Klatos by Vixoris
Integrity

How the record is kept.

A record is only worth as much as the machinery behind it. So here is that machinery, in plain terms: how a day closes, how the past freezes, how you take your data out, and how you delete it for good. No fine print, and nothing here the code doesn't already do.

How a day closes

You mark each habit while the day is still today. When your local midnight passes, that day's record settles for good. There is no back-filling, ever, and no plan unlocks it: the day locks the same way on every plan, free or paid.

One thing stays open, on purpose. A written note on the day can be revised for seven days after it closes. A check-in is proof of what you did, and proof you can rewrite is not proof; a note is your reading of the day, and making sense of a day often takes longer than the day. The proof locks; the note gets room. The help page has the reason in full.

How the record freezes

At day's end, the day's score is written once as a frozen snapshot. Every day gets one, including the missed days and the days you committed to nothing. A day with no due habits is stored as a genuine blank, an explicit not applicable. A zero means you committed and did not do it. The two are never confused.

Each snapshot records the version of the scoring rules that produced it. If those rules ever evolve, old days are not silently recomputed. No change reaches the past: change is only forward looking. What you read months from now reads as it did the morning after.

How export works

Your data is yours and you can download it at any time: habits, spaces, check-ins, notes. One export gives you everything you logged as machine-readable JSON, or as a zip of CSV files with that JSON bundled in. It is free on every plan, with no cap and no ceremony. The data a partner shared with you stays theirs and is not part of your export.

How deletion works

When you delete your account, nothing is destroyed on the spot. It enters a 14 days grace window, during which you can recover everything by signing back in — the request has to be started with a fresh re-authentication, so no one else can trip it for you, and you can cancel it at any point in those two weeks.

When the window closes, the purge is real and final: your record is erased permanently and cannot be brought back, leaving only a tombstone with no personal information in it. Deletion means deletion.

How it's run

The promises above are only as good as the hands that keep them. Klatos runs on cloud-native infrastructure built and operated by Vixoris, the studio behind it. It is a stack we understand end to end. Security is built in, not bolted on. Your data lives on servers in the EU. It is encrypted at rest, on every disk. It is encrypted in transit, including between the services inside the cluster. And the platform is locked down the cloud-native way: hardened pods, a service mesh, deny-by-default between namespaces.

Signing in is handled by Vixoris' shared identity, a dedicated identity server. Klatos never sees your password, and holds none to lose. What it receives is a token that server signed, and it checks that signature on every request, not once at sign-in. The door itself is held to the same standard: passwords of at least twelve characters, common ones refused outright, repeated failed attempts locked out. Or sign in with Google or LinkedIn and never set a password at all.

Access is settled the same way. Whether an account is an administrator is read from that signed token, never from a switch in the database that could be flipped quietly — and an administrator is refused the habit and check-in endpoints outright. Running the service and using it are two different accounts.

The engineering is written up in the open: how the platform was built from scratch, and the road to running it on Kubernetes.

Here is who runs it.

One more thing

If any of this doesn't hold up to a hard question, that's worth an email — write to us. The mechanics are meant to be checked, not taken on faith.

Join the waitlist →