Privacy Policy
Last updated: 20 June 2026
This Privacy Policy explains how Clane AI Ltd ("Clane", "we", "us") collects, uses, shares, and protects personal data when you visit our website, join our early-access programme, or use the Clane service (the "Service"). It applies to clane.ai and the signed-in product. By using the Service you agree to this Policy.
For data you put into Clane to do work ("Customer Data"), you are the controller and we act as your processor under your instructions and your agreement with us; this Policy governs the personal data for which we are the controller (e.g. your account and website data).
1. Who we are
Clane AI Ltd is the data controller for personal data described in this Policy. Contact our privacy team at privacy@clane.ai.
2. Data we collect
- Account & contact data — name, work email, company, role, and messages you send us (e.g. an early-access or demo request).
- Customer Data & connected-service data — files, prompts, and the data Clane reads or writes in tools you connect (e.g. storage, email, CRM, finance systems) to perform the work you ask for.
- Authentication data — if you sign in with a third-party identity provider (e.g. Google, Microsoft), we receive your basic profile (name, email, avatar) and the OAuth tokens needed to access the scopes you grant.
- Usage & device data — pages viewed, actions taken, approximate location (from IP), browser/device type, collected via privacy-first, aggregate analytics.
- Cookies & similar — strictly-necessary cookies for the app session; analytics that do not use cross-site tracking cookies.
3. How we use data
- To provide, operate, secure, and improve the Service and run the workflows you request.
- To authenticate you and maintain your session.
- To communicate about your account, your invite, support, and material changes.
- To detect, prevent, and address fraud, abuse, and security incidents.
- To comply with legal obligations.
4. Google / Microsoft API user data — Limited Use
If you connect a Google or Microsoft account, Clane's use of information received from those APIs adheres to the provider's API Services User Data Policy, including the Limited Use requirements. Specifically: we only access the scopes you grant; we use that data solely to provide and improve the user-facing features you requested; we do not sell it, use it for advertising, or use it to train generalised/ shared AI models; and we do not transfer it except as needed to provide the Service, comply with law, or with your consent. You can revoke access at any time from your provider's security settings or from within Clane.
5. Legal bases (EEA/UK)
We process personal data on the bases of: performance of a contract (to provide the Service); our legitimate interests (to secure and improve the Service); your consent (where required, e.g. certain communications); and compliance with legal obligations.
6. Sharing & subprocessors
We do not sell your personal data. We share it only with: service providers/subprocessors that host and run the Service (e.g. cloud infrastructure, model providers, analytics) under data-processing terms; the third-party tools you choose to connect; and authorities where legally required. A current subprocessor list is available on request and will be published as we scale.
7. AI & your data
We do not use your Customer Data or connected-service data to train shared or third-party foundation models, and we do not mix one customer's data with another's. Per-customer isolation is enforced.
8. Retention & deletion
We keep personal data only as long as needed for the purposes above or as required by law. You can request deletion of your account data at any time and we action it promptly (typically within 30 days). Disconnecting an integration purges the associated connected-service data.
9. Security
Data is encrypted in transit (TLS 1.3) and at rest (AES-256). We use sandboxed execution, role-based access, audit logging, and per-customer isolation. EU data residency is available. No method is 100% secure, but we work to protect your data and improve continuously.
10. International transfers
Where data is transferred outside the EEA/UK, we rely on appropriate safeguards (e.g. Standard Contractual Clauses) and offer EU data residency for customers who require it.
11. Your rights
Subject to applicable law (incl. GDPR and CCPA), you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to processing, and to withdraw consent. To exercise these, email privacy@clane.ai. You may also complain to your local data-protection authority.
12. Cookies
We use strictly-necessary cookies to run the signed-in app and privacy-first analytics that avoid cross-site tracking. You can control cookies in your browser settings.
13. Children
The Service is for business use and is not directed to children under 16. We do not knowingly collect their data.
14. Changes
We may update this Policy; material changes will be notified and the "last updated" date revised.
15. Contact
Clane AI Ltd — privacy questions and requests: privacy@clane.ai. See also our Terms of Service.