Effective August 24, 2026
Spectrality, LLC (“we,” “our,” or “us”) operates Klar, a service for reading the documents you upload. This policy explains what we collect, why, and what we do with it. Klar is currently in alpha; this policy reflects how the alpha actually works today.
The information we hold about you is limited to what the service needs to operate.
| Category | Examples |
|---|---|
| Account data | Your email address and a salted hash of your password. We never store your password in plaintext. |
| Library content | The documents you upload (PDFs, photographs, scans), stored in our self-hosted object storage (MinIO), and the rendered output we produce from them. |
| Reading progress | Your position within each document, so the reader can resume where you left off. |
| Audit logs | Records of security-relevant events tied to your account — logins, password resets, and support requests — kept so we can investigate problems and abuse, and deleted along with your account when you close it. |
Which model reads your documents depends on your plan. Making a PDF, photograph, or scan readable means sending every one of its pages to a third-party AI model provider, listed in section 4. That provider is the only one your documents reach.
Your plan is recorded when you upload, not when we read. A document is processed on the tier that applied at the moment you uploaded it. Upgrading later does not un-send a page that was already sent, and downgrading later does not reach back to documents you uploaded while paid.
We rely on a small number of vendors to operate the service. Each receives only the data it needs to do its job.
| Processor | What they receive, and why |
|---|---|
| Document extraction provider | This is where your documents are read. Every page of every PDF, photograph, and scan you upload is rendered as an image and sent to a third-party AI model provider, whose model reads the whole page and returns its text and structure. It is the only path by which a page is read, not a fallback used when something else fails. Which tier of that model we use depends on your plan: the free plan uses a lower-cost tier whose terms license the provider to train on what it is sent — which here is an image of your page and the text transcribed from it — and paid plans use the standard tier, whose terms do not permit that. It is a single global API endpoint with no region selection available to us, so we cannot tell you which country it runs in. Formats that carry their own text — EPUB, DOCX, PPTX, and plain text — are parsed on our own servers and are never sent to that provider or to any other model. |
| Website hosting provider | This public website is served from a cloud provider’s object storage and content-delivery network, which receive the ordinary request data any web server receives — your IP address, the page you asked for, and your browser’s user-agent. This provider receives no documents and no account data. It previously also ran supporting model steps around the main extraction — receiving page images, cropped regions, and extracted text in the United States — and no longer does: extraction is now a single provider, described in the row above. |
| Infrastructure hosting provider | Hosting infrastructure for the service. The Spectrality application servers, database, and object storage — including your library content — run in data centres in Germany (EU). Model inference is the exception, and is described in the extraction-provider row above. |
| Transactional email provider | Your email address, when we need to send you a transactional email such as a password reset or a reply to a support request. |
| Web font provider | Our pages load their typefaces from a third-party font service, so your browser requests those font files from it directly. That provider receives your IP address and browser user-agent as part of that request. No documents and no account data are involved. |
Where processing happens. Your account data and library content are stored in the EU. Model inference is the one step that leaves it, and it now has a single destination: for a PDF, photograph, or scan, every page is transmitted to the extraction provider, whose endpoint is global and whose country we therefore cannot name. Nothing about your documents is sent to any other model provider. We store nothing at that provider ourselves; which tier applied to a given document depends on the plan you were on when you uploaded it, and what each tier’s licence permits that provider to do with what it received is described in the extraction-provider row above.
We use a single essential cookie to keep you signed in across requests. We don’t use analytics, advertising, or tracking cookies, so the service does not display a cookie consent banner during alpha.
No system on the open Internet is completely secure. We aim to apply current best practices and to disclose breaches promptly if they occur.
To exercise any of these, write to privacy@spectrality.works.
Different things are kept for different lengths of time, so here is each one with the number that actually governs it.
Database backups — 14 days. We continuously archive our databases into our own object storage so we can recover from outages and accidents, and that archive is retained for 14 days before it rotates out. After you delete your account, residual copies of your account record, reading progress, and document metadata may persist there until that rotation. Your uploaded files are not part of this archive — it covers the databases only — so deleting your account removes them outright. Backups are not used for any other purpose.
Security and audit records — until you delete your account. The audit records described in section 1 carry no separate expiry. They are deleted in the same transaction that deletes your account, not on a timer.
Operational logs — 90 days once the log store is in use. Our services also emit ordinary operational logs: request and error records, which can carry your account identifier and the identifiers of your documents. The centralized log store we are building applies a 90-day retention. During alpha the services are not yet writing to it, so these logs stay on the servers that produced them.
We do not sell, trade, or rent your personal information. Beyond the third-party processors listed above, we may share information with legal authorities if we are required to by law or by valid legal process.
Klar is not directed to children under 13, and we do not knowingly collect data from them. If you believe a child has provided us information, contact us and we will delete it.
We may update this policy from time to time. Material changes will be announced in the service or by email before they take effect. The effective date at the top of this page reflects the current version.
Spectrality, LLC
New York, NY
privacy@spectrality.works