Security & Trust
Klonr handles your family's schedules, school emails, and reminders. Here is exactly how that data is protected, in plain language. Last updated August 24, 2026.
Klonr never connects to your inbox
This is the design decision everything else follows from. You get a dedicated forwarding address ([email protected]) and you choose which emails to send there, one at a time. Klonr has no OAuth connection to Gmail or Outlook, no background sync, no standing access. If you never forward an email, Klonr never sees one.
Most assistants in this category ask for full inbox access because it makes onboarding faster. We accepted the slower path on purpose: the messages Klonr reads are exactly the messages you decided it should read.
Outbound messages need your yes
Klonr drafts emails to teachers, coaches, and other parents, but sending one always requires your explicit approval first. That rule is enforced in code as a hard override, not a preference: no learned behaviour, no setting, and no amount of assistant confidence can skip the approval step for a message that leaves your household.
Encryption
All traffic between your phone, our servers, and our providers moves over TLS. Data at rest lives in a managed PostgreSQL database with disk-level encryption. Payment card details never touch our servers at all: billing runs through Stripe, and we store only the subscription state.
What we log, and what we refuse to
Your messages and emails are personal. Our operational logs reference record identifiers, not content: when we debug a delivery problem, we see that message 48f2 to user 91c7 failed at 9:14, not what the message said. Analytics events follow the same rule and carry counts and categories, never text.
Consent and Quebec Law 25
Klonr is built in Montreal, and Quebec's privacy law sets our default posture. Analytics cookies run only after you accept them in the consent banner; refuse, and analytics stay cookieless with nothing stored on your device. Identification, location, and profiling functions stay off until you opt in, which is what Law 25 requires and what we would want as users anyway.
Webhooks and third parties
Every webhook we receive (Twilio for SMS, Postmark for email, Stripe for billing) is signature-verified before processing, so a forged request gets dropped at the door. We do not sell your data, share it with advertisers, or use it to train foundation models.
Your data, your exit
Email [email protected] and we will delete your account and its data. No retention tricks, no 90-day dark pattern. We would rather earn you back later than hold your family's schedule hostage.
Questions
Security disclosures and privacy questions both go to [email protected], and you will get the founder, not a queue. If you find a vulnerability, tell us before you publish it and we will fix it fast and credit you if you want the credit.