Privacy Policy
Last updated: 17 September 2026
This page explains what personal information Klaudius collects, how we use it, and who we share it with. We aim to keep this straightforward and to collect as little personal data as possible.
Who we are
Klaudius is operated by Cloudbot Limited, a company registered in England and Wales. Throughout this page, “we”, “us”, and “our” refer to that company. “You” refers to anyone who visits our website or buys our product.
For privacy questions, contact us at hello@klaudius.dev.
What we collect
Information you give us
- Email correspondence: when you email us, we receive your email address and the contents of your message.
- Purchase information: when you buy a Klaudius licence, you provide payment information to our merchant of record (Lemon Squeezy), not directly to us. Lemon Squeezy passes us your name and email address as part of order fulfilment.
Information collected automatically
- Server logs: standard web server logs (IP address, timestamp, page accessed, user agent) are kept for 30 days for security and abuse-prevention purposes.
- Licence key validation requests: when the Klaudius CLI or desktop app validates a licence key against our servers, or the desktop app checks for updates, we may record the request (licence key, timestamp, IP address) for fraud detection.
- Desktop app usage data and diagnostic reports: see The Klaudius desktop app below.
klaudius.dev uses PostHog for analytics, which stores a first-party cookie in your browser so it can recognise repeat visits. See “Who we share it with” below.
How we use it
We use the information we collect to:
- Fulfil your order and provide support
- Validate licence keys and detect fraudulent use
- Find and fix problems in Klaudius, and improve it
- Communicate with you about your purchase, updates, and support inquiries
- Comply with legal obligations
We do not sell your personal data.
Who we share it with
We share personal information only with the following processors, and only as necessary to operate the service:
- Lemon Squeezy: our merchant of record. Lemon Squeezy processes payments, handles tax calculation, and sends receipts. We share your email and billing address with Lemon Squeezy at checkout. Lemon Squeezy never shares your card details with us.
- Resend: sends transactional emails (purchase confirmations, licence-key delivery). We share your email address and the email content with Resend.
- Supabase: hosts the database where licence records are stored.
- Vercel: hosts klaudius.dev and stores diagnostic reports sent from the Klaudius desktop app.
- Fastmail: operates our email infrastructure.
- PostHog: provides product analytics for klaudius.dev. We collect anonymous pageviews, click events, and session recordings of how visitors interact with the page. PostHog’s default masking obscures input, textarea, and password fields so keystrokes and entered values are not captured. PostHog also receives usage data from the Klaudius desktop app, described below. Data is hosted in PostHog’s EU region.
How long we keep it
- Licence key records: kept for the lifetime of your licence
- Support emails: kept for 24 months from the last interaction
- Server logs: 30 days
- Desktop app diagnostic reports: 90 days
- Website analytics and desktop app usage data: one year, which is PostHog’s standard retention period for our plan
Data you process when running Klaudius
Klaudius is installed locally and runs from your own machine. When you run it, the pipeline gathers information about businesses you’ve chosen to target — their public contact details, photos, and other publicly available data — and uses that to build websites and send outreach. This data never reaches our servers. Every credential the wizard collects is written to your local .env file, and the pipeline uses those credentials directly against each provider from your machine.
In data-protection terms, this means you are the data controller for the data you process through Klaudius. We are not a processor for that flow. If a recipient of your outreach exercises rights under UK GDPR, EU GDPR, or any equivalent regime — access, correction, deletion, objection — those requests are directed to you, not to Klaudius.
The Klaudius desktop app
The Klaudius desktop app runs on your own computer. Your conversations with your AI agent, your clients’ details, your credentials, and the websites Klaudius builds stay on your machine or go straight to the services you have connected, such as your AI provider, your database, and your hosting. None of that is sent to us. The app does send us two kinds of information, described below.
Usage data
By default, the app sends us usage events. They record things like: the app being opened, a run or setup step starting, finishing, or failing and how long it took, an update being found or installed, an error happening, the app having closed unexpectedly or one of its processes stopping, how many leads a search returned, and your database being unreachable. Each event includes the app version and your operating system. Error events include a short error message, with anything that could identify you, your clients or your accounts removed before it leaves your computer: file paths, web addresses, internet host names, email addresses, phone numbers, and long codes. A hosting provider’s address keeps only the provider, never your project’s name. A name that appears inside an error message, such as a business name, can still get through. Usage events never include your prompts, your messages, what Klaudius writes, your clients’ details, or your credentials.
Events carry two pseudonymous IDs, linked to each other: one made from a one-way hash of your licence key (a random ID stands in before you have entered one), and a random ID that stays the same for as long as the app is installed, so we can connect an error to a support request if you contact us. They are stored with PostHog in its EU region. As with any request over the internet, PostHog sees the IP address the data is sent from. We rely on our legitimate interest in keeping the app working and improving it. You can turn usage data off at any time in the app’s Settings.
If you also switch on “Share pipeline totals” in Settings (off by default), the app sends daily counts, such as how many businesses you are tracking and how many sites are live. These are numbers only, never names.
Diagnostic reports
There are three kinds of diagnostic report:
- Automatic run reports are on by default. The app tells you about them the first time you use it, with a button to turn them off, and you can change this at any time with “Send run reports automatically” in Settings. After each run, the report lists which tools ran, whether they worked, and how long they took. It also includes any error messages and the app’s log lines from around that run, with anything that could identify you, your clients or your accounts removed before they leave your computer: file paths, web addresses, internet host names, email addresses, phone numbers, and long codes. Of a tool’s error output, only its first line, the line that names the cause, and the exit code are kept. A name that appears inside an error message, such as a business name, can still get through. Automatic reports never include your prompts, your messages, or what Klaudius writes.
- Automatic crash reports. If one of the app’s processes stops, it sends a crash report straight away; if the whole app closes unexpectedly, it sends one on the next start. The report holds the app’s own log lines from around the crash, treated the same way as a run report, plus what stopped: for a process, which part of the app it was, why it went and its exit code; for an unexpected close, which run was in flight at the time — the name of the command, never what it was working on — and how long the app had been open. It never includes a conversation. Crash reports are controlled by the same “Send run reports automatically” switch, and are not shown to you first.
- Problem reports you send yourself, including the one the app offers after a run fails. The full report is shown to you before you send it. It includes recent lines from the app’s own log, and it can include the conversation from the run you are reporting.
Every report includes the app version and your operating system, with your computer’s user folder name removed. Reports are stored with Vercel, our hosting provider, at an unlisted and unguessable web address, filed under a hash of your licence key rather than the key itself. Only we read them, and only to find and fix problems. We delete them after 90 days.
For automatic run and crash reports, we rely on our legitimate interest in finding and fixing faults in the app. You can object at any time by turning them off in Settings. For problem reports you send yourself, we rely on your consent, which you give by pressing Send. You can ask us to delete any report you have sent by emailing hello@klaudius.dev.
Your rights
Under UK GDPR, you have the right to:
- Request a copy of the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data (subject to legal retention obligations)
- Object to or restrict our processing of your data
- Receive your data in a portable format
To exercise any of these rights, email us at hello@klaudius.dev.
Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top will reflect the most recent change. Substantial changes will be communicated by email to active customers.
Complaints
If you are unhappy with how we handle your data, you have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk.