Privacy Policy
Last updated August 12, 2026
1. Scope
This Privacy Policy explains how Clone Labs, Inc. (“Clone,” “we,” “us,” or “our”) collects, uses, shares, and otherwise processes personal information when you use our websites, desktop applications, APIs, and related services (collectively, the “Services”). It does not govern third-party services that have their own privacy policies.
When Clone processes personal information on behalf of an organization under a Data Processing Addendum (“DPA”), Clone acts as a service provider or processor for the Customer Personal Data defined in that DPA, and the DPA governs to the extent of any conflict with this Policy.
2. Information we collect
Account and authentication information
We may collect your email address, name, account identifiers, hashed credentials, and authentication records. If you use a third-party sign-in provider, we may receive the identifiers and profile information that provider makes available.
Product content and data flow
Depending on the features you enable, Clone may process screen and application activity, screenshots and extracted text, typed input, audio and transcripts, speaker information, voice features, connected or imported content, prompts, conversations, memories, predictions, and related AI activity.
Desktop product content is generally stored locally on your device. When you use a cloud, AI, synchronization, mobile, or integration feature, the content needed for that feature may be transmitted through Clone's systems to the applicable service provider. Screen and application recording, including typed-input capture, is off by default and begins only after you enable it and grant the required operating-system permissions. Background Voice and Desktop product analytics are also off by default.
Sensitive content and voice features
Clone applies an automated privacy filter to supported outbound text before it is sent to a remote service. Automated filtering and application exclusions may not identify every password field, item of sensitive information, sensitive application, or sensitive window. You should pause recording or exclude applications before handling passwords, financial information, health information, privileged communications, or other sensitive material.
If you use Voice or speaker-enrollment features, Clone may process audio, transcripts, speaker segments, and a voice embedding used to distinguish speakers. Enrollment information may be stored locally on your device. Recordings may include other people, and you are responsible for providing legally required notices and obtaining required permissions before recording them.
Turning off a feature stops or limits new collection for that feature but does not automatically delete information previously stored on your device or processed by Clone or its providers.
Billing, communications, device, and usage information
Payment-card details are handled by Stripe or another payment processor. We may receive billing contact, customer, subscription, plan, status, and transaction information, but we do not receive or store your full payment-card number.
We also collect information you provide when you contact us, request support, or join a waitlist, as well as device, browser, IP address, operating-system, usage, diagnostic, performance, referral, and timestamp information generated through use of the Services.
3. Sources of information
We collect information directly from you, automatically from your device and use of the Services, from services you choose to connect, and from vendors that help us operate the Services, such as authentication, analytics, infrastructure, AI-model, and payment providers.
4. How we use information
We use personal information to:
- provide, personalize, maintain, and improve the Services;
- create and secure accounts, authenticate users, and process payments;
- operate agent, memory, prediction, and user-model features you select;
- respond to questions, provide support, and send service communications;
- understand usage, diagnose problems, and develop new features;
- prevent fraud, abuse, security incidents, and violations of our terms; and
- comply with law and protect the rights, safety, and integrity of Clone, our users, and others.
5. AI, subprocessors, and personalized user models
When you use a cloud, AI, transcription, analytics, authentication, payment, infrastructure, or integration feature, Clone may transmit the information needed for that feature through Clone's systems to the applicable provider.
| Recipient | Information and purpose |
|---|---|
| Clone API | Authenticated gateway for selected prompts, context, outputs, mobile relay objects, integration data, and request metadata |
| FriendliAI and hosted models, including DeepSeek | Selected text prompts, context, and outputs for hosted model inference and user-model features |
| OpenAI / Codex | Selected prompts, context, files, outputs, and agent-execution content for OpenAI and Codex features |
| Anthropic / Claude | Selected text and supported image content for Claude features and content enrichment |
| ElevenLabs | Audio and returned transcripts when you separately select Enhanced transcription |
| PostHog | Opt-in Desktop product analytics events and related account, device, and usage properties |
Additional providers may include Google for authentication and website analytics, Stripe for billing, AWS for software distribution and infrastructure, and Slack and Tiro for user-directed integrations. The providers involved depend on the feature you select.
Clone applies automated privacy filtering to supported outbound text, but automated filtering may not identify every item of sensitive information. A personalized user model may learn from your content and activity to provide features such as memories or predictions.
Clone does not use private product content to train a general-purpose model for other users without explicit consent. Clone may use Deidentified Data and Analytics Data as described in the Terms to improve and train its models, algorithms, products, and services. Provider processing, retention, training practices, deletion support, and location depend on the feature, provider, account configuration, and applicable agreement. AI-generated outputs may be incomplete or inaccurate and should be reviewed before use.
6. Analytics
We use analytics and marketing technologies, including Google Analytics and PostHog, to understand website and product usage. Where enabled, Google Ads may be used for attribution and advertising measurement. These technologies may process account, device, usage, attribution, page-view, referral, and feature-event information.
Our websites and service providers may use cookies, local-storage technologies, pixels, and similar technologies for security, functionality, analytics, and marketing. Where consent is required, optional analytics and advertising technologies remain off unless you accept them. You can manage available choices through our consent controls and browser settings.
Desktop product analytics are off by default and operate only after opt-in. We do not include the content of Desktop goals or intents in product analytics. Where required by applicable law, we treat supported Global Privacy Control signals as requests to opt out of sale or sharing and honor Do Not Track signals for optional website tracking.
Account analytics
Account analytics are a separate optional choice from website analytics. If you opt in at signup or in Account settings, Clone may send limited account-linked events, such as subscription lifecycle and first signed-in Desktop activation, to PostHog. These analytics events exclude message or goal content, email addresses, payment or provider identifiers, authentication tokens, URLs, query strings, referrers, and free text.
This setting does not enable website cookies or browser analytics, and website consent does not enable account analytics. Withdrawing account analytics stops future account-linked analytics after the change is confirmed and causes queued optional events to be discarded. It does not by itself delete analytics already processed; account deletion or a separate privacy request is required for deletion.
7. Connected X accounts
If you connect an X account, we may process OAuth tokens, drafts you approve for publishing, resulting post IDs, and metrics for posts owned by your connected account so that we can publish and measure content at your direction. Your use of X remains subject to X’s terms and policies. Our X integration is not designed to automate likes, follows, direct messages, or unsolicited replies.
You can revoke Clone’s X access through X’s Apps and sessions settings. You may also contact us to request deletion of X data associated with your account. We delete or update stored X content when it is deleted or modified on X, when X or the applicable account owner asks us to do so, and as otherwise required by X’s policies and applicable law.
8. Connected Slack workspaces
If you connect a Slack workspace, Clone stores encrypted Slack bot and user OAuth access tokens, the workspace ID and name, the connected Slack user ID, and applicable app and bot user IDs. When you use the integration, Clone may also process member, user, and bot names and other information Slack makes available for the action you request.
Clone requests member and public-channel lists, message threads, and related Slack content on demand to support workspace sync, user-directed posts, and replies to the threads you choose to follow. The hosted Slack connector does not persist Slack response payloads as a separate cloud archive. Goal, thread, and related Slack context used by Clone Desktop may persist locally on your device until you delete it or remove the applicable application data.
Your Slack user OAuth token is retained while your individual Slack connection remains active. If you disconnect Slack or delete your Clone account, that user token is removed from the active connection and staged for revocation with Slack. The shared workspace bot token remains available while other active Clone connections to that workspace exist. It is removed from active use and staged for revocation only after no active connections to the workspace remain. Hash-only tombstones may remain to prevent revoked tokens from being reactivated; these hashes cannot be used to access Slack.
Slack content is used only for the user-directed Clone features and model inference you request. Slack data is never used to train large language models.
9. How we share information
We may share personal information with:
- Service providers that support hosting, AI features, authentication, analytics, payments, communications, support, and security;
- Integrations you direct when you connect or instruct us to interact with a third-party service;
- Authorities or other parties when reasonably necessary to comply with law, respond to valid legal process, enforce our terms, or protect rights, safety, and security; and
- Transaction participants in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of our business, subject to appropriate safeguards.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
10. Retention and deletion
Retention periods depend on the category of information, the feature used, your choices, and legal or operational requirements. Local product content remains on your device until you delete it through available controls or remove the applicable application data. Signing out, disabling a feature, or disconnecting an integration does not necessarily delete existing local data.
We retain account-linked and cloud-processed information for as long as reasonably necessary to provide the Services, comply with law, protect the Services, and resolve disputes. Disabling a feature stops or limits new processing but does not automatically delete copies previously processed by Clone, its providers, or connected services.
You may request account or data deletion by emailing contact@clone.is with the subject “Deletion request” and identifying the affected account, device, feature, or data category. We may verify your identity and route the request to applicable providers where required. Some information may remain temporarily in backups, security logs, billing records, or other records retained as required or permitted by law.
11. Security
We use reasonable administrative, technical, and organizational measures designed to protect personal information, including access controls, encrypted network transport, and operating-system security controls where appropriate.
No method of storage or transmission is completely secure. You should protect your account and device, enable device encryption, exclude sensitive applications, and pause recording before handling sensitive information.
12. Your choices and rights
Acceptance of the Terms and acknowledgment of this Policy are separate from feature-specific privacy choices. Where a feature presents a separate control for capture, Voice, enhanced transcription, analytics, or another optional processing activity, your choice applies to that feature and may be changed through available settings. Current defaults and known limitations, including Desktop capture after operating-system permission, are described in Section 2. Withdrawing or disabling a feature stops or limits new processing for that feature but does not by itself delete existing copies; see Section 10.
You may update certain account information through the Services and may disconnect integrations through the connected provider’s controls where available, or by contacting us.
Depending on where you live, you may have the right to request access to, correction of, deletion of, or a copy of your personal information, or to object to or restrict certain processing. You may also have the right to appeal our response or contact a local data-protection authority.
To make a privacy request, email contact@clone.is. We may need to verify your identity before completing a request. Authorized agents may submit requests where applicable, subject to verification of their authority.
13. International processing
Clone and its service providers may process information in the United States and other countries, depending on the feature, provider, and routing configuration. These countries may have data-protection laws that differ from those where you live. Where required, Clone will use appropriate transfer mechanisms and safeguards.
14. Age requirement
The Services are for people age 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided us with personal information, please contact us so we can review and address it.
15. Changes to this Policy
We may update this Privacy Policy as the Services and law evolve. We will post the updated Policy and revise the “Last updated” date. If changes are material, we will provide additional notice when reasonably practicable.
16. Contact us and incident procedure
Clone Labs, Inc. is the responsible contact for privacy requests, deletion requests, and suspected security incidents. Email contact@clone.is and use “Privacy request,” “Deletion request,” or “Security incident” in the subject. Include the affected account, device or feature, approximate time, and a description, but do not email passwords, API keys, raw recordings, or other secrets. Clone will acknowledge the report, verify identity when needed, assess the affected systems and providers, take containment or deletion steps, and provide legally required notices and status updates.