Privacy policy

Version française

How we handle your data.

Last updated: 19 May 2026.

1 · In short

Kleym is a B2B tool that helps UGC creators track the delivery of their videos in Meta's public Ad Library. To work, Kleym needs a few pieces of data about you: your email for your account, the brands you choose to track, the usage rights terms you enter, and, if you subscribe to a paid plan, the billing information needed for payment. No analytics, no ad tracking, no data resale.

2 · Who is the data controller

The controller of your data is The Browz, the agency that publishes Kleym, registered in France.

For any question about your data or this policy, write to: dpo@kleym.app.

3 · What data we collect

A few categories, and nothing more:

Account data

  • Email address (used as your identifier)
  • First and last name
  • Password (never in plain text: hashed with a state-of-the-art key derivation algorithm)
  • Session identifier, duration and sign-in IP address

Business profile data

  • Cost per video, rights billing model, default rights duration
  • Approximate monthly volume, language, region
  • Alert preferences

Brand tracking data

  • Brands you add (Meta page identifier, display name, logo)
  • Ads you pin, the rights duration you assign to them, optional notes
  • A local cache of the ads' public metadata (snippet, delivery dates, thumbnail) from the Meta Ad Library

Billing data (paid plans)

  • Subscribed plan, billing cycle, subscription status and payment history
  • Billing details passed to our payment provider (name, email, country, VAT or company number if you provide one)
  • Customer and payment references at Stripe (never your full card number, which we never see)

What we do not collect: no ad-tracking cookies, no third-party analytics, no precise geolocation data, no sensitive data within the meaning of the GDPR.

4 · Why we collect this data

Each piece of data serves a specific purpose:

  • Identification & sign-in: to give you access to your account.
  • Providing the service: calculating rights overruns, showing your estimated losses, monitoring the brands you added.
  • Security: detecting unauthorised access, limiting abuse.
  • Transactional communication: email verification, alerts about your account.

5 · Legal basis

  • Performance of the contract (art. 6(1)(b) GDPR): for everything needed to run Kleym.
  • Legitimate interest (art. 6(1)(f) GDPR): for security and fraud prevention.
  • Consent (art. 6(1)(a) GDPR): for any communication that is not strictly necessary (never used in V0).

6 · Who sees your data (processors)

To run, Kleym relies on three technical providers. No one else has access to your data.

Cloudflare, Inc.

Hosts our database (D1), our thumbnail storage (R2) and runs the application itself (Workers). Cloudflare's security and GDPR commitments: cloudflare.com/trust-hub. Data is stored primarily in data centres in the European Union.

Meta Platforms, Inc.

Kleym queries the Meta Ad Library, Meta's public ad transparency database, to retrieve the list of ads run by the brands you track. Meta sees: the brand name Kleym queries (server-side, never linked to your identity). Meta does not see: your email, your name, your rights entries, your notes. Meta Business Tools terms.

Stripe Payments Europe, Ltd.

Handles payments and billing for paid plans. Stripe receives only the data strictly needed for payment: amount, email, card details (entered directly with Stripe, never on our servers), country and VAT number if you provide one. Kleym stores no card data. Stripe is PCI DSS Level 1 certified. stripe.com/privacy.

7 · How long we keep your data

  • Active account: for as long as you use Kleym.
  • Deleted account: all your data is erased within 30 days of the deletion request (see our data deletion page).
  • Sessions: 30 rolling days, renewed at each sign-in.
  • Backups: 30 rolling days, encrypted at rest.
  • Invoices: kept for 10 years, a mandatory legal retention period under the French Commercial Code (Code de commerce, art. L.123-22).
  • Security logs: 12 months at most.

8 · Security

Passwords are hashed (never stored in plain text), connections are encrypted with TLS 1.3, database access is limited to the application service, and no local copies of user data are kept on workstations.

9 · Cookies

Kleym uses one strictly necessary cookie: your session cookie, set after you sign in. No ad trackers, no analytics tags.

On payment screens, our provider Stripe may set cookies strictly necessary for security and fraud prevention. They are never used for ad profiling.

10 · Your GDPR rights

At any time, you can:

  • Access all the data we hold about you
  • Rectify anything that is incorrect
  • Delete your account and all associated data
  • Restrict or object to certain processing
  • Request the portability of your data in a structured format
  • Leave post-mortem instructions (a French-law provision) for what happens to your data after your death

To exercise any of these rights, write to dpo@kleym.app. You will get an answer within 30 days at most (usually sooner).

11 · Complaints to a supervisory authority

If you believe your rights are not being respected, you can lodge a complaint with the French supervisory authority, the CNIL: cnil.fr/en/plaintes, or with the supervisory authority in your country of residence.

12 · Changes to this policy

If we change this policy, we update the date at the top of this page and, for any significant change, we let you know by email. Continuing to use Kleym after an update counts as acceptance of the new terms.