Privacy policy and legal documents for the KlickBox iOS app.
Last updated: 2026-08-02 Operator: Mohammad Soltaniehha (“we”, “us”) Contact: soltaniehha.m@gmail.com
KlickBox is a personal task manager. We designed it to keep your data yours. This policy explains exactly what we collect, what we do with it, and how to delete it.
| Data | Why | Where it’s stored |
|---|---|---|
| Apple ID identifier | To authenticate you with Sign in with Apple and isolate your tasks from other users. | Supabase (US region). |
| Email address (only if you choose to share it via Sign in with Apple) | So we can contact you about your account if needed. | Supabase (US region). |
| Content you create — Tasks (titles, notes, tags, due dates, scores) and Ideas (notes, quotes, links, and the Projects you file them under) | This is the product — we cannot show you your tasks and ideas without storing them. | Supabase (US region). |
| Attachments you add to a task, a comment, or an idea (photos, audio recordings you make in the app, PDFs, files) | So your attachments persist across devices. | Supabase Storage (US region). |
| Debrief audio and transcripts (in transit only) | Your own AI agent records spoken Debriefs for you; our Mailbox carries them to your phone. | Supabase Storage (US region), as transport only — deleted once your phone confirms pickup, and swept after 30 days even if never collected. The durable copy lives on your own iCloud Drive, not our servers (see below). |
| Voice Replies (in transit only) | Voice notes you record in the app for your own AI agent to collect. | Supabase Storage (US region), as transport only — deleted once your agent confirms pickup, and swept after 30 days even if never collected. |
| API Key (hashed) | To authorize your own AI agent (OpenClaw, Claude Code, Claude Cowork, Codex, or any other agent you deploy) to read and write your tasks. | Supabase (US region). The plaintext key is shown to you once at creation and never stored in plaintext on our servers. We also record when a key was last used and how many requests it has made, so you can spot a key being used without your knowledge and so we can rate-limit it. |
Reminders / notifications. KlickBox uses local notifications only — the app schedules reminders on your device. We do not collect a push notification token and we do not run a remote push server. If we add server-side push in a future version, we will update this policy first.
Your own AI agent can record spoken Debriefs for you, and you can answer with recorded Voice Replies. Both travel through a server-side Mailbox that is transport, never storage:
KlickBox/Debriefs/), on your iCloud quota, under Apple’s iCloud terms. If iCloud Drive is off, they are kept in the app’s private storage on your device instead. Neither copy is on our servers.IDFA or App Tracking Transparency permission. We do not advertise.All KlickBox data is stored in Supabase, hosted in the United States. Supabase encrypts data at rest and in transit. We use Postgres Row-Level Security (RLS) so that every database query is constrained to your user ID at the database level — not just at the application level.
KlickBox supports an optional integration with any AI agent you deploy and run on infrastructure you control — OpenClaw (our open-source reference agent), Claude Code, Claude Cowork, Codex, or any other model that can read documentation and call an HTTP API. If you generate an API Key in Settings and paste it into your agent, that agent can read and modify your KlickBox Tasks, Tags, Comments, Checklists, and Attachments on your behalf — exactly the same operations you can perform yourself. We do not host any agent, we do not see what prompts you send it, and we do not control where it runs.
The API Key is the sole authorization for this access. You can revoke it at any time in Settings → API Key → Rotate (or by signing out), which immediately ends the agent’s access. We never share your API Key plaintext with anyone — we don’t have it; only its hash is stored.
We keep your data until you delete it. There is no automatic purge of completed tasks, deferred tasks, or archived attachments. The one exception is the Mailbox: Debriefs and Voice Replies in transit are deleted on pickup and swept at 30 days, as described above — that purge protects you, since nothing is meant to persist there. If you delete your account, all data tied to your user ID is removed within 30 days from primary storage and within 90 days from encrypted backups.
You can delete your account from inside KlickBox: Settings → Account → Delete Account. The deletion is processed immediately on the primary database; encrypted backup rotation completes within 90 days. After deletion you cannot recover your data.
If you cannot access the app, email soltaniehha.m@gmail.com from the email tied to your Apple ID and we will process the deletion manually within 7 business days.
KlickBox is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe we have, contact soltaniehha.m@gmail.com and we will delete it.
We use industry-standard encryption in transit (TLS 1.2+) and at rest, Postgres RLS for authorization, and short-lived JWTs for app sessions. No system is perfectly secure — if you discover a vulnerability, please email soltaniehha.m@gmail.com.
If we change this policy, we will update the Last updated date at the top, and (if the changes are material) notify you in-app on next launch.