Klora Privacy Policy
Effective date: July 28, 2026 · Last updated: July 28, 2026
Plain-English summary: Klora uses the account, property, location, design, device, and transaction information needed to provide and improve its landscape-design service. Designs are private unless you publish them. Klora may use private Design Content to train and improve its systems; at launch, there is no separate opt-out from that internal improvement use. We keep precise location and direct identity fields out of generalized training datasets as described below. This summary does not replace the full Policy.
This Privacy Policy explains how Klora LLC, a Maryland limited liability company doing business as Klora (“Klora,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects personal information when you use klora.app, our applications, design tools, communications, and related products and services (collectively, the “Services”).
“Personal information” means information that identifies, relates to, describes, or can reasonably be linked to a person or household. Laws may use terms such as “personal data” or “personal information”; this Policy uses “personal information” for all of them. “Design Content” means plot plans, plans or surveys, property images, measurements, addresses or location inputs, site conditions, prompts, instructions, selections, edits, comments, project data, generated outputs, and other material submitted to, created in, or stored through the Services.
By using the Services, you acknowledge the practices described here. Our Terms of Service govern your use of the Services and include additional provisions about User Content and Design Data. If a just-in-time notice presented in a feature differs from this Policy, the more specific notice applies to that feature.
1. Scope
This Policy applies to the Services and to related support, billing, transactional email, surveys, privacy requests, and business communications. It does not apply to third-party websites, products, integrations, or services that have their own privacy notices, including payment, mapping, weather, geocoding, or other providers when they act independently of Klora.
The Services are currently directed to users in the United States. If you access them from another country, Section 12 explains that information may be processed in the United States and other locations used by our providers.
2. Information We Collect
2.1 Information you provide
- Account and contact information, such as name, email address, username, password or authentication credential, mailing address if provided, profile photo, display name, communication preferences, and account settings.
- Billing and transaction information, such as plan, purchase, renewal, cancellation, transaction status, billing contact details, and limited payment-method information. Stripe processes payment-card and related payment information; Klora generally does not receive or store the full card number.
- Design Content, including plot plans, surveys, property photos, drawings, dimensions, boundaries, structures, hardscape, soil or site notes, sunlight, water, drainage, climate or hardiness-zone inputs, desired plants and materials, prompts, edits, ratings, corrections, generated designs, lists, exports, and project history.
- Address and location information, such as a property address, city, ZIP code, map location, latitude/longitude, or device location if you choose to permit it. Exact coordinates may be sensitive personal information under some laws.
- Public and community information, if offered, such as a public display name, avatar, design, image, title, caption, tags, reactions, comments, reports, or other information you choose to publish or submit for featuring.
- Communications and feedback, such as support requests, privacy requests, survey responses, contest or promotion entries, and messages or attachments you send to us.
2.2 Information collected automatically
- Device and network information, such as IP address, device type, operating system, browser type, language, approximate location derived from IP, identifiers, and mobile or application information.
- Usage and activity information, such as pages and features used, button clicks, searches, project events, referring and exit pages, dates and times, session information, diagnostics, crashes, errors, performance data, and interactions with emails.
- Cookies and similar technologies, as described in Section 7. We use essential technologies and may use analytics or functionality technologies identified in our cookie controls or notices.
- Security and fraud information, such as authentication events, failed logins, suspicious activity, abuse signals, rate-limit events, and audit logs.
2.3 Information from other sources
We may receive information from service providers and public or licensed sources, including Stripe transaction and fraud signals; authentication providers; Geocodio address and coordinate results; Open-Meteo weather and climate data; Esri mapping and geospatial data; email delivery, bounce, and complaint data from Amazon SES; and information from any integration you direct us to connect. We may combine this information with information collected through the Services.
We may derive or infer information such as hardiness zone, approximate climate, site conditions, plant or design preferences, likely feature interests, project status, and recommendations from the information above.
3. How We Use Information
We use personal information for the following purposes:
- Provide, operate, maintain, personalize, and support the Services, including creating accounts, authenticating users, processing projects and uploads, generating designs, retrieving maps and weather, recommending plants or materials, saving projects, producing exports, and restoring eligible designs.
- Process purchases, renewals, cancellations, taxes, invoices, payment failures, chargebacks, and other billing events, and prevent transaction fraud.
- Communicate with you about your account, purchases, projects, security, support, legal terms, service changes, surveys, and—where permitted—marketing. You may unsubscribe from marketing, but not essential transactional or security messages.
- Analyze, test, develop, train, evaluate, validate, and improve Klora’s products, features, recommendations, algorithms, and artificial-intelligence or machine-learning systems, as described in Section 4.
- Create and use aggregated or de-identified statistics, benchmarks, patterns, datasets, insights, and other information for research, analytics, product development, model improvement, and other lawful business purposes.
- Protect the Services and users; authenticate access; enforce limits and policies; detect, investigate, prevent, and respond to errors, misuse, fraud, security incidents, harmful conduct, and legal violations.
- Comply with law, legal process, and regulatory requirements; exercise, establish, or defend legal claims; enforce our agreements; and protect rights, safety, and property.
- Carry out a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, diligence process, or similar corporate transaction, subject to applicable law.
Where applicable law requires a legal basis, we process information as needed to perform a contract with you, for our legitimate interests, to comply with law, to protect vital interests, or with consent. The applicable basis depends on the information and context.
4. Product Improvement and AI or Machine-Learning Training
Klora may use Design Content—including Design Content in private projects—along with feature interactions, prompts, outputs, corrections, ratings, and related usage information to develop, train, test, evaluate, validate, secure, and improve Klora’s products, recommendations, algorithms, and artificial-intelligence or machine-learning systems. This may include human review by authorized personnel or contractors when reasonably needed for quality, safety, support, or development and subject to access controls and confidentiality obligations.
At launch, this internal improvement use is part of the Services and is not subject to a separate account opt-out. If you do not agree to this use, do not upload or create Design Content through the Services. Deleting content or an account stops new use of the deleted source content after deletion is completed, but does not require Klora to delete or “untrain” generalized learnings, system improvements, trained model parameters, or properly de-identified or aggregated information created beforehand when reversal is not reasonably feasible or legally required.
We use a separate, minimized process for generalized training. We take measures designed to exclude full street addresses, precise latitude/longitude, EXIF GPS metadata, payment data, account credentials, and other designated sensitive or direct-identity fields from generalized training datasets. Exact location may still be processed and stored when needed to provide a site-specific feature you request. If we cannot reliably separate designated sensitive information from material selected for generalized training, we will not use that material for generalized training unless the processing is lawful and any required permission has been obtained.
Service providers may process Design Content for Klora under our instructions. We do not authorize a provider to use content submitted through Klora to train an unrelated general-purpose model for itself or other customers unless we tell you in advance and obtain any permission required by law.
We may create and use information that has been aggregated or de-identified so that it is not reasonably linkable to a person or household. We maintain de-identified information in that form and do not attempt to re-identify it except to test or maintain de-identification, security, or legal compliance. To the extent permitted by law, we may retain, use, disclose, license, and commercialize de-identified or aggregated information without payment or attribution.
5. Private, Shared, and Public Designs
Designs are private by default. Private Design Content is accessible to you and to Klora personnel and service providers only as reasonably needed for the purposes in this Policy, subject to access restrictions. We do not use a private plot plan, address, property photograph, or design as identifiable public marketing material merely because it is stored in Klora.
If Klora offers collaboration or link sharing, you control the people or link recipients you authorize. Anyone with access may view, copy, download, screenshot, or reshare information, depending on the feature. Review permissions and share only with people you trust. A private share link is not the same as publishing to a public gallery.
If Klora offers a public gallery or community, a design becomes public only after you affirmatively choose to publish it. The publication screen will identify the information to be displayed. Public information may be viewed without an account, searched within Klora, indexed by search engines, embedded, copied, downloaded, screenshotted, or reshared by others. Avoid publishing a full address, exact location, contact details, or other information you do not want made public.
You may unpublish content using the available control or by contacting support@kloragarden.com. We will remove it from Klora-controlled public display within the deletion period in Section 8, but copies, search-engine caches, archives, and material independently saved or shared by others may remain outside our control. Additional terms may apply when you separately submit content to a contest, testimonial, campaign, or featured-design program.
6. How We Disclose Information
We may disclose personal information as follows. “Disclose” does not necessarily mean a “sale” or “sharing” as those terms are defined by state privacy laws.
| Recipient | Why and what may be disclosed |
|---|---|
| Infrastructure and data providers | Vercel for hosting and delivery; Supabase for authentication, databases, and storage. They may process account data, Design Content, IP/device data, logs, and service activity for Klora. |
| Payments | Stripe for checkout, subscriptions, billing, tax or fraud functions, including contact, transaction, payment-method, device, and fraud information. Stripe may act under our instructions and, for some activities, under its own legal obligations. |
| Location, map, and weather | Geocodio for geocoding; Esri for maps and geospatial functions; Open-Meteo for weather and climate functions. They may receive an address or location query, coordinates, IP address, device/request information, and related usage data. |
| Amazon SES for sending transactional or service messages and processing email address, message, delivery, bounce, complaint, IP, and related log data. | |
| AI, analytics, monitoring, and support | Our AI/model, analytics, error-monitoring, and customer-support providers may process the information needed to perform their contracted function. We require providers to protect information and limit processing as appropriate. |
| Other users and the public | People you invite or share with receive the information covered by your settings. Public designs, profiles, captions, comments, and community activity are available to the public as described in Section 5. |
| Professional advisers and authorities | Lawyers, accountants, auditors, insurers, regulators, courts, law enforcement, and other parties when reasonably necessary for advice, compliance, legal process, claims, safety, security, or protection of rights. |
| Corporate transactions | Potential or actual investors, lenders, buyers, sellers, advisers, and successors in connection with financing, diligence, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate safeguards and law. |
| At your direction | Other recipients or integrations when you request, authorize, or consent to the disclosure. |
We may also disclose aggregated or de-identified information that is not reasonably linkable to a person or household, subject to applicable law and the commitments in Section 4.
7. Cookies and Similar Technologies
We and our providers use cookies, local storage, pixels, SDKs, and similar technologies to keep you signed in, remember settings, secure the Services, process purchases, understand performance and feature use, diagnose errors, and communicate. Essential technologies are necessary for the Services. If we use optional analytics, functionality, or advertising technologies, we will identify available choices through in-product cookie controls or another notice where required.
At launch, Klora does not sell personal information for money, share personal information for cross-context behavioral advertising, or use personal information for targeted advertising or profiling in furtherance of decisions that produce legal or similarly significant effects. We will update this Policy and provide any required notice and opt-out method before adopting such practices.
Browser “Do Not Track” signals are not standardized. We honor Global Privacy Control and other legally recognized universal opt-out signals where required and applicable to our practices. You may also manage cookies in your browser or device, but disabling essential technologies may prevent the Services from working.
8. Retention and Deletion
We retain personal information only as long as reasonably necessary for the purposes described in this Policy, considering the account relationship, service needs, data sensitivity, security, legal obligations, disputes, and technical feasibility. Our current retention framework is:
- Active accounts and projects: for as long as the account or paid access is active and the information is needed to provide the Services.
- Recovery after paid access ends: Design Content may be kept in restricted inactive storage for 15 months after paid access ends so you can reactivate and recover projects. After that window, we delete or de-identify it unless the account becomes active again or a narrow exception applies.
- Account deletion: after we verify a deletion request, we begin deletion promptly and target removal of the account, private Design Content, and direct identifiers from active production systems within 30 days. Routine encrypted backups ordinarily expire within 90 days and are not restored except for disaster recovery, security, or legal necessity.
- Public content: we target removal from Klora-controlled public display within 30 days after account deletion or a valid removal request. Copies and caches outside our control may remain.
- Limited records: we may retain transaction, tax, accounting, fraud, security, audit, privacy-request, support, dispute, and legal records for longer periods reasonably necessary for those purposes or required by law. We minimize what is retained and restrict its use.
- De-identified information and trained systems: properly de-identified or aggregated information and generalized learnings, improvements, and trained model parameters may be retained as long as useful and lawful, as described in Section 4.
Cancellation is not account deletion. Cancelling automatic renewal stops future charges but does not delete your account or projects. To delete your account, use the account control or submit a verified request under Section 10. We may delay or deny deletion only where permitted or required by law, such as to complete a transaction, protect security, prevent fraud, comply with a legal obligation, or establish or defend claims.
9. Security
We use reasonable administrative, technical, and physical safeguards designed to protect personal information, such as access controls, authentication, encryption in transit and at rest where appropriate, logging, vendor review, backup controls, and incident-response procedures. No service, transmission, or storage system is completely secure. We cannot guarantee absolute security or that information will never be lost, misused, accessed, disclosed, altered, or destroyed without authorization.
Protect your credentials, use a unique password, log out of shared devices, review sharing settings, and notify us promptly at support@kloragarden.com if you suspect unauthorized access. Do not send sensitive information through unencrypted support messages unless we ask you to use a secure method.
10. Your Choices and U.S. State Privacy Rights
10.1 Account, communication, and design choices
- Access or correct certain account and project information through account settings or by contacting us.
- Export available designs before your access ends or before requesting account deletion.
- Cancel automatic renewal through the method shown in account settings or at purchase. Cancellation affects billing; it does not delete data.
- Unsubscribe from marketing using the link in the message. We may still send service, billing, legal, security, and other transactional communications.
- Manage cookies through in-product cookie controls and browser or device controls, where available.
- Unpublish public designs using the available control. Copies outside Klora’s control may remain.
At launch, Klora does not provide a separate opt-out from the internal training and improvement use described in Section 4. This does not limit any non-waivable right available under applicable law.
10.2 Privacy rights available in certain states
Depending on where you live and whether the applicable law covers Klora and the processing, you may have rights to:
- confirm whether we process your personal information and access or obtain a portable copy of it;
- correct inaccurate personal information;
- delete personal information, subject to legal exceptions;
- obtain information about categories of personal information, sources, purposes, and recipients or categories of third parties;
- opt out of a sale, targeted advertising, certain sharing, or qualifying profiling;
- limit certain uses or disclosures of sensitive personal information or withdraw consent where applicable;
- appeal a decision we make about a request; and
- receive equal service and not be unlawfully discriminated against for exercising a privacy right.
To submit a request, email legal@kloragarden.com. Describe the right you want to exercise and the account or email involved. We may ask for information reasonably necessary to verify your identity and authority. We will use verification information only for the request. If you use an authorized agent, we may require proof of authorization and direct verification with you, as permitted by law.
We will respond within the time required by applicable law. If we deny a request, our response will explain the reason and any appeal method. To appeal, reply to the decision or email legal@kloragarden.com with “Privacy Appeal” in the subject line. If an appeal is denied, we will provide any regulator-contact information required by law.
10.3 Maryland residents
If the Maryland Online Data Privacy Act applies, Maryland residents acting in an individual or household context may exercise the access, correction, deletion, portability, opt-out, nondiscrimination, and appeal rights described above. They may also request a list of the categories of third parties to which we have disclosed personal information, as provided by law. Klora does not sell sensitive data. We process precise geolocation only when strictly necessary to provide or maintain a specific feature the consumer requested, and we keep it out of generalized training datasets as described in Section 4.
10.4 California residents — notice at collection
The table below summarizes categories of personal information we may have collected in the preceding 12 months, the purposes, and the categories of recipients. We retain each category under Section 8 rather than for a single fixed period. Categories are defined under California law; including a category does not mean we collect every example within it.
| Category and examples | Purposes | Categories of recipients |
|---|---|---|
| Identifiers and customer records: name, email, account ID, IP address, address, username, billing contact and limited payment information | Account, service delivery, billing, support, security, legal compliance, communications, and improvement | Infrastructure, payments, email, support, security, advisers, authorities, and directed recipients |
| Commercial information: plans, purchases, renewals, cancellations, transaction and project history | Billing, entitlements, support, analytics, fraud prevention, records, and improvement | Payments, infrastructure, support, analytics, advisers, and authorities |
| Internet/electronic activity: feature events, pages, clicks, device/browser data, logs, diagnostics, and email interactions | Operate, secure, diagnose, analyze, personalize, and improve the Services | Infrastructure, analytics, monitoring, security, email, and support providers |
| Geolocation: approximate IP location, property address, map location, and coordinates | Map, weather, zone, site-specific design, security, fraud prevention, and approximate analytics | Infrastructure, Geocodio, Esri, Open-Meteo, security, and directed recipients |
| Sensory/electronic content: property photos, drawings, plans, uploads, messages, and generated content | Provide projects; support; safety; develop, train, test, and improve products and models | Infrastructure, AI/model, support, monitoring where minimized, public or shared recipients at your direction |
| Inferences: climate/site characteristics, preferences, likely interests, recommendations, and project status | Personalization, recommendations, analytics, and improvement | Infrastructure, analytics, and AI/model providers |
| Sensitive personal information: precise geolocation and account-access credentials | Requested location features, authentication, security, and fraud prevention—not to infer characteristics about you | Infrastructure, authentication/security, Geocodio, Esri, and Open-Meteo as needed |
Klora does not sell personal information or share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information to infer characteristics about California residents. California residents may exercise applicable rights using the methods in Section 10.2. We do not provide financial incentives for personal information at launch. If that changes, we will provide the notice required by law.
11. Children
The Services are intended for adults and are not directed to children under 13. Our Terms require users to be at least 18. We do not knowingly collect personal information from a child under 13. If you believe a child has provided personal information, contact legal@kloragarden.com. We will investigate and delete it as required. Do not upload personal information about a child unless necessary, lawful, and authorized.
12. Processing in the United States and Other Locations
Klora is based in the United States. We and our providers may process and store information in the United States and other countries where we or they operate. Those places may have privacy laws different from the laws where you live. Where required, we use appropriate safeguards for cross-border transfers. The Services are not currently marketed to residents outside the United States unless Klora expressly states otherwise.
13. Changes to This Policy
We may update this Policy as our Services, vendors, or legal obligations change. We will post the updated Policy and revise the “Last Updated” date. If a change is material, we will provide additional notice as required, such as by email or an in-product notice. We will not apply a materially expanded use of previously collected personal information retroactively without the notice, consent, or other basis required by law. We encourage you to review the Policy periodically.
14. Contact Us
Questions, requests, or complaints about this Policy or our privacy practices may be sent to:
Klora LLC
Attn: Privacy
Email: legal@kloragarden.com
Support: support@kloragarden.com
If you need this Policy in an accessible alternative format, contact support@kloragarden.com.