Who we are
Kleyra (“Kleyra”, “we”, “us”) is operated by Affekt Pty Ltd, 1A Arundel Road, Cape Town, Western Cape 7700, South Africa. Kleyra measures how AI assistants answer questions about your business and tells you what to fix.
For anything in this policy, contact us at hello@kleyra.com.
What we collect
Information you give us
- Account details — your email address, and your name if you provide one.
- Business details — your business name, website, location, category, and any competitors you choose to track.
- Questions you configure — the buyer questions you want asked of AI assistants.
Information from your Google account (only if you connect it)
Connecting Google is optional. Kleyra works without it; connecting it lets us show your AI visibility next to your real search traffic. If you connect, we request these scopes and nothing else:
| Scope | What we read | Why |
|---|---|---|
webmasters.readonly | Your list of Search Console sites, and the search queries, clicks, impressions and average positions for the site you select | To show whether fixes we recommend moved your actual search traffic |
analytics.readonly | Your Google Analytics 4 property list, and aggregate traffic metrics for the property you select | To tie AI visibility to sessions and conversions on your site |
userinfo.email, userinfo.profile | Your email address and basic profile | To identify which Google account is connected |
Every one of these is read-only. Kleyra cannot create, edit or delete anything in your Google account, and never attempts to.
Information we generate
- Scan results — the answers AI assistants return to your questions, stored in full, plus whether your business was mentioned.
- Usage and diagnostic logs — standard server logs used to keep the service running and debug faults.
How we use Google user data
We use data from your Google account for exactly one purpose: to display your search and analytics performance back to you inside Kleyra, alongside your AI visibility results, so you can see whether a fix worked.
We do not, and will not:
- sell or transfer your Google user data to anyone;
- use it for advertising, ad targeting, or building ad profiles;
- use it to train, fine-tune or improve any generalised or artificial intelligence model;
- send it to the AI assistants Kleyra queries — those receive only your questions and public business details, never your Google data;
- allow humans to read it, except with your explicit permission, where needed to resolve a support issue you raised, for security purposes, or where required by law.
Google API Services Limited Use disclosure. Kleyra’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Where your data lives, and how it’s protected
- Application data is stored in Google Cloud Firestore, hosted in the European Union (Netherlands,
europe-west4). - Your Google refresh token is envelope-encrypted using Google Cloud KMS before it is written to storage. The plaintext token is never persisted.
- Tokens are readable only by our server. Database rules deny all client access to them outright.
- Data is encrypted in transit (TLS) and at rest.
- Each customer workspace is isolated; one customer cannot read another’s data.
No system is perfectly secure, and we won’t claim otherwise. If we ever suffer a breach affecting your data, we will tell you.
Who else processes your data
We use a small number of sub-processors. They receive only what they need to do their job:
| Provider | Purpose | Receives Google user data? |
|---|---|---|
| Google Cloud / Firebase | Hosting, database, key management | Yes — it is the origin and the store |
| Cloudflare | DNS, CDN, and this marketing site | No |
| OpenAI, Anthropic, Google Gemini, Perplexity, DataForSEO | Running your questions through AI assistants and search data providers | No — they receive questions and public business details only |
We do not sell your personal information to anyone, and we do not share it with advertisers.
How long we keep it
- Account and business data — for as long as your account exists.
- Scan results — retained so you can compare over time and prove a fix worked. Deleting your account deletes them.
- Google tokens — deleted immediately when you disconnect Google or delete your account.
Your choices and rights
- Disconnect Google at any time — from within Kleyra, or directly at myaccount.google.com/permissions. We delete the stored token and stop all access.
- Access, correct, export or delete your data — email hello@kleyra.com and we will act within 30 days.
- Depending on where you live, you may have rights under the GDPR (EU/UK) or POPIA (South Africa), including the right to object to processing and to complain to your data protection authority.
Children
Kleyra is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children.
Changes to this policy
If we change how we handle your data in a way that materially affects you, we will update the date at the top of this page and notify account holders by email before the change takes effect.
Contact
Affekt Pty Ltd, 1A Arundel Road, Cape Town, Western Cape 7700, South Africa · hello@kleyra.com