Legal
Privacy
What we hold, who else sees it, how long it stays and how to get rid of it. Written to be checked rather than skimmed: everything here corresponds to something in the code, and where we are unsure we say so.
Who holds it
Klarion Technologies, Inc., a corporation incorporated in Delaware, United States, is the data controller. Write to [email protected] about anything on this page.
We have not yet appointed a representative in the EU or the UK. If it turns out we need one, this page will name them.
The free edition sends nothing
Klarion Free has no account, no licence file and no activation. There is no telemetry and no usage counter, in any edition. We do not know you are running it, and there is nothing on our side that could tell us.
The one request Klarion can make on its own is the update check, and it is off until you turn it on. Not off-by-default in the sense of a dialogue you dismiss: the application refuses to check until an answer has been recorded, and no answer counts as no. When it does run it is one GET carrying the version you are running and nothing else, and we do not log it. You can also ask once, by hand, without changing the setting.
Your analysis never reaches us
Not the names of the binaries you open, not their hashes, not their contents, not your notes, not your project files. Klarion makes no network request while analysing anything. This is a property of how the application is built rather than a promise about how we behave: there is no code in it that could send us those things.
What we hold if you have an account
Your email address. It is the account. Sign-in is a one-time link sent to it, so there is no password — nothing for you to remember and nothing for us to leak. A display name and company, if you enter them.
Your licence. The key, which edition, how many seats, when it was issued and until when updates are covered.
One record per activated machine. A fingerprint, a name, the platform, the version of Klarion running there, and when it last checked in. Seat counting is the only reason any of it exists.
A record of changes to your seats. Which machine was activated or released, and when. It is how a dispute about seats gets settled, and it cannot be edited by us or by you.
The fingerprint is a hash, not an inventory
It is computed on your machine from the identifier your operating system generated when it was installed — Windows’ MachineGuid, systemd’s machine-id, macOS’s IOPlatformUUID — and what leaves your machine is the hash. Thirty-five characters, starting k1-.
We never see the input. It is not built from serial numbers, MAC addresses or a list of your components, and we cannot turn it back into a description of your hardware. A domain separator is mixed in, which means our fingerprint for your machine does not match anybody else’s fingerprint for the same machine.
What it can do is say two activations are the same machine. That makes it personal data and we treat it as such.
The machine name, and how to stop sending it
Klarion sends your machine’s host name at activation, so that your account page can show you which machine holds which seat in terms you recognise. On a company laptop a host name is often somebody’s actual name, so this is the one field the application sends that can identify a person.
It is useful and it is personal data, both. So: it is sent by default, you can rename or remove it on your account page at any time, and you can stop it being sent at all by setting KLARION_NO_HOSTNAME=1 before activating. Activation works either way; the seat simply shows as an unnamed machine.
What we deliberately do not collect
No analytics, on any page. No advertising, no tracking pixels, no third-party scripts of any kind — the site’s content security policy will not load one, which you can check in your browser’s network tab.
Downloads are counted without being attributed. One row per completed download, with the build and the time, and at most the host somebody arrived from — never a full URL. No IP address, no user agent, no cookie, no identifier. The consequence is real and we accept it: we can tell you how many downloads there were and we genuinely cannot tell you how many people that was.
We never see your card. It is entered on Stripe’s own page and never touches anything of ours.
Cookies: one, and only after you sign in
This site sets no cookies at all until you sign in. Not on the home page, not on the download page, not on the sign-in page itself. Signing in sets one session cookie, which is what keeps you signed in. That is the entire list.
So there is no cookie banner. Not as an oversight — a banner asking permission for a cookie that needs none is a dialogue with one honest answer, and putting one on a site sold to people who are professionally suspicious of exactly that would be the wrong thing to do. If we ever add something that genuinely needs consent, you will get a real choice rather than a wall to click through.
Who else sees it
Five companies, each doing one job. Stripe takes the payment and holds the billing record. Supabase hosts the database and the sign-in system. AgentMail delivers your sign-in links and your licence email. Cloudflare sits in front of the site and therefore sees every request to it. IONOS hosts the server.
All five are in or route through the United States. We do not sell data to anybody, we do not share it for advertising, and there is no sixth.
Server logs
The web server records the address every request came from, which is personal data. It is kept for fourteen days and then deleted, and it exists so that an attack on the server can be investigated. It is not indexed by account and is not used to build any picture of anyone.
The one exception is the endpoint Klarion asks for the latest version. Requests to it are not logged at all — the web server is configured to write nothing for that path, and the address is stripped before the application sees it. It is called by a tool installed on your analysis machine, where the address is the only thing a request could reveal about you, so the honest thing to do with it is not to keep it.
How long we keep things
Nothing is kept forever. Your account and licence stay for as long as you have them. A seat you released is stripped of its fingerprint and machine name after eighteen months. The record of seat changes goes after two years, download counts after two years, and payment webhook records after ninety days. An account that never bought anything and has not signed in for two years is deleted outright — if you asked for a sign-in link once and never came back, we will not still be holding your email address in 2028.
Getting a copy of everything
There is a button on your account page that hands you a JSON file with all of it: your account record, your licences, every machine, your billing history read live from Stripe, and the log of changes to your seats.
It also lists what we looked for and do not have, which is the part of an answer like this that is usually missing. No waiting, and no need to ask us.
Deleting your account, and what that costs
The same page has a delete button. It removes your email address, your profile, and every fingerprint and machine name we hold. You confirm by typing your email address, because it cannot be undone.
It also revokes your licences. We would rather say that here than have you find out afterwards. Once the account is gone there is no way to move a seat to a new machine, and continuing to count seats would mean continuing to hold the fingerprints you just asked us to delete. If you want your data deleted but your licence kept working, write to us first and we will talk about it rather than making that decision for you.
Two things survive, and both are deliberate. Our record that a payment produced a particular licence key on a particular day stays, with your name off it, for as long as tax law requires — deleting it would not remove anything from Stripe, it would only make our books unreconcilable. And the log of seat changes stays, with your identity removed from it, because it is a security record and the person it records should not be able to erase it.
A licence file already on your machines keeps working until it expires or that machine next reaches us. We have no way to reach into an offline installation, which is the same limitation that applies to us as to anybody else.
Your other rights
You can have anything we hold corrected, ask us to stop or limit a particular use, or object to it. Machine names you can change yourself; for anything else write to [email protected] and we will answer within a month. If you are in the EU or the UK you can also complain to your national data protection authority, and you do not have to come to us first.
What is not settled
This page describes what the software does, and every claim on it was checked against the code. The legal side is less finished: our lawful basis for each of these uses is drafted but not yet reviewed, the agreements with the five companies above are not all in place, and whether we need a representative in the EU is a question we have asked and not yet answered.
We would rather write that down than imply a completeness we have not reached. Nothing on this page is legal advice, and where it describes behaviour it is accurate; where it would describe a legal conclusion, it says this instead.
Changes
If we change how any of this works we will change this page, and if the change matters we will email account holders rather than relying on you to re-read it. Last updated 31 August 2026.