Encrypted keys
Provider keys saved under Connections are encrypted on the server with AES-GCM before being stored. They never go through the chat and are never shown again.
This page describes what Kloel does today to protect your content, and also what it does not do yet.
The Kloel app is currently available in Portuguese. These public pages are translated; the workspace itself remains in Portuguese.
Provider keys saved under Connections are encrypted on the server with AES-GCM before being stored. They never go through the chat and are never shown again.
Every record belongs to an account, and the server checks the owner on every read and change. Sharing releases only the chosen item, with the chosen role.
In temporary mode the conversation stays out of your history. Kloel keeps only minimal usage data.
Personal memory starts off. You can turn it on or off and delete the notes you do not want to keep.
Delete chats and agent tasks one by one or in bulk. The item leaves visible history; minimal reconciliation metadata remains. Shared copies and provider-held data are not erased by this action.
Export eligible account records in an open format, with an integrity check for each part.
Background tasks require consent to provider-defined retention. Deleting local history does not confirm remote erasure.
When billing is active, card data will be entered on the payment processor’s secure page, never on Kloel servers.
When you use a model, the request and the necessary context go to that model’s provider, such as OpenRouter, OpenAI, ElevenLabs or fal. Kloel does not train models with your content. Each provider handles data under its own terms, and when you use your own key, your agreement with that provider applies.
You can already delete your history and export your data. Complete account deletion, including every file and record, is still in development.
Kloel does not have audits such as SOC 2 or ISO 27001 yet. We will say so here when it does.