Skip to main content

Privacy

Last updated 2026-09-02.

This page explains what we collect on the marketing site (clue2app.ai) and how the website chatbot handles conversations you start there. Platform-side privacy (workloads deployed on Clue2App by signed-in customers) is covered separately in the platform's Shared responsibility doc.

If anything here is unclear, or you want your data removed, email support@clue2app.ai.

What the marketing site collects

The site is served as static pages. We do not set advertising cookies, we do not run session-replay, and we do not sell traffic data.

  • Aggregate traffic counts through the CDN — page path and country, no user identifier.
  • Contact form submissions when you send them (name, email, the message you wrote, the page you sent it from). Stored for as long as needed to answer, then archived.
  • Cookies: strictly-necessary only. No third-party trackers.

Website chatbot

The "How can I help you?" widget on this site is optional. It only starts a session when you open it and send your first message — nothing is stored on your device before that.

What we collect

FieldWhen collectedPurpose
Messages you sendEvery turn you sendAnswering your question, safety review.
Model repliesEvery turn we returnSame as above.
Session idGenerated the first time you send a turnGrouping turns in one conversation.
IP hashPer sessionAbuse defense (rate limit, spam detection).
Approximate countryPer sessionRegional routing, aggregate analytics.
Email + nameOnly if you fill the contact / handoff formFollowing up on your question.
TimestampsEvery turnRetention + billing accuracy.

We do not collect: your raw IP, precise location, browser fingerprint, tracking cookies, or any information from other sites you visit.

Third parties

The widget passes your messages to two vendors so it can work:

  • Anthropic (via our platform's LLM gateway) — generates the reply. Anthropic processes the message under its own commercial terms and does not train its foundation models on the data.
  • Cloudflare Turnstile — a bot-check the widget runs invisibly to keep spam and scripted abuse out. Turnstile receives a challenge token, not your message content.

No other vendors receive chat content. We do not share your messages with advertising, analytics, or profiling services.

Retention

  • Raw transcripts + IP hash: 30 days, then deleted.
  • Aggregate counts (session count per day, model + token totals, no message content): 365 days for capacity planning and cost reporting.
  • Contact-form escalations that become a support case: retained under the same retention window as any other support ticket you open with us.

Lawful basis (GDPR / UK GDPR)

  • Legitimate interest for the pre-sales chat itself — visitors reasonably expect a "How can I help?" button on a product site to answer product questions.
  • Consent for the contact / escalation form — you enter your email yourself and click a labelled button to send it.

You can refuse the widget by not opening it. Nothing about the widget loads a session, sets a cookie, or contacts our servers until you open it and send a first turn.

Your rights

You can, at any time, email support@clue2app.ai to:

  • Ask for a copy of the transcripts tied to your session id or email.
  • Ask us to delete a transcript, or all transcripts tied to an email.
  • Ask what the model was told about you (the system prompt is document-grounded, not personal-data-grounded, but we will show you the answer if asked).
  • Object to any of the processing described above.

We respond inside 30 days.

Safety and abuse

We review a small sample of transcripts each week to spot prompt injection attempts, jailbreaks, and abuse. Reviewers see the transcript and the IP hash — never the raw IP or any information not listed above. Confirmed abuse can be rate-limited, blocked, or reported to law enforcement where required.

Contact form

When you submit the contact form (with or without the widget), we receive your name, email, message body, and the page you sent it from. The form uses the same anti-abuse checks as the chat (Turnstile + honeypot + minimum-time-to-submit).

We use the message to answer you and, if you ask a sales question, to follow up. We do not add you to newsletters or marketing lists without a second, explicit opt-in.

Cookies

We use one strictly-necessary cookie for the marketing site's theme choice (light/dark). The website chatbot uses sessionStorage — not a cookie — to keep your conversation grouped inside a single tab, and only after you open the widget. Closing the tab clears it.

Contact

  • Email: support@clue2app.ai
  • Postal address: available on request; we are a small US-based company. Give us a heads-up by email first so the right person opens the envelope.

Changes to this page

We date the top of this page each time it changes. Material changes (new vendors added, retention lengthened, new categories collected) are noted in the platform's release notes.