Klavity Snap & Klavity Cloud · Last updated 21 August 2026
Klavity ("we", "us") is built by Quantana. Klavity Snap is a browser
extension and web service that lets AI personas ("Sims") review web pages and file bug and
feature tickets to your issue tracker. This policy explains what we collect, why, who we share
it with, and the controls you have. It covers the browser extension and the Klavity Cloud
backend at klavity.in.
What we collect
Data
Why
Account email
To sign you in (one-time email code; no password) and associate your tickets and workspace.
Page screenshots — a screenshot of the visible area of a page (not the full page, not other tabs)
So Sims can see and react to the page, and so a bug report carries visual context.
Page context — the page URL path (query strings and fragments are dropped), a structural signature of the page, and the title
To attribute feedback to the right page and avoid re-reviewing an unchanged view.
Diagnostic context — for a manual bug report: browser and screen info, and the most recent console and network errors on the page
To make the ticket actionable for your engineers.
Integration credentials — API tokens for the tracker you connect (Jira, Linear, GitHub, Plane) or a webhook
To file tickets on your behalf. Stored encrypted at rest (AES-GCM) and never returned to the browser.
When we collect it — capture is consent-gated
Sims review a page only after you consent. For pages your workspace monitors, each member confirms once before their first capture; for the "Analyze this page" action, you confirm once per website.
Automatic review happens only on URLs your workspace has explicitly allow-listed, or on a page you explicitly choose with "Analyze this page".
A manual bug/feature report is captured only when you open the reporter and submit it.
We never capture other tabs, background pages, or pages you have not consented to.
How we use it
To generate Sim feedback, the screenshot and page context are sent to a large-language-model provider (OpenRouter, currently routing to Google Gemini models) for processing. This is automated; the output becomes the ticket you see.
When a ticket is filed or "copied to" an external destination, the relevant ticket content is sent to the tracker you configured (Jira, Linear, GitHub, Plane, or your webhook).
We use aggregate, non-identifying usage and cost metrics to operate and improve the service. We do not sell your data, and we do not use your page content to train third-party models.
Legal bases for processing (GDPR Art. 6)
Where the GDPR applies, we rely on the following lawful bases to process personal data:
Contract — to provide the service you sign up for: authenticating you, capturing the pages you consent to, generating Sim feedback, and filing tickets to your tracker.
Legitimate interests — to secure, operate, debug and improve Klavity using aggregate, non-identifying usage and cost metrics, where those interests are not overridden by your rights.
Consent — for page capture (which is consent-gated before the first capture) and for non-essential analytics on our marketing site (see our Cookie Notice). You can withdraw consent at any time.
Legal obligation — where we must retain or disclose data to comply with the law.
Where a customer uses Klavity to process the personal data of their own end users, the customer is
the controller and Quantana acts as processor on their documented
instructions under our Data Processing Addendum.
Who processes your data (sub-processors)
OpenRouter — LLM routing/inference for Sim reviews (currently routing to Google Gemini).
Object storage (S3-compatible) — private storage of screenshots.
Turso (libSQL) — application database (accounts, tickets, settings); hosted in the Mumbai region (aws-ap-south-1).
SendGrid — transactional email and one-time login codes (OTP).
Your configured issue tracker — receives the tickets you file (Jira, Linear, GitHub, Plane, or your webhook).
The full, current sub-processor list, including purposes and locations, is maintained in
Annex III of our Data Processing Addendum. Analytics tools used only
on our marketing site are listed in the Cookie Notice.
International transfers
Klavity is operated from Australia, and some of our sub-processors are based elsewhere. Your data may
therefore be processed in the United States (OpenRouter, Google, PostHog) and
India (our application database, hosted in the Mumbai region). Some of these countries
are not the subject of an "adequacy decision" under the GDPR. Where we transfer personal data out of the
EEA or the UK to a country without adequacy, we rely on appropriate safeguards —
principally the European Commission's Standard Contractual Clauses (and the UK
International Data Transfer Addendum for UK transfers) — as reflected in our
Data Processing Addendum.
Retention
Screenshots are stored privately and expire automatically 30 days after capture.
Tickets and account data are retained for as long as your workspace is active, until you delete them or close your account.
You can delete your account and all associated data yourself at any time from Dashboard → Settings → Your data & privacy, or ask us to do it (see Contact).
Security
All traffic is encrypted in transit (HTTPS).
Integration secrets are encrypted at rest with AES-GCM and are redacted from any response sent to the browser.
Screenshots are stored with private access and served only via short-lived signed links to authorized workspace members.
Your controls
Consent is required before the first capture on any page or website.
Pause Sims on a page from the in-page indicator at any time.
Global switch — turn automatic reviews off entirely from the extension's Options page.
Sign out from the popup to clear your local session.
Download my data — export a machine-readable JSON copy of your account, memberships and reports from Dashboard → Settings → Your data & privacy (GDPR Art. 15 and 20).
Delete my account — permanently erase your account, reports and screenshots from the same Settings section (GDPR Art. 17). Deletion is immediate and irreversible.
You can also request access, correction, or deletion by contacting us (see Contact).
Your rights under the GDPR
If the GDPR (or UK GDPR) applies to you, you have the following rights over your personal data. You
can exercise the export and deletion rights yourself from Dashboard → Settings → Your
data & privacy, or exercise any of them by contacting us (see Contact):
Access — obtain confirmation of, and a copy of, the personal data we hold about you (Art. 15).
Rectification — have inaccurate or incomplete personal data corrected (Art. 16).
Erasure — have your personal data deleted where there is no overriding reason to keep it (Art. 17).
Restriction — ask us to limit how we process your data, for example while a dispute is resolved (Art. 18).
Portability — receive a machine-readable copy of your data, or have it transferred, where processing is based on consent or contract (Art. 20).
Objection — object to processing based on our legitimate interests (Art. 21).
Withdraw consent — where we rely on your consent, withdraw it at any time, without affecting processing already carried out.
Lodge a complaint — complain to a data-protection supervisory authority in your country of residence or work if you are unhappy with how we handle your data. We would appreciate the chance to address your concern first (see Contact).
Children
Klavity is a tool for software teams and is not directed to children under 13. We do not knowingly collect data from children.
Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected by the
"Last updated" date above and, where appropriate, communicated in-product.