Privacy
What stays on your machine, what leaves it, and what we can and cannot see. Last updated 10 October 2026.
The short version. Your primary workspace files, brains and file index live on your computer. Content leaves your device only when you choose a feature that needs it, such as cloud sync, sharing, collaboration, clipboard sync or cloud AI. A shared space file is encrypted before upload, but its title, invitation-key records, chat messages and live collaboration deltas are not all unreadable to KLYPIX. The iPhone app sends only the items you hand it, the names of spaces you create on it, a short record of the phone that pairing needs and, if you allow notifications, a notification token; it encrypts the item payload on the phone first, and adds keyed word fingerprints so you can search your history without the server reading the words. If you choose Share with AI for a conversation, the phone also publishes a readable, unencrypted copy of it: its notes and links as sent, file names and send times, and descriptions an AI writes of its photos, videos and voice notes, which the phone sends through our relay to Google Gemini.
Who is responsible for this notice
The provider is Abdullah Aldahshan, trading as KLYPIX. Service/postal address: ALSALAM, Riyadh, 1666, Saudi Arabia.
What stays on your machine
Your .klypix files, spaces and embedded items are stored on your own disk. Chat history, memory and settings are stored locally too. We do not receive those local copies merely because they exist; selected content can leave the device when you use cloud sync, sharing, collaboration, cloud AI or another network feature described below.
About the API keys you paste in. They stay on your machine and are never sent to us. Be aware, though, that they are not all protected equally: some are held in Windows’ encrypted store, while others — including the Gemini key — are kept in the app’s ordinary local storage in readable form, so the app can load them instantly. Anyone who can use your Windows account, or who can reach the app’s data folder, could read those. Treat them like any other saved password, and revoke a key from the provider if a machine is lost.
Ask your files runs locally. When you point that feature at a folder, it reads those documents where they sit, builds a search index on your disk, and answers questions using a language model on your machine. The question and retrieved passages stay in that local subsystem. Its model and optional acceleration components must first be downloaded; this local statement does not cover cloud chat, screen understanding, cloud OCR or document generation.
What leaves your machine, and when
AI you ask for. With your own API key, chat, file, space and agent requests normally go directly to your selected provider under that provider's terms. Screen understanding is the exception: screen images are sent through the KLYPIX relay to our managed provider account, require a signed-in account and count toward the included allowance. If you use included AI without your own key, eligible request content also passes through the KLYPIX relay and is processed by our model provider. Using your own key keeps the agent’s requests between you and your provider, but the agent run totals described below still reach us.
Spaces you choose to sync or share. Cloud sync and share links are opt-in, per space. The saved space file is encrypted on your machine before upload. For a link-only share, the saved-file key is carried after the # in the link, which browsers do not send to the server. Space titles, live collaboration edit deltas and messages posted in a space’s chat panel are stored in readable form, so collaborators who join later can read the conversation; chat messages stay until the space is removed from the cloud or the account that wrote them is deleted. Changes you made to a space that someone else owns stay part of that space after you delete your account; they are no longer linked to your account. When you invite a collaborator by email, KLYPIX stores the space’s key so it can be provided to the authorised recipient. These exceptions mean the service as a whole is not described as end-to-end encrypted or unable to read every part of a shared space.
Spaces you connect to ChatGPT or Claude. Private AI copies and saved work, including generated files, are stored in readable form on KLYPIX servers. You choose which spaces an assistant may read and separately whether it may save work, add sources or request AI readings. See connected AI spaces below for what is stored and how access, deletion and retention differ.
Clipboard items you pin, if you turn on sync. Cross-device clipboard sync is off unless you turn it on in Settings. While it is on and you are signed in, each clipboard item you pin is stored on our server in readable form so your other signed-in computers can show it: its text or image, the paths of copied files (not the files themselves) and the name of the app it came from. Unpinned clipboard history is not sent. The app stops showing a synced item after 30 days, but we do not yet delete the server copy automatically, and turning sync off does not remove items already sent. Unpinning an item on the computer where you pinned it does not remove that copy; unpinning it on a computer that received it through sync does. To have them removed, write to the address below or delete your account.
Your account. If you sign in, we hold your email address, display name and plan so the app knows who you are. Sign-in is handled by Supabase.
Two records kept whatever you choose about usage sharing. They are not covered by the product usage choice below: one is kept for your account and the other for each of your computers. We also count them: for example, how many accounts signed in or were active on a given day and which app versions are in use. First, each time you sign in to the Windows app with an email address and password, we note the time on your account. Second, while you are signed in, the Windows app keeps one record for that computer: its Windows computer name, the KLYPIX version, the last time it checked in, and a short identifier of the sync key it holds, never the key itself. That record is what lets your iPhone and klypix.com show your PC by name and tell whether your pairing still works. It stays after you sign out, until you delete your account or ask us to remove it. The iPhone app keeps a similar record for the phone, described below. Our admin view shows these records for an account.
Agent run totals. When you are signed in, each Chat Agent mode run that finishes also sends its totals to your account: the name of the model, the number of input, output and cached tokens, the cost in US dollars the app estimated, and the time. This happens whether you use your own API key or included AI, and whatever you choose about product usage sharing. The reason is the daily agent spending limit in the app’s settings: it checks this total on our servers as well as the one on your computer, so clearing the tally on your computer does not reset it. No prompt, reply, file or tool detail is sent with these totals. They are kept until you delete your account.
Updates. The app checks for new versions, which reveals your IP address to the update host in the ordinary way any download does.
What we can see
We can see that an account exists, its plan, when it was created and last signed in, the device records described above and in the iPhone section, the totals of each finished agent run (model, token counts, estimated cost and time), storage usage, space titles, server-held invitation key records, live collaboration deltas, messages posted in a shared space’s chat panel, the text, images, file paths and source app name of clipboard items you pin while Cross-device clipboard sync is on, request content handled by the KLYPIX AI relay, the readable details of items sent between your phone, klypix.com and your PC (the iPhone section lists them for an item the phone sends; an item your PC sends to the phone carries the same kind of details, with the PC’s computer name as the sending device), the phone’s search fingerprints (also described there), and the limited analytics described below. We can also read the copies you publish with Share with AI (see the iPhone section), and private AI source copies, saved reports and generated files (see connected AI spaces). A saved space blob is ciphertext to us when we do not hold its key, but that protection does not apply to every related metadata, collaboration or AI path. Local files that you do not send through a network feature remain on your device.
Website and product analytics
On the public website, we measure page views and a short, fixed list of actions such as viewing pricing, requesting a download, opening GitHub or Drive, and copying the project-brain install command. We keep the public route, English or Arabic, the page’s audience journey, a broad location such as hero or pricing, a broad device class, a two-letter country estimate, active visible browsing seconds and maximum scroll depth rounded to 0, 25, 50, 75 or 100 percent. Active time stops after 30 seconds without interaction. We also keep a coarse source category such as search, social, referral or direct. If a link uses one of our approved campaign categories, we keep that category; arbitrary campaign values are discarded. We do not store city, region, postal code, coordinates, a full referring address, query string, cursor trail, key values or any text you type.
The site does not set a tracking cookie or persistent visitor identifier. To estimate daily visitors without keeping an IP address or browser string, the server combines those values with the current UTC date and turns them into an identifier using a fixed secret key that we keep private. Because the date is part of what goes in, the same browser gets a different identifier each day. The identifier cannot be turned back into the address or browser string; someone holding that key could only test a guessed address and browser string against it. The original values are used in memory for that operation and are not written to the analytics database or analytics error logs, so the stored identifier cannot on its own follow a browser from one day to the next.
In the desktop product, we ask before collecting product usage: nothing in this paragraph or the next two is sent until you choose Share usage in the first-run prompt, or turn on Share product usage in Settings under Privacy. If you agree, we record a fixed list of milestones, namely the app opening, creating an account, starting a project, opening a space that has something in it and completing project-brain setup, plus the app version and operating-system family. While the KLYPIX window is visible and focused, it also sends a small heartbeat every few minutes so we can count active installations. A minimized window or tray-only process does not send that heartbeat. When you are signed in, the milestones and the heartbeat also update your account’s last-active time. That is how desktop version 1.3.164 and later behave. Versions before 1.3.164 do not fully honour the choice: if you are signed in and have chosen No thanks, or have not answered yet, they record four of those milestones (creating an account, starting a project, opening a space and completing project-brain setup) against your account. Updating to 1.3.164 or later stops this.
For a signed-out installation, the app creates a random installation token and stores it only on that computer. The server transforms it into a one-way pseudonymous key before storage. The admin view can distinguish that installation over time but cannot identify the person using it. If the same installation later signs in, it is linked to that account deterministically; we do not use fingerprinting or probabilistic matching to guess identities across devices.
When you are signed in, each milestone except the heartbeat is also recorded against your account, with controlled labels only: app version, platform, your account type and, for some milestones, where in the app it started and which sign-in method you used. We never put an email, name, IP address, prompt, chat, screenshot, filename, file path, space content or user-written property into the product-analytics dataset. You can turn product usage sharing off in Settings under Privacy. Collection stops immediately, apart from the four milestones that versions before 1.3.164 record as described above, and the app requests deletion of that installation record; if the computer is offline, it retries the deletion on a later connected launch. Milestones already recorded against your account are not removed by that switch; they follow the retention periods below, and you can ask us to delete them.
We use these measurements to understand which pages and product capabilities are useful, improve onboarding, plan capacity, measure the business and prepare aggregate company reporting. Raw events for guest installations are deleted after 90 days; other raw analytics events are deleted after 400 days. We do not sell personal data or event-level records. Aggregate, de-identified business metrics may be used in financing, due diligence or a sale of the business. There is no commercial analytics export today; any future market-insights product would require a separate purpose, legal review, updated disclosures and technical safeguards. Any transfer of personal data as part of a business transaction remains subject to this notice and applicable law.
The public site honors browser Do Not Track and Global Privacy Control signals. You can also make a browser-specific choice here. Depending on where KLYPIX is offered, additional consent choices may be shown before analytics begins.
Analytics preference on this browser
Turning this off stops future public-site analytics events from this browser. Do Not Track and Global Privacy Control are also honored automatically.
The iPhone app
KLYPIX for iPhone is a companion to the Windows app. Its job is to put something from your phone into a space on your PC and, when you choose Share with AI, to publish a readable copy of a conversation for an AI assistant (described below). It sends the photos, files, links and text you hand it, from inside the app or through the iOS share sheet, and no other content from your phone. Alongside each item it sends the routing details and the keyed word fingerprints described below, and when you search it sends the fingerprints of what you typed. When you create a space on the phone, the name you give it is stored with the space in readable form, like any space title. So that pairing works, it also keeps a short record of the phone on our servers: an identifier iOS assigns the app on this phone, the name iOS gives the app for the phone (just “iPhone”), the app version, when the app was last opened and, from app version 1.1, a short identifier of the sync key it holds, never the key itself. If you allow notifications, it also registers a notification token and the app’s language, so we can tell the phone when your PC sends it something; the notification carries none of the item’s content. The phone’s record is also counted in KLYPIX’s own admin statistics, which show how many phones run each app version, and the items you send from the phone are counted there per day and by kind (text, link, photo or file).
Signing in with Google. KLYPIX’s own code never asks iOS for your contacts, your location or your phone number. If you sign in with Google, that step is handled by Google’s sign-in library, which declares its own collection to Apple: your name, email address, phone number, coarse location, account and device identifiers, other usage data and other data types, linked to you and not used for tracking. Google declares most of them as needed for its sign-in to work, the account identifier and the other data types for analytics as well, and the device identifier and the other usage data for analytics only. KLYPIX asks Google for nothing beyond the standard sign-in, and it passes our sign-in service only the identity token Google returns. Apple counts what a bundled library declares as part of the app’s collection, which is why the App Store listing shows those types, including Phone Number and Coarse Location.
Your photo library. When you pick photos or videos, iOS passes the app only the ones you picked and keeps the rest of the library to itself. Last Photo works differently: the first time you tap it, iOS asks whether KLYPIX may access your photos, and you can allow all of them, only the ones you select, or none. If you allow it, each tap reads the newest photo you have let it see and sends it; from app version 1.1 it is named after that photo’s original file name or, when that says nothing, the time it was taken. The app reads nothing else from the library. You can change that permission at any time in the iPhone’s Settings. Saving a photo from KLYPIX to your library asks for add-only access, which lets the app add photos but not see them.
Every item is encrypted on the phone before it is uploaded. The key is your sync key, made on your devices when you paired them — or, for an item you send into a space you have already shared to yourself, that space’s own key. The key stays on your devices. What reaches our servers is a blob we cannot open, plus the details that have to stay readable for it to arrive and be found: which account it belongs to, whether it is text, a link, a photo or a file, which space it is bound for, when it was sent, when it expires, which device sent it, which of your keys sealed it (by a short identifier, never the key), a keyed fingerprint of the item that lets us spot a duplicate, and whether you marked it Keep. So that you can search your history from the phone, the phone also sends keyed fingerprints of words from an item’s text, link title or file name. Never a link’s address (an address typed or pasted inside a note is fingerprinted like the note’s other words), never a number on its own, never a file’s type, and never more than the first sixteen words of a long note, counting only words that are fingerprinted at all: words shorter than three characters, very common words such as “the” and repeated words are skipped, so those sixteen can come from further into the note. The extensions come off the end of a file’s name before anything is fingerprinted, however many it carries; a word in the middle of a dotted name counts as part of the name and is kept. The phone does this from app version 1.1, and only for items sent from 17 September 2026 at 08:40 UTC, when this description first went live; nothing sent before then is fingerprinted. A link gets its fingerprints once the phone has loaded its title, whether the phone or klypix.com sent it. Notes, photos and files sent from klypix.com carry no fingerprints. Search on our servers cannot find those, or anything sent before that time; the app’s own search still looks through the messages the phone has already loaded. The key for those fingerprints is derived on your devices from your sync key, or from that space’s own key, and is never handed to us. Every indexed item carries the same fixed number of fingerprints, padded with unmatchable ones, so the fingerprints do not show how many words it has, although the size of the encrypted item still shows roughly how long or large it is. The server can tell that two fingerprints are equal, which is how a search finds an item, but it cannot turn a fingerprint back into the word. What it can see is the pattern: which of your items share a word, among everything sealed with the same sync key, whichever space it went to, or within one space that has its own key; and, at the moment you search, which fingerprints the search asks for, whether it is limited to one space or to Kept items, and which items it matched. When you search, what you typed is fingerprinted the same way before it leaves the phone. The request is handled like any other and not stored as a search history by us; our hosting provider’s logs may record that a search happened and which of your spaces it looked in. The most a log could hold about the words is the keyed fingerprints, never the words themselves. Because of those logs, the App Store listing declares Search History. For a space you share by email invitation, KLYPIX also holds that space’s key so invited people can open it; items you send to such a space are readable to us in the same way, and they are not indexed for search.
How long it stays there. An item waits on our servers until something removes it. Your PC collecting it marks it delivered, but that alone does not erase it — which is what the settings below are for. Deleting an item in the app removes its record and its encrypted text immediately. For a photo or a file, the encrypted attachment is removed when you delete your account. The automatic sweep that will also clear an attachment once your PC has placed the item, or once the deadline you set below has passed, is not running yet; when it runs it will skip items you marked Keep, whose record and attachment stay until you delete them. Keep is enforced on our servers, so it holds while your PC is off; deleting your account still removes everything.
You set how long, per conversation. Your PC, and each space you send to, has its own pair of settings, and the two work differently. The first covers items your PC has already collected: leave them in your history until you delete them, which is the default, or have them go once your PC has them, or after a day, a week or a month. Your iPhone is what carries that one out, so it happens the next time you open the app rather than on a timer of ours: it deletes those items’ records, and the encrypted text inside them, from our servers, and leaves behind the encrypted attachment of a photo or a file, which goes when you delete your account. The second covers items your PC has not collected yet, and it is a deadline rather than a deletion: once it passes your PC stops collecting the item and it stops counting as waiting, but the item itself is not erased by it. Both dials skip items you have marked Keep. That second deadline is stamped when the item is sent, so changing it never reaches back to what you sent last week; changing the first one does, because it is read fresh against everything your PC has already collected.
Keep, per item. Marking an item Keep tells our servers to hold its record and its encrypted attachment until you delete it, whatever the deadlines above are set to, and while your PC is off. The mark itself is one of the readable routing details.
A space you make on the phone. From app version 1.1.1, what you send into a space you made on your iPhone goes into that space, with no PC involved. The phone seals the card, and the bytes of a photo or a file, with that space’s own key, the same key its link carries, so anyone who can open the space’s link can see what is in it. Besides the routing details above, our servers can read that the phone placed the item in the space, and when; a photo’s or a file’s bytes are stored under the space by a keyed name that does not show the file’s own name. A placed item belongs to its space, not to Keep or the deadlines above: it stays while the space exists. When the space is deleted, its items go with it and nobody can open those bytes any more; the bytes themselves are removed when your account is deleted, and a scheduled cleanup that will remove them sooner is not running yet.
The camera and microphone only run when you open them. The camera is used to scan a pairing or Drive code shown by your PC or in your browser, and to take a photo or video you are sending. The microphone runs while you record a voice note, and for the sound on a video you record. Neither runs in the background, and nothing is captured outside the code scanner, camera or recorder you opened.
Opening a space on the phone. The built-in viewer loads the same page klypix.com serves to a share link. The decryption key travels in the part of the address browsers never send to a server, so the space is put together on the phone out of bytes we still cannot read.
Sharing a conversation with an AI assistant. When you choose Share with AI for a conversation, the phone publishes a readable copy of what was sent to it, so that an assistant you give the link to can read it. This copy is not encrypted. It holds the conversation’s name; your notes and links as you sent them; when each item was sent, in your time zone with its UTC offset, and whether it came from the phone or the PC; the name, size and length of every file; and in place of each photo, video and voice note a description in words. Any other file is listed by its name and size only. The items themselves are not stored in the copy. To write those descriptions the phone sends each photo, a few frames and the sound of each video, and each voice note through the KLYPIX relay to our model provider, Google Gemini, when you share or update. An item that already has its description is not sent again. That use counts toward the included allowance. The phone asks you before the first time. Anyone who has the link can read the copy, and so can we; the assistant’s own provider receives the words it reads, under its terms. Stop sharing deletes the copy’s contents from our servers at once. A record that the link existed (its address, which conversation, your UTC offset, and when it was made and stopped) stays until you delete your account. A copy you do not update stops being readable thirty days after you last created or updated it, and its words are deleted about a week after that.
Deleting your account from the phone. It is at Settings → Delete account, and it is reachable before the phone is paired as well as after. It permanently removes the account, the encrypted spaces stored for it, everything the phone has sent, and — if you signed in with Apple — the link between your Apple ID and KLYPIX, revoked with Apple. The pairing is cleared off the phone at the same time. Files on your PC are untouched; they were never ours to delete. There is no undo.
Screenshots
KLYPIX can capture what is on your screen when you invoke a screen-aware feature. After the required consent, that image passes through the KLYPIX relay to our managed AI provider for the request; it does not go directly under your own API key. The relay therefore handles the image, so it is incorrect to say that screen imagery never reaches KLYPIX infrastructure. You can leave screen features unused and use the on-device Ask your files feature instead.
Spaces connected to ChatGPT, Claude or another AI app
You sign in with KLYPIX and choose which spaces the connected app may access. Permissions to save work, add sources and request new AI readings are separate from reading existing contents. Within the selected spaces, it can retrieve readable source copies and saved work, including work saved by another assistant. What it reads becomes available to that AI provider under its terms. The connection does not receive your KLYPIX password or your space’s encryption key.
Private AI copies. You can publish a prepared copy manually or, where available, enable automatic AI access for a space. Turning it on in the browser also copies the space’s current board, and you can update that board copy when you choose. With your per-space consent, supported phone and web clients copy readable notes, links and decrypted original files and sync later captures. These copies, source details, project structure and saved readings are stored privately on KLYPIX servers. Our service can read them; they are not encrypted with your space’s key. The encrypted originals remain separate and unchanged. We also keep connection records: your account, the connected app, selected spaces, permissions, relevant dates and hashes of connection credentials.
Requested media readings. With reading permission, an assistant can request missing contents. For supported images, audio, video and PDFs, KLYPIX sends selected contents or a supported public-video URL to Google Gemini to prepare a reading. This can reserve and use your KLYPIX AI allowance. We store the reading, its source reference and limitations, job status, model and available token-use and allowance records. A saved link or preview does not mean its video was read; blocked links can require the original file. Plain-text notes can be prepared without a Google request.
Reading on save. If you turn on “Read new items automatically” for a space, KLYPIX prepares readings for new links and files in that space as they are saved, without an assistant asking. The same Google Gemini reading, storage and allowance rules apply, with at most 60 automatic readings per account in 24 hours; a failed reading is not retried automatically. Turning off AI access for the space also turns this off. For some links no AI model is used: KLYPIX asks the platform’s public embed service for the post text or caption (X, TikTok), fetches the text of public web pages from its servers, and extracts the text of Word, Excel and PowerPoint files itself. Those services receive the link, as any visitor would.
Larger files may use a temporary Google Files API upload. KLYPIX attempts to delete that upload when the reading job ends, including on failure. If deletion cannot be completed, Google documents automatic deletion of Files API uploads after 48 hours. This period applies to that temporary upload, not to every record a provider may keep or to readings and work saved in KLYPIX. Google’s processing is subject to its applicable terms.
When permitted, an assistant can save text reports and supported output files to the space’s Saved work. This does not automatically copy your entire AI conversation. We store saved text, actual file contents, filenames, file types, sizes, checksums and records linking the work to its source revision. These outputs are stored privately, separately from encrypted source files. They are readable by our service and are not encrypted with your space’s key.
Your controls have different effects. Revoke access disconnects that assistant without deleting source copies or saved work. Turn off AI access stops automatic sync, removes that space from existing AI connections and removes its readable source copies and saved source readings; private source-file contents are queued for cleanup. Stop publishing also removes the prepared source revisions and blocks connected access. Your encrypted originals and completed Saved work remain. Removing one original phone item removes its current AI source copy, but historical copies, readings and saved reports may still contain its information. Delete result clears the saved report’s text and blocks new downloads of its attached files. These actions cannot recall copies already received by an AI provider or downloaded elsewhere.
A download link already issued can remain usable for up to one minute. Deleted source and output files enter a cleanup queue with a minimum three-hour delay; a scheduled worker removes their stored contents and retries failures. This is not a promise of deletion within three hours. Upload links already issued can remain usable for up to two hours, but revoked access cannot finalize a saved result. Unfinished upload reservations expire after 24 hours and are then queued for cleanup.
Deletion records remain to prevent retries from recreating deleted work. These can include identifiers, dates, source checksums and file metadata such as filenames, types and sizes. They remain until the cloud space is deleted. The separate storage-cleanup record remains until the stored file has been removed. The current AI source copy and completed Saved work have no automatic time-based expiry. We keep a limited history of full-space source copies and prune eligible older copies under storage and revision limits. Exact saved readings and their source records can remain after an older full-space copy is pruned; that does not preserve the entire historical space. Turning off AI access removes those saved source readings, while completed Saved work remains until separately deleted.
العربية — ترجمة قسم المساحات المرتبطة بالذكاء الاصطناعي فقط
تسجّل الدخول بحساب KLYPIX وتختار المساحات التي يُسمح للتطبيق المتصل بالوصول إليها. صلاحيات حفظ الأعمال وإضافة المصادر وطلب قراءات جديدة بالذكاء الاصطناعي منفصلة عن قراءة المحتوى الموجود. يمكنه داخل المساحات المختارة استرجاع نسخ المصادر المقروءة والأعمال المحفوظة، بما فيها أعمال حفظها مساعد آخر. ويصبح ما يقرأه متاحًا لمزوّد ذلك المساعد وفق شروطه. لا يحصل الاتصال على كلمة مرور حسابك في KLYPIX أو مفتاح تشفير المساحة.
النسخ الخاصة للذكاء الاصطناعي. يمكنك نشر نسخة مجهّزة يدويًا، أو تفعيل الوصول التلقائي للذكاء الاصطناعي للمساحة حين تتوفر هذه الميزة. ويؤدي تفعيله من المتصفح أيضًا إلى نسخ اللوحة الحالية للمساحة، ويمكنك تحديث نسخة اللوحة متى شئت. بموافقتك الخاصة بتلك المساحة، تنسخ تطبيقات الهاتف والويب المدعومة الملاحظات والروابط والملفات الأصلية بعد فك تشفيرها، وتزامن العناصر المرسلة لاحقًا. تُحفظ هذه النسخ وتفاصيل المصادر وبنية المشروع والقراءات المحفوظة بشكل خاص على خوادم KLYPIX. يمكن لخدمتنا قراءتها، وهي غير مشفّرة بمفتاح المساحة. تبقى الأصول المشفّرة منفصلة ودون تغيير. ونحتفظ أيضًا بسجلات الاتصال: حسابك، والتطبيق المتصل، والمساحات المختارة، والصلاحيات، والتواريخ المرتبطة بها، وبصمات بيانات اعتماد الاتصال.
قراءة الوسائط عند الطلب. عند منحه صلاحية طلب القراءات، يستطيع المساعد طلب المحتوى الذي لم يُقرأ بعد. للصور والصوت والفيديو وملفات PDF المدعومة، يرسل KLYPIX المحتوى المختار أو رابط فيديو عام مدعوم إلى Google Gemini لإعداد قراءة. قد يحجز ذلك جزءًا من رصيد الذكاء الاصطناعي في KLYPIX ويستهلكه. نخزّن القراءة ومرجع مصدرها وحدودها وحالة الطلب والنموذج، وما يتوفر من سجلات استخدام الرموز والرصيد. حفظ الرابط أو المعاينة لا يعني قراءة الفيديو؛ وقد تتطلب الروابط المحجوبة الملف الأصلي. يمكن تجهيز الملاحظات النصية دون إرسال طلب إلى Google.
القراءة عند الحفظ. إذا فعّلت «اقرأ العناصر الجديدة تلقائيًا» لمساحة ما، يجهّز KLYPIX قراءات للروابط والملفات الجديدة فيها لحظة حفظها، دون أن يطلبها مساعد. تنطبق القواعد نفسها الخاصة بقراءة Google Gemini وتخزينها والرصيد، بحد أقصى ٦٠ قراءة تلقائية للحساب خلال ٢٤ ساعة، ولا تُعاد القراءة الفاشلة تلقائيًا. إيقاف وصول الذكاء الاصطناعي للمساحة يوقف هذا أيضًا. ولبعض الروابط لا يُستخدم أي نموذج ذكاء اصطناعي: يطلب KLYPIX نص المنشور أو التعليق من خدمة التضمين العامة للمنصة (X وTikTok)، ويجلب نص صفحات الويب العامة من خوادمه، ويستخرج نص ملفات Word وExcel وPowerPoint بنفسه. تتلقى تلك الخدمات الرابط كما يتلقاه أي زائر.
قد تُرفع الملفات الأكبر حجمًا مؤقتًا عبر Google Files API. يحاول KLYPIX حذف النسخة المرفوعة عند انتهاء طلب القراءة، بما في ذلك عند فشله. إذا تعذّر إتمام الحذف، فإن وثائق Google تنص على حذف الملفات المرفوعة عبر Files API تلقائيًا بعد 48 ساعة. تخص هذه المدة النسخة المؤقتة المرفوعة، ولا تشمل كل سجل قد يحتفظ به المزوّد أو القراءات والأعمال المحفوظة في KLYPIX. تخضع معالجة Google لشروطها السارية.
عند منحه الصلاحية، يستطيع المساعد حفظ تقارير نصية وملفات مدعومة ضمن «الأعمال المحفوظة» في المساحة. ولا يعني ذلك نسخ محادثتك كاملة تلقائيًا. نخزّن النص المحفوظ ومحتويات الملفات الفعلية وأسماءها وأنواعها وأحجامها وبصماتها، وسجلات تربط العمل بإصدار مصادره. تُحفظ هذه المخرجات بشكل خاص ومنفصل عن ملفات المصادر المشفّرة. ويمكن لخدمتنا قراءتها، وهي غير مشفّرة بمفتاح المساحة.
لكل خيار أثر مختلف. «إلغاء الوصول» يفصل ذلك المساعد من دون حذف نسخ المصادر أو الأعمال المحفوظة. «إيقاف وصول الذكاء الاصطناعي» يوقف المزامنة التلقائية، ويزيل المساحة من الاتصالات الحالية، ويحذف نسخ مصادرها المقروءة وقراءات المصادر المحفوظة، ويضع محتويات ملفات المصادر الخاصة في قائمة الحذف المؤجّل. كذلك يزيل «إيقاف النشر» إصدارات المصادر المجهّزة ويمنع الوصول المتصل. تبقى أصولك المشفّرة والأعمال المحفوظة المكتملة. إزالة عنصر أصلي واحد من الهاتف تزيل نسخته الحالية المخصّصة للذكاء الاصطناعي، لكن قد تبقى معلوماته في نسخ تاريخية أو قراءات أو تقارير محفوظة. «حذف النتيجة» يمحو نص التقرير المحفوظ ويمنع إصدار روابط تنزيل جديدة لملفاته المرفقة. ولا تسترجع هذه الإجراءات نسخًا سبق أن تلقّاها مزوّد الذكاء الاصطناعي أو نُزّلت في مكان آخر.
قد يبقى رابط تنزيل صدر سابقًا صالحًا لمدة تصل إلى دقيقة. تُدرج ملفات المصادر والمخرجات المحذوفة في قائمة تنظيف مع مهلة انتظار لا تقل عن ثلاث ساعات؛ وتزيل مهمة مجدولة محتوياتها المخزّنة وتعيد المحاولة عند الفشل. وهذا ليس وعدًا بإتمام الحذف خلال ثلاث ساعات. وقد تبقى روابط الرفع الصادرة سابقًا صالحة لمدة تصل إلى ساعتين، لكن إلغاء الوصول يمنع إتمام حفظ النتيجة. تنتهي طلبات الرفع غير المكتملة بعد 24 ساعة، ثم تُدرج للتنظيف.
تبقى سجلات الحذف لمنع إعادة إنشاء الأعمال المحذوفة عند تكرار الطلبات. وقد تشمل المعرّفات والتواريخ وبصمات المصادر وبيانات الملفات، مثل أسمائها وأنواعها وأحجامها. تبقى هذه السجلات إلى أن تُحذف المساحة السحابية. ويبقى سجل تنظيف التخزين المنفصل إلى أن يُزال الملف المخزّن. لا تنتهي صلاحية النسخة الحالية لمصادر الذكاء الاصطناعي والأعمال المحفوظة المكتملة تلقائيًا لمجرد مرور الوقت. نحتفظ بسجل محدود من النسخ الكاملة لمصادر المساحة، ونزيل النسخ الأقدم المؤهلة للحذف وفق حدود التخزين وعدد الإصدارات. قد تبقى القراءات المحفوظة نفسها وسجلات مصادرها بعد حذف نسخة كاملة قديمة؛ وهذا لا يحفظ المساحة التاريخية بأكملها. إيقاف وصول الذكاء الاصطناعي يحذف قراءات المصادر المحفوظة هذه، فيما تبقى الأعمال المحفوظة المكتملة إلى أن تُحذف بشكل منفصل.
klypix-mcp and the KLYPIX Claude plugin
This section describes the local developer program and its Claude Code plugin. Hosted AI connections are described separately above.
klypix-mcp is the free, open-source program that lets an AI tool such as Claude Code read and add to your project brain and spaces. The KLYPIX Claude plugin is the same program, packaged for Claude. It runs on your computer. It has no account and sends no telemetry: we receive nothing from it.
What it keeps, and where. Your brain and spaces are ordinary files: the brain is a file in your project folder, and spaces are kept in your project or in the folder you point it at. It also keeps coordination state on your computer, in your home folder: which AI sessions are active, the notes those sessions leave for each other, a list of the projects that have a brain, and restore points for each brain. None of this is uploaded.
Its only network use. Installing it downloads the package from the npm registry. Outside plugin mode, it also asks the npm registry from time to time whether a newer version exists, an anonymous request that carries nothing about you or your projects beyond the IP address any download reveals, and installs a newer release when it finds one; setting KLYPIX_AUTO_UPDATE=0 turns both off. In plugin mode it does neither: the only other request is a one-off npm view when you ask brain_doctor to check npm. If you turn on its optional on-device semantic search, it downloads that model from Hugging Face; searching still happens on your computer.
What your AI provider receives. What Claude, or another AI tool, reads through klypix-mcp’s tools, such as cards, notes and file names, becomes part of your conversation with that AI and is sent to its provider, under that provider’s terms.
Your choices
You can use local workspace capabilities without an account, and some capabilities work offline after any required models or resources have been downloaded. Account access, sync, sharing, collaboration, cloud AI, screen understanding, updates and downloads require an internet connection. You can keep your .klypix files and export a saved space to Markdown or JSON Canvas, but those exports are not lossless and some item types or asset relationships may not map exactly. You can delete your account from the iPhone app, at Settings → Delete account: that removes your profile, the encrypted blobs stored for it, and everything your phone has sent. The Windows app has no delete button of its own yet; until it does, write to the email address below and we will do it for you.
Children
KLYPIX is not intended for children under 13, and we do not knowingly collect their data.
Changes
If this notice changes materially, the date above changes with it. We will not quietly widen what we collect.
Contact
Questions, requests to access or delete your data, or anything else: privacy@klypix.com. Provider: Abdullah Aldahshan, trading as KLYPIX. Service/postal address: ALSALAM, Riyadh, 1666, Saudi Arabia.
Service/postal address: ALSALAM, Riyadh, 1666, Saudi Arabia