Legal & Trust
Trust Center
Privacy, security, responsible AI, and transparency.
Trust Center
Welcome. This page exists to help you understand how Klugliv uses data, how we protect it, and what we’re improving over time.
If something is unclear, please reach out via hello@klugliv.com.
Our principles
Klugliv is designed to be privacy-first and security-first. We explain our system in plain language and we update this Trust Center when our architecture changes.
Privacy first
Our Privacy Policy is the public explanation of what data we collect and why:
Security
We protect data using encryption, least-privilege access controls, and controlled logging. Where relevant, we describe our retention approach and incident handling here:
Cloud architecture
In the current product slice, Klugliv uses a hybrid architecture:
- Mobile app (Expo / React Native)
- Marketing website (Vercel)
- Product data and auth (Supabase)
- OCR pipeline on AWS (API Gateway + Lambda) with Secrets Manager and KMS
- Encrypted receipt images and controlled storage (Supabase Storage today; S3 dual-write in the migration slice)
This page focuses on user trust. For engineering-oriented details, see our engineering playbook and ADRs as they mature.
Responsible AI
Klugliv’s “AI” in early stages is receipt OCR and receipt understanding. We do not present OCR output as truth without review.
Full detail: Responsible AI
We:
- parse receipts into structured fields
- let you correct OCR outcomes before they influence your saved history
- document our OCR pipeline and third parties for transparency
Receipt intelligence
Receipt intelligence is designed to be:
- understandable: you can review what was extracted
- correctable: you can remove or adjust receipt lines
- tied to your data: insights are based on what you store in your account
Transparency
We keep transparency up to date with:
- this Trust Center
- the Vendor Register and Subprocessors
- the Incident Response procedures
- the Risk Register and Launch Compliance Checklist
Accessibility
Compliance
We do a GDPR readiness review and we keep a clear record of gaps and next actions:
Your data
You can request data-related actions in the mobile app under Settings → Trust & privacy, or via the procedures described here:
Roadmap
We treat trust work as an engineering capability. Self-service data export and account deletion are available in the mobile app under Trust & privacy.