1. Introduction
This Privacy Policy explains how Kleeping ("we") collects, uses, and protects your information ("you", "user") when you use the Kleeping app. By using Kleeping, you agree to the practices described on this page.
Kleeping is available for Android and iOS. This policy will be updated as new features ship, and any significant change will be communicated before it takes effect.
2. Data We Collect
We collect as little data as possible — only what's genuinely needed to make the app's core features work:
- Account data. For anonymous accounts, we store a unique device identity generated automatically by Firebase Authentication (no personal information involved). If you choose to sign in with Google, we store the email address, display name, and profile photo provided by Google.
- Your saved link data. The original URL, title, thumbnail image, source platform (e.g. Instagram, Shopee), the binders you create, and the pinned/hidden status of each link you save.
- Technical data. A device notification token (if you allow notifications), activity timestamps (when a link was saved/changed), and standard technical logs used for error diagnostics.
- Secure Folder. If you enable this feature, we store a one-way hash of your secret passphrase — never the passphrase itself — so not even our own team can read it.
We do not read the content of pages you save (e.g. private captions or messages), and we don't collect contacts, precise location, or browsing history beyond what you actively share to Kleeping.
3. How We Use Your Data
Data we collect is used solely to run and improve the Kleeping service, specifically to:
- Store, display, and manage your links, binders, and account settings.
- Automatically fetch the title and thumbnail image for the links you save.
- Keep your account secure, including detecting suspicious activity (e.g. repeated Secure Folder passphrase attempts).
- Send notifications related to your account activity (this feature is still in development).
- Fix bugs and improve app performance through anonymous technical logs.
We don't use your data for third-party advertising, and we never sell your personal data to anyone.
4. Sharing Data with Third Parties
We work with trusted service providers to run Kleeping. Each of them only receives the data genuinely needed to perform its function:
- Firebase Authentication (Google) — handles sign-in (both anonymous and Google Sign-In) and identity verification for every request to our server.
- Cloudflare R2 — stores a copy of the thumbnail images for the links you save, so they can load quickly inside the app.
- Server hosting provider — runs Kleeping's backend server where your account and link data is stored.
We don't share your personal data with advertisers, data brokers, or any other third party for commercial purposes. Data may only be disclosed where required by applicable Indonesian law.
5. Data Storage & Retention
Your data is kept for as long as your account stays active. If you choose to delete your account, we apply a 30-day grace period — during this window, your data isn't permanently removed yet, and the deletion can be undone simply by signing back in with the same account. After 30 days, the data is permanently deleted from our systems and can no longer be recovered.
Individual links you delete (without deleting the whole account) follow a similar mechanism: they're moved to an internal "trash" rather than being deleted immediately.
6. Data Security
We apply a number of technical safeguards to protect your data, including: server-side verification of identity tokens on every request (never trusting a raw identity sent from the device), storing your Secure Folder passphrase as a one-way hash, and automatic progressive lockouts when repeated failed passphrase attempts are detected.
That said, no system is completely risk-free. We encourage you not to share your Secure Folder passphrase with anyone, and to contact us right away if you suspect unauthorized activity on your account.
7. Your Rights
As a user, you have the right to:
- Access the data stored in your account directly through the app.
- Delete individual links, binders, or your entire account at any time.
- Export your data in CSV format (data export is a Premium feature).
- Withdraw consent by discontinuing use of the app and deleting your account.
These rights are consistent with Indonesia's Law No. 27 of 2022 on Personal Data Protection (UU PDP). For any data-related request you can't complete on your own inside the app, contact us using the details at the bottom of this page.
8. Anonymous vs. Signed-In Accounts
Important to understand: anonymous accounts are tied to a specific device and app install — if the app is uninstalled, that account's data cannot be recovered on any device, including by the Kleeping team itself. This is a technical limitation of how anonymous accounts work, not a policy that can be relaxed on request.
If you want your data to be recoverable or synced across devices, use the sign-in-with-Google option inside the app.
9. Children's Privacy
Kleeping is not directed at children under the age of 13, and we do not knowingly collect personal data from children under that age. If you're a parent or guardian and believe a child under this age has provided personal data to us, please contact us so we can act on it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time, especially as Kleeping's feature set grows. Significant changes will be communicated through the app or this page before they take effect. The "last updated" date at the top of this page always reflects the current version.
11. Contact Us
Have a question about privacy, or want to submit a data-related request? Send us an email — we'll respond as quickly as we can.
Kleeping