Klorn processes mailbox contents, which is about as personal as work data gets. This page is the short, practical version: what role we play, what we hold, and how to make us act on your rights. The binding detail is in the privacy policy.
| Question | Answer |
|---|---|
| Who is the controller? | For an individual account, Klorn. If your employer deployed Klorn for you, they are the controller and Klorn is the processor |
| What is processed | Account details, Google OAuth tokens, Gmail metadata and content, calendar events, and the classifications and summaries derived from them |
| Why | To perform the service you asked for — sorting mail, showing the reason, and preparing actions you approve |
| Where it is stored | Database in Seoul (Supabase, ap-northeast-2); API in Singapore (Render); web app on Vercel's edge |
| Automated decision-making | Classification into lanes is automated. It has no legal or similarly significant effect: it changes how loudly a message reaches you, and you can move any message to another lane |
| Training on your mail | No. Your mail is not used to train models. Corrections tune your own account's behaviour |
| Retention | Operational logs are swept on a fixed schedule — 30, 90 or 180 days depending on the table. Account deletion removes the account data |
Access, rectification, erasure, restriction, portability and objection: email k0820086@gmail.com from the address on the account. Klorn is a small product with a single maintainer, so requests are handled by a person rather than a portal — expect a reply within days, not minutes.
You can revoke Klorn's access to your mailbox at any time and without asking us, from your Google account permissions. That cuts off future sync immediately.
What this page is not. It is a plain-language summary written by the maintainer, not legal advice and not a substitute for the privacy policy. Where the two differ, the privacy policy governs. If you need a signed data processing agreement, see DPA.