KlyoKlyoKlyo
Open Klyo

Privacy policy

Last updated: July 21, 2026

On this page

  1. 1. Who we are
  2. 2. What data we process and why
  3. 3. Google user data
  4. 4. Revoking access and deleting data
  5. 5. Sub-processors and hosting
  6. 6. Legal bases, retention, and your rights
  7. 7. Cookies and analytics
  8. 8. Changes to this policy

1. Who we are

Klyo is a creative production and activation platform operated by Digitl GmbH. Digitl GmbH is the controller responsible for the personal data described here. For the controller's full identity, registered address, and contact details, see the Digitl imprint. This policy covers the Klyo product and this website. Your use of Klyo is also governed by ourterms of use.

2. What data we process and why

You sign in to Klyo with a Google account only. We process the following categories of data to run the service.

  • Account data. Your Google sign-in profile: email address, display name, and profile photo URL as provided by your Google account, plus a timezone you set yourself. We use it to identify you, run your account, and record who took which action. Sign-in and identity verification run through Firebase Authentication.
  • Organization content. The campaign briefs, catalogues, uploaded assets, and the creatives Klyo generates and renders for you. We process this to run the production pipeline you use Klyo for.
  • Memberships and invites. Who belongs to your organization, their role, and the invites sent to add them.
  • Channel connection data. The connected-account records and the access you grant when you link a channel, described in the Google user data section below.
  • External reviewer contact. When your organization sends creatives out for approval, the reviewer's email address entered by the organization is stored so we can deliver the review invitation and verify the signed review link.
  • Usage records. An activity log of actions taken in the product, credit metering for paid AI and render steps, and your conversations with the in-app assistant. We use these to operate, meter, and support the service.
  • Transactional email. Records of the invites, approval requests, and notifications we send you, so we can deliver them and show their status.

3. Google user data

When you connect an advertising or hosting channel, Klyo asks Google for access through the OAuth consent screen. We only ever use this access to provide the features you start yourself. The channel-connection flow requests exactly these scopes:

  • YouTube upload (youtube.upload). Upload your organization's rendered ad video to your connected YouTube channel as a new video, so your own creative is hosted there before a Google Ads ad references it or its organic stats are tracked.
  • YouTube read-only (youtube.readonly). List the YouTube channels the signed-in Google account owns, so an admin can pick which channel Klyo uploads to and we can check the connection still works.
  • YouTube Analytics read-only (yt-analytics.readonly). Read daily per-video performance stats (views, estimated watch time, likes, comments, shares, subscribers gained) for videos Klyo uploaded, feeding your own reporting. No ad-revenue or monetary scope is requested.
  • Display & Video 360 (display-video). Requested for a future DV360 integration that would create line items and creatives on your connected advertiser. It is not active today; the connection currently gates the reporting feature and the DV360 export handoff.
  • Bid Manager reporting (doubleclickbidmanager). Run a Bid Manager reporting query to pull daily impressions, clicks, spend, and conversions for the DV360 campaigns you track, for your own reporting.
  • Google Ads (adwords). Read your accessible Google Ads accounts, campaigns, ad groups, and existing ads for the ad-group picker, and create one new, paused Demand Gen video ad in an ad group you pick, referencing your already-hosted YouTube video. It never creates campaigns or budgets, never enables an ad, and never duplicates one.
  • Campaign Manager 360 (dfatrafficking). List the CM360 profiles and advertisers the signed-in account can traffic, then upload your rendered video into the chosen advertiser's creative library and create a creative that references it, so the same video is hosted for cross-channel serving.

Separately, when you import a Google Sheet as a data feed or a file from Google Drive as an asset, Google's own file picker grants Klyo the drive.file scope, which is limited to the single file you choose. Klyo reads only that file and has no access to anything else in your Drive.

How we store and handle access tokens

Klyo requests offline access so the connection keeps working, which returns a refresh token. That token is stored in Google Secret Manager, encrypted at rest by Google Cloud, and referenced only by name. It is never written to Klyo's application database.

We do not share or sell these tokens. We do not use your Google data to build advertising profiles. No person reads your tokens or connected-account data, except where it is needed to investigate abuse or a security incident, to meet a legal obligation, or with your explicit consent.

The reporting Klyo pulls from your connected accounts is aggregate: daily counts per video or per campaign. We do not request or store per-viewer or demographic data.

Klyo's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Revoking access and deleting data

You can disconnect a connected account at any time from the connections screen in Klyo. Disconnecting revokes the token at Google and deletes the connection record from Klyo, along with any auto-activation wired to it. The revoked token's encrypted value may remain briefly in our secret storage until routine cleanup removes it, and once revoked it can no longer be used.

You can also revoke Klyo's access directly from yourGoogle account permissions.

To delete your account or your organization's data, contact us through the details in the Digitl imprint. We remove the data unless we are required to keep it to meet a legal obligation.

5. Sub-processors and hosting

We rely on a small set of providers to run the service.

  • Google Cloud. Hosting, database, and secret storage in EU regions (europe-west1 and europe-west3). AI inference (the Gemini and Veo models behind storyboards, images, voice, and the assistant) runs on Google's global Vertex AI endpoint and is not pinned to the EU today; we are working to confirm EU-only placement for this workload.
  • Creatomate. Our render partner, which assembles the final video or image from your template and content.
  • Transactional email over SMTP. We send invites, approval requests, and notifications through an SMTP email service.

6. Legal bases, retention, and your rights

Under the GDPR, we process your data on these legal bases: performance of a contract with you or your organization (Art. 6(1)(b)), our legitimate interest in operating and securing the service (Art. 6(1)(f)), and your consent where it applies (Art. 6(1)(a)).

We keep personal data for as long as your organization's account exists, or longer where the law requires us to retain it.

You have the right to access your data, to have it corrected or erased, to receive a portable copy, and to object to certain processing. You also have the right to lodge a complaint with a data protection supervisory authority.

7. Cookies and analytics

This website sets no analytics cookies and runs no tracking. The Klyo product itself uses only the technically required session state needed to keep you signed in. If we enable analytics later, we will update this policy before doing so.

8. Changes to this policy

We may update this policy as the product and its data practices change. When we make a material change, we will reflect it here and update the "Last updated" date at the top of the page.

Back to top

Klyo is a product of Digitl GmbH

Privacy policyTerms of useImprintDigitlDocumentation