Privacy policy

Last updated August 17, 2026

1. Who is responsible for what

Klibon is the data controller for account data — your email, your profile, your programs and your statements.

For visitors to a merchant's website, the relationship is different. The _klb cookie is a first-party cookie set on the merchant's own domain, on pages the merchant serves. The merchant is the controller for it and is responsible for declaring it in their cookie notice and obtaining consent where consent is required. Klibon acts as their processor for that data.

2. What we collect

From account holders

  • Email address, and a display name if you provide one.
  • Sign-in sessions (a session token, its expiry, the IP and user agent that created it).
  • Payment details you enter as free text so merchants can pay you. We never process them.
  • Subscription state mirrored from Creem. We never see or store card details.

From visitors who click a tracked link

  • The referral code, the destination, and the time of the click.
  • A salted hash of the IP address and of the user agent — never the values themselves. They are used to deduplicate repeated clicks and flag fraud, and cannot be reversed back to an IP address.
  • The referring page and the country derived from the request.

From payment processors

  • Payment amount, currency, type (sale, renewal, refund) and a customer identifier.
  • A salted hash of the customer's email address, used to detect self-referral. We do not store the address itself.

3. Cookies we set on klibon.com

  • A session cookie, so you stay signed in. Strictly necessary.
  • A short-lived cookie remembering where you were headed before signing in.
  • A short-lived cookie carrying an Uneed product identifier, when you arrive through "Continue with Uneed", so we can pre-fill your product.

We use OpenPanel for privacy-friendly analytics on our own site. It sets no advertising cookies and builds no cross-site profile.

4. Who we share with

  • Merchants — an affiliate's profile and payment details, when a statement is due.
  • Creem — our merchant of record for subscription billing.
  • Sequenzy — transactional email delivery.
  • Supabase — database hosting, in the European Union.
  • Cloudflare and our hosting provider — serving the application.

We do not sell personal data, and we do not share it for advertising.

5. How long we keep it

Account data is kept while your account exists, then deleted within 30 days of a deletion request — except records we must retain for accounting purposes. Click records are kept for 24 months; the hashes they contain are not reversible in any case. Raw payment events are kept for the life of the program so commissions can be audited and recomputed.

6. Your rights

If you are in the EU, UK or a jurisdiction with comparable law, you may request access to your data, its correction, its deletion, or a portable copy, and you may object to processing. Write to [email protected] — we respond within 30 days. You also have the right to complain to your local supervisory authority.

7. Security

Payment-processor credentials are encrypted at rest with AES-256-GCM. Personal identifiers used only for comparison are stored as salted hashes. Traffic is served over TLS. Access to the production database is limited to the operator.

8. Contact

Questions about this policy: [email protected].