Legal
Privacy Policy
Last updated: February 28, 2026
1. Introduction
ClutterAI ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service at app.clutter-ai.com (the "Service").
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address
- Name
- Password (encrypted)
- Profile information you choose to provide
2.2 Connected Service Data
When you connect third-party services (Google Drive, Gmail, Slack, Calendar, Notion), we collect and store:
- Files and documents you've granted us access to
- Email messages and metadata
- Slack messages and channel information
- Calendar events and details
- Notion pages, databases, and workspace content
2.3 Usage Information
We automatically collect:
- Questions you ask our AI
- Search queries and interactions
- Device information and IP address
- Browser type and operating system
- Usage statistics and analytics
2.4 Payment and Transaction Information
All payments are processed by Lemon Squeezy LLC ("Lemon Squeezy"), which acts as our Merchant of Record. This means Lemon Squeezy, not ClutterAI, is the legal seller of record for all transactions. Your invoice and credit card statement will show Lemon Squeezy, not ClutterAI — this is expected and confirms your purchase was processed successfully. We do not store your credit card information. Lemon Squeezy collects and processes:
- Payment information (credit/debit card details)
- Billing address and contact information
- Transaction history and receipts
- Tax information (VAT, GST, sales tax, etc.)
- Purchase metadata
Lemon Squeezy's use of your payment information is governed by their Privacy Policy, available at: lemonsqueezy.com/privacy
We receive limited transaction data from Lemon Squeezy (such as your email, subscription status, and purchase date) solely to provide you access to the Service. We do not receive your full payment card details.
3. How We Use Your Information
We use collected information to:
- Provide and maintain the Service
- Process your questions through our AI-powered search engine
- Index and enable semantic search across your connected content
- Generate relevant search results using natural language processing
- Verify subscription status and grant access (via Lemon Squeezy)
- Send service updates and support communications
- Improve our Service and develop new features
- Detect and prevent fraud or abuse
- Comply with legal obligations
3.1 AI Processing
To provide intelligent search functionality, we process your queries and content using:
- OpenAI GPT-4: Your search queries are sent to OpenAI to understand intent and generate responses. OpenAI processes queries in accordance with their data usage policies for API customers.
- Pinecone Vector Database: Your document content is converted to vector embeddings and stored in Pinecone to enable semantic search. This allows you to find information based on meaning, not just keywords.
Important: We do not use your data to train AI models. Your content is processed solely to provide search functionality to you. OpenAI's API does not use customer data submitted via API to train or improve their models. Your content remains private and is only used to answer your specific questions.
4. Data Sharing and Third-Party Service Providers
To provide ClutterAI's functionality, we share your information with trusted third-party service providers. These providers process data only as necessary to deliver our Service and are bound by data processing agreements to protect your information.
4.1 Essential Service Providers
- Lemon Squeezy LLC: Merchant of record for all transactions, payment processing, tax handling, and subscription management. When you make a purchase, your payment information and email address are processed by Lemon Squeezy in accordance with their Privacy Policy. ClutterAI does not store or have access to your payment card details.
- Convex: Backend database and authentication infrastructure for storing your account data and preferences. Privacy Policy
- Vercel: Web hosting and deployment platform. Privacy Policy
- OpenAI: Natural language processing and AI-powered query understanding. Your search queries are sent to OpenAI's API to generate intelligent responses. OpenAI does not use API customer data for training. Privacy Policy
- Pinecone: Vector database infrastructure for semantic search. Your document content is converted to vector embeddings and stored in Pinecone to enable meaning-based search across your connected services. Privacy Policy
4.2 Data Processing Agreements
We have data processing agreements in place with all service providers listed above to ensure:
- Your data is processed only for the purposes described in this policy
- Appropriate security measures are maintained
- Data is not used for their own purposes or shared with other parties
- Compliance with applicable data protection regulations (GDPR, CCPA, etc.)
4.3 What We Do NOT Do
We do not:
- Sell your personal data to third parties
- Use your data for advertising purposes
- Share your data with non-essential third parties
- Train AI models on your private content
- Allow service providers to use your data for their own purposes
4.4 Legal Requirements
We may disclose your information if required by law, court order, or government request, or to protect our rights, property, or safety.
4.5 Legal Basis for Processing (EU/UK Users)
If you are an EU/UK resident, we process personal data on the following legal bases:
- Contract: To provide the Service and perform our contract with you.
- Legitimate Interest: To improve the Service, detect fraud, ensure security, and analyze usage patterns.
- Consent: Where required (e.g., optional marketing communications). You may withdraw consent at any time.
- Legal Obligation: To comply with applicable laws and regulations.
4.6 Business Transfers
If ClutterAI is acquired or merged with another company, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our Service of any change in ownership.
5. Data Security
We implement industry-standard security measures to protect your information:
- TLS/SSL encryption for data in transit
- Encryption at rest for sensitive data
- Access controls and authentication requirements
- Regular security audits and monitoring
- Secure credential storage (passwords are hashed and salted)
- OAuth tokens encrypted and stored securely
In the event of a data breach affecting personal data, we will notify affected users and regulators as required by applicable law (including within 72 hours for GDPR-covered incidents).
No system is 100% secure. While we strive to protect your data using commercially reasonable measures, we cannot guarantee absolute security.
6. Your Rights and Choices
6.1 General Rights
Subject to local law, you have the right to:
- Access: Request a copy of your personal data
- Correct: Update inaccurate or incomplete information
- Delete: Request deletion of your account and associated data
- Restrict Processing: Limit how we use your data
- Object: Object to processing based on legitimate interests
- Data Portability: Receive your data in a portable format
- Withdraw Consent: Withdraw previously given consent
- Lodge a Complaint: File a complaint with your data protection authority
6.2 How to Exercise Your Rights
To exercise these rights, email support@clutter-ai.com with "Data Request" in the subject line. We will acknowledge receipt within 5 business days and respond within 30 days.
6.3 EU/UK Residents
EU and UK residents may lodge a complaint with their local data protection authority. A list of EU data protection authorities is available at: edpb.europa.eu
6.4 California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights including:
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information
- Right to opt-out of the sale or sharing of personal information
- Right to correct inaccurate personal information
- Right to non-discrimination for exercising your rights
We do not sell or share personal information as defined by the CCPA/CPRA.
6.5 Subscription and Payment Management
For subscription changes or billing questions, contact Lemon Squeezy directly via their support portal or email us at support@clutter-ai.com. You can also manage your subscription through the Lemon Squeezy customer portal link included in your billing confirmation email.
6.6 Connected Services Management
You can disconnect any integrated service at any time through your account settings. Disconnecting will:
- Immediately revoke ClutterAI's access to that service
- Stop syncing new content from that service
- Retain previously indexed content for up to 30 days (for data recovery)
- Permanently delete all associated data after 30 days
7. Data Retention
- Active Accounts: Data retained while your account is active
- After Account Deletion: Most data deleted within 30 days; backups purged within 90 days
- Vector Embeddings: Deleted from Pinecone within 30 days of account deletion
- Transaction Records: Retained by Lemon Squeezy as required for legal and tax purposes (typically 7 years)
- Aggregated/Anonymized Data: May be retained indefinitely for analytics
For earlier deletion or a data export, contact support@clutter-ai.com.
8. Cookies and Tracking
We use essential cookies necessary for the Service to function:
- Authentication Cookies: To keep you logged in
- Session Cookies: To maintain your session and preferences
- Security Cookies: To detect fraud and abuse
We do not use advertising or third-party tracking cookies.
9. Children's Privacy
The Service is not intended for children under 13 (or 16 in the EU/UK). If we learn we have collected personal data from a child without appropriate consent, we will delete it promptly. Contact us at support@clutter-ai.com if you believe we may have collected information from a child.
10. International Data Transfers
Your data may be transferred to and processed in the United States and other countries where our service providers operate. For transfers from the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses approved by the European Commission.
11. Third-Party Services
When you connect third-party services, you are also subject to their respective privacy policies:
- Google: policies.google.com/privacy
- Slack: slack.com/privacy-policy
- Notion: notion.so/Privacy-Policy
We only access data you explicitly authorize through OAuth permissions. You can revoke our access at any time through your account settings or the third-party service directly.
12. Changes to This Policy
We will notify you of material changes by:
- Sending an email to your registered email address
- Posting a prominent notice on our Service
- Updating the "Last Updated" date at the top of this policy
Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
13. Contact Us
For questions about this Privacy Policy or our data practices:
- Email: support@clutter-ai.com
- Subject line: "Privacy Inquiry"
For payment and subscription inquiries, contact Lemon Squeezy at: lemonsqueezy.com/support