Privacy Policy

Last updated: March 2026

Klaira ("we", "us", or "our") is committed to protecting your privacy and handling your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This policy explains what information we collect, why we collect it, and how we use it.

1. Information We Collect

We collect personal information only to the extent necessary to provide our service. This includes:

  • Account information: your name, email address, and password when you create a Klaira account.
  • Chat transcripts: conversations between your website visitors and your Klaira chatbot. These are stored so you can review them in your dashboard.
  • Lead contact information: if your chatbot is configured with lead capture, visitor names and email addresses submitted through the chat widget are stored and associated with your account.
  • Usage data: technical information such as IP addresses, browser type, pages visited, and feature usage patterns. This is used in aggregate and is not linked to individual identities for marketing purposes.
  • Billing information: payment method details processed and stored by our payment provider. We do not store raw card numbers.

2. How We Use Your Information

We use collected information to:

  • Provide, maintain, and improve the Klaira service
  • Process payments and manage your subscription
  • Send important service-related notices (not marketing emails without your consent)
  • Diagnose technical issues and improve product reliability
  • Understand how the product is used so we can improve it

We do not sell your personal information to third parties. We do not use chat transcripts or your uploaded knowledge base content to train our own AI models.

3. Third-Party Services

To deliver Klaira, we rely on a small number of trusted third-party providers:

OpenAI

We use OpenAI's API to generate AI responses. Chat messages are transmitted to OpenAI's servers to produce responses. OpenAI's data usage policy applies. We use API access and have opted out of data training where available.

Supabase

We use Supabase for database storage, authentication, and file storage. Your data is stored in Supabase's hosted infrastructure. Data is stored in AWS data centres.

Vercel

Klaira is hosted on Vercel. Web requests, including IP addresses, pass through Vercel's infrastructure. Vercel's privacy policy governs that processing.

By using Klaira, you acknowledge that data may be processed outside Australia by these providers. We take reasonable steps to ensure these providers maintain appropriate data protections.

4. Data Retention

We retain your account data and chat history for as long as your account is active. If you cancel your subscription or request account deletion, we will delete or anonymise your personal data within 90 days, except where we are required to retain it by law (for example, financial records required for tax compliance).

Chat transcripts captured by your chatbot are retained for 12 months by default. You can delete individual conversations or bulk-clear transcripts from within your dashboard at any time.

5. Security

We take reasonable technical and organisational measures to protect your information. These include encryption in transit (TLS/HTTPS), encryption at rest, access controls limiting data access to authorised personnel, and regular security reviews.

No system is completely secure. If we become aware of a data breach that is likely to result in serious harm, we will notify affected users and, where required, the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme.

6. Your Rights under the Australian Privacy Act 1988

Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the right to:

  • Request access to the personal information we hold about you
  • Request correction of inaccurate or outdated information
  • Request deletion of your personal information (subject to legal retention obligations)
  • Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we have not handled your information appropriately

To exercise any of these rights, contact us at hello@klaira.io. We will respond within 30 days.

7. Cookies

We use cookies and similar technologies to maintain your login session and to collect aggregate analytics. We do not use third-party advertising cookies. You can disable cookies in your browser settings, but doing so may prevent some features from working correctly.

8. Changes to This Policy

We may update this policy from time to time. If we make material changes, we will notify you by email or by displaying a prominent notice in the application. The "last updated" date at the top of this page reflects the most recent revision.

9. Contact Us

If you have questions or concerns about this privacy policy or how we handle your personal information, please contact us:

Klaira

Australia

hello@klaira.io