Security & Trust

Klonr handles your family's schedules, school emails, and reminders. Here is exactly how that data is protected, in plain language. Last updated August 24, 2026.

Klonr never connects to your inbox

This is the design decision everything else follows from. You get a dedicated forwarding address ([email protected]) and you choose which emails to send there, one at a time. Klonr has no OAuth connection to Gmail or Outlook, no background sync, no standing access. If you never forward an email, Klonr never sees one.

Most assistants in this category ask for full inbox access because it makes onboarding faster. We accepted the slower path on purpose: the messages Klonr reads are exactly the messages you decided it should read.

Outbound messages need your yes

Klonr drafts emails to teachers, coaches, and other parents, but sending one always requires your explicit approval first. That rule is enforced in code as a hard override, not a preference: no learned behaviour, no setting, and no amount of assistant confidence can skip the approval step for a message that leaves your household.

Encryption

All traffic between your phone, our servers, and our providers moves over TLS. Data at rest lives in a managed PostgreSQL database with disk-level encryption. Payment card details never touch our servers at all: billing runs through Stripe, and we store only the subscription state.

What we log, and what we refuse to

Your messages and emails are personal. Our operational logs reference record identifiers, not content: when we debug a delivery problem, we see that message 48f2 to user 91c7 failed at 9:14, not what the message said. Analytics events follow the same rule and carry counts and categories, never text.

Consent and Quebec Law 25

Klonr is built in Montreal, and Quebec's privacy law sets our default posture. Analytics cookies run only after you accept them in the consent banner; refuse, and analytics stay cookieless with nothing stored on your device. Identification, location, and profiling functions stay off until you opt in, which is what Law 25 requires and what we would want as users anyway.

Webhooks and third parties

Every webhook we receive (Twilio for SMS, Postmark for email, Stripe for billing) is signature-verified before processing, so a forged request gets dropped at the door. We do not sell your data, share it with advertisers, or use it to train foundation models.

Your data, your exit

Email [email protected] and we will delete your account and its data. No retention tricks, no 90-day dark pattern. We would rather earn you back later than hold your family's schedule hostage.

Questions

Security disclosures and privacy questions both go to [email protected], and you will get the founder, not a queue. If you find a vulnerability, tell us before you publish it and we will fix it fast and credit you if you want the credit.