Legal
Privacy Policy
This policy explains what personal data we collect through this website, why we collect it, how long we keep it and what rights you have.
Last updated: 21 August 2026
Who we are
Klyro Digital Ltd (Registered in England & Wales, company number 17407496) operates klyro-digital.com and is the data controller for the personal data described in this policy. You can reach us through our contact form.
Customer accounts
You do not need an account to use this website. The free tools and the service request form work without one, and we never create an account from a service request — that is always something you ask for.
If you do have an account, we hold:
- your name, the email address the account uses, and your company name if you gave one;
- your password, stored only as an Argon2id hash. We cannot read it, and nobody at Klyro can tell you what it is;
- the service requests linked to your account, and their history;
- the orders placed for you, including the price agreed at the time;
- your support tickets, the messages on them and any files you attached — described in more detail below;
- which plan the account is on, and anything you have chosen to save from the tools while on a Klyro Pro plan;
- the account activity shown on your dashboard — when a request was submitted, when its status changed, when an order was confirmed or delivered;
- when the account was created, when it was last used to log in, and whether the email address has been verified.
We also keep short-lived security records so the account system works safely: an identifier for each active login session, single-use tokens for email verification and password resets, and server log lines noting that a login attempt, a successful login or a password reset happened. Those log lines never contain a password, a token or a session cookie.
Account details are used to run your account and nothing else. We do not profile you, we do not sell anything, and having an account does not put you on a mailing list.
Service emails
We use your email address to send service messages about things you have asked us to do: verifying your address, resetting your password, confirming a service request, telling you an order has moved on, letting you know we have replied to a support ticket, confirming a change to your plan, and sending you an invoice or telling you one has been paid or voided. These are not marketing messages and there is no mailing list to leave — we send nothing else.
A message is sent through an email delivery provider acting on our instructions, which receives the address, the subject and the content of that message in order to deliver it. We keep a delivery record of when a message was attempted, who it was addressed to, which message it was, which record it concerned and whether the provider accepted it. That record holds no verification or reset link and no message content. We do not use tracking pixels, so we do not know whether you opened a message or clicked a link in it.
Work you save to your account
The free tools do not save anything. If you are signed in on Klyro Pro, some tools let you choose to save what you are working on to your account — a website report, a workflow, a campaign, a schedule, a snippet. Nothing is saved because you typed it: it is saved when you press Save, and using a tool signed out, or signed in without saving, stores nothing at all.
A saved item holds the name you gave it, which tool it came from, the dates it was created, changed and last opened, and the content of that piece of work itself — the structured data the tool needs to open it again. Some tools deliberately save less than you might expect: the image compressor saves your settings and never your images, and the CSV converter saves your column and format choices and never the data you pasted.
Saved work belongs to one account. It is readable only by you while signed in, it is never public, and there is no sharing link. If your Pro access ends we keep what you saved rather than deleting it, so it is still there if you come back; you can delete any saved item yourself at any time, permanently, from Saved Work.
Billing details and invoices
If we invoice you for work, we hold the billing details you enter in your account: whether you are billing as an individual or a company, the name or company name to bill, a billing email address, a postal address, and a VAT or tax number if you give one. We record a tax number as you supply it and do not verify it against any register.
Each invoice we issue holds the invoice number, what it is for, the amounts, the currency, its dates and its status, and the order or plan it relates to. An issued invoice also keeps a copy of the billing details as they were on the day it was issued, because an invoice has to stay a record of what it said at the time; changing your billing details changes future invoices, not ones already issued.
Invoices are business and accounting records, so we keep them for the periods set out below even if you close your account. Your invoices and their PDFs are available only to you while signed in, and to Klyro staff handling your account. We take no payments on this website: there is no checkout, no card form and no stored payment method, and we hold no card or bank details. Where an invoice is marked paid, that is our own record that payment reached us, together with any reference we noted.
Support tickets
If you open a support ticket from your account, we hold the ticket itself and the conversation on it: the subject, the category you chose, its status, the order or service request you linked it to if you linked one, and the date it was opened and last updated.
Each message in the conversation is stored with who wrote it and when. That includes replies from Klyro. Some notes written by our staff are internal working notes and are not shown to you; they are held against the same ticket and are used only to handle your request.
If you attach a file, we store the file itself, its original filename, its type and its size. Attachments are held in a private area of our server, outside anything the web serves publicly, under a randomly generated name. They can only be downloaded by you while signed in to the account the ticket belongs to, and by Klyro staff handling it.
Support records are business records. If you ask us to close your account we will not automatically delete them, because we may need to keep a record of work discussed and delivered; the retention periods below apply.
Information you send through our forms
The contact form is for general questions. It receives the name and email address you enter, your company name and website address if you give them, and the content of your message. We use those only to answer you.
The service request form is separate, and asks the questions the service you chose actually needs. It receives your name, email address and company name if you give one, which service you are asking about, and your answers to that service's questions. We use those to scope and deliver the work. If you were signed in when you sent it, the request is linked to your account so you can follow it on your dashboard; if you were not, it is stored against the reference you were shown, and you can link it to an account later.
Submissions are stored on the server that runs this website. We do not sell them, and we do not add you to a mailing list.
Using the free tools
The free tools need no account and no sign-up. They fall into two groups, and which group a tool is in decides entirely what happens to what you put into it. Every tool page states which of the two it is.
Tools that run on our server
The website and technical checks — the website health check, HTTP status check, redirect check, certificate check and the SEO meta check — work by asking you for a public web address and then fetching that address from our server.
- What we receive is the address you entered, and what our server reads back from it.
- Both are used only to build the result shown on your screen. They are not written to a database, not saved as a report, and not linked to you or to any account.
- These tools take a public address, not credentials. Do not enter a password, a private link or anything confidential into them.
To stop these checks being used in bulk, we hold recent request times against your IP address in the server's memory. That is temporary, is not written to disk by the application, and is cleared when the process restarts.
Saved work on a Klyro Pro account
Anonymous use of the free tools is not stored. Nothing you type into a tool is kept, whether it runs in your browser or on our server, unless you are signed in and choose to save it.
On a Klyro Pro account you can save selected tool output and settings to your account — a batch of check results, a set of campaign parameters, a saved preset. When you do, we store what you saved, the name you gave it, which tool it belongs to and when it was created and last changed. It is visible only to you, and you can delete any of it from the tool it was saved in.
Saving is always a deliberate action. Running a tool never saves anything on its own, on any plan.
Tools that run in your browser
The remaining tools — the business, design and media, automation and operations, marketing and developer utilities — do their work in the page itself. That covers document generation, image processing, colour contrast calculation, JSON and CSV formatting and conversion, schedule building, workflow mapping and link and code building.
- Nothing you type, paste or upload into them is sent to us. There is no request to our server carrying it, so we never receive it and cannot store it.
- Files these tools produce — a PDF, an image, an exported diagram — are created on your own device and downloaded from it.
- The workflow mapper keeps your working draft in your browser's local storage so it survives a page reload. That stays on your device, is not sent to us, and clearing your browser data removes it.
Requesting a tool page produces a normal web server log line, described below, in the same way as any other page. That records the request, never the contents of the tool.
Server logs
Our web server keeps standard access logs. These record the IP address of the request, the date and time, the address requested, the response code and the browser user-agent string. They are used to keep the site running and secure, and to investigate faults or abuse. Logs are rotated and deleted by the server on a rolling basis.
Cookies and analytics
We use no analytics, advertising or tracking services, and set no cookie for those purposes. There are no tracking pixels, no advertising tags and no third-party marketing cookies on this website. Fonts are served from our own server, so viewing a page does not send a request to any third party.
There is exactly one cookie, and only signed-in visitors ever receive it:
klyro_session— strictly necessary, authentication. Set when you log in, and only then. It keeps you securely signed in as you move between pages of your account. It is required for the account area to work at all, and it is not used for advertising, profiling or behavioural tracking.- It contains a random token and nothing else — no name, no email address and no information about you. The token is meaningless on its own; the session it refers to is held on our server.
- It is marked
HttpOnly(unreadable by scripts in the page),Secure(sent over HTTPS only) andSameSite=Lax(not sent from other websites). It expires after 30 days, and is extended while the account is in use. - Signing out deletes it and ends the session on the server, so the token cannot be reused afterwards. Changing your password ends your other sessions in the same way.
Because this cookie is strictly necessary to provide the account service you asked for, it does not require consent, and there is no cookie banner. Browsing the public site, using the free tools and sending a request all work without ever setting it.
Service enquiries and orders
If you order a fixed-price service or commission a project, we will hold the correspondence and the records needed to deliver the work, raise an invoice and meet our accounting obligations. Where a website address or access credentials are needed to carry out the work, we use them only for that work.
Third parties we rely on
- Our hosting provider. The website and its data sit on a virtual server we rent. The provider can technically access the server as part of running the infrastructure.
- The websites you ask us to check. When you use a checking tool, our server makes a request to the address you entered. That site's own logs will record the request as coming from our server, not from you.
We use an email delivery provider to send the service messages described above. We do not use a third-party email marketing platform, CRM or analytics provider for this website. If that changes, this policy will be updated first.
Legal basis
We process contact-form data on the basis of taking steps at your request before entering into a contract, and to perform that contract if you place an order. Server logs and rate-limiting are processed on the basis of our legitimate interest in keeping the site available and secure. Records kept for accounting are processed to meet a legal obligation.
How long we keep it
- Enquiries that do not lead to work: kept for up to 12 months, then deleted.
- Records relating to paid work: kept for six years after the end of the relevant financial year, as UK tax rules require.
- Support tickets and their attachments: kept alongside the request or order they relate to, and for up to 12 months where they relate to nothing else.
- Work you saved from the tools: kept until you delete it or close the account.
- Server access logs: rotated and deleted on a rolling basis.
Your rights
Under UK data protection law you can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict how we use it, object to our use of it, or ask for it in a portable format. Contact us through the contact form and we will respond within one month.
If you are not satisfied with our response you can complain to the Information Commissioner's Office at ico.org.uk.
Changes to this policy
If we change how we handle personal data we will update this page and the date shown at the top of it.