Privacy Policy – Klara

Last updated: 28 August 2026

1. Introduction

This Privacy Policy explains how we process personal data when you use the Klara language-learning application, our website and related services.

Klara provides personalised language-learning services using text, audio and video/avatar interactions as well as artificial intelligence. Depending on the functions you use, different categories of personal data may be processed.

We process personal data in accordance with the General Data Protection Regulation („GDPR“), the German Federal Data Protection Act („BDSG“) and, where applicable, other relevant data protection laws.

2. Controller

The controller responsible for the processing of personal data is:

Klara Cognitive Learning GmbH
Im Geyer 4
35781 Weilburg
Germany

E-mail: jf@klaracl.com
Legal Notice: https://klara-cl.com/impressum/

3. Categories of Personal Data We Process

Depending on how you use Klara, we may process the following categories of personal data.

Account and profile data

  • username;
  • email address;
  • login and authentication data;
  • hashed password data;
  • internal/backend user ID;
  • profile image;
  • age-range information;
  • gender information;
  • app language;
  • learning language;
  • language and learning preferences.

Learning data

  • current learning level;
  • CEFR-related progress and scores;
  • learning progress and activity;
  • information derived from previous learning interactions;
  • information used to personalise future learning sessions;
  • cross-session learning notes and memory summaries.

Conversation data

  • text messages entered in chat;
  • AI-generated responses;
  • conversation history;
  • written transcripts generated from spoken conversations;
  • summarised information derived from previous conversations;
  • audio streams transmitted during spoken conversations;
  • information required for avatar and video interaction.

Subscription and access data

  • subscription and access status;
  • product or subscription information;
  • transaction-related identifiers supplied by Apple or Google;
  • renewal or expiry information;
  • organisation-provided access or activation codes;
  • validity and activation status.

We do not directly store complete credit card numbers, bank account details or comparable payment credentials used for Apple App Store or Google Play purchases.

Marketing, analytics and attribution data

  • backend user ID;
  • age range and gender, where consented;
  • app and learning language;
  • registration, login, trial-start and subscription events;
  • referral, promotional, influencer or campaign identifiers;
  • installation and attribution information;
  • technical identifiers used for campaign measurement.

Technical data

  • IP address;
  • device type;
  • operating system;
  • app version;
  • timestamps;
  • installation or session identifiers;
  • backend user ID;
  • crash stack traces;
  • error, diagnostic and log information;
  • technical application state.

4. Purposes of Processing

We process personal data for the following purposes:

  • creating and administering user accounts;
  • authenticating users;
  • providing the Klara language-learning service;
  • conducting text, audio and avatar/video conversations;
  • generating AI-based responses;
  • creating written transcripts of spoken interactions;
  • assessing and tracking learning progress;
  • adapting conversations to the learner’s language level;
  • providing continuity between learning sessions;
  • personalising the learning experience;
  • administering free trial access, subscriptions and organisation-provided access;
  • providing customer support;
  • maintaining security and preventing misuse;
  • identifying technical errors and improving application stability;
  • analysing use of the application and marketing effectiveness;
  • attributing registrations, trials and subscriptions to campaigns or referrals;
  • fulfilling legal and contractual obligations.

5. Legal Bases for Processing

Performance of a Contract – Article 6(1)(b) GDPR

We process personal data where this is necessary to provide the Klara services requested by you, including registration, authentication, language-learning functions, text/audio/video conversations, AI processing, transcription, learning progress, CEFR information, personalisation, cross-session continuity and access administration.

Consent – Article 6(1)(a) GDPR

Where legally required, we ask for your consent, in particular for certain analytics functions, marketing analytics, attribution technologies, device identifiers and optional device permissions. Age range and gender are transmitted to Firebase Analytics and AppsFlyer for analytics and marketing-analysis purposes only where the relevant consent has been given.

You may withdraw your consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Legitimate Interests – Article 6(1)(f) GDPR

Where permitted by law, processing may be based on our legitimate interests in maintaining application security, preventing misuse, resolving technical problems, ensuring stability, administering our business and establishing, exercising or defending legal claims.

6. Special Categories and Sensitive Information

Klara does not require users to provide sensitive or special-category personal data. However, open-ended conversations may voluntarily contain such information.

If sensitive information is included in a conversation, it may be processed as part of the current conversation, stored conversation history or transcript, and information derived for learning continuity and personalisation.

Users should avoid providing sensitive personal data that is not necessary for their language-learning interaction.

Klara does not use such information for advertising or any other purposes than to facilitate learning and naturalise the communication with Klara.

7. Hosting and Technical Infrastructure

Amazon Web Services

The Klara backend and application infrastructure are hosted using Amazon Web Services (AWS). The primary hosting region is AWS eu-central-1 – Frankfurt, Germany.

Amazon Web Services EMEA SARL
38 Avenue John F. Kennedy
L-1855 Luxembourg

MongoDB Atlas

Klara uses MongoDB Atlas for database storage in AWS Frankfurt (eu-central-1), Germany. The production configuration is designed so that database data remains within the EU/EEA, with no cross-region replication or intended cross-region backup distribution.

The database may contain account data, profile information, authentication information, learning progress, CEFR information, chat history, transcripts from spoken conversations, cross-session memory information, subscription/access status and referral/campaign identifiers.

AWS S3

We use AWS S3 storage for user-uploaded profile images. Profile images are deleted when the account is deleted, subject to limited technical backup periods and statutory retention requirements.

8. Registration and User Account

You may create a Klara user account. We process username, email address, authentication information, hashed password information, backend/internal user ID, account status and subscription or access status.

Passwords are not stored in plain text. User accounts are not publicly visible. Processing is generally based on Article 6(1)(b) GDPR.

9. Profile Information

Klara uses profile information to provide and personalise the language-learning service. This may include name or username, profile image, age range, gender, learning level, app language, learning language and language-learning information.

Profile data required to personalise the service is generally processed under Article 6(1)(b) GDPR. Age-range and gender information may additionally be used for analytics and marketing analysis where the user has expressly consented. For this purpose they may be transmitted as user properties to Firebase Analytics and AppsFlyer.

No advertising SDKs are currently integrated into the application.

10. Learning Progress and CEFR Information

Klara stores information about your learning progress in order to adapt the learning experience to your abilities and previous activity. This includes CEFR progress scores, learning progress information, information used to estimate your current level and information derived from previous learning interactions.

Learning and progress information is retained for as long as your user account remains active and is deleted when your account is deleted unless continued retention is required by law. The legal basis is Article 6(1)(b) GDPR.

11. AI-Based Processing

Artificial intelligence is an essential component of Klara. AI systems are used to understand user input, generate responses, conduct language-learning conversations, adapt conversations to the learner’s level, provide continuity between sessions, process spoken interactions and provide avatar/video functionality.

Depending on the function, external AI or speech-processing providers may receive conversation content, prompts, previous conversation context, selected profile information, learning progress, CEFR information, cross-session memory information, transcripts or spoken input.

Klara does not use AI to make automated decisions producing legal effects or similarly significant effects for users.

12. Text Chat – Microsoft Azure OpenAI

Klara uses Microsoft Azure OpenAI services for AI-powered text conversations and related functions. Information required to generate an appropriate response may include your message, relevant previous conversation content, selected profile information, CEFR progress, learning information and cross-session memory.

Azure OpenAI processing used for Klara is configured within Microsoft’s European infrastructure. Microsoft does not use Klara conversation data for model training.

Depending on the applicable security and abuse-monitoring configuration, certain content may be temporarily retained for abuse-monitoring purposes for up to 30 days.

The legal basis for conversation processing is generally Article 6(1)(b) GDPR; security and abuse-monitoring may additionally rely on Article 6(1)(f) GDPR where applicable.

13. Cross-Session Memory and Personalisation

Klara stores a cross-session memory together with other learning information in the Klara backend to provide continuity between learning sessions.

The information may include selected learner-profile information, age-range and gender information contained in the profile, CEFR progress, learning-relevant notes, summarised information derived from previous interactions and information derived from stored conversation transcripts.

The memory is used to take previous learning progress into account, adapt future conversations, avoid unnecessary repetition, continue previous learning topics and provide a more personalised learning experience.

At the beginning of a new AI session, relevant profile, progress and memory information may be supplied to the relevant AI system as contextual information. Stored audio transcripts may also be used to support long-term memory, learning continuity and personalisation features.

Because open-ended conversations may include sensitive information, such information may technically be reflected in the stored summary. Conversation history and cross-session memory are separate forms of storage. Cross-session memory is retained while the account remains active and deleted when the account is deleted.

14. Storage of Conversation History and Transcripts

Klara stores conversation history in the Klara database, including text-chat conversations, AI-generated conversational responses and written transcripts generated from the learner’s spoken input.

The stored information is used to maintain conversation continuity, support personalised learning, support the creation and maintenance of cross-session memory, assess learning progress and provide future sessions with relevant learning context.

Conversation history and stored audio transcripts are retained for as long as the user’s account remains active. There is currently no separate shorter retention period. When the user deletes the account, the stored conversation history and transcripts are deleted, subject to limited technical backup retention.

15. Audio Conversations

Klara allows users to conduct spoken language-learning conversations and requires microphone access for this function.

User → ElevenLabs speech recognition → conversational AI processing → ElevenLabs voice generation → User

Audio is streamed and processed in real time for speech recognition, interpretation of spoken input, generation of conversational responses and speech synthesis.

Neither Klara nor ElevenLabs permanently stores the raw audio recording as part of the normal conversation process. However, Klara stores a written transcript of what the learner said as part of the user’s conversation history. These transcripts are also used to support long-term memory, continuity and personalisation features across learning sessions.

The transcript is retained for as long as the user’s account remains active and is deleted with the account, subject to limited technical backup periods.

16. ElevenLabs

Klara uses ElevenLabs for speech recognition, voice generation and agent-related processing in spoken conversations.

Klara uses ElevenLabs with Zero Retention Mode enabled for the production agent configuration. Under this configuration, ElevenLabs is not intended to retain conversation content such as raw audio, transcripts or prompts after the processing necessary to provide the conversation.

This does not affect the separate transcript stored by Klara in its own database. The current ElevenLabs configuration uses the provider’s standard US-hosted infrastructure; EU data residency is not currently enabled for the Klara ElevenLabs account.

The legal basis for processing necessary to provide a spoken conversation is generally Article 6(1)(b) GDPR. International transfers are addressed in Section 32.

17. Underlying Conversational Model – Google Gemini 2.5 Flash

For certain spoken conversations, ElevenLabs Agents uses Google Gemini 2.5 Flash as an underlying language model. Klara does not operate a separate direct Gemini integration for this conversation flow.

Information processed may include system prompts, conversational instructions, individual conversation turns, text generated through speech recognition and contextual information necessary to provide the conversation.

Under the Zero Retention configuration reported for the ElevenLabs agent, conversation content is intended to be processed for responding to the request and not retained by ElevenLabs as ongoing conversation storage or used for model training under the relevant provider arrangements.

18. Video and Avatar Lip-Sync Processing – Simli

Klara uses Simli for avatar and lip-sync processing.

Simli AS
Oslo, Norway

For an active avatar session, Klara sends Simli only the information required to establish and operate the session, currently a short-lived server-generated session token and the audio stream transmitted during the active avatar session.

Klara does not intentionally transmit the user’s name, email address, backend user ID or profile information to Simli as part of the session. The Simli API key is held server-side and is not exposed to the application client.

Simli data is processed under the provider’s applicable EU/EEA data-processing arrangements; deletion requests are handled in accordance with those arrangements, while billing-related records may be retained where legally required.

19. Device Permissions and Profile Images

Depending on the functions you use, Klara may request access to device permissions such as the microphone and access required to select or upload a profile image.

Permissions can be managed through your device settings. Denying a permission may prevent the relevant function from working.

Profile images are stored using AWS S3 and linked to the relevant account. They are generally retained until replaced, deleted or the account is deleted.

20. Free Trial

Klara offers a free trial of up to one hour. The free trial does not require activation of an Apple App Store or Google Play subscription and does not automatically convert into a paid subscription.

No payment information is processed by Klara merely because the user starts or completes the free trial. A trial-start event may be recorded for analytics where the user has consented to the relevant processing.

21. Subscriptions and In-App Purchases

Individual paid Klara subscriptions may be purchased through the Apple App Store or Google Play. Payment processing is handled by Apple or Google.

Klara does not directly receive or store complete credit-card numbers, bank-account numbers, card security codes or comparable payment credentials.

We receive information necessary to administer access, such as subscription status, product/subscription type, transaction identifiers, purchase status, renewal status and expiry information.

Processing required to provide a paid subscription is generally based on Article 6(1)(b) GDPR. Certain transaction-related information may additionally be retained where required by law.

22. Organisation-Provided Access

Companies and other organisations may purchase Klara access directly from Klara and provide access to authorised users.

Klara may generate an organisation-specific activation or access code with a defined number of permitted users and a defined validity period.

We process the access code, relevant organisation or licence allocation, activation status, validity period and backend user ID as necessary to verify and administer the entitlement.

23. Firebase Crashlytics

Klara uses Firebase Crashlytics, a Google service, to identify application crashes, errors and technical problems. Klara currently attaches the backend user ID to Crashlytics reports but does not intentionally transmit username or email address as report fields.

Crashlytics may process crash stack traces, app version, operating-system information, device model and technical characteristics, application state, installation/session identifiers and timestamps.

Crash data is retained for 90 days in accordance with the applicable Firebase Crashlytics retention rules. Processing may involve international Google infrastructure.

24. Firebase Analytics

Klara uses Firebase Analytics to understand how the application is used and to improve the service.

Where the required consent has been given, Firebase Analytics may process events such as registrations, logins, trial starts, subscriptions and other app interactions as well as technical device or installation information.

Age range and gender may be transmitted as analytics user properties only where the user has consented. Analytics consent is not required to use the core language-learning service and may be withdrawn for future processing.

25. AppsFlyer – Marketing Attribution

Klara uses AppsFlyer to measure marketing effectiveness and understand how users discover Klara.

Depending on consent and platform settings, AppsFlyer may process installation information, campaign/referral identifiers, device or installation identifiers, interaction and conversion events, subscription-related conversion information and technical device information.

AppsFlyer processing requiring tracking consent is based on Article 6(1)(a) GDPR. On Apple devices, applicable App Tracking Transparency permissions and restrictions are respected.

26. Referral, Promotional and Influencer Attribution

Klara may use identifiers associated with referral links, promotional codes, marketing campaigns, influencers and organisation access programmes.

This allows us to determine whether a source resulted in registration, trial use or subscription and may be used for campaign-performance analysis, conversion attribution, administration of promotional programmes and calculation of campaign-related remuneration or commissions.

Referral information is not used to determine the user’s language ability or CEFR assessment.

27. Contact and Customer Support

If you contact us by email, contact form or another communication channel, we process the information you provide to respond to your request. This may include name, email address, account information, message content and technical information necessary to investigate an account or application issue.

Where the communication relates to your account or contract, processing is generally based on Article 6(1)(b) GDPR; other enquiries may rely on Article 6(1)(f) GDPR.

28. Website and Web Hosting

When you access our website, technically necessary information is processed to provide the website and ensure its security. This may include IP address, date/time of access, requested page/file, browser type, operating system, referrer information and technical logs.

United Domains

united-domains AG
Gautinger Straße 10
82319 Starnberg
Germany

WordPress / Automattic

Our website may use WordPress services provided by Automattic or related entities for website creation, hosting and related functions.

29. Cookies and Similar Technologies

Our website and, where applicable, our application may use cookies or similar technologies. Technically necessary technologies may be used to provide requested functions, maintain security, manage sessions and remember user settings.

Other technologies may be used for analytics, marketing measurement and campaign attribution. Where consent is legally required for storage of or access to information on a user’s device, such technologies are used only after consent has been obtained.

30. Social Media

We maintain profiles on social networks including Instagram, Facebook, TikTok and YouTube to provide information about Klara and communicate with users.

When you visit or interact with these platforms, personal data may also be processed independently by the respective provider. Where you contact Klara directly through a social network, we process the information required to respond to your communication.

31. Disclosure of Personal Data to Service Providers

We use external service providers to operate and provide Klara. Depending on the function, recipients may include providers of cloud infrastructure and hosting, database services, artificial-intelligence processing, speech recognition and voice processing, avatar/lip-sync processing, analytics, crash monitoring, marketing attribution, payment/app-store services, website hosting and customer support.

Where providers process personal data on our behalf, we use appropriate contractual arrangements as required by applicable data-protection law. Service providers receive only the information required for the respective purpose and technical configuration.

32. International Data Transfers

Some providers used by Klara are located outside the EU/EEA or may process personal data there. The Klara core backend and MongoDB database are hosted in Frankfurt, Germany.

International processing may occur in particular because ElevenLabs currently uses standard US-hosted infrastructure, Google services may use international infrastructure, AppsFlyer processing may involve infrastructure outside the EU/EEA, and subprocessors of external AI/speech services may process data internationally.

Where personal data is transferred outside the EU/EEA, we use the applicable safeguards, such as adequacy decisions, the EU-US Data Privacy Framework where applicable, Standard Contractual Clauses or other legally recognised safeguards, together with additional technical and organisational measures where necessary.

33. Data Retention

We store personal data only for as long as required for the purpose for which it was collected, unless longer retention is required or permitted by law.

Account data

Account and profile information is generally stored for the duration of the account.

Learning progress and cross-session memory

Learning progress, CEFR information and cross-session memory are generally retained until the account is deleted.

Conversation history and transcripts

Text chat history and stored audio transcripts are retained while the account is active and deleted with the account, subject to limited backup periods.

Raw audio

Raw audio recordings are not permanently stored by Klara as part of the normal conversation process. ElevenLabs is used in Zero Retention Mode for the relevant production agent configuration.

Azure OpenAI

Depending on the applicable security and abuse-monitoring configuration, certain content may be temporarily retained for up to 30 days.

Crashlytics

Firebase Crashlytics crash data is retained for 90 days.

Firebase Analytics and AppsFlyer

Analytics and attribution information is retained in accordance with the respective service configuration, consent settings and provider retention arrangements and is subsequently deleted or anonymised.

Profile images

Profile images are generally retained until replaced, deleted or the account is deleted.

Legal and accounting information

Information required for tax, accounting, contractual or other legal obligations may be retained for the applicable statutory period.

34. Account Deletion

Users may delete or request deletion of their Klara account. Account deletion triggers deletion of active Klara records associated with the account, including the user account, chat history, stored audio transcripts, learning progress, cross-session memory notes, Klara purchase-history information and profile image.

Backup copies may continue to exist for a limited period in technically secured backups. MongoDB production backups are intended to remain in the Frankfurt region and not be distributed through cross-region backups.

Separate information may remain where retention is required by tax, accounting or contractual law, security requirements or for legal claims.

Deletion of the Klara account does not itself cancel an Apple App Store or Google Play subscription.

35. Logout and Analytics User Properties

Where age range and gender have been assigned as analytics user properties, the application clears these user properties on logout. This prevents them from continuing to be associated with subsequent logged-out app activity through the Klara user profile.

Clearing a user property on logout does not necessarily remove analytics data lawfully processed before logout. Users may withdraw analytics consent at any time for future processing.

36. Security Measures

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, accidental or unlawful loss, alteration, disclosure, destruction and misuse.

Measures include, where appropriate, encrypted transmission, access controls, authentication mechanisms, hashed password storage, restricted administrative access, secure infrastructure, backup/recovery procedures, monitoring and technical security measures. Connections are protected using appropriate encryption technologies such as TLS.

37. Rights under the GDPR

Where the GDPR applies, you have the following rights subject to statutory requirements:

  • right of access;
  • right to rectification;
  • right to erasure;
  • right to restriction of processing;
  • right to data portability;
  • right to object where processing is based on Article 6(1)(f) GDPR;
  • right to withdraw consent at any time for future processing;
  • right to lodge a complaint with a competent data-protection supervisory authority.

38. Rights under Swiss Data Protection Law

Where the Swiss Federal Act on Data Protection applies, affected persons have the rights granted under Swiss law, including, where applicable, the right to information, rectification, deletion or destruction, objection to certain processing and receipt or transfer of personal data in a commonly used electronic format.

International transfers subject to Swiss data-protection law are carried out in accordance with the applicable requirements for disclosure of personal data abroad.

39. Provision of Personal Data

Some personal data is necessary to use particular Klara functions. Registration information is required to create an account, authentication information to access it, conversation content to provide AI conversations, microphone access for spoken conversations and learning information for personalised learning continuity.

Other information may be optional. In particular, analytics consent is not required to use the core Klara language-learning service.

40. Changes to this Privacy Policy

We may update this Privacy Policy where necessary, particularly if functions of Klara change, new services are introduced, service providers or technical infrastructure change, retention configurations change or legal requirements change.

The version available through Klara or our website at the relevant time applies. Where a change requires consent or individual notification under applicable law, we will obtain such consent or provide such notification.

41. Definitions

Personal Data

„Personal data“ means any information relating to an identified or identifiable natural person.

Processing

„Processing“ means any operation performed on personal data, including collection, storage, use, transmission, analysis, alteration and deletion.

Content Data

Content data includes information supplied or generated during the use of Klara, including text, transcripts, images, audio and other conversation information.

Learning Data

Learning data includes information about a user’s language-learning activity, level, progress, assessments and CEFR-related development.

Cross-Session Memory

Cross-session memory means a summarised set of information derived from previous Klara interactions and stored in order to provide continuity and personalise future learning sessions.

Conversation Transcript

A conversation transcript is a written representation of spoken user input generated during an audio interaction and stored by Klara as part of the user’s conversation history.

Usage and Analytics Data

Usage and analytics data includes information about how the application is used, such as events, interactions, device information, trial starts, registrations and subscription events.

Technical Identifiers

Technical identifiers are identifiers associated with a device, application installation, backend account, transaction or session that may be used to provide, secure, analyse or measure digital services.

Artificial Intelligence

Artificial intelligence refers to machine-based systems used to process input and generate outputs such as text, audio, recommendations or conversational responses.