Legal
Privacy Policy
Last updated: June 4, 2026
Klaapy is developed and operated by Merkava Studio ("we", "our"). This policy explains what data we collect when you use klaapy.com, how we use it, and what rights you have over it.
If you have questions, write to us at hello@merkavastudio.com.
1. Data we collect
1.1 Data you provide us
- Email address — when you sign up with a magic link. It's your unique identifier on Klaapy.
- Post content — the copy, images, and videos you upload to publish on Instagram or Facebook.
- Workspace settings — workspace name, roles assigned to team members.
1.2 Data we obtain from Meta
When you connect your Facebook or Instagram account via OAuth, Meta grants us an access token that we store encrypted. With this token we read and write:
- Facebook Pages and Instagram Business accounts linked to your profile.
- Comments and messages on your posts (for the unified Inbox).
- Performance metrics of your posts (reach, impressions, engagement).
- Basic follower information (for Audience Intelligence).
We do not permanently store data about your followers. It's processed to calculate quality scores and then discarded.
1.3 Data we generate while you use the service
- CAFS Score and quality metrics calculated for each post.
- Publishing logs and the status of each attempt.
- IP address and device type (for security and diagnostics).
2. How we use your data
- To provide the service — authenticate you, publish on your behalf, calculate scores, and show you metrics.
- To improve Klaapy — analyze aggregated, anonymous usage patterns to prioritize the roadmap.
- Transactional communications — send you magic links, critical error notifications, or important service changes.
- Legal compliance — retain records when the law requires it.
We do not use your data for third-party advertising. We do not sell your information.
3. Third parties with access to your data
| Provider | Purpose | Data shared |
|---|---|---|
| Meta Platforms | Publishing and reading content | Post content, OAuth token |
| Anthropic (Claude) | Generating AI suggestions and variants | Post copy (no personally identifiable data) |
| Amazon Web Services | Server hosting and storage | All data (encrypted at rest) |
4. Security
- Meta tokens are stored encrypted with Fernet (AES-128-CBC).
- All communications use HTTPS/TLS 1.2 or higher.
- Authentication is via a single-use magic link (15-minute validity) or an optional password. Passwords are stored with bcrypt hashing; never in plain text.
- Servers are hosted on AWS (us-east region) with access restricted by IP and SSH key.
5. Data retention
- Active account — we keep your data while the account is active.
- Cancelled account — we delete your personal data 30 days after cancellation. Posts already published on Meta remain on Meta, not on Klaapy.
- Meta tokens — deleted immediately when you disconnect your account from Settings.
6. Your rights
You have the right to:
- Access the data we hold about you.
- Rectify incorrect information.
- Delete your account and all your data.
- Portability — request an export of your data in JSON or CSV format.
- Revoke Klaapy's access to your Meta account at any time from Settings.
To exercise any of these rights, write to us at hello@merkavastudio.com with the subject "Privacy — [type of request]". We respond within a maximum of 72 business hours.
7. Minors
Klaapy is not directed at individuals under 18 years of age. If we detect that a minor has created an account, we will delete it immediately.
8. Changes to this policy
If we make material changes, we'll notify you by email at least 15 days in advance. Continued use of the service after the effective date implies acceptance of the changes.
9. Contact
Merkava Studio / Klaapy
hello@merkavastudio.com
