CasesPricingContact
Sign in
Book a call

Privacy Policy

Last updated: September 5, 2026

0. Scope

Clonify processes personal data in two distinct roles. As a data controller, we process the personal data of creators using Clonify in a trial or paid plan. As a data processor, we process the personal data of visitors interacting with a creator's published clone on behalf of that creator.

A. Creator data (Clonify customer)

In this section, Clonify acts as data controller.

A.1 Controller

  • Entity: Marea Kiss LLC
  • Address: 30 N Gould St, Ste R, Sheridan, WY 82801, USA
  • Email: privacy@clonify.com

A.2 Data we collect

  • Account: email, name, profile photo, subdomain, language preference.
  • Billing: fiscal data, country, subscription plan, payment history. Card data is processed by our payment provider; Clonify does not store card numbers.
  • Uploaded content: audios, videos, documents, URLs and derived artifacts (transcripts, embeddings, knowledge graph, voice profile).
  • Technical: IP address, user agent, session cookies, error logs.
  • Usage: pages viewed, actions in admin panel, quota consumption and, only with consent, a protected navigation replay with interface text and personal fields masked.
  • Optional advertising measurement: only with consent, Meta click and browser identifiers, pages viewed and registration, trial, subscription and first-purchase events. Email and local user identifiers included in server events are normalised and securely hashed before transmission.

A.3 Purposes and legal basis

  • Service provision, authentication, billing, support — contractual necessity (art. 6.1.b GDPR).
  • Tax and accounting obligations — legal obligation (art. 6.1.c).
  • Product analytics, fraud prevention, service improvement — legitimate interest (art. 6.1.f).
  • Optional protected session replay to identify usability blocks — consent (art. 6.1.a GDPR). It can be rejected without affecting the service.
  • Optional Meta advertising measurement, attribution and audience improvement — consent (art. 6.1.a GDPR). It remains off until accepted and can be rejected without affecting the service.
  • Commercial communications about features and similar services — legitimate interest based on existing contractual relationship (LSSI-CE art. 21.2), with opt-out in every email.

A.4 Google Calendar connection (Google user data)

Connecting your Google account is optional and only relevant if you use the Meetings module. When you connect it, Clonify requests two Google Calendar permissions through Google's OAuth flow, and reads the email address of the connected account to display which calendar is linked:

  • See your availability (calendar.freebusy): we read only the busy/free time ranges of your primary calendar, to hide already-busy slots on your public booking page.
  • See and edit events (calendar.events): we create, update, and delete on your calendar only the events that correspond to bookings managed by Clonify, so each meeting appears on your agenda and you are never double-booked.

What we do NOT do: we do not read, modify, or store any of your other calendar events, nor do we use Google Calendar data for advertising, profiling, or any purpose beyond the booking sync described above. We only manage the events Clonify itself generates from your bookings.

Storage and revocation: we store the Google access and refresh tokens encrypted at rest and use them solely for the operations above. You can revoke access at any time from Clonify (Meetings → Integrations) or from your Google account's permissions page; once revoked, we stop accessing your calendar.

Clonify's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

A.5 Google Drive connection (Google user data)

Connecting Google Drive is optional and only relevant if you use the "Google Drive folder" connector to feed your clone's brain. When you connect it, Clonify requests one permission through Google's OAuth flow:

  • See and download your Drive files (drive.readonly): we read the files in the folder you choose, and its subfolders, so their content can feed your clone. We need read access rather than a one-off file picker because the point of the connector is that files you add to that folder LATER are brought in automatically, and those files do not exist yet when you grant consent.

What we do with it: we download the files of that folder, transcribe videos and audio, extract the text of PDFs, text files and Google Docs, Sheets and Slides, split it into passages and index it, so your clone can answer using that content. The subfolder structure is mirrored inside Clonify. Once a day we check the folder and bring in whatever is new or changed.

What we do NOT do: we never write, modify or delete anything in your Drive — access is read-only. We do not access files outside the folder you selected. We do not use Google Drive data for advertising, profiling, or any purpose beyond feeding the clone you configured. Deleting a file in Drive does not delete it from your brain: we tell you and you decide.

Storage and revocation: we store the Google access and refresh tokens encrypted at rest and use them solely for the operations above. You can disconnect the folder at any time from Clonify (Brain → Knowledge) or revoke access from your Google account's permissions page; once revoked, we stop accessing your Drive. Content already ingested stays in your brain until you delete it.

A.6 Who we share Google user data with

We do not sell Google user data and we do not transfer it to third parties for advertising. We share, transfer or disclose it only with the following service providers, who act as our processors under a data processing agreement and only to the extent needed to provide the features described above:

  • Cloudflare R2 — temporary storage: only the videos and audio of that folder pass through it, so they can be sent for transcription, and the file is deleted as soon as the transcription finishes. PDFs, text files and Google Docs, Sheets and Slides are processed in memory and never stored there.
  • AssemblyAI Inc. — transcribes the videos and audio of that folder into text.
  • OpenAI L.L.C. — turns the extracted text into the numeric vectors used to search it, and generates clone replies.
  • Anthropic PBC — language models that generate clone replies from that content.
  • Cohere Inc. — reorders the retrieved passages by relevance before they reach the model.
  • Neon Inc. — the PostgreSQL database where the extracted text and its vectors are stored.
  • Vercel Inc. — hosts and runs the application that performs the operations above.

The list above describes the Google Drive connection (A.5). The Google Calendar connection (A.4) involves fewer providers: calendar data is only handled by Neon, as the database, and Vercel, as the hosting that runs the sync — it never goes to the transcription or language-model providers.

Each of these providers is listed in section C with its location and its data processing agreement. Beyond them, we disclose Google user data only where legally required. We do not use Google user data to develop, improve or train generalised or non-personalised artificial intelligence or machine learning models, and our providers process it under contract without using it to train theirs.

A.7 Facebook and Instagram Lead Ads connection

Connecting a Meta account is optional. When a creator enables it, Clonify reads the Meta user's identifier and display name, the identifiers and names of the Pages they administer, the identifier and username of any linked Instagram professional account, and the identifiers and names of Lead Ads forms. Access and Page tokens are encrypted at rest.

The permissions pages_show_list, pages_read_engagement, pages_manage_ads and leads_retrieval are used only to list the creator's authorised Pages and forms and retrieve the leads generated by those forms. pages_manage_metadata is used only to subscribe or unsubscribe the selected Pages from real-time lead notifications. Clonify does not create or modify campaigns or ads, and does not read or manage messages, comments or reviews.

The creator can disconnect Meta at any time under Settings → Facebook and Instagram leads. This revokes Clonify's Page subscriptions and deletes the stored Meta tokens and connection metadata; contacts already imported remain in the creator's CRM until the creator deletes them. A Meta data-deletion request also deletes the connection associated with that Meta user.

B. Contact and visitor data processed for a creator

When a visitor interacts with a creator's clone, the creator is the data controller and Clonify is the data processor, bound by the Data Processing Addendum.

B.1 Data processed

  • Identifiers: email and optional name when the visitor logs in via OTP; anonymous cookie ID when anonymous.
  • Conversations: full transcripts of messages with the clone.
  • Memory profile: AI-generated summary plus five neutral fields (context, goal, problem, constraints, next step) derived from the conversation, to personalise future replies.
  • Technical: IP address, user agent, language, originating page.
  • Meta Lead Ads: when the creator enables the connection, the name, email and phone number submitted by the person, together with the Page, form and ad identifiers needed to identify the source. Clonify does not retain other custom form answers. The creator is the controller of this data and determines the wording, legal basis and retention of their ad form.
  • Cookies: see the Cookie Policy.

B.2 OTP clickwrap

When a visitor enters the one-time code received by email, they accept the visitor terms and this privacy policy. The acceptance is timestamped and linked to the email address.

B.3 Profiling (art. 22 GDPR)

The memory profile is automated processing designed to personalise the clone's behaviour. It does not produce legal effects or decisions significantly affecting the visitor. Visitors may reset or delete their memory profile by writing to privacy@clonify.com, or continue anonymously to avoid building one.

C. Subprocessors

We rely on the following subprocessors, each bound by a DPA with appropriate safeguards (Standard Contractual Clauses for US-based vendors).

VendorPurposeLocationDPA
Neon Inc.PostgreSQL databaseEE.UU. / UEview
Upstash Inc.Rate limiting and cacheEE.UU. / UEview
OpenAI L.L.C.Language models (clone replies)EE.UU.view
Anthropic PBCLanguage models (clone replies)EE.UU.view
Cohere Inc.Reranking of retrieved passagesEE.UU. / Canadáview
Resend Inc.Transactional email deliveryEE.UU.view
AssemblyAI Inc.Audio transcriptionEE.UU.view
Replicate Inc.Auxiliary audio processingEE.UU.view
Vercel Inc.Web application hostingEE.UU.view
Cloudflare R2File storageEE.UU. / UEview
PostHog Inc.Product analytics, usage behaviour and technical error loggingUE (Frankfurt)view
Meta Platforms, Inc. / Meta Platforms Ireland Ltd.Advertising measurement and attribution through Meta Pixel and Conversions APIUE / EE.UU.view

PostHog analytics and protected replays on public marketing pages or during active trials only activate after analytics consent. Technical error logging (what broke, on which page and in which browser, without identifying you or storing anything on your device) is sent to PostHog without consent, on the basis of our legitimate interest in keeping the service working. Meta and Google Ads measurement, including YouTube campaigns, only activates after advertising consent and when those tools are configured.

D. Retention

Clonify applies a Shopify-style soft-delete retention schedule:

  • Active tenant: creator data retained indefinitely while the subscription is active. Visitor data retained for 3 years from last interaction.
  • Tenant cancelled: workspace enters "suspended" state, visitor data retained for 90-day grace period.
  • After 90 days: visitor data purged. Minimal tenant skeleton (billing/tax records) kept 4 years for Spanish fiscal obligations, then deleted.
  • Visitor deletion request: processed immediately, regardless of tenant status.

E. Your rights

Under GDPR and Spanish data protection law you have the rights of access, rectification, erasure, opposition, restriction, portability, and not to be subject to solely automated decisions (ARSULIPO).

To exercise any of these, write to privacy@clonify.com including proof of identity. We respond within 30 days. If you are a visitor of a clone, we will forward the request to the corresponding creator (controller) when applicable.

You may also lodge a complaint with the Spanish AEPD (www.aepd.es) or your local supervisory authority.

F. Security

We apply technical and organisational measures: multi-tenant isolation enforced by code review and lint, TLS in transit, encryption at rest by Neon, rate limiting on sensitive endpoints, OTP for sensitive flows, role-based access control, and CORS pinning.

G. International transfers

Some subprocessors are based in the United States. Transfers are covered by Standard Contractual Clauses (Commission Decision 2021/914) and, where applicable, by the EU-US Data Privacy Framework.

H. Minors

Clonify is intended for users over 16. We do not knowingly collect data from minors below this age.

I. Changes

We may amend this policy to reflect legal or service changes. Material changes will be notified by email or by a prominent notice on the platform.

← Back to home

© 2026 Clonify · Marea Kiss LLC

Book a callSuccess storiesContact usPrivacyCookiesTermsDPA