KKlykBack to Klyk

Privacy Policy

Last updated July 10, 2026

This Privacy Notice for Afillix LLC ("we", "us", "our"), a Wyoming limited liability company at 75 E 3rd St, Sheridan, WY 82801, United States, describes how and why we collect, store, use, and share your personal information when you use Klyk (the "Services"), including the web application at klykit.io, the CLI, and related APIs. Questions or concerns? Reading this notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use the Services. Contact: [email protected].

Summary of key points

  • We collect the personal information you give us (account email, OAuth profile name, billing plan) and the test content you create.
  • Credentials you store for scenarios are encrypted at rest and used only to run your tests.
  • We do not sell personal information, we do not use it for advertising, and we run no advertising trackers.
  • We use analytics (Google Analytics and PostHog, the latter hosted in the EU) to understand how the Services are used and to improve them.
  • We share data only with the service providers that run Klyk: cloud hosting and storage, Stripe for payments, transactional email delivery, and the analytics providers above.
  • You can access, correct, or delete your data at any time; contact us or use the in-app controls.

1. What information do we collect?

Personal information you disclose to us.

  • Account data. Your email address and, if you sign in with a third-party provider (Google or GitHub), the name and email address that provider shares with us. Klyk has no passwords of its own.
  • Test content. The scenarios you write, the URLs they target, environments you configure, and any sign-in details you choose to store. Stored credentials are encrypted at rest and used only to authenticate runs of your scenarios.
  • Payment data. Payments are processed by Stripe, Inc. We store your plan, subscription status, and usage; your full card details never touch our systems. Stripe's handling of your data is governed by its own privacy notice.

Information automatically collected.

  • Run artifacts. Screenshots, video recordings, console and network logs, and reports produced by running your scenarios against your application. These may contain personal information present in the application you test; you are responsible for what your test environments expose.
  • Technical data. A session token kept in your browser to keep you signed in, and standard server logs (IP address, timestamps, requested endpoints) used for security and operations.

We do not collect sensitive categories of personal information and we do not purchase data from third parties.

2. How do we process your information?

  • to provide the Services: executing your scenarios, storing and showing results, and operating schedules;
  • to manage accounts: sign-in codes, session management, and support;
  • to send transactional communications: sign-in codes, run-failure alerts, quota and billing notices (these are service messages, not marketing);
  • to bill subscriptions and metered usage through Stripe;
  • to secure the Services: abuse prevention, rate limiting, and incident investigation; and
  • to comply with legal obligations.

3. What legal bases do we rely on to process your information?

If you are in the European Economic Area, the United Kingdom, or Switzerland, we process your personal information on these bases: performance of a contract (operating the Services you signed up for), legitimate interests (securing and improving the Services in ways that do not override your rights), legal obligations (tax, accounting, lawful requests), and consent where we ask for it, which you may withdraw at any time.

4. When and with whom do we share your personal information?

We share personal information only with:

  • Service providers that run Klyk under contract with us: cloud infrastructure and storage providers that host the Services and your artifacts, Stripe for payment processing, email delivery providers for transactional mail, and analytics providers (Google Analytics; PostHog, hosted in the EU) that measure how the Services are used. Each processes data only to provide its service to us.
  • Business transfers. In connection with a merger, sale of company assets, financing, or acquisition of all or part of our business, your information may be transferred as part of that transaction.
  • Legal requirements. Where disclosure is required to comply with law, legal process, or enforceable governmental request, or to protect the rights, property, or safety of Afillix, our users, or the public.

We do not sell or rent personal information, and we do not share it for cross-context behavioral advertising.

5. What is our stance on third-party websites?

The Services let you run tests against web applications you choose. Those applications, and any third-party sites linked from the Services, are not operated by us, and we are not responsible for their content or privacy practices. Data your own application exposes during a test appears in your run artifacts under your control.

6. Do we use cookies and other tracking technologies?

For the Services to function we store a session token in your browser to keep you signed in, plus short-lived state used during sign-in flows. We also use analytics to understand how the Services are used: Google Analytics (cookies) and PostHog (browser local storage; data processed on EU servers). These measure page views and product usage tied to your account id; we run no advertising trackers. Stripe's hosted checkout and portal pages set their own cookies under Stripe's policies.

7. How do we handle your social logins?

If you sign in with Google or GitHub, we receive the profile information that provider makes available (typically your name and email address). We use it only to create and operate your account. What the provider itself collects is governed by its own privacy notice; we recommend reviewing it.

8. Is your information transferred internationally?

The Services are operated from the United States with infrastructure in the United States and the European Union. If you access the Services from other regions, your information will be transferred to, stored, and processed in those locations. Where European data protection law applies to a transfer, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses with our service providers.

9. How long do we keep your information?

We keep personal information only as long as necessary for the purposes set out in this notice. Account data is kept while your account is active. Scenarios and run artifacts are kept so you can review your test history and are deleted when you delete them or close your account, on a reasonable schedule. Billing records are retained as required by tax and accounting law. Server logs are rotated on a short schedule.

10. How do we keep your information safe?

We use organizational and technical security measures appropriate to the data we process: encryption in transit (TLS), encryption at rest for stored sign-in details (envelope encryption with a managed key service, or a local master key in self-managed deployments), credential scrubbing in traces and logs, screenshots skipped on password entry during runs, per-account data isolation, and least-privilege access. However, no electronic transmission or storage technology can be guaranteed 100% secure, so we cannot promise that unauthorized third parties will never defeat our security; you transmit personal information at your own risk.

11. Do we collect information from minors?

We do not knowingly solicit data from or market to anyone under 18 years of age. By using the Services, you represent that you are at least 18. If we learn that data from a user under 18 has been collected, we will deactivate the account and take reasonable measures to promptly delete it. If you become aware of any such data we may have collected, contact us at [email protected].

12. What are your privacy rights?

Depending on where you live, you may have the right to request access to, correction of, or deletion of your personal information; to object to or restrict our processing; to data portability; and to withdraw consent where processing is based on consent (withdrawal does not affect processing before withdrawal). You can exercise account-level controls directly in the app, and any of these rights by contacting us (section 16). We respond to verifiable requests within the timeframes required by applicable law.

If you are in the EEA, the UK, or Switzerland and believe we are processing your personal information unlawfully, you also have the right to complain to your local data protection supervisory authority.

13. Controls for do-not-track features

Most browsers include a Do-Not-Track ("DNT") feature. No uniform technology standard for recognizing DNT signals has been finalized, and we do not currently respond to them. We run no advertising trackers; the analytics described in section 6 operate the same regardless of a DNT signal.

14. Do United States residents have specific privacy rights?

If you are a resident of California, Colorado, Connecticut, Texas, Utah, Virginia, or another US state with a comprehensive privacy law, you may have specific rights regarding your personal information: the right to know what we collect and how it is used and shared, the right to access and obtain a copy, the right to correct inaccuracies, the right to delete, and the right to non-discrimination for exercising your rights.

In the preceding twelve months we have collected the categories of personal information described in section 1 (identifiers such as email address and name; commercial information such as plan and usage; internet activity limited to service logs; and user-provided test content). We collect it for the purposes in section 2, share it only as described in section 4, and retain it as described in section 9. We do not sell or share personal information as those terms are defined by the California Consumer Privacy Act, and we have not done so in the preceding twelve months. We do not use or disclose sensitive personal information for purposes requiring a right to limit under the CCPA.

To exercise these rights, contact us as described in section 16. You may use an authorized agent; we will require proof of the agent's authorization and verification of your identity. If we decline a request, you may appeal by replying to our decision; if your appeal is denied, you may contact your state attorney general.

15. Do we make updates to this notice?

Yes, we will update this notice as necessary to stay compliant with relevant laws. The updated version will be indicated by the "Last updated" date at the top. If we make material changes, we will notify account holders by email or by a prominent notice in the Services before the changes take effect.

16. How can you contact us about this notice?

If you have questions or comments about this notice, or wish to exercise your rights, email us at [email protected] or write to:

Afillix LLC
75 E 3rd St
Sheridan, WY 82801, United States

17. How can you review, update, or delete the data we collect from you?

You can review and update account details and delete scenarios, runs, and stored credentials directly in the app. To request a copy of your personal information, ask for corrections we cannot make in-app, or request full deletion of your account and data, contact us at [email protected]. We will act on verifiable requests within the timeframes required by applicable law.