Log in

Privacy policy

Last updated October 5, 2026

Klipstack keeps what you save so you can read it. It doesn't sell your data, show ads or track you. This page explains what we collect, why, who helps us run the service, and what you can do about it.

1.Who we are

Klipstack is owned and operated by Klipstack SpA ("we"), a company in Chile. We decide how your data is used, and we answer for it.

Questions, requests or complaints: privacy@klipstack.com.

2.What we collect

  • Your account: name, email address, and your password as a one-way hash, never the password itself. Your language and reading settings.
  • If you sign in with Google or GitHub: the name, email address and profile picture they send us. We don't keep their access tokens.
  • What you save: each link, the page's text and images, a copy of the page as it was saved, and the time you saved it.
  • What you add: highlights, notes, tags, saved searches, the feeds you follow, your reading progress and what you finished.
  • Sign-ins: for each device you're signed in on, its IP address and the browser's description of itself (user agent). We keep them with the sign-in, to protect your account. A sign-in ends 30 days after you last use it.
  • If you ask for an invite: your email address, the note you write, and your language. Only the people who run Klipstack see them.
  • If you report a public page: the reason, what you write, your email address if you give one, and your language. Only the people who run Klipstack see them. The page's author never sees your report or your address.
  • Abuse limits: for sign-in attempts, invite requests and reports, a scrambled (hashed) form of the IP address and email address. We delete these within about a day.
  • Server logs: which page was asked for, the result and how long it took. They don't include your IP address or your account. Logs about saving can name an article's number or a website's name.

We don't use analytics, ads, trackers, third-party scripts, third-party fonts or error-reporting services.

3.How we use it

  • To run Klipstack: save, clean up, store, show and search what you save.
  • To send account emails: sign-in links, address checks and password resets. We don't send newsletters or marketing.
  • To answer a request for an invite. We email you only if we send you one.
  • To decide on a report about a public page, and to email you the decision if you gave an address. If we take a page down, we tell its author why, without saying who reported it.
  • To keep the service secure and stop abuse.
  • To fix problems.

We don't sell your data. We don't use it for ads, and we don't train AI models on it.

The people who run Klipstack can reach the database to operate it. We look at your content only to fix a problem you report, to keep the service secure, or when the law requires it.

4.When Klipstack fetches pages for you

  • When you save a link, our server downloads the page and its images. The website sees our server, not you.
  • The browser extension sends the page as your browser shows it, including pages behind a login or a paywall. Save private pages with care: what the extension sends is stored in your library.
  • Our server checks the feeds you follow for new posts, and reads a page's title and summary to preview a link. Previews are kept for 15 minutes, in memory only.
  • To save a post from X (Twitter), our server asks FxTwitter for the post, using its address.
  • Some pictures in lists load straight from the original website. Your browser asks for them without saying which page you came from.

5.Who else handles your data

A few companies help us run Klipstack. They handle your data only to provide their service to us.

  • Hetzner Online hosts our servers and the database.
  • Cloudflare stores the images from pages you save, and our encrypted database backups (R2).
  • Resend sends our emails. It receives your email address and the message.
  • Better Stack checks from outside that Klipstack is up. It sees no account data.
  • Google or GitHub, only if you choose to sign in with them.
  • FxTwitter, only when you save a post from X.

We don't share your data with anyone else, unless the law requires it. If that happens, we tell you, unless the law forbids it.

6.Cookies and storage on your device

Every cookie we set is needed for Klipstack to work or to remember your settings. None are for ads or tracking, so there is no cookie banner.

  • klip.session_token keeps you signed in, for up to 30 days.
  • klip.state protects a Google or GitHub sign-in, for 5 minutes.
  • lng keeps your language, for a year.
  • klip_tz, klip_layout, klip_sidebar and klip_hl_view keep your time zone and how you like lists shown, for a year. Signing out removes the last three.

Your browser also keeps the last highlight color you used, and copies of your recent articles so they open offline. Signing out deletes those copies.

7.Apps, the extension and AI assistants

  • The browser extension acts only when you click it or use its menu. It removes scripts and hidden form fields before it sends a page. It asks to reach every site so it can save whichever page you choose.
  • The iPhone app, in testing, keeps your sign-in in the iPhone's Keychain and keeps copies of articles so they open offline. It reads aloud on the phone itself: the text never leaves it. Its voice files download once, from Hugging Face and GitHub. It reads the clipboard only when you tap Paste. It has no analytics and no crash reports.
  • You can connect other apps and AI assistants to your library (API keys, MCP). They can reach only what you allow, and you can remove them in Settings at any time. What they do with the data is up to them and their own privacy policies.

8.How long we keep it

  • Your library stays as long as your account does.
  • Things in the trash are deleted after 30 days. Saves that failed are deleted 7 days after you move them to the trash.
  • A request for an invite is deleted when we answer it, with an invite or without one. If we send you an invite, the invite keeps your email address.
  • A report, with your address, is deleted when we decide on it. The record of the decision keeps no part of the report.
  • When you delete your account, we delete your data and images at once. Encrypted backups keep a copy for up to 30 days, then it is gone. The server also keeps its own backups for 3 days.
  • Server logs are overwritten as they grow, and start over with each update.
  • Records of administrative actions keep no content. When you delete your account, they no longer point to you, and they are deleted after 90 days.

9.Your choices and rights

  • Get a copy: export your whole library, with highlights and notes, as Markdown and JSON from Settings. Your feeds export as OPML.
  • Correct it: change your name in Settings. To change your email address, write to privacy@klipstack.com.
  • Delete it: delete your account in Settings.
  • Anything else, such as asking what we hold about you or objecting to a use: write to privacy@klipstack.com. We answer within 30 days.

You can also complain to the data protection authority where you live.

10.How we protect it

All traffic is encrypted (HTTPS). Passwords and API keys are stored only as hashes. Images from your saved pages are private and reach only your account. Backups are encrypted, and the key to read them is kept offline. Only the people who run Klipstack can reach the servers.

No system is perfectly secure. If a breach puts your data at risk, we will tell you and the authorities, as the law requires.

11.Children

Klipstack is not meant for anyone under 16. We don't knowingly collect their data.

12.Changes to this policy

When this policy changes, we update the date at the top. If a change affects how we use your data, we email you before it applies.