Legal
Cookie Policy
Last reviewed: September 16, 2026
This page lists every cookie and every piece of browser storage klawusa.org uses, what each one is for, how long it lasts, and how to say no. The tables are generated from the same code that sets them, so what you read here is what the site does. The Privacy Policy covers everything else we collect.
1.Who we are
Klaw is run by Penusila Digital Solutions LLC, which is the data controller for everything described on this page. Klaw is an identity-protection service: it checks whether your email address appears in known breaches, watches for new exposure, and helps remove your details from data brokers.
Data controller
Penusila Digital Solutions LLC
Mailing address available on request by email.
Cookie and privacy questions: privacy@klawusa.org
Everything else: help@klawusa.org
3.What we set and why
Everything the site stores, grouped the way the Cookie preferences panel groups it, so the switch you press and the table you read are the same thing. “First party” means our own code, or the Base44 platform SDK acting for us against our own backend. “Third party” means another company can read it. A row marked only with consent is not written at all until you allow the group it belongs to.
Strictly necessary — always on
Keeps you signed in, tells the app where our backend is, remembers this cookie choice itself, and — on the two screens that need it — protects your account with two-factor verification and your card payment with Stripe’s fraud checks.
There is nothing to switch off here: without these the site cannot sign you in, cannot complete a payment you asked to make, and cannot even remember that you said no to everything else.
Strictly necessary
The site does not work without these: your sign-in session, the settings the app needs to reach our backend, and your cookie choice itself. We do not ask before setting them because there is no meaningful alternative to offer — the only way to avoid them is not to use the site.
| Name | Purpose | Storage and lifetime | Set by |
|---|---|---|---|
| klaw-cookie-consent | Your cookie choice: one true/false per category, the version of the shape it was written in, and the time you chose. Read before anything decides whether an analytics tag may load or an interface preference may be written. | localStorage Until you clear site data, or until we raise the consent version and ask again | first party |
| base44_access_token, token | Your sign-in session with our backend. Both keys hold the same token; the second name exists for an older version of the platform. The token is sent only to our own API, in an Authorization header. | localStorage Until you sign out, or the token expires and you sign in again | first party (Base44 SDK) |
| base44_app_id, base44_functions_version, base44_app_base_url, base44_from_url | Settings the app needs to reach the right backend: the application id, the backend functions version, the platform base URL, and the address you arrived on, which the sign-in flow uses to bring you back to the same page. base44_clear_access_token is stored only if you arrive through a link carrying that flag, which tells the app to drop the session token. | localStorage Until you clear site data | first party (Base44 SDK) |
| base44_analytics_session_id | A random identifier for this browser, created the first time the app calls our backend before you are signed in. The SDK sends it with every such request (as the header X-Base44-Anonymous-Id) so the backend can tell one anonymous browser from another; signed-in requests carry your session token instead. If you accept analytics, the platform's service-health events (section 4) reuse it. It is not sent to any other company. | localStorage Until you clear site data | first party (Base44 SDK) |
Payments and security
Protect your account and payments. They exist only on the screens that need them.
| Name | Purpose | Storage and lifetime | Set by |
|---|---|---|---|
| klaw_2fa_verified, klaw_2fa_timestamp, klaw_2fa_server_token | Remembers that you passed two-factor authentication in this tab, so you are not asked again for 24 hours: which account and method, when, and a token issued by our server that proves it. | sessionStorage Until you close the tab; treated as expired after 24 hours | first party |
| __stripe_mid, __stripe_sid | Fraud prevention for Stripe, our payment processor. Stripe.js is loaded on one screen only — the bank-verification step of the enterprise application, when you press "Connect Bank Account" — and sets identifiers such as these there. The names and lifetimes are Stripe's and can change. Subscription checkout happens on checkout.stripe.com, Stripe's own site, under Stripe's cookie policy, not on klawusa.org. | cookie __stripe_mid about 1 year; __stripe_sid about 30 minutes | Stripethird party |
Functional
Remembers choices you make in the interface: light or dark mode, which of your accounts you were last in, where you left the onboarding tour, and which dashboard notices, recommendations and checklist items you have already dealt with.
The site still works, but it forgets: your light or dark choice is not kept, so the next visit follows your system setting instead — nothing reads the old value back — the app opens in your default account, and dismissed notices, your tour position and your checklist progress all come back. Switching this off deletes those keys from this browser straight away.
Each row below is written only when you use the control it names, and only while the switch is on. None of it is sent anywhere; it stays in this browser.
| Name | Purpose | Storage and lifetime | Set by |
|---|---|---|---|
| klaw-themeonly with consent | Your light or dark choice, so the page paints in the right colours before it has loaded. With the Functional switch off it is not written, and public/theme-init.js — which runs before anything else — ignores and deletes any value left over, so the page follows your system setting instead of an answer you withdrew. | localStorage Until you clear site data or switch Functional off | first party |
| klaw.activeMembershipIdonly with consent | Which of your accounts — personal, API or organization — you last switched to, so the app opens in it after a reload. Written only while you are signed in and only when you switch account. | localStorage Until you clear site data or switch Functional off | first party |
| klaw_tour_resume_steponly with consent | Where you left the onboarding tour, so it resumes there. Written only while you are signed in and only while you are taking the tour. | localStorage Until the tour resumes, you clear site data, or you switch Functional off | first party |
| klaw_checklist_data, klaw_checklist_completed, klaw_checklist_keyonly with consent | Your Security Training Checklist: the generated items, which ones you have ticked, and the key that says which version they belong to. Written only while you are signed in and only on that page; with Functional off the checklist works for the visit but is generated again next time. | localStorage Until you clear site data or switch Functional off | first party |
| klaw_dismissed_notifsonly with consent | Notifications you dismissed on the enterprise employee dashboard, so they stay hidden. Written only while you are signed in and only when you dismiss one. | localStorage Until you clear site data or switch Functional off | first party |
| klaw_dismissed_recs, klaw_dismissed_recs_count, klaw_recs_generated, klaw_acted_recsonly with consent | Security recommendations on your dashboard: which you dismissed, how many, when they were last generated, and which you acted on (that count earns the Proactive Protector badge). Written only while you are signed in and only when you use those controls. | localStorage Until you clear site data or switch Functional off | first party |
Analytics
Counts visits so we can see which pages are read and which are broken: Google Analytics 4, Opinly, and the service-health events built into the platform SDK that runs this site, which go only to our own backend.
Nothing you can see changes — no script is fetched, no cookie is set and no event is sent; we simply cannot tell which pages work, so we find the broken ones more slowly.
Nothing below is fetched, written or sent until the switch is on. One more thing belongs to this category although it stores nothing of its own, so the table cannot show it: the service-health events built into the Base44 SDK (page opened, still open, closed, an error occurred), which go to our own backend, carry the base44_analytics_session_id identifier from the first table, and are sent only while you allow analytics — see section 4.
| Name | Purpose | Storage and lifetime | Set by |
|---|---|---|---|
| _ga, _ga_EHQKG7NGL7only with consent | Tell Google Analytics one browser from another so page views can be counted as visits, for property G-EHQKG7NGL7. Google Consent Mode grants analytics storage only; advertising storage, ad user data and ad personalisation stay denied. Rejecting later expires both cookies from our domain. | cookie About 2 years, extended on each visit (Google's default) | Google (Google Analytics 4)third party |
| Opinly visitor identifier (name set by the vendor)only with consent | Opinly web analytics, which shows us which blog and marketing pages are read. Its script (static.opinly.ai/p.js) stores a visitor identifier under names Opinly defines, as a cookie or in local storage; we do not control them. Rejecting later means the script is not loaded again, but anything it already stored stays until it expires or you clear site data. | cookie Set by the vendor; see Opinly's privacy notice | Opinlythird party |
Requests to other companies that store nothing
Loading a file from another company’s server tells that server your IP address and browser details, even when it sets no cookie. These are the ones on this site.
Google Fonts
Every page
The three typefaces the site uses are loaded from fonts.googleapis.com and fonts.gstatic.com. Google states that its Fonts API sets no cookies.
Carto basemap tiles
The threat map on the signed-in dashboard
The map background is drawn from tiles served by basemaps.cartocdn.com. Your IP address reaches Carto with each tile request. No cookies are set on klawusa.org.
Stripe Checkout and the Stripe customer portal
When you start a paid plan or manage billing
You are sent to checkout.stripe.com or billing.stripe.com, Stripe's own pages. Whatever Stripe stores there is on Stripe's domain and covered by Stripe's cookie policy.
4.How consent works on this site
The banner
On your first visit a small panel appears at the bottom of the page. It does not block anything and it offers three buttons drawn the same way, side by side: Reject non-essential, Customise and Accept all. Refusing and choosing category by category are each one press, exactly like accepting. Until you press one of them, nothing optional loads and nothing optional is written. There is no fourth state: not answering is the same as rejecting for as long as the banner is up.
The banner asks once. Once there is an answer it never comes back — changing it is what Cookie settings in the footer is for, and that opens the preferences panel rather than the banner. That is also why the banner has no close control and ignores the Escape key: there would be nothing to fall back on, and a question you can wave away without answering is not a question.
The categories, and what each switch does
Customise opens Cookie preferences: one row per group, each with a switch, the number of things in it, their names, and a link to its own part of section 3 above. It opens showing what is allowed right now, which on a first visit means the required group on and everything else off — a box we ticked for you would not be consent. Save my choices stores exactly what the switches show; Accept all and Reject non-essential are there as shortcuts. All three take effect immediately, with no reload. Closing the panel without pressing one of them changes nothing.
Strictly necessaryalways on
Keeps you signed in, tells the app where our backend is, remembers this cookie choice itself, and — on the two screens that need it — protects your account with two-factor verification and your card payment with Stripe’s fraud checks.
There is nothing to switch off here: without these the site cannot sign you in, cannot complete a payment you asked to make, and cannot even remember that you said no to everything else.
Functional
Remembers choices you make in the interface: light or dark mode, which of your accounts you were last in, where you left the onboarding tour, and which dashboard notices, recommendations and checklist items you have already dealt with.
The site still works, but it forgets: your light or dark choice is not kept, so the next visit follows your system setting instead — nothing reads the old value back — the app opens in your default account, and dismissed notices, your tour position and your checklist progress all come back. Switching this off deletes those keys from this browser straight away.
Analytics
Counts visits so we can see which pages are read and which are broken: Google Analytics 4, Opinly, and the service-health events built into the platform SDK that runs this site, which go only to our own backend.
Nothing you can see changes — no script is fetched, no cookie is set and no event is sent; we simply cannot tell which pages work, so we find the broken ones more slowly.
The required group cannot be switched off, and we would rather say so than hide it: the sign-in session, the settings that reach our backend, the record of this very choice, the two-factor check on your own account and Stripe’s fraud checks on a payment you asked to make are all either the service you came for or the law’s own exception for it. A switch we would then ignore would be a lie. Everything else is genuinely optional, and those two switches are the whole of it — there is nothing else on this site to decide about.
What is stored, and how the version works
Your answer is kept in local storage under klaw-cookie-consent as a small record with three fields — the version of the shape it was written in, one true/false per category, and when you chose. Pressing “Accept all” today writes:
{"version":2,"categories":{"necessary":true,"functional":true,"analytics":true},"at":"2026-09-16T14:03:00.000Z"}“Reject non-essential” writes the same record with every optional category false, and saving your own choices writes exactly what the switches showed. The version is currently 2. Version 1 held a single status of "granted" or "denied"; if you answered then, we translate rather than forget — “granted” becomes every category on, “denied” becomes the required group alone — and rewrite it at version 2, because the meaning of what you said has not changed. We raise the number only when a new category would make an old answer genuinely ambiguous, and then the banner asks again. A record we cannot read counts as no answer at all, never as a yes.
Global Privacy Control
If your browser sends the Global Privacy Control signal, we treat it as “Reject non-essential”: the banner does not appear, nothing optional loads or is written, and — because you have not been asked — nothing is stored either. Several states in the table below require this; we do it for everyone. A choice you make yourself in Cookie preferences is stored and wins over the signal, so you can still opt in from a GPC browser.
What allowing analytics starts, and what withdrawing it stops
Allowing analytics loads Google Analytics 4 (property G-EHQKG7NGL7, cookies _ga and _ga_EHQKG7NGL7) and Opinly’s script at once, and a page view for the page you are on is recorded. Google is told, through Consent Mode, that only analytics storage is allowed; advertising storage stays denied.
It also switches on the platform telemetry: the Base44 SDK that runs this site reports when a page is opened, that it is still open (once a minute), when it is closed, and when something goes wrong, to our own backend. These events carry the base44_analytics_session_id identifier from the first table — which exists anyway, because the SDK also uses it to tell anonymous browsers apart — and your account id if you are signed in. They start on your next page load, because the module is built when the page loads and cannot be switched on in place.
Withdrawing analytics after having allowed it tells Google Analytics to stop storing data and expires its cookies from our domain, shuts down the platform telemetry at once, and stops Opinly’s script from loading on later visits. We cannot delete what Opinly’s script may already have stored under its own name; that expires on the vendor’s schedule or when you clear site data.
What allowing functional storage starts, and what withdrawing it stops
Allowing it lets the keys in section 3 be written as you use the controls they belong to — and only then. Withdrawing it does two things at once: nothing further is written, and every key in that group is deleted from this browser immediately. Your light or dark choice goes with them, so the page follows your system setting from the next visit; the script that paints the theme before anything else loads checks the same switch, so a value left behind by an older visit cannot come back to life.
Changing your mind
The Cookie settings button in the site footer, on the Privacy Policy and twice on this page opens the preferences panel with your current answer already filled in. Change a switch and press Save my choices, or use Accept all or Reject non-essential. There is no penalty for any of it and no need to tell us why.
Browser controls
Every browser lets you block or delete cookies and site data for one site or all of them, usually under Settings → Privacy. Clearing this site’s data signs you out, forgets your theme, and forgets your cookie choice — so the banner will ask again. Blocking storage for this site altogether breaks it: the app keeps the settings it needs to reach our backend in local storage, and cannot sign you in without somewhere to keep the session token.
Do Not Track
California’s Online Privacy Protection Act asks us to say how we respond to a browser’s “Do Not Track” header. We do not act on it, because there is still no agreed meaning for it. It makes no difference here: no analytics runs without your consent, and we honour Global Privacy Control, the signal that replaced it.
5.Your privacy rights under U.S. state law
Twenty states have comprehensive consumer privacy laws in force as of the review date. They differ in detail, and many apply only to businesses far larger than Klaw, but we do not sort visitors by state: every choice on this page is available to every visitor, wherever you live. The table records what each law grants so you can see where your rights come from.
For cookies specifically, the only thing a state law might call a “sale”, “sharing” or “targeted advertising” is the analytics data that reaches Google and Opinly once you allow analytics — and we use none of it for advertising. Turning that switch off, pressing “Reject non-essential”, or sending Global Privacy Control opts you out of it entirely. We do not profile visitors in any way that produces legal or similarly significant effects. Our Privacy Policy, section 5, describes a separate practice that does not involve cookies: the sale of anonymized, aggregated statistics drawn from Free plan accounts.
Comprehensive state laws
| State | Law and citation | Effective | Your rights | Opt-out signal | Response time | Notes |
|---|---|---|---|---|---|---|
| California | California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA) Cal. Civ. Code § 1798.100 et seq.; regulations at Cal. Code Regs. tit. 11, § 7000 et seq.; see also the California Online Privacy Protection Act, Cal. Bus. & Prof. Code § 22575 et seq. | January 1, 2020; CPRA amendments operative January 1, 2023 |
| required — an opt-out preference signal such as Global Privacy Control must be honored | 45 days, extendable once by 45 days | CalOPPA also requires this policy to say how we respond to Do Not Track signals. |
| Virginia | Virginia Consumer Data Protection Act (VCDPA) Va. Code Ann. § 59.1-575 et seq. | January 1, 2023 |
| not required by statute; we honor it anyway | 45 days, extendable once by 45 days | — |
| Colorado | Colorado Privacy Act (CPA) Colo. Rev. Stat. § 6-1-1301 et seq.; rules at 4 Colo. Code Regs. 904-3 | July 1, 2023 |
| required since July 1, 2024 | 45 days, extendable once by 45 days | — |
| Connecticut | Connecticut Data Privacy Act (CTDPA), as amended by Public Act 25-62 (Senate Bill 1295) Conn. Gen. Stat. § 42-515 et seq. | July 1, 2023; the 2025 amendments took effect July 1, 2026 |
| required since January 1, 2025 | 45 days, extendable once by 45 days | The 2025 amendments widened who the law covers, broadened what counts as sensitive data, tightened data minimisation, and added the right to a list of third parties. |
| Utah | Utah Consumer Privacy Act (UCPA) Utah Code Ann. § 13-61-101 et seq. | December 31, 2023 |
| not required by statute; we honor it anyway | 45 days, extendable once by 45 days | No statutory right to correct, no profiling opt-out and no appeal process. |
| Texas | Texas Data Privacy and Security Act (TDPSA) Tex. Bus. & Com. Code ch. 541 | July 1, 2024 |
| required since January 1, 2025 | 45 days, extendable once by 45 days | — |
| Oregon | Oregon Consumer Privacy Act (OCPA) Or. Rev. Stat. § 646A.570 et seq. | July 1, 2024 (nonprofit organizations: July 1, 2025) |
| required since January 1, 2026 | 45 days, extendable once by 45 days | House Bill 2008 (2025), in force since January 1, 2026, also bars the sale of precise geolocation data and of the personal data of anyone under 16. We do not sell personal data at all. |
| Florida | Florida Digital Bill of Rights (FDBR) Fla. Stat. § 501.701 et seq. | July 1, 2024 |
| not required by statute; we honor it anyway | 45 days, extendable once by 15 days | Most FDBR obligations apply only to controllers with more than $1 billion in global gross annual revenue that meet additional criteria; we extend the same choices to Florida residents voluntarily. |
| Montana | Montana Consumer Data Privacy Act (MCDPA) Mont. Code Ann. § 30-14-2801 et seq. | October 1, 2024; amendments effective October 1, 2025 |
| required since January 1, 2025 | 45 days, extendable once by 45 days | — |
| Delaware | Delaware Personal Data Privacy Act (DPDPA) Del. Code Ann. tit. 6, ch. 12D | January 1, 2025 |
| required since January 1, 2026 | 45 days, extendable once by 45 days | — |
| Iowa | Iowa Consumer Data Protection Act (ICDPA) Iowa Code ch. 715D | January 1, 2025 |
| not required by statute; we honor it anyway | 90 days, extendable once by 45 days | No statutory right to correct and no profiling opt-out. |
| Nebraska | Nebraska Data Privacy Act (NDPA) Neb. Rev. Stat. § 87-1101 et seq. | January 1, 2025 |
| required since January 1, 2025 | 45 days, extendable once by 45 days | — |
| New Hampshire | New Hampshire Privacy Act (NHPA) N.H. Rev. Stat. Ann. ch. 507-H | January 1, 2025 |
| required since January 1, 2025 | 45 days, extendable once by 45 days | — |
| New Jersey | New Jersey Data Privacy Act (NJDPA) N.J. Stat. Ann. § 56:8-166.4 et seq. | January 15, 2025 |
| required since July 15, 2025 | 45 days, extendable once by 45 days | — |
| Tennessee | Tennessee Information Protection Act (TIPA) Tenn. Code Ann. § 47-18-3201 et seq. | July 1, 2025 |
| not required by statute; we honor it anyway | 45 days, extendable once by 45 days | — |
| Minnesota | Minnesota Consumer Data Privacy Act (MCDPA) Minn. Stat. ch. 325O | July 31, 2025 |
| required since July 31, 2025 | 45 days, extendable once by 45 days | — |
| Maryland | Maryland Online Data Privacy Act (MODPA) Md. Code Ann., Com. Law § 14-4601 et seq. | October 1, 2025 (applies to processing on or after April 1, 2026) |
| required | 45 days, extendable once by 45 days | Maryland limits collection to what is reasonably necessary and prohibits the sale of sensitive data outright. |
| Indiana | Indiana Consumer Data Protection Act (ICDPA) Ind. Code art. 24-15 | January 1, 2026 |
| not required by statute; we honor it anyway | 45 days, extendable once by 45 days | — |
| Kentucky | Kentucky Consumer Data Protection Act (KCDPA) Ky. Rev. Stat. Ann. § 367.3611 et seq. | January 1, 2026 |
| not required by statute; we honor it anyway | 45 days, extendable once by 45 days | — |
| Rhode Island | Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) R.I. Gen. Laws ch. 6-48.1 | January 1, 2026 |
| not required by statute; we honor it anyway | 45 days, extendable once by 45 days | — |
California
California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA)
Cal. Civ. Code § 1798.100 et seq.; regulations at Cal. Code Regs. tit. 11, § 7000 et seq.; see also the California Online Privacy Protection Act, Cal. Bus. & Prof. Code § 22575 et seq.
- Effective
- January 1, 2020; CPRA amendments operative January 1, 2023
- Your rights
- know and access
- delete
- correct
- portability
- opt out of sale or sharing
- limit use of sensitive personal information
- non-discrimination
- Opt-out signal
- required — an opt-out preference signal such as Global Privacy Control must be honored
- Response
- 45 days, extendable once by 45 days
- Notes
- CalOPPA also requires this policy to say how we respond to Do Not Track signals.
Virginia
Virginia Consumer Data Protection Act (VCDPA)
Va. Code Ann. § 59.1-575 et seq.
- Effective
- January 1, 2023
- Your rights
- access
- delete
- correct
- portability
- opt out of targeted advertising, sale, and profiling
- appeal a refused request
- Opt-out signal
- not required by statute; we honor it anyway
- Response
- 45 days, extendable once by 45 days
Colorado
Colorado Privacy Act (CPA)
Colo. Rev. Stat. § 6-1-1301 et seq.; rules at 4 Colo. Code Regs. 904-3
- Effective
- July 1, 2023
- Your rights
- access
- delete
- correct
- portability
- opt out of targeted advertising, sale, and profiling
- appeal a refused request
- Opt-out signal
- required since July 1, 2024
- Response
- 45 days, extendable once by 45 days
Connecticut
Connecticut Data Privacy Act (CTDPA), as amended by Public Act 25-62 (Senate Bill 1295)
Conn. Gen. Stat. § 42-515 et seq.
- Effective
- July 1, 2023; the 2025 amendments took effect July 1, 2026
- Your rights
- access
- delete
- correct
- portability
- a list of the third parties we disclosed your data to
- opt out of targeted advertising, sale, and profiling
- appeal a refused request
- Opt-out signal
- required since January 1, 2025
- Response
- 45 days, extendable once by 45 days
- Notes
- The 2025 amendments widened who the law covers, broadened what counts as sensitive data, tightened data minimisation, and added the right to a list of third parties.
Utah
Utah Consumer Privacy Act (UCPA)
Utah Code Ann. § 13-61-101 et seq.
- Effective
- December 31, 2023
- Your rights
- access
- delete
- portability
- opt out of targeted advertising and sale
- Opt-out signal
- not required by statute; we honor it anyway
- Response
- 45 days, extendable once by 45 days
- Notes
- No statutory right to correct, no profiling opt-out and no appeal process.
Texas
Texas Data Privacy and Security Act (TDPSA)
Tex. Bus. & Com. Code ch. 541
- Effective
- July 1, 2024
- Your rights
- access
- delete
- correct
- portability
- opt out of targeted advertising, sale, and profiling
- appeal a refused request
- Opt-out signal
- required since January 1, 2025
- Response
- 45 days, extendable once by 45 days
Oregon
Oregon Consumer Privacy Act (OCPA)
Or. Rev. Stat. § 646A.570 et seq.
- Effective
- July 1, 2024 (nonprofit organizations: July 1, 2025)
- Your rights
- access, including a list of specific third parties that received your data
- delete
- correct
- portability
- opt out of targeted advertising, sale, and profiling
- appeal a refused request
- Opt-out signal
- required since January 1, 2026
- Response
- 45 days, extendable once by 45 days
- Notes
- House Bill 2008 (2025), in force since January 1, 2026, also bars the sale of precise geolocation data and of the personal data of anyone under 16. We do not sell personal data at all.
Florida
Florida Digital Bill of Rights (FDBR)
Fla. Stat. § 501.701 et seq.
- Effective
- July 1, 2024
- Your rights
- access
- delete
- correct
- portability
- opt out of targeted advertising, sale, and profiling
- opt out of the collection of precise geolocation and of voice or facial recognition data
- Opt-out signal
- not required by statute; we honor it anyway
- Response
- 45 days, extendable once by 15 days
- Notes
- Most FDBR obligations apply only to controllers with more than $1 billion in global gross annual revenue that meet additional criteria; we extend the same choices to Florida residents voluntarily.
Montana
Montana Consumer Data Privacy Act (MCDPA)
Mont. Code Ann. § 30-14-2801 et seq.
- Effective
- October 1, 2024; amendments effective October 1, 2025
- Your rights
- access
- delete
- correct
- portability
- opt out of targeted advertising, sale, and profiling
- appeal a refused request
- Opt-out signal
- required since January 1, 2025
- Response
- 45 days, extendable once by 45 days
Delaware
Delaware Personal Data Privacy Act (DPDPA)
Del. Code Ann. tit. 6, ch. 12D
- Effective
- January 1, 2025
- Your rights
- access, including the categories of third parties that received your data
- delete
- correct
- portability
- opt out of targeted advertising, sale, and profiling
- appeal a refused request
- Opt-out signal
- required since January 1, 2026
- Response
- 45 days, extendable once by 45 days
Iowa
Iowa Consumer Data Protection Act (ICDPA)
Iowa Code ch. 715D
- Effective
- January 1, 2025
- Your rights
- access
- delete
- portability
- opt out of sale
- opt out of targeted advertising (by notice)
- appeal a refused request
- Opt-out signal
- not required by statute; we honor it anyway
- Response
- 90 days, extendable once by 45 days
- Notes
- No statutory right to correct and no profiling opt-out.
Nebraska
Nebraska Data Privacy Act (NDPA)
Neb. Rev. Stat. § 87-1101 et seq.
- Effective
- January 1, 2025
- Your rights
- access
- delete
- correct
- portability
- opt out of targeted advertising, sale, and profiling
- appeal a refused request
- Opt-out signal
- required since January 1, 2025
- Response
- 45 days, extendable once by 45 days
New Hampshire
New Hampshire Privacy Act (NHPA)
N.H. Rev. Stat. Ann. ch. 507-H
- Effective
- January 1, 2025
- Your rights
- access
- delete
- correct
- portability
- opt out of targeted advertising, sale, and profiling
- appeal a refused request
- Opt-out signal
- required since January 1, 2025
- Response
- 45 days, extendable once by 45 days
New Jersey
New Jersey Data Privacy Act (NJDPA)
N.J. Stat. Ann. § 56:8-166.4 et seq.
- Effective
- January 15, 2025
- Your rights
- access
- delete
- correct
- portability
- opt out of targeted advertising, sale, and profiling
- appeal a refused request
- Opt-out signal
- required since July 15, 2025
- Response
- 45 days, extendable once by 45 days
Tennessee
Tennessee Information Protection Act (TIPA)
Tenn. Code Ann. § 47-18-3201 et seq.
- Effective
- July 1, 2025
- Your rights
- access
- delete
- correct
- portability
- opt out of targeted advertising, sale, and profiling
- appeal a refused request
- Opt-out signal
- not required by statute; we honor it anyway
- Response
- 45 days, extendable once by 45 days
Minnesota
Minnesota Consumer Data Privacy Act (MCDPA)
Minn. Stat. ch. 325O
- Effective
- July 31, 2025
- Your rights
- access, including a list of specific third parties that received your data
- delete
- correct
- portability
- opt out of targeted advertising, sale, and profiling
- question the result of profiling and be told what you could change
- appeal a refused request
- Opt-out signal
- required since July 31, 2025
- Response
- 45 days, extendable once by 45 days
Maryland
Maryland Online Data Privacy Act (MODPA)
Md. Code Ann., Com. Law § 14-4601 et seq.
- Effective
- October 1, 2025 (applies to processing on or after April 1, 2026)
- Your rights
- access, including a list of the categories of third parties that received your data
- delete
- correct
- portability
- opt out of targeted advertising, sale, and profiling
- appeal a refused request
- Opt-out signal
- required
- Response
- 45 days, extendable once by 45 days
- Notes
- Maryland limits collection to what is reasonably necessary and prohibits the sale of sensitive data outright.
Indiana
Indiana Consumer Data Protection Act (ICDPA)
Ind. Code art. 24-15
- Effective
- January 1, 2026
- Your rights
- access
- delete
- correct
- portability
- opt out of targeted advertising, sale, and profiling
- appeal a refused request
- Opt-out signal
- not required by statute; we honor it anyway
- Response
- 45 days, extendable once by 45 days
Kentucky
Kentucky Consumer Data Protection Act (KCDPA)
Ky. Rev. Stat. Ann. § 367.3611 et seq.
- Effective
- January 1, 2026
- Your rights
- access
- delete
- correct
- portability
- opt out of targeted advertising, sale, and profiling
- appeal a refused request
- Opt-out signal
- not required by statute; we honor it anyway
- Response
- 45 days, extendable once by 45 days
Rhode Island
Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
R.I. Gen. Laws ch. 6-48.1
- Effective
- January 1, 2026
- Your rights
- access
- delete
- correct
- portability
- opt out of targeted advertising, sale, and profiling
- appeal a refused request
- Opt-out signal
- not required by statute; we honor it anyway
- Response
- 45 days, extendable once by 45 days
Narrower state laws that touch cookies
Nevada: Nevada online privacy law (Senate Bill 220 of 2019, as amended)
Nev. Rev. Stat. § 603A.300 et seq.
Operators of commercial websites must post a privacy notice and let Nevada consumers opt out of the sale of covered information. We do not sell covered information; requests are answered within 60 days.
Washington: My Health My Data Act
Wash. Rev. Code ch. 19.373
Requires consent before collecting or sharing consumer health data, including inferences drawn from online activity. We do not use cookies or analytics to infer health information.
If your state is not listed
Federal law applies to every visitor, and every state has a consumer-protection statute that forbids deceptive practices, so this page must be accurate wherever you are. And as said above, every choice here — accepting, rejecting, the Global Privacy Control signal, and the requests below — is open to you regardless of where you live.
Federal Trade Commission Act, Section 5
15 U.S.C. § 45
Prohibits unfair or deceptive practices. This policy must accurately describe what we do, and we must keep the promises it makes.
Children's Online Privacy Protection Act (COPPA)
15 U.S.C. § 6501 et seq.; 16 C.F.R. pt. 312
We do not knowingly collect personal information from children under 13, and our services are not directed to them.
How to exercise your rights
- Opting out of analytics needs no request: open Cookie settings and either turn the Analytics switch off and press “Save my choices”, or press “Reject non-essential” to turn off everything optional at once. Sending Global Privacy Control does the same without asking us.
- Everything else — access, deletion, correction, a copy of your data, or an opt-out you want in writing — goes to privacy@klawusa.org with the subject line “Privacy Request”. Tell us which right you are using, the state you live in, and the email address on your Klaw account if you have one.
- Verification. For a request about an account we confirm it through the email address on that account, and ask for nothing more. A request from a visitor without an account cannot be matched to anything we hold about them, and we say so.
- Timing. We answer within the time the table gives for your state and aim for 30 days. If we need the extension the law allows, we tell you before the first deadline and say why.
- Appeals. If we refuse a request and your state’s law provides an appeal, reply to our answer with “Appeal” in the subject line. Someone who was not involved in the first decision reviews it and answers within the time your state allows — 45 or 60 days, never longer — and, if we still refuse, tells you how to reach your state attorney general.
- Authorized agents (California). Someone else may make a request for you if they send your signed permission with it. We may check with you directly before acting on it.
- No penalty. We do not charge more, offer less or treat you differently because you exercised a right.
6.Visitors outside the United States
Klaw is operated from the United States and its servers are there. The laws below apply to visitors from those places, and we apply the same consent model to everyone.
European Economic Area: General Data Protection Regulation (GDPR) and the ePrivacy Directive
Regulation (EU) 2016/679, arts. 6, 7 and 13; Directive 2002/58/EC art. 5(3), as amended by Directive 2009/136/EC
Non-essential cookies and similar storage require prior consent that is freely given, specific, informed and as easy to withdraw as to give. Strictly necessary storage is exempt.
United Kingdom: UK GDPR and the Privacy and Electronic Communications Regulations (PECR)
Data Protection Act 2018; PECR 2003 (SI 2003/2426) reg. 6
Same consent standard as the EEA for non-essential cookies.
Canada: PIPEDA and CASL
Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5; Canada's Anti-Spam Legislation, S.C. 2010, c. 23
Consent for non-essential cookies may be implied where the purpose is clear and the information is not sensitive; we ask for express consent anyway.
The lawful basis we rely on
- Strictly necessary items are covered by the exemption for storage needed to provide the service you asked for (ePrivacy Directive article 5(3), PECR regulation 6(4)), and their processing by our contract with you (GDPR article 6(1)(b)).
- Payments and security items rest on the same exemption and on our legitimate interest in keeping accounts and payments safe (article 6(1)(f)).
- Functional items rest on your consent too (articles 6(1)(a) and 7), given through the Functional switch and withdrawable there; each one is additionally written only when you use the control it remembers — choosing dark mode, dismissing a notice — and every one of them is deleted from your browser the moment you withdraw it.
- Analytics rests on your consent alone (articles 6(1)(a) and 7), given through the banner or the Analytics switch and withdrawable at any time with one press in Cookie settings.
Data that reaches Google or Opinly after you consent is transferred to the United States. The Privacy Policy, section 17, explains the transfer safeguards. If you believe we have handled your data badly you can complain to the supervisory authority where you live; we would rather hear from you first at privacy@klawusa.org.
7.Children
This site is not directed to children under 13 and we do not knowingly collect personal information from them, as the Children’s Online Privacy Protection Act requires. Our Terms of Service, section 3, go further: you must be at least 18 to create a Klaw account, or 13 with verified parental consent. Nothing on this page works differently for a 13-to-17-year-old using the site with that consent — the same banner, the same choices, the same storage.
If you believe a child under 13 has given us personal information, email privacy@klawusa.org and we will delete it.
8.Changes to this policy
The “Last reviewed” date at the top changes whenever we check this page against the code or change what it says. If a change would add a category, so that an answer you already gave no longer means what it meant, we raise the consent version described in section 4 and every visitor is asked again rather than held to an old answer. A change that only moves something inside a category you already answered about is translated instead, and you are not asked twice. Changes that matter to your account are announced the way the Privacy Policy, section 21, describes.
9.Contact
Data controller
Penusila Digital Solutions LLC
Mailing address available on request by email.
Privacy rights requests: privacy@klawusa.org
Security reports: security@klawusa.org
Your cookie choice is yours to change at any time:
© 2026 Penusila Digital Solutions LLC. All rights reserved.