login credentials
- Device identifiers, IP addresses, or browser fingerprints (beyond what Supabase receives if you use cloud sync)
3. Where Your Data Lives
π±
Local only (default): All data is stored in your browser's localStorage on this device. Nothing is sent to any external server. You can clear it at any time via Settings β Data Management β Reset all data, or by clearing your browser's site data.
β
Cloud Sync (optional β opt-in): If you sign in, your data is encrypted in transit (TLS 1.2+) and stored in a Supabase PostgreSQL database. Each user's data is protected by Row Level Security (RLS) β only you can access your data. You can delete your cloud data at any time from Settings β Privacy β Delete cloud data.
π€
AI Advisor (optional β opt-in): When you chat with the AI Advisor, a financial summary only (average monthly income, average monthly expenses, account count, debt count, region) is sent to Groq Inc's API β never raw transaction data. Two specific features work differently: "Explain transaction" sends that one transaction's description and amount to Groq so it can explain it, and the month-end checklist sends your upcoming bill names and amounts to generate a checklist. Both are actions you trigger yourself. Account numbers are never transmitted to Groq under any feature.
π€
Automated decision-making: Klar's AI Advisor uses automated processing to generate personalised financial insights and recommendations based on your transaction data. This processing does not produce legal or similarly significant effects β all AI outputs are advisory only and require your review before any action is taken. You may opt out of AI features at any time by not using the AI Advisor functionality.
π³
Payments (optional β opt-in): Subscription billing is handled by Dodo Payments. Clicking a subscription button opens Dodo Payments' hosted checkout. Klar never receives or stores your payment card details. Refer to Dodo Payments' privacy policy.
π³
Bill Hub (no processor involved): Bill Hub logs the reference number and amount you enter for tracking, then opens the relevant utility or service provider's own official website in a new tab so you can pay them directly. Klar has no payment processor for this feature and never receives, sees, or stores your payment card details.
π¬
Support chat (optional): If you use the in-app chat support (Crisp), your messages and your email address (if provided) are processed by Crisp Chat. Refer to Crisp's privacy policy.
π
Analytics (optional): We use PostHog (EU-hosted) to collect usage events (page views, feature use, plan selected). No financial data is included. Before you sign in, events are anonymous; once you sign in for cloud sync, events are linked to your account (email and user ID) so we can improve the product and support you. You can opt out by blocking analytics in your browser or ad-blocker.
4. Third-Party Processors
| Service | Purpose | Data sent | Location | When active |
| Supabase | Cloud backup & auth | Encrypted app data, email | EU / USA | Only if signed in |
| Groq | AI Advisor responses | Financial summary; transaction/bill details for "Explain transaction" & the month-end checklist | USA | Only when you query AI |
| Dodo Payments | Subscription billing | Email, payment details | Global | Only when subscribing |
| Saltedge | UK bank feeds | OAuth token, account list | EU | Only if bank feed connected |
| Frankfurter | Live FX rates | Currency pair (no personal data) | EU | When FX conversion active |
| Crisp | Support chat | Chat messages, email (optional) | EU | When chat opened |
| PostHog EU | Product analytics | Usage events, region, plan tier β plus email & user ID once signed in | EU | Always; anonymous until sign-in |
All third-party services operate under their own privacy policies and are bound by applicable data-protection law. None are active unless you use the specific feature, except PostHog, which runs by default (anonymously before sign-in, linked to your account afterward).
5. Legal Basis for Processing
πΏπ¦
POPIA (South Africa): Processing is lawful under Β§11(1)(a) (consent) and Β§11(1)(f) (legitimate interest). Local processing of your own personal financial records may also fall under the personal or household activity exemption of POPIA Β§6(1)(e).
π¬π§
UK GDPR / DPA 2018: Article 6(1)(a) β Consent for optional cloud/AI/analytics features. Article 6(1)(f) β Legitimate interests for local processing of your own data. As a data controller, we are assessing our ICO registration obligations. If you have questions about our regulatory status, please contact us at privacy@klarfinance.co.za.
πͺπΊ
EU GDPR: Article 6(1)(a) consent; Article 6(1)(f) legitimate interests. Where applicable, Article 9 is not engaged as we do not process special-category data.
π
Other jurisdictions (CCPA, LGPD, PDPA, PIPEDA): Klar does not sell personal information. Consent and purpose-limitation principles are implemented by design. Rights under each applicable law are available via Settings β Privacy.
6. Your Rights
You have the following rights with respect to your personal data, exercisable at any time:
β
Access
Settings β Data Management β Full data backup (JSON)
βοΈ Rectification
Edit any transaction, account, or record directly in the app
ποΈ Erasure (local)
Settings β Data Management β Reset all data
ποΈ Erasure (cloud data only)
Settings β Privacy β Delete cloud data
ποΈ Erasure (full account)
Settings β Privacy β Delete account permanently. Irreversible β deletes your cloud data and your login itself.
π¦ Portability
Export as JSON, CSV, or Excel via Settings β Data Management
π« Restriction / Withdrawal
Sign out of cloud sync; remove API key to disable AI; decline analytics
To exercise any right not directly actionable in the app, contact us at privacy@klarfinance.co.za. We will respond within 30 days.
7. Data Retention
You control all data retention:
- Local data persists in your browser's localStorage until you clear it or reset the app.
- Cloud data (Supabase) persists until you delete your account or use Settings β Privacy β Delete cloud data.
- AI query context is not retained by Groq beyond the API response cycle (per Groq's privacy policy).
- Support chat transcripts are retained by Crisp subject to their data retention policy.
- Analytics events are retained by PostHog for up to 12 months β anonymised for pre-sign-in usage, linked to your account (email, user ID) for events recorded while signed in.
8. Security
- Local data: stored in browser localStorage, accessible only to the origin serving the app. We recommend using the app PIN lock (Settings β App Lock) if you share a device.
- Cloud data: transmitted via TLS 1.2+; stored with Supabase's encryption-at-rest (AES-256). Row Level Security ensures only you can read your data.
- AI data: transmitted via TLS to Groq's API. General AI Advisor chat sends a financial summary only. "Explain transaction" and the month-end checklist additionally send the specific transaction description or bill name/amount you're asking about.
- Payments: all card data for subscriptions is handled by Dodo Payments' PCI-DSS-compliant infrastructure. We never see your card details. Bill Hub has no payment processor at all β it never collects card data in the first place.
Your responsibility: Keep your sign-in credentials secure. Do not share your Klar access with others on shared devices without using the PIN lock feature.
9. Cross-Border Data Transfers
If you use optional features, your data may be transferred to servers outside your country of residence:
- Supabase β EU-hosted by default; may also use USA infrastructure. Supabase maintains GDPR Standard Contractual Clauses (SCCs) and is certified under the EU-US Data Privacy Framework.
- Groq β USA. By enabling the AI Advisor, you consent to the transfer of a financial summary β and, for "Explain transaction" and the month-end checklist, the specific transaction or bill details involved β to Groq's USA servers.
- Dodo Payments β Global. Dodo Payments is GDPR-compliant and maintains SCCs for cross-border transfers.
By enabling these optional features, you consent to the associated cross-border transfers described above.
10. Children's Data
Klar is not intended for persons under 18 years of age. We do not knowingly collect personal information from minors. If you believe a minor has used this app and entered personal data, please clear all data via Settings β Data Management β Reset all data, and contact us at privacy@klarfinance.co.za.
11. Responsible Party / Data Controller
For POPIA purposes, and to the extent Klar operates as a data processor: Klar Money is the data controller. For personal use of the app where you are processing solely your own financial data for personal and household purposes, you are both the data subject and responsible party.
Contact: privacy@klarfinance.co.za
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be presented for your consent on the next app launch (the version number will increment). Minor clarifications may be made without notice. The version number and effective date are always shown at the top of this document.
Continued use of Klar after a version change constitutes acceptance of the updated policy.
13. Cookies & Local Storage
Klar does not use advertising cookies or cross-site tracking cookies.
We use the following browser storage mechanisms:
- localStorage β Your financial data, preferences, and app state are stored in your browser's localStorage on your device only. This is not a cookie and is not transmitted to any server by default. You can clear it at any time via Settings β Data Management β Reset all data.
- sessionStorage β Temporary session data (e.g. draft form values) may be stored for the duration of your browser session and cleared when you close the tab.
- Analytics (optional) β If analytics is active, we use PostHog in cookieless, memory-only mode (no persistent cookie, no cross-site tracking, PECR compliant). Events are anonymous until you sign in for cloud sync, after which they're linked to your account (email, user ID) for support and product-improvement purposes.
- Supabase auth (optional) β If you sign in for cloud sync, your authentication token is stored in localStorage to keep you signed in. You can sign out at any time.
No third-party advertising networks, social media trackers, or behavioural profiling cookies are used on this site.
14. Contact Us
For any privacy questions, rights requests, or concerns:
We aim to respond to all requests within 30 days.