Legal

Privacy Policy

What we collect, why, how long we keep it, who can see it, and the choices you have.

Effective

The short version: we collect what we need to run the Services and bill you, we do not sell your data or use it for advertising, AI providers see your prompts only under zero-retention terms, and anything you build on the platform is yours. The rest of this page is the detail.

1.Who this policy covers

This policy applies to everything Clusterbase Inc. (“Clusterbase”, “we”, “us”) operates, together the “Services”:

  • Cluster — the consumer app for search, chat, bots, images, and apps, on the web, iOS, Android, and desktop.
  • Cluster Build — the terminal coding assistant and its cloud planning and review features.
  • Clusterbase platform — the console, CLI, and APIs for functions, compute, databases, storage, sandboxes, domains, managed agents, and the LLM gateway.
  • Our websites, documentation, and support channels.

When you use the platform to build something for your own users, we process their data on your behalf and on your instructions. Data you process on the platform explains that split. Your own privacy notice, not this one, governs what you do with your users’ data.

2.What we collect

Information you give us

CategoryExamples
AccountName, email address, password hash or single sign-on identifier, profile picture, organization memberships.
ContentPrompts, queries, uploaded files, conversation history, generated outputs, code you run through Cluster Build, and resources you deploy on the platform.
BillingPlan, invoices, and the last four digits and expiry of a payment card. Full card numbers are held by our payment processor, never by us.
ConnectionsOAuth credentials for services you choose to connect, such as GitHub or Gmail. See Connected services.
SupportAnything you send us when you ask for help or report a problem.

Information we collect automatically

CategoryExamples
Device and connectionIP address, browser and OS, device type, language, time zone, and request timestamps.
UsageFeatures used, pages visited, actions taken, error reports, and performance measurements.
Platform telemetryInvocation counts, execution time, resource consumption, build and deployment logs. Used to run the service and to bill you.
CookiesA session cookie for sign-in and a first-party analytics cookie. We do not use advertising cookies or cross-site trackers.

We do not require you to give us sensitive data such as health, biometric, or precise location information, and we ask that you do not put it into prompts unless you need to.

3.How we use it

  • Run the Services. Answer your queries, run your code, host your resources, keep you signed in, and sync across your devices.
  • Bill you. Meter usage, charge your plan, detect fraud, and send invoices.
  • Keep the Services secure. Detect abuse, enforce rate limits, investigate incidents, and protect other users.
  • Improve the Services. Understand which features are used, find bugs, and measure performance. Wherever we can, we do this with aggregated or de-identified data.
  • Talk to you. Send service notices, security alerts, and replies to your support requests. Product announcements are opt-out.
  • Comply with the law. Meet our legal obligations and respond to lawful requests.

Model training

We may use content from Cluster consumer accounts to improve our models unless you turn that off in your account settings. We never train on content from organization or platform accounts, on Cluster Build sessions, or on data obtained through a connected service such as Gmail or GitHub. Turning training off applies to content going forward; it does not undo training that already happened.

4.AI model providers

Cluster runs on a mix of models we host and models from third-party providers. When a request is routed to a third party, the prompt and any attached content are sent to that provider to generate the response.

We use these providers under zero data retention terms wherever the provider offers them: the provider processes the request, returns the output, and does not store the content, log it for human review, or train on it. Where a provider cannot offer zero retention, we say so in the model picker.

Providers never receive your name, email address, or account identifiers. They receive only what is needed to generate the answer.

5.Connected services and Google user data

You can connect third-party accounts to Cluster so it can act on your behalf. Every connector is off by default, is enabled only when you explicitly grant access on the provider’s consent screen, and can be revoked at any time from the Plugins screen inside Cluster or from the provider’s own settings.

Gmail

The Gmail connector requests these scopes, each only for the purpose stated:

  • gmail.readonly — search your mailbox and read message content so the assistant can answer questions about and summarize your mail. A metadata-only scope cannot answer questions about what a message says.
  • gmail.compose — create and update drafts so you can review and send them yourself.
  • gmail.send — send a message only when you directly ask for it. The assistant never sends mail on a schedule, in bulk, or without an instruction from you.

Gmail content is processed in memory for the duration of the request that needed it and then discarded. We do not copy your mailbox, build an index of your messages, or keep message bodies, subjects, attachments, or recipient lists after the request completes. Gmail data is never used to train any model and is never sold, rented, or used for advertising. It is disclosed only to the AI model provider that processes your request, under the zero-retention terms in AI model providers, and where the law requires.

The one thing we keep is the OAuth credential Google issues when you connect. It is scoped to your account, stored encrypted with restricted access, and deleted when you disconnect. You can also revoke it from your Google Account permissions.

Cluster App’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

GitHub and other connectors

The same rules apply to every other connector: we request the narrowest scopes that make the feature work, hold only the credential, and access the connected account only to carry out what you asked.

6.When we share it

We do not sell personal data, and we do not share it for advertising. We share it only:

  • With service providers who process it for us — cloud hosting, payment processing, email delivery, error and analytics tooling, and the AI model providers. Each is bound by contract to use the data only to provide their service to us.
  • Inside your organization. If you belong to an organization on the platform, its administrators can see your membership, role, and the resources and usage attributed to you.
  • When the law requires it — in response to a subpoena, court order, or other binding request. We tell you first where we are legally allowed to.
  • To protect people. Where necessary to prevent serious harm, fraud, or a security incident.
  • In a business transfer. If Clusterbase is acquired or merges, your data moves with the company and remains subject to this policy.
  • With your consent for anything else.

7.How long we keep it

DataRetention
AccountUntil you delete your account, then removed within 30 days.
Conversations and filesUntil you delete them, or until the account is deleted. Temporary chats are not stored after the session ends.
Platform resourcesUntil you delete the resource or the organization that owns it. Backups roll off within 30 days after that.
Connector credentialsUntil you disconnect the service or delete your account.
Invoices and billing recordsSeven years, as tax and accounting law requires.
Request and security logsUp to 90 days, then deleted or de-identified.
Support conversationsTwo years after the ticket closes.

We may keep data longer where we must to comply with a legal hold, resolve a dispute, or enforce our agreements, and we keep de-identified aggregates indefinitely.

8.Data you process on the platform

If you build on the Clusterbase platform, the data your functions, databases, stores, sandboxes, and agents handle is your data. You are the controller of it and we are your processor. That means:

  • We access it only to provide the Services, to support you when you ask, and as the law requires.
  • We never use it for model training, analytics, or any purpose of our own.
  • We store it in the region you choose, where the product offers a choice.
  • We delete it when you delete the resource, on the schedule in How long we keep it.
  • We use subprocessors — cloud infrastructure and the AI model providers — and will provide the current list and notice of changes on request.

Organizations that need a data processing agreement can request one at privacy@clusterbase.ai.

9.Your rights and choices

Regardless of where you live, you can:

  • Access and export your data from your account settings.
  • Correct your profile at any time.
  • Delete individual conversations, files, resources, or your whole account.
  • Turn off model training for your consumer account.
  • Disconnect any connected service.
  • Opt out of product announcements using the link in any email.

If you are in the European Economic Area, the United Kingdom, or Switzerland, you also have the right to object to or restrict processing, to data portability, and to lodge a complaint with your supervisory authority. Our legal bases are performance of our contract with you, our legitimate interests in running and securing the Services, consent where we ask for it, and compliance with law.

If you are a California resident, the rights above cover your rights to know, delete, correct, and opt out under the CCPA. We do not sell or share personal information as those terms are defined there, and we do not use sensitive personal information to infer characteristics about you. We will not treat you differently for exercising any right.

To exercise a right we cannot serve from account settings, email privacy@clusterbase.ai. We respond within 30 days, and we may need to verify that the request comes from you.

10.Security

Data is encrypted in transit and at rest. Credentials and connector tokens are stored encrypted with access restricted to the systems that need them. Every workload on the platform runs in its own isolated virtual machine, so one tenant’s code cannot reach another’s. Access by our staff is role-based, logged, and limited to what the job needs.

No system is perfectly secure. If we learn of a breach that affects your data, we will notify you and any regulator without undue delay, as the law requires.

11.International transfers

We are based in the United States and process data there and wherever our service providers operate. When we move personal data out of the EEA, UK, or Switzerland we rely on the European Commission’s Standard Contractual Clauses, the UK Addendum, and equivalent safeguards.

12.Children

The Services are not for anyone under 13, or under the age at which a person can consent to data processing where they live, if higher. We do not knowingly collect data from children. If you think we have, email privacy@clusterbase.ai and we will delete it.

13.Changes to this policy

When we change this policy we update the effective date at the top. If a change materially reduces your rights or expands what we collect, we will tell you by email or in the product before it takes effect.

14.Contact

Questions, requests, and complaints go to privacy@clusterbase.ai.

Clusterbase Inc.
Attn: Privacy

See also: Terms of Service