Privacy Policy
Last updated July 19, 2026
klk is a private, invite-only app for sharing photos and video inside small groups, which the app calls klks. This policy describes what the app collects, why, who can see it, and — just as importantly — what we can still see ourselves.
The honest version, up front. Everything you post is visible only to the members of the klk you posted it to. That is enforced by server-side security rules, not by convention. It is not end-to-end encrypted today, which means klk's operator has the technical ability to access content stored on its servers. So the accurate claim right now is "only your klk can see it" — not "not even we can see it." End-to-end encryption is planned; until it ships, this paragraph stands.
What we collect
Account information
- Email address and password. Used only to sign you in. Your password is handled by Firebase Authentication and is never visible to us. Your email is not shown to other users anywhere in the app and is not part of your visible profile.
- Display name and profile photo, if you set one. Visible to people who share a klk with you.
- A user id generated at sign-up, used to attach your content and klk memberships to you.
Content you share
- Photos and video you post as Posts, Moments or Clips, together with captions, comments, likes, and — for Moments — who has viewed them.
- Which klks you belong to, who created each klk, its name and its colour.
- Media is uploaded as you selected it. We do not strip embedded metadata such as EXIF location from photos, so assume that anything your camera recorded travels with the photo to the other members of that klk.
Device and diagnostic information
- A push notification token for each device you sign in on, so klk can tell you about activity in your klks. It is readable only by you.
- Crash and error reports, sent to Sentry when the app fails. These include the error, technical details of the device and app version, and your user id, email address and display name so a report can be tied back to an affected account.
What we do not collect
- No advertising identifiers, and no advertising of any kind.
- No behavioural analytics or usage tracking product is installed in the app.
- No contacts, no address book access, no location permission.
- No data is sold, rented, or shared with third parties for their own purposes.
Who can see what
- Other members of a klk can see everything posted to that klk, and can see your display name and profile photo.
- People you share no klk with cannot see your content and cannot see your profile at all — they cannot search for you, mention you, or find that your account exists.
- The public sees nothing. klk has no public profiles, no explore feed, and no web-visible content.
- We can technically access content stored on the servers, as described above. We access it only where necessary to operate the service, to investigate a specific abuse or safety report, or where legally required.
How invites work
Joining a klk is only possible through an invite link created by a member. Each link is a single-use, unguessable, expiring token, and it is redeemed on the server — the app cannot add anyone to a klk on its own. Anyone who created invites can revoke every unused link at once. There is no directory to browse and no way to request access to a klk you were not invited to.
Service providers
We use a small number of processors, and only for the purposes listed:
- Google Firebase (Authentication, Firestore, Cloud Storage, Cloud Functions) — hosts accounts, content and media. Data is stored on Google Cloud infrastructure in the United States.
- Expo — delivers push notifications to your device.
- Sentry — receives crash and error reports.
Retention and deletion
Content stays until it is deleted. You can delete your own posts, moments, clips and comments at any time, and deleting one removes its media from storage. Leaving a klk removes your access to it; content you already posted there remains visible to that klk unless you delete it first.
To delete your account and everything attached to it, email privacy@klkapp.com from the address on the account. We will delete your account, profile, push tokens and the content you posted, and remove you from your klks. Backups may retain copies for up to 30 days before they age out.
Children
klk is not directed at children under 13, and we do not knowingly create accounts for them. Parents commonly share photos of their own children inside a family klk; that content belongs to the adult who posted it and is governed by this policy. If you believe a child under 13 has created an account, contact us and we will remove it.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal information, and to object to certain processing. Email privacy@klkapp.com and we will action it. We do not discriminate against anyone for exercising these rights.
Security
Content is transmitted over TLS and access is restricted by server-side security rules that check klk membership on every read and write. No system is perfect; we will notify affected users of a breach that puts their content at risk.
Changes
If this policy changes materially — in particular if what we collect changes, or when end-to-end encryption ships and the callout at the top of this page no longer applies — the date at the top will change and the app will tell you.