§ Plain English · No dark patterns

Privacy,
in English.

Effective 27.May.2026
Version 1.0 · v0.5 (pre-launch)
Controller Kledon, Greece 🇬🇷
TL;DR — the four sentences that matter

If you only read one box,
read this one.

~30s read
  • We collect what we need to send you a brief. Your email, the tickers you watch, and basic app usage. That's it.
  • We do not sell, rent, or share your data with advertisers. There are no ad SDKs in the app. There never will be.
  • You can delete everything in one tap. One email to hello@kledon.app and your account, watchlist and history are gone within 7 days.
  • We don't connect to your brokerage. Kledon never sees your balance, holdings, or trades. You type tickers in; we read public news.
§ 01

Who we are.

Kledon is a small product team building a daily ETF brief for long-horizon retail investors. We're based in Greece, and we're the data controller for everything described below.

The operating entity is in the process of being incorporated in Greece. Until then Kledon is run by its founder, who acts as the data controller. You can reach us any time at hello@kledon.app.

This policy covers our marketing site (kledon.app) and the Kledon iOS & Android apps once they launch. It does not cover anything you read at the news outlets we link to — those are governed by their own policies.

Kledon is built for adults making their own investment decisions — you must be 18 or older to sign up.

If you'd rather skim than read, the TL;DR card above is honest. If you want the line-by-line, keep going.

§ 02

What we collect.

We try to collect as little as possible. Here's the full list, and whether it's required for the product to work or optional.

Field
What it is
Status
Email address
So we can deliver the brief and the launch invite.
Required
Watchlist tickers
The ETF symbols you choose to follow. Public tickers, not holdings.
Required
Push token
An anonymous device identifier issued by Apple/Google so we can send your morning brief.
Optional
Brief read state
Which briefs you opened, so we can stop re-notifying you about the same day.
Required
Country & locale
For currency display (€, $, £) and quiet hours timezone. Inferred from your device.
Optional
Subscription & payment status
Your plan (free or premium) and a payment reference from our processor. We never see or store your card number.
If you subscribe
!What we do not collect. No brokerage credentials, no portfolio balances, no trade history, no card numbers (your card is handled entirely by our payment processor), no contacts, no location beyond country, no microphone, no camera, no biometric data, no advertising IDs. We don't read your photos. We don't track you across other apps.

Usage analytics. We collect anonymous, first-party information about how the Kledon app is used — which screens are viewed and which actions are taken (for example, adding a ticker or opening a daily read) — to understand where people get stuck and to improve the product. This data is stored on our own EU-hosted infrastructure, is never sold or shared with third parties, and you can turn it off any time under Settings → Privacy.

§ 03

Why we collect it.

Under GDPR we need a legal basis for each kind of processing. Ours boils down to two:

  • Contract. If you sign up for the brief, we need your email and watchlist to actually send it. That's not optional — without them there's no product. If you subscribe, we also use your details to take payment and manage your subscription.
  • Legitimate interest. Aggregated, anonymous usage stats so we can fix bugs and decide which features to build next. We never use these to profile you.

We do not run ads, we do not sell ads, and we do not use your data to train external models. The summaries inside Kledon are generated from public news — never from your personal data.

§ 04

Who else sees it.

We use a small number of standard infrastructure providers ("subprocessors"). They're listed in full here, what they do, and where they sit:

  • Supabase (EU, Frankfurt) — database & authentication. Your email and watchlist live here.
  • Resend (US/EU) — transactional email. The launch invite, the morning digest, and your sign-in links.
  • Apple Push Notification Service / Firebase Cloud Messaging — to deliver the lockscreen push. Apple and Google see a push token, not your email.
  • Vercel (US, with EU regions) — hosting, serverless functions, and privacy-friendly analytics. No cookies, no cross-site tracking.
  • Viva Wallet (Greece, EU) — our payment processor. Viva handles your card details directly; Kledon only stores a payment reference and your subscription status.

That's the whole list. We do not share your data with advertising networks, data brokers, or social platforms. The brief summaries are generated by an LLM (Anthropic, US) from public news only — none of your personal data is ever sent to it. For our US-based providers, transfers rely on the EU Standard Contractual Clauses. If we ever need to add another provider, we'll update this page before they go live.

§ 05

Your rights.

If you're in the EU/EEA, UK, or Switzerland, GDPR gives you a set of rights over your data. Most of them are reasonable everywhere else too, and we honour them globally.

01 · ACCESS

See what we have

Ask for a copy of everything we store about you. We'll send it as a JSON file within 30 days.

02 · RECTIFY

Fix what's wrong

Most fields you can edit in Settings yourself. For anything you can't reach, just email us.

03 · ERASE

Delete everything

One tap in Settings → Delete account, or one email. Everything is purged within 7 days; backups within 30.

04 · PORTABILITY

Take it elsewhere

Your data export comes as machine-readable JSON. Move it wherever you want, no lock-in.

05 · OBJECT

Opt out of processing

We process very little under legitimate interest, and our analytics are anonymous. If you still want to object, email us — the product keeps working.

06 · COMPLAIN

Lodge a complaint

If we've done something wrong, the Hellenic Data Protection Authority (dpa.gr) is your supervisor.

To exercise any of these, email hello@kledon.app from the address tied to your account. We answer within seven days, usually faster.

§ 06

How long we keep it.

The shortest possible time that still makes the product useful.

  • Active accounts. Kept while your account is open. Stop using Kledon for 18 months and we'll email you, then delete the account if you don't reply.
  • Deleted accounts. Hard-deleted within 7 days of you asking. Backup copies expire within 30 more.
  • Waitlist signups (right now). If you've given us your email pre-launch and don't end up signing up, we delete it 90 days after launch.
  • Payment records. Kept as long as Greek tax law requires (typically 5 years), even after you delete your account — we're legally obliged to retain invoices.
  • Anonymous analytics. Site analytics roll up in aggregate and aren't tied to you.
§ 07

Security.

Standard practice, nothing exotic: TLS everywhere, secrets in a managed vault, database encrypted at rest, principle of least privilege on the backend. Sign-in is passwordless — magic links and Apple/Google sign-in — so there's no password for anyone to steal or for us to leak. Two people on the team have production access; everything they do is logged.

If something does go wrong and your data is exposed, we'll email you within 72 hours of becoming aware of it — alongside the regulator, as the law requires.

§ 08

Cookies & tracking.

This site uses one cookie, and only after you sign in: a session token so the server knows you're you. There are no marketing cookies, no Facebook pixel, no Google Analytics, no fingerprinting, no cross-site trackers.

Our analytics provider, Vercel, runs without cookies — it counts page views using anonymised signals and stores nothing that identifies you. There's nothing to opt out of because nothing about you is stored.

§ 09

Changes & contact.

If we materially change this policy — adding a subprocessor, collecting a new field, changing a retention window — we'll email everyone on the list and put a banner on the home page for 30 days. Cosmetic edits (fixing a typo, restructuring a paragraph) don't get an email.

Privacy questions, GDPR requests, suspected breaches, anything else — write to hello@kledon.app. There's a human on the other end. We answer within seven days, usually within one.

Last updated 27 May 2026. Effective immediately for all new signups; existing users notified by email.

Still have questions?

We're a small team and we read every email. Ask anything — what we store, why, how to get rid of it. We answer within a day.