The short version: we collect what we need to run the Services and bill you, we do not sell your data or use it for advertising, AI providers see your prompts only under zero-retention terms, and anything you build on the platform is yours. The rest of this page is the detail.
1.Who this policy covers
This policy applies to everything Clusterbase Inc. (“Clusterbase”, “we”, “us”) operates, together the “Services”:
- Cluster — the consumer app for search, chat, bots, images, and apps, on the web, iOS, Android, and desktop.
- Cluster Build — the terminal coding assistant and its cloud planning and review features.
- Clusterbase platform — the console, CLI, and APIs for functions, compute, databases, storage, sandboxes, domains, managed agents, and the LLM gateway.
- Our websites, documentation, and support channels.
When you use the platform to build something for your own users, we process their data on your behalf and on your instructions. Data you process on the platform explains that split. Your own privacy notice, not this one, governs what you do with your users’ data.
2.What we collect
Information you give us
| Category | Examples |
|---|---|
| Account | Name, email address, password hash or single sign-on identifier, profile picture, organization memberships. |
| Content | Prompts, queries, uploaded files, conversation history, generated outputs, code you run through Cluster Build, and resources you deploy on the platform. |
| Billing | Plan, invoices, and the last four digits and expiry of a payment card. Full card numbers are held by our payment processor, never by us. |
| Connections | OAuth credentials for services you choose to connect, such as GitHub or Gmail. See Connected services. |
| Support | Anything you send us when you ask for help or report a problem. |
Information we collect automatically
| Category | Examples |
|---|---|
| Device and connection | IP address, browser and OS, device type, language, time zone, and request timestamps. |
| Usage | Features used, pages visited, actions taken, error reports, and performance measurements. |
| Platform telemetry | Invocation counts, execution time, resource consumption, build and deployment logs. Used to run the service and to bill you. |
| Cookies | A session cookie for sign-in and a first-party analytics cookie. We do not use advertising cookies or cross-site trackers. |
We do not require you to give us sensitive data such as health, biometric, or precise location information, and we ask that you do not put it into prompts unless you need to.
3.How we use it
- Run the Services. Answer your queries, run your code, host your resources, keep you signed in, and sync across your devices.
- Bill you. Meter usage, charge your plan, detect fraud, and send invoices.
- Keep the Services secure. Detect abuse, enforce rate limits, investigate incidents, and protect other users.
- Improve the Services. Understand which features are used, find bugs, and measure performance. Wherever we can, we do this with aggregated or de-identified data.
- Talk to you. Send service notices, security alerts, and replies to your support requests. Product announcements are opt-out.
- Comply with the law. Meet our legal obligations and respond to lawful requests.
Model training
We may use content from Cluster consumer accounts to improve our models unless you turn that off in your account settings. We never train on content from organization or platform accounts, on Cluster Build sessions, or on data obtained through a connected service such as Gmail or GitHub. Turning training off applies to content going forward; it does not undo training that already happened.
4.AI model providers
Cluster runs on a mix of models we host and models from third-party providers. When a request is routed to a third party, the prompt and any attached content are sent to that provider to generate the response.
We use these providers under zero data retention terms wherever the provider offers them: the provider processes the request, returns the output, and does not store the content, log it for human review, or train on it. Where a provider cannot offer zero retention, we say so in the model picker.
Providers never receive your name, email address, or account identifiers. They receive only what is needed to generate the answer.
5.Connected services and Google user data
You can connect third-party accounts to Cluster so it can act on your behalf. Every connector is off by default, is enabled only when you explicitly grant access on the provider’s consent screen, and can be revoked at any time from the Plugins screen inside Cluster or from the provider’s own settings.
Gmail
The Gmail connector requests these scopes, each only for the purpose stated:
- gmail.readonly — search your mailbox and read message content so the assistant can answer questions about and summarize your mail. A metadata-only scope cannot answer questions about what a message says.
- gmail.compose — create and update drafts so you can review and send them yourself.
- gmail.send — send a message only when you directly ask for it. The assistant never sends mail on a schedule, in bulk, or without an instruction from you.
Gmail content is processed in memory for the duration of the request that needed it and then discarded. We do not copy your mailbox, build an index of your messages, or keep message bodies, subjects, attachments, or recipient lists after the request completes. Gmail data is never used to train any model and is never sold, rented, or used for advertising. It is disclosed only to the AI model provider that processes your request, under the zero-retention terms in AI model providers, and where the law requires.
The one thing we keep is the OAuth credential Google issues when you connect. It is scoped to your account, stored encrypted with restricted access, and deleted when you disconnect. You can also revoke it from your Google Account permissions.
Cluster App’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
GitHub and other connectors
The same rules apply to every other connector: we request the narrowest scopes that make the feature work, hold only the credential, and access the connected account only to carry out what you asked.
7.How long we keep it
| Data | Retention |
|---|---|
| Account | Until you delete your account, then removed within 30 days. |
| Conversations and files | Until you delete them, or until the account is deleted. Temporary chats are not stored after the session ends. |
| Platform resources | Until you delete the resource or the organization that owns it. Backups roll off within 30 days after that. |
| Connector credentials | Until you disconnect the service or delete your account. |
| Invoices and billing records | Seven years, as tax and accounting law requires. |
| Request and security logs | Up to 90 days, then deleted or de-identified. |
| Support conversations | Two years after the ticket closes. |
We may keep data longer where we must to comply with a legal hold, resolve a dispute, or enforce our agreements, and we keep de-identified aggregates indefinitely.
8.Data you process on the platform
If you build on the Clusterbase platform, the data your functions, databases, stores, sandboxes, and agents handle is your data. You are the controller of it and we are your processor. That means:
- We access it only to provide the Services, to support you when you ask, and as the law requires.
- We never use it for model training, analytics, or any purpose of our own.
- We store it in the region you choose, where the product offers a choice.
- We delete it when you delete the resource, on the schedule in How long we keep it.
- We use subprocessors — cloud infrastructure and the AI model providers — and will provide the current list and notice of changes on request.
Organizations that need a data processing agreement can request one at privacy@clusterbase.ai.
9.Your rights and choices
Regardless of where you live, you can:
- Access and export your data from your account settings.
- Correct your profile at any time.
- Delete individual conversations, files, resources, or your whole account.
- Turn off model training for your consumer account.
- Disconnect any connected service.
- Opt out of product announcements using the link in any email.
If you are in the European Economic Area, the United Kingdom, or Switzerland, you also have the right to object to or restrict processing, to data portability, and to lodge a complaint with your supervisory authority. Our legal bases are performance of our contract with you, our legitimate interests in running and securing the Services, consent where we ask for it, and compliance with law.
If you are a California resident, the rights above cover your rights to know, delete, correct, and opt out under the CCPA. We do not sell or share personal information as those terms are defined there, and we do not use sensitive personal information to infer characteristics about you. We will not treat you differently for exercising any right.
To exercise a right we cannot serve from account settings, email privacy@clusterbase.ai. We respond within 30 days, and we may need to verify that the request comes from you.
10.Security
Data is encrypted in transit and at rest. Credentials and connector tokens are stored encrypted with access restricted to the systems that need them. Every workload on the platform runs in its own isolated virtual machine, so one tenant’s code cannot reach another’s. Access by our staff is role-based, logged, and limited to what the job needs.
No system is perfectly secure. If we learn of a breach that affects your data, we will notify you and any regulator without undue delay, as the law requires.
11.International transfers
We are based in the United States and process data there and wherever our service providers operate. When we move personal data out of the EEA, UK, or Switzerland we rely on the European Commission’s Standard Contractual Clauses, the UK Addendum, and equivalent safeguards.
12.Children
The Services are not for anyone under 13, or under the age at which a person can consent to data processing where they live, if higher. We do not knowingly collect data from children. If you think we have, email privacy@clusterbase.ai and we will delete it.
13.Changes to this policy
When we change this policy we update the effective date at the top. If a change materially reduces your rights or expands what we collect, we will tell you by email or in the product before it takes effect.
14.Contact
Questions, requests, and complaints go to privacy@clusterbase.ai.
Clusterbase Inc.
Attn: Privacy
See also: Terms of Service