Privacy at kloo
Privacy Policy
kloo exists to preserve engineering intent, not to turn project context or personal information into an advertising product. This policy explains the information we need to operate kloo and the choices available to you.
1. Scope and who we are
This Privacy Policy describes how Daedalus Embedded, Inc. (“Daedalus,” “kloo,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information when you visit usekloo.com, request early access, create or use a kloo account, communicate with us, or otherwise interact with the kloo platform and related services (collectively, the “Services”).
Daedalus Embedded, Inc. is a Delaware corporation with its principal mailing address at 427 South Cummings Avenue, Glassboro, NJ 08028, United States. For questions about this policy or our privacy practices, contact [email protected].
This policy applies to personal information about individuals. It does not convert engineering files, project artifacts, or other non-personal technical information into personal information unless that information identifies or can reasonably be linked to an individual.
2. Information we collect
Information you provide
- Early-access and contact information. Your name, email address, professional role, project context, and the contents of messages you send us.
- Account information. Contact details and identifiers associated with your account. Authentication credentials and authentication events are handled through Clerk; we do not receive your plaintext password.
- Profile and organization information. Your display name, organization, team membership, role, preferences, and permissions when those features are available.
- Project and collaboration information. Engineering intent, decisions, comments, project names, artifact metadata, integration references, and other material you choose to place in the Services. Project content may sometimes contain personal information, such as an engineer’s name, work email, authorship, or revision history.
- Support and feedback. Information you provide when requesting assistance, reporting an issue, participating in research, or suggesting improvements.
- Transaction information. If paid features are offered, Stripe will process payment-card information. We may receive billing contact details, subscription status, transaction identifiers, and limited payment-related records, but we do not intend to store full payment-card numbers.
Information collected automatically
When you use the Services, we and our infrastructure providers may automatically process technical information such as IP address, browser and device type, operating system, approximate location derived from IP address, request timestamps, pages or features accessed, referring URLs, diagnostic information, and security or authentication events. Cloudflare may process request and security logs when delivering the site, and Clerk uses information necessary to authenticate users and maintain sessions.
Information from connected services
If you connect a repository, cloud drive, engineering tool, AI provider, or other third-party service, we may receive account identifiers, permissions, artifact metadata, and content that you direct the service to provide. The information available to kloo depends on the permissions you grant and the connected service’s practices. You should only connect accounts and content you are authorized to use.
3. How we use information
We use personal information to:
- respond to early-access requests and communicate about availability;
- create, authenticate, administer, and secure accounts and organizations;
- provide project organization, intent capture, artifact presentation, handoff, collaboration, and related functionality;
- follow your instructions concerning connected tools and services;
- provide support and respond to questions or feedback;
- maintain, troubleshoot, test, and improve the Services;
- detect fraud, abuse, security incidents, and violations of our Terms;
- administer subscriptions and transactions if paid features are offered; and
- comply with law, enforce agreements, and protect the rights, safety, and integrity of users, Daedalus, and others.
We do not currently use personal information for third-party behavioral advertising, and we do not use project content for advertising. We do not use project content to train general-purpose AI models unless you expressly opt in to a separate program. We do not make decisions that produce legal or similarly significant effects about individuals solely through automated processing.
Legal bases for EEA and UK users
Where European or UK data-protection law applies, we process personal information under one or more of these legal bases:
- Contract. Processing necessary to provide the Services you request and administer your account.
- Legitimate interests. Operating, securing, improving, and communicating about the Services, provided those interests are not overridden by your rights.
- Consent. Where we ask for a specific, freely given choice, including for non-essential cookies or certain communications if introduced.
- Legal obligation. Processing necessary to comply with applicable law or valid legal process.
6. Retention
We retain personal information for as long as reasonably necessary for the purposes described in this policy, including to provide an account or requested service, maintain security and business records, comply with law, resolve disputes, and enforce agreements. The period depends on the nature of the information, the sensitivity and risk associated with it, your relationship with us, and applicable legal requirements.
When information is no longer reasonably necessary, we will delete or de-identify it, subject to limited retention in backups, security records, transaction records, or legal archives. You may ask us to delete your account or personal information as described below. Connected services may retain copies under their own policies.
7. Security
We use administrative, technical, and organizational safeguards intended to protect personal information. No system, transmission, or storage method can be guaranteed completely secure, however. You are responsible for maintaining the security of your account, using appropriate authentication methods, and promptly notifying us if you suspect unauthorized access.
During early access, the Services are not designed for classified information, export-controlled technical data, regulated health or financial data, or other information requiring specialized contractual or regulatory controls. Please review the Terms of Service before submitting project content.
8. Your choices and privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of your personal information; receive a portable copy; withdraw consent; or appeal a decision concerning a privacy request. You may also have the right to complain to a data-protection authority.
To exercise a privacy right, email [email protected]. We may need to verify your identity and authority before completing a request. We will not discriminate against you for exercising a privacy right. Authorized agents may submit requests where permitted by law, subject to verification.
You may opt out of non-transactional marketing emails using the unsubscribe method in the message or by contacting us. We may still send account, security, service, or legal notices.
9. International users and transfers
Daedalus is based in the United States, and the Services may be operated from or supported in the United States and other countries. As a result, personal information may be transferred to and processed in countries whose laws differ from those where you live.
Where required, we use recognized safeguards for international transfers, such as contractual protections, adequacy decisions, or other lawful transfer mechanisms. EEA and UK users may contact us for more information about safeguards relevant to their information and may lodge a complaint with their local supervisory authority.
10. Younger users
The Services are not directed to children under 16, and we do not knowingly collect personal information from anyone under 16. If you believe a person under 16 has provided personal information, contact us so we can take appropriate action.
Users who are 16 or 17 may use the Services only with the authorization of a parent, legal guardian, school, or other organization where required by applicable law and our Terms.
11. Changes to this policy
We may update this policy as the Services, vendors, or legal requirements change. We will post the revised policy here with a new effective date and provide additional notice when required. Material changes will apply prospectively unless the law permits otherwise.
12. Contact us
Questions, requests, and concerns about privacy may be sent to:
Daedalus Embedded, Inc.Attn: Privacy
427 South Cummings Avenue
Glassboro, NJ 08028
United States
[email protected]