Privacy & Security
Trust should be understandable.
Here is the plain-language version of what Klabbo keeps, what it does not do with your information, and where the limits are. No vague “trust us” language.
What Klabbo is designed to remember
Klabbo remembers information when you choose to create, select, or save it so it can be useful in a later related experience. In Dine, that can include preferences, avoidances, familiar choices, restaurant-specific experiences, and helpful notes. In Health, that can include preparation items, questions, medications or other notes you choose to enter, and previous preparation you choose to bring forward.
What Klabbo does not do with your continuity
We do not sell your saved continuity data. We do not use it for targeted advertising. We do not use your saved experiences, preparation notes, preferences, or avoidances to train a Klabbo AI model. Klabbo is designed to use that information for you, inside the experiences you choose.
Can people at Klabbo read my information?
Klabbo does not routinely monitor or review user-created continuity. Access controls are designed so users access their own information. Because Klabbo operates the service and uses cloud infrastructure, limited authorized technical access may still be possible when necessary for security, support, legal obligations, or service operation. We will not tell users “nobody at Klabbo can ever see your data” unless the architecture makes that literally true.
How is it protected?
Klabbo uses encrypted network connections, authentication and account-level authorization, provider encryption at rest where applicable, least-privilege access practices, and server-side gateways for private service credentials. Supabase provides the database and authentication foundation; Cloudflare Workers are used as protected gateways for selected services; Google services support authorized calendar access and menu image reading; and ElevenLabs provides Klabbo’s generated voice. The exact internal configuration is intentionally not published.
What happens when I use menu reading?
A menu image you choose may be sent to Google Cloud Vision so text can be extracted for the menu-reading feature. Google states that content sent to the online Vision API is used to provide the service, is not used to train Cloud Vision, and for immediate-response operations the image data is processed in memory rather than persisted to disk. Klabbo then uses the returned menu information to support the experience you requested.
What happens when Klabbo speaks?
Text needed to generate a spoken response is sent through Klabbo’s protected voice gateway to ElevenLabs. ElevenLabs offers account-level controls over whether submitted data may be used to improve its models. Klabbo does not claim provider-level “no training” unless the Klabbo account is configured and verified for that setting. Before broad public release, Klabbo should keep the provider setting aligned with the privacy promise published here.
Does Klabbo store my Google Calendar?
Klabbo Health can read limited upcoming event information after you authorize Google access so it can help identify an appointment. Connecting the calendar is optional. Klabbo does not need permission to create, edit, or delete your calendar events for the current Health experience.
Is Klabbo Health HIPAA-covered?
Not automatically. Klabbo Health is currently a consumer preparation and continuity tool. It is not a healthcare provider, does not diagnose or recommend treatment, and does not claim that every Health interaction is covered by HIPAA. HIPAA status depends on the parties, data, and role involved. We will not use “HIPAA compliant” as a marketing label unless the applicable service and agreements actually support that statement.
Can I delete my data?
Yes. Users can remove user-created information through available Klabbo controls and can request account or personal-data deletion through support@klabboexp.com. Deleted information may remain temporarily in backups, security records, or records required by law before aging out, but it is not retained there for ordinary product use.
What if Klabbo closes?
If the service is permanently discontinued, Klabbo intends to provide reasonable notice when practical and a way to delete or retrieve user-controlled information where supported. Remaining personal information would be deleted or de-identified when no longer required, subject to legal, security, and backup obligations.
Who is responsible for security?
Klabbo LLC is responsible for the security of the Klabbo service. We use specialist infrastructure providers, but responsibility for choosing, configuring, restricting, and monitoring those services remains with Klabbo. Security concerns can be reported to support@klabboexp.com.
Who founded Klabbo?
Klabbo is privately developed and operated by Klabbo LLC in Wisconsin. During the private Founding Experience Program, the public website is intentionally focused on the product rather than publishing a founder biography. Qualified investors and partners should receive founder, ownership, capitalization, and financing information directly as part of diligence. Public founder disclosure can be added when it serves Klabbo’s next stage.
How does “continuity” work?
At a high level, Klabbo connects user-chosen information to a bounded real-world experience, keeps that information associated with the user, and can bring relevant prior information forward when a related situation returns. The user decides what to keep, what to remove, and what to bring forward. Klabbo is not presented as a general chatbot, note-taking service, medical decision system, or autonomous assistant. We publish the product behavior, not security-sensitive implementation details.
