KLYPIX

Privacy

What stays on your machine, what leaves it, and what we can and cannot see. Last updated 13 August 2026.

The short version. Your primary workspace files, brains and file index live on your computer. Content leaves your device only when you choose a feature that needs it, such as cloud sync, sharing, collaboration or cloud AI. A shared canvas file is encrypted before upload, but its title, invitation-key records and live collaboration deltas are not all unreadable to KLYPIX. The iPhone app sends only what you hand it and encrypts the item payload on the phone first.

Who is responsible for this notice

The provider is Abdullah Aldahshan, trading as KLYPIX. Service/postal address: ALSALAM, Riyadh, 1666, Saudi Arabia.

What stays on your machine

Your .klypix files, canvases and embedded items are stored on your own disk. Chat history, memory and settings are stored locally too. We do not receive those local copies merely because they exist; selected content can leave the device when you use cloud sync, sharing, collaboration, cloud AI or another network feature described below.

About the API keys you paste in. They stay on your machine and are never sent to us. Be aware, though, that they are not all protected equally: some are held in Windows’ encrypted store, while others — including the Gemini key — are kept in the app’s ordinary local storage in readable form, so the app can load them instantly. Anyone who can use your Windows account, or who can reach the app’s data folder, could read those. Treat them like any other saved password, and revoke a key from the provider if a machine is lost.

Ask your files runs locally. When you point that feature at a folder, it reads those documents where they sit, builds a search index on your disk, and answers questions using a language model on your machine. The question and retrieved passages stay in that local subsystem. Its model and optional acceleration components must first be downloaded; this local statement does not cover cloud chat, screen understanding, cloud OCR or document generation.

What leaves your machine, and when

AI you ask for. With your own API key, chat, file, canvas and agent requests normally go directly to your selected provider under that provider's terms. Screen understanding is the exception: screen images are sent through the KLYPIX relay to our managed provider account, require a signed-in account and count toward the included allowance. If you use included AI without your own key, eligible request content also passes through the KLYPIX relay and is processed by our model provider.

Canvases you choose to sync or share. Cloud sync and share links are opt-in, per canvas. The saved canvas file is encrypted on your machine before upload. For a link-only share, the saved-file key is carried after the # in the link, which browsers do not send to the server. Canvas titles and live collaboration edit deltas are stored in readable form. When you invite a collaborator by email, KLYPIX stores the canvas key so it can be provided to the authorised recipient. These exceptions mean the service as a whole is not described as end-to-end encrypted or unable to read every part of a shared canvas.

Your account. If you sign in, we hold your email address, display name and plan so the app knows who you are. Sign-in is handled by Supabase.

Updates. The app checks for new versions, which reveals your IP address to the update host in the ordinary way any download does.

What we can see

We can see that an account exists, its plan, storage usage, canvas titles, server-held invitation key records, live collaboration deltas, request content handled by the KLYPIX AI relay, and the limited analytics described below. A saved canvas blob is ciphertext to us when we do not hold its key, but that protection does not apply to every related metadata, collaboration or AI path. Local files that you do not send through a network feature remain on your device.

Website and product analytics

On the public website, we measure page views and a short, fixed list of actions such as viewing pricing, requesting a download, opening GitHub or Drive, and copying the project-brain install command. We keep the public route, English or Arabic, the page’s audience journey, a broad location such as hero or pricing, a broad device class, a two-letter country estimate, active visible browsing seconds and maximum scroll depth rounded to 0, 25, 50, 75 or 100 percent. Active time stops after 30 seconds without interaction. We also keep a coarse source category such as search, social, referral or direct. If a link uses one of our approved campaign categories, we keep that category; arbitrary campaign values are discarded. We do not store city, region, postal code, coordinates, a full referring address, query string, cursor trail, key values or any text you type.

The site does not set a tracking cookie or persistent visitor identifier. To estimate daily visitors without keeping an IP address or browser string, the server turns those values into a one-way identifier using a secret that rotates by date. The original values are used in memory for that operation and are not written to the analytics database or analytics error logs. The identifier cannot follow a browser from one day to the next.

In the desktop product, we ask before collecting product usage. If you agree, we record a fixed list of milestones such as the app opening, opening a populated canvas, starting a project or completing project-brain setup, plus the app version and operating-system family. While the KLYPIX window is visible and focused, it sends a small heartbeat so we can count active installations. A minimized window or tray-only process does not send that heartbeat.

For a signed-out installation, the app creates a random installation token and stores it only on that computer. The server transforms it into a one-way pseudonymous key before storage. The admin view can distinguish that installation over time but cannot identify the person using it. If the same installation later signs in, it is linked to that account deterministically; we do not use fingerprinting or probabilistic matching to guess identities across devices.

Product events may include controlled labels such as app version, platform, plan and whether an allowed action succeeded. We never put an email, name, IP address, prompt, chat, screenshot, filename, file path, canvas content or user-written property into the product-analytics dataset. You can turn product usage sharing off in Settings under Privacy. Collection stops immediately and the app requests deletion of that installation record; if the computer is offline, it retries the deletion on a later connected launch.

We use these measurements to understand which pages and product capabilities are useful, improve onboarding, plan capacity, measure the business and prepare aggregate company reporting. Raw events for guest installations are deleted after 90 days; other raw analytics events are deleted after 400 days. We do not sell personal data or event-level records. Aggregate, de-identified business metrics may be used in financing, due diligence or a sale of the business. There is no commercial analytics export today; any future market-insights product would require a separate purpose, legal review, updated disclosures and technical safeguards. Any transfer of personal data as part of a business transaction remains subject to this notice and applicable law.

The public site honors browser Do Not Track and Global Privacy Control signals. You can also make a browser-specific choice here. Depending on where KLYPIX is offered, additional consent choices may be shown before analytics begins.

Analytics preference on this browser

Turning this off stops future public-site analytics events from this browser. Do Not Track and Global Privacy Control are also honored automatically.

The iPhone app

KLYPIX for iPhone is a companion to the Windows app, and it does one thing: it puts something from your phone onto a canvas on your PC. It sends the photos, files, links and text you hand it — from inside the app, or through the iOS share sheet — and nothing else. It has no access to your photo library, your contacts or your location. When you pick a photo, iOS passes the app that one photo and keeps the rest of the library to itself.

Every item is encrypted on the phone before it is uploaded. The key is the one your phone received when you paired it with your PC — or, for an item you send into a canvas you have already shared to yourself, that canvas’s own key. Neither is ever handed to us. What reaches our servers is a blob we cannot open, plus the routing details that have to stay readable for it to arrive: which account it belongs to, whether it is text, a link, a photo or a file, which canvas it is bound for, and when it was sent. Not the contents, and not the file name — those are inside the encrypted part.

How long it stays there. An item waits on our servers until something removes it. Your PC collecting it marks it delivered, but that alone does not erase it — which is what the settings below are for. Deleting an item in the app removes its record and its encrypted text immediately; for a photo or a file, the encrypted attachment is swept when the item expires or when you delete your account.

You set how long, per conversation. Your PC, and each canvas you send to, has its own pair of settings. The first covers items your PC has already collected: keep them forever, which is the default, or remove them the moment they land, or after a day, a week or a month. The second covers items your PC has not collected yet: follow the window your PC sets, expire after a day, a week or a month, or wait indefinitely. The expiry is stamped when the item is sent, so changing a setting never reaches back and deletes what you sent last week.

The camera and microphone only run when you open them. The camera is used to scan your PC’s pairing code, and to take a photo or video you are sending. The microphone runs while you record a voice note, and for the sound on a video you record. Neither runs in the background, and nothing is captured outside the picker or the recorder you opened.

Opening a canvas on the phone. The built-in viewer loads the same page klypix.com serves to a share link. The decryption key travels in the part of the address browsers never send to a server, so the canvas is put together on the phone out of bytes we still cannot read.

Deleting your account from the phone. It is at Settings → Delete account, and it is reachable before the phone is paired as well as after. It permanently removes the account, the encrypted canvases stored for it, everything the phone has sent, and — if you signed in with Apple — the link between your Apple ID and KLYPIX, revoked with Apple. The pairing is cleared off the phone at the same time. Files on your PC are untouched; they were never ours to delete. There is no undo.

Screenshots

KLYPIX can capture what is on your screen when you invoke a screen-aware feature. After the required consent, that image passes through the KLYPIX relay to our managed AI provider for the request; it does not go directly under your own API key. The relay therefore handles the image, so it is incorrect to say that screen imagery never reaches KLYPIX infrastructure. You can leave screen features unused and use the on-device Ask your files feature instead.

Your choices

You can use local workspace capabilities without an account, and some capabilities work offline after any required models or resources have been downloaded. Account access, sync, sharing, collaboration, cloud AI, screen understanding, updates and downloads require an internet connection. You can keep your .klypix files and export a saved canvas to Markdown or JSON Canvas, but those exports are not lossless and some item types or asset relationships may not map exactly. You can delete your account from the iPhone app, at Settings → Delete account: that removes your profile, the encrypted blobs stored for it, and everything your phone has sent. The Windows app has no delete button of its own yet; until it does, write to the email address below and we will do it for you.

Children

KLYPIX is not intended for children under 13, and we do not knowingly collect their data.

Changes

If this notice changes materially, the date above changes with it. We will not quietly widen what we collect.

Contact

Questions, requests to access or delete your data, or anything else: privacy@klypix.com. Provider: Abdullah Aldahshan, trading as KLYPIX. Service/postal address: ALSALAM, Riyadh, 1666, Saudi Arabia.

Service/postal address: ALSALAM, Riyadh, 1666, Saudi Arabia

← klypix.com