Skip to main content
Security and privacy

Your words stay with you

Klaavi predicts locally, on your computer. Text you enter in other applications is not sent to a server to generate suggestions.

Below, we explain the most important safeguards in plain language. No scare tactics and no promises beyond what Klaavi actually does.

Our core rule

Suggestions are created locally

Klaavi learns the way you write on your computer. Suggestions, personalization history and your personal dictionary all work locally. We do not send sentences to the cloud to analyse them or generate suggestions there.

Figures shown in the application, such as clicks saved, are calculated locally. Klaavi does not continuously report what you click, how long you type or which words you use.

What you type in other applications helps Klaavi work locally — it is not used to build a language profile on our server.

Online only when needed

Every connection has a specific purpose

Klaavi does not need the internet for typing itself. It connects in a few clearly defined situations.

When Klaavi uses the internet Closed scope

Account, trial and licence

Email-code sign-in, trial activation and periodic PRO entitlement checks. Your typing content and local dictionary are not part of these requests.

klaavi.app

Updates and language packs

Checking for a signed application release and downloading a language you choose.

assets.klaavi.app

Feedback you choose to send

An answer or comment reaches the Platform only after you select the send button.

klaavi.app

Payments

Checkout and the subscription portal open in your browser and are handled by Paddle.

Paddle
Every category of connection has one documented purpose.

Klaavi PRO works offline between periodic licence checks. It currently keeps PRO access for seven days after the last successful verification. After that, core FREE functions continue to work, and PRO returns after the next connection.

Local data

Your dictionary lives on your disk. Encrypted.

Klaavi protects local data with authenticated AES-256-GCM encryption. The key is protected by Windows mechanisms and tied to your system account.

Phrases, panels, settings and personalization remain local. We do not automatically synchronize them through our cloud.

When you want to move your data to another computer, you export it to one file protected with a password you choose. Klaavi does not store that password and cannot recover it.

Control in your hands

Private Mode stops learning with one switch

Sometimes you simply do not want the keyboard to remember anything. Enable Private Mode in settings or assign it to your own panel. Klaavi immediately pauses learning new data and hides suggestions based on local history.

The mode stays active after restarting the application until you turn it off. It does not delete earlier history — it keeps it encrypted and makes it available again when Private Mode is disabled.

Protecting secrets

Klaavi also knows what it should not learn

Password fields. Klaavi uses information exposed by Windows. When it recognizes a protected field, it does not show suggestions and does not add the entered content to personalization history.

Sensitive-data filter. Before adding new content to the local dictionary, Klaavi rejects many common patterns, including email addresses, web addresses, card numbers, IBANs, Polish PESEL numbers, access keys, one-time codes and random strings that resemble tokens.

The filter is an additional layer of protection, not a promise to recognize every possible secret. Use Private Mode whenever you need complete discretion.

Integrity

Signed and checked before installation

Installer and updates. Klaavi uses signed release information, verifies the installer's digital signature and compares the downloaded file's SHA-256 with the expected value. If something does not match, the update is not launched.

Language packs. Every pack has a signature and hash. Installation is transactional: a new version becomes active only after download and verification complete successfully.

Additional components. The application runs only components that comply with a closed set of rules and recognized signatures.

Application design

Built defensively

The keyboard interface runs in a sandbox, without direct access to Node.js, the operating system or arbitrary files. It can only use a narrow, explicitly defined set of operations exposed by the main process.

Klaavi does not open arbitrary links. Every external address must match an allowed operation, host, path and expected parameters.

Before a release, automated tests cover areas including the sandbox, inter-process communication, updates, signatures and the external URL policy. We also inspect the dependencies used by the application.

Account and device

An account without a traditional password

You sign in to Klaavi using a one-time code sent by email. The code is stored on our side as an irreversible hash, has a limited lifetime and is protected by attempt limits.

The token that lets the application remain connected to your account is also stored by the Platform only as a hash.

Klaavi assigns a random identifier to the installation. Separately, to prevent repeated free trials on the same computer, it creates a one-way hash locally from a Windows identifier. The raw Windows identifier is never sent to the Platform.

Servers and infrastructure providers may process an IP address in standard security logs. We do not use it to analyse typing content or build a user language profile. The Privacy Policy describes this processing in more detail.

Payments

Full card details do not reach Klaavi

Checkout, payments, invoices and the subscription portal are handled by Paddle. You enter card details on Paddle pages. Klaavi receives only the information needed to assign and manage the subscription, not the full card number.

Your decision

Feedback is sent only after your click

Klaavi may occasionally ask for feedback. Until you select the send button, answers stay in the open form and are not passed to the Platform.

If delivery cannot complete immediately, the answer you approved may be placed in an encrypted local queue and sent later. Do not include passwords, health information or other particularly sensitive data in a comment.

The application and website are separate layers

What happens on klaavi.app

This page primarily describes the desktop application. The klaavi.app website uses Plausible to measure page views and selected events without creating a profile of your typing content. Crisp chat is loaded only after you select the chat button.

The exact scope, legal bases, recipients and retention periods are described in our Privacy Policy and Cookie Policy.

Working together

Found a security issue? Tell us.

Email [email protected]. We take good-faith reports seriously and respond as quickly as we can.

Questions and answers

Common questions

Does Klaavi send what I type to the cloud?

It does not send typing content for remote suggestion generation. Prediction and personalization run locally on your computer.

Can I use Klaavi without the internet?

Yes. Typing and FREE features work locally. PRO remains active for seven days after the last successful licence verification and returns after the next connection.

What happens to my dictionary after switching to FREE?

It does not disappear. It stays encrypted on disk. Features that use full personalization return when you activate PRO again.

Can I stop learning without deleting my history?

Yes. Enable Private Mode. Klaavi stops remembering new data and hides history-based suggestions while keeping earlier personalization encrypted.

Is Klaavi designed around GDPR principles?

We design Klaavi around data minimization and privacy by design. The full description of processing and user rights is available in the Privacy Policy.

Last updated: 5 August 2026