Privacy policy
Last updated: August 8, 2026
Who we are
This privacy policy explains how Maksim Burov, trading as clonq.io ("Clonq", "we", "us"), collects, uses, and protects personal data when you visit our website, sign up for an account, or use the Clonq product. For our full company details, see our Impressum.
Scope: two roles we play
Clonq is a knowledge platform: creators upload their own content, and the platform answers their community’s questions using it. That means personal data flows through us in two different ways, and we play a different legal role in each.
- As the operator of clonq.io, we are the data controller for account, billing, and website data described in this policy — your sign-up details, payment records, support requests, and how you use the dashboard.
- As the provider of the bot service, we are typically a data processor for the content a creator uploads to their Vault and for the messages their Discord community sends to the bot. The creator (account holder) is the controller for that data, the same way a CRM or form-builder is a processor for its customers’ data. If you’re a community member asking a bot a question, the vault owner — not Clonq — is responsible for that data under GDPR, though we’re glad to help route a request to them.
Data we collect
- Account & identity data — when you sign in via Clerk (Discord, Google, or email one-time passcode), we receive your email address, auth provider, and, if you sign in with Discord, your Discord user ID. This lets us skip a second OAuth step when you connect a bot to your own server.
- Vault content — text, audio, video, PDF files, and URLs (e.g. YouTube, Loom, podcast links) you upload to your Vault. We process this with Google Gemini to extract statements, tone, and phrasing, and to generate embeddings for search. You’re responsible for the personal data contained in whatever you upload — see Scope above.
- Chat & query data — when someone asks your bot a question, we log the message, the bot’s answer (if any), timestamps, token counts, latency, and whether the reply used your own Gemini key. This exists to answer the question, show it in your dashboard, and let you turn unanswered questions into new Vault content — not to build a profile of that person.
- BYOK API key — if you bring your own Google Gemini API key, it’s encrypted at rest (AES-256-GCM) and decrypted only in memory for the duration of an API call. We never log or persist the decrypted key.
- Billing data — subscriptions are handled by Lemon Squeezy, our merchant of record. Lemon Squeezy collects your name, billing address, and payment details directly and acts as an independent controller for that data; we only receive your plan, subscription status, and billing period dates.
- Usage & device data — standard web request metadata (IP address, browser/OS, referrer, timestamps) collected for security and abuse prevention, plus aggregated product-analytics events (see Cookies & analytics below).
- Support & communication — if you email or use a contact form, we keep the message and your contact details to respond to you.
How we use it
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Provide the account and dashboard | Account & identity data | Contract (1)(b) |
| Ingest and compile Vault content, generate embeddings | Vault content | Contract (1)(b) |
| Answer questions asked to your bot | Chat & query data | Contract (1)(b); legitimate interest (1)(f) |
| Enforce Vault Hours / Replies quotas, prevent abuse | Account, usage data | Legitimate interest (1)(f) |
| Process payments, invoicing, VAT | Billing data | Contract (1)(b); legal obligation (1)(c) |
| Secure the site, debug, prevent fraud | Usage & device data | Legitimate interest (1)(f) |
| Product analytics (aggregated) | Usage data (PostHog) | Consent (1)(a) |
| Send the monthly Impact Summary digest | Account, aggregated chat data | Contract / legitimate interest (1)(b)/(1)(f) — opt out anytime |
| Respond to support requests | Contact & communication data | Legitimate interest (1)(f) |
| Comply with tax and accounting law | Billing data | Legal obligation (1)(c) |
AI processing
We use Google Gemini exclusively for AI processing — multi-modal ingestion of your Vault content, generating embeddings, and producing replies to questions. On Clonq’s managed API credits, your content and queries are sent to Google’s Gemini API under Google’s API terms. If you bring your own Gemini key (BYOK), those calls run under your own Google account and billing, subject to Google’s terms directly.
We do not use your Vault content, chat messages, or query data to train our own models. Google’s published terms for the Gemini API state that API traffic isn’t used to train Google’s models by default — we rely on those published terms rather than independently auditing Google’s systems, and this section will be updated if that changes.
The bot only answers from what you’ve uploaded. If a question isn’t covered by your Vault, it stays silent and logs the question as unanswered instead of generating an answer from outside sources.
Cookies & analytics
We use PostHog for product analytics, and only capture custom, aggregated events — plan tier, feature usage, latency, token counts. We never send raw prompts, chat messages, or completions to PostHog.
A single first-party cookie (clonq_cookie_consent) records your cookie choice for a year. Setting it doesn’t itself require consent, since it’s a record of your decision, not a tracking identifier.
Analytics cookies from PostHog only load after you accept the cookie banner. Decline, and we don’t load them — change your mind anytime via the cookie settings link in the footer.
Sharing & subprocessors
We don’t sell personal data, and we don’t share it for third-party advertising. We share personal data only with the service providers that run the platform, each bound by a data processing agreement where required:
| Provider | Purpose | Region |
|---|---|---|
| Clerk, Inc. | Authentication (sign-in/up, session management) | United States |
| Discord Inc. | OAuth sign-in, bot delivery of replies | United States |
| Google LLC | Gemini AI processing (ingestion, embeddings, replies) | United States / global |
| Supabase, Inc. | Database (Postgres) and file storage | European Union (Frankfurt) |
| Vercel Inc. | Web app hosting | United States / global edge |
| Railway Corp. | Discord bot worker hosting | United States |
| Inngest Inc. | Background job orchestration | United States |
| PostHog Inc. | Product analytics (consent-gated) | European Union |
| Lemon Squeezy, LLC | Payments, billing, merchant of record | United States |
| Google LLC (Workspace) | Business email | United States / global |
| Haufe-Lexware GmbH (Lexoffice) | Invoicing & accounting | Germany |
Where a provider processes data outside the EU/EEA, we rely on the EU Standard Contractual Clauses or the provider’s certification under the EU-US Data Privacy Framework.
Data retention
Chat logs are kept for a period tied to your plan — 7 days on SANDBOX, 30 on LAUNCH, 90 on GROW, and indefinitely on SCALE — then auto-purged. Vault statements persist until you delete them or your account. Account records are kept until you delete your account, plus a short window for fraud and dispute handling. Invoices and other financial records are kept for the period German tax law requires (currently at least eight years).
Delete your account from Account Settings, and we cascade-delete your Discord integrations, sources, statements, chat sessions and messages, and ledger entries. Records we’re legally required to keep, like invoices, are retained in redacted form.
Security
We encrypt data in transit (TLS) and encrypt BYOK API keys at rest with AES-256-GCM. Access to production systems is limited to the people who need it. No system is perfectly secure, and we don’t claim ours is — if you find a security issue, email us and we’ll get back to you.
Your rights
If GDPR applies to you, you have the right to access, correct, delete, or export the personal data we hold about you, to restrict or object to its processing, and to withdraw consent at any time with effect for the future. To exercise any of these, write to . We may ask you to verify your identity first.
If you’re not satisfied with our response, you can lodge a complaint with your local supervisory authority. Ours is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).
Children's privacy
Clonq is built for founders, creators, and community operators — we don’t knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we’ll delete it.
Third-party services & links
Signing in, uploading a YouTube or Loom link, or connecting a Discord server all involve third-party platforms with their own privacy practices — Clerk, Discord, Google, and whichever service hosts content you link into your Vault. This policy doesn’t cover their processing; check their own policies.
Changes to this policy
We may update this policy as the product or the law changes. We’ll update the date at the top when we do, and for material changes, tell you by email or a notice in the dashboard. Continuing to use Clonq after a change takes effect means you accept the update.
Contact
Questions, requests, or complaints about this policy: . For our full company details, see the Impressum.
See also our Impressum and Terms of service.