Skip to main content
Legal

Privacy Policy

Last updated: April 11, 2026

“Clevername is committed to protecting your privacy. This policy explains what information we collect, how we use it, and your rights regarding that information.”

Information we collect

We collect the email address you use to create an account. When you use the AI Hub features, we store metadata about your requests (token counts, model used, timestamps) to provide usage analytics. The chat feature (persistent dashboard conversations) has been discontinued. Any conversation history stored while that feature was available is retained solely so we can fulfill your data-export and deletion requests. This historical data belongs to you — we do not use your conversation content to train models, improve our algorithms, or for any purpose other than providing the service to you and running security scans you have enabled. API keys you provide for third-party services (OpenAI, Anthropic, Gemini) are stored in Google Cloud Secret Manager and are never written to our database or logged. Our database retains only a masked display hint. See our Security page for full details. When you register an agent, we store the agent name and configuration. Push notification device tokens are stored to deliver approval notifications.

How we use your information

We use your email address to authenticate you and, if you opt in, to send you notification emails about approval requests requiring your attention. Usage metadata is used to provide the analytics dashboard. We do not sell your data, use it for advertising, or use it to train AI models. When you enable runtime security features (CleverGuard, content scanning, agent drift detection), we process your AI inputs and outputs in real time to detect threats such as prompt injection, PII exposure, secret leakage, and unauthorized tool usage. This processing is performed solely to enforce your security policies. Scan results and flagged events are logged to your audit trail — we do not retain or analyze your content beyond what is necessary to provide the security service.

Data retention

Historical conversation data from the discontinued chat feature is retained only to satisfy export and deletion requests; you can request deletion of all your data at any time. Audit logs and security events are retained according to your plan: 7 days on Free, 30 days on Pro, and 365 days on Team. Enterprise retention is set by contract with no fixed platform expiry. Usage analytics are retained for 12 months. Account data is retained until you delete your account. You may request an export of your data or erase all of your data by contacting us at privacy@clevername.net. Account deletion is available in dashboard settings. Erasure removes your conversation content, projects, API keys, and analytics. Audit logs are anonymized rather than deleted to preserve the integrity of organizational security records.

Routing and proxy services

When you route AI requests through Clevername (via the dashboard chat or the gateway), your requests are forwarded to your chosen AI provider using your own API keys. We process request and response content in transit to apply your security policies (content scanning, tool drift detection, guardrail enforcement). Content scanning happens in memory. By default we log metadata only (timestamp, model, token count, latency) — not the prompt or response content itself. Full I/O logging, storing a copy of prompts and responses for audit and replay, is opt-in and configurable per org; when you enable it you can store content directly or turn on encrypted (zero-knowledge) I/O logging, where stored content is encrypted under a key derived from your passphrase that we cannot read. Clevername is a BYOK platform for customer inference. AI requests you make are routed using your own provider API keys — we do not supply managed LLM compute for your inference. (Clevername does run a small amount of its own paid compute for governance features, such as the ClaimGuard claim extractor and ScopeGuard scope embeddings; these process content only to enforce your security policies and are not customer-facing inference.) The same privacy protections apply to all requests regardless of which provider you use.

Third-party services

Clevername uses Supabase for database and authentication services. We use SendGrid for transactional email delivery. Apple Push Notification service (APNs) is used to deliver push notifications to iOS devices. Your API keys for OpenAI, Anthropic, and Google are transmitted directly to those providers when processing requests. We do not share your data with any third party except as necessary to route your AI requests to the provider you select.

Cookies

Clevername uses only strictly necessary cookies — cookies that are essential to operate the service. Specifically, we set session cookies issued by Supabase (our authentication provider) to keep you logged in. These cookies are required for the service to function and do not track you across other websites. We do not use advertising cookies, analytics cookies, or any third-party tracking technologies. No consent is required for strictly necessary cookies under applicable law, but you may disable cookies in your browser settings. Doing so will prevent you from logging in.

Google user data

When you connect a Google account to sign in, Clevername accesses only the Google user data required for that specific purpose. Sign-in: We request your email address and basic profile information to create and identify your account. Google Drive (discontinued): The Google Drive file-attachment integration has been removed. Clevername no longer requests, reads, or stores Google Drive files, and no longer requests Drive scopes at sign-in. Any file references stored while the integration was available are retained only to fulfill export and deletion requests. Clevername's use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements. Specifically: • We use Google user data only to provide the features you explicitly enable — we do not use it for advertising, profiling, or any purpose unrelated to the feature you authorized. • We do not share Google user data with third parties except as necessary to deliver the service (for example, to authenticate your sign-in session). • We do not allow humans to read your Google user data unless you explicitly request support and grant access, or it is necessary for security purposes such as investigating abuse. • We do not use Google user data to train machine learning models.

Security

All data is transmitted over HTTPS. API keys are encrypted at rest in Google Cloud Secret Manager. Authentication tokens are stored securely using platform-appropriate mechanisms. We conduct regular security reviews and follow industry best practices for data protection. Our infrastructure runs on Google Cloud Platform with strict IAM policies and no public endpoints.

Your rights

You may access, correct, or delete your personal data by contacting us at privacy@clevername.net or through dashboard account settings. To request a complete export of all data we hold about you, contact privacy@clevername.net. Upon account deletion, all your data is permanently removed within 30 days.

Changes to this policy

We may update this policy from time to time. We will notify you of significant changes by email. Continued use of the service after changes take effect constitutes acceptance of the new policy.

Contact

For privacy questions or data requests, contact us at privacy@clevername.net.