Privacy
Last updated 2026-09-02.
This page explains what we collect on the marketing site
(clue2app.ai) and how the website chatbot handles conversations you
start there. Platform-side privacy (workloads deployed on Clue2App by
signed-in customers) is covered separately in the platform's
Shared responsibility doc.
If anything here is unclear, or you want your data removed, email support@clue2app.ai.
What the marketing site collects
The site is served as static pages. We do not set advertising cookies, we do not run session-replay, and we do not sell traffic data.
- Aggregate traffic counts through the CDN — page path and country, no user identifier.
- Contact form submissions when you send them (name, email, the message you wrote, the page you sent it from). Stored for as long as needed to answer, then archived.
- Cookies: strictly-necessary only. No third-party trackers.
Website chatbot
The "How can I help you?" widget on this site is optional. It only starts a session when you open it and send your first message — nothing is stored on your device before that.
What we collect
| Field | When collected | Purpose |
|---|---|---|
| Messages you send | Every turn you send | Answering your question, safety review. |
| Model replies | Every turn we return | Same as above. |
| Session id | Generated the first time you send a turn | Grouping turns in one conversation. |
| IP hash | Per session | Abuse defense (rate limit, spam detection). |
| Approximate country | Per session | Regional routing, aggregate analytics. |
| Email + name | Only if you fill the contact / handoff form | Following up on your question. |
| Timestamps | Every turn | Retention + billing accuracy. |
We do not collect: your raw IP, precise location, browser fingerprint, tracking cookies, or any information from other sites you visit.
Third parties
The widget passes your messages to two vendors so it can work:
- Anthropic (via our platform's LLM gateway) — generates the reply. Anthropic processes the message under its own commercial terms and does not train its foundation models on the data.
- Cloudflare Turnstile — a bot-check the widget runs invisibly to keep spam and scripted abuse out. Turnstile receives a challenge token, not your message content.
No other vendors receive chat content. We do not share your messages with advertising, analytics, or profiling services.
Retention
- Raw transcripts + IP hash: 30 days, then deleted.
- Aggregate counts (session count per day, model + token totals, no message content): 365 days for capacity planning and cost reporting.
- Contact-form escalations that become a support case: retained under the same retention window as any other support ticket you open with us.
Lawful basis (GDPR / UK GDPR)
- Legitimate interest for the pre-sales chat itself — visitors reasonably expect a "How can I help?" button on a product site to answer product questions.
- Consent for the contact / escalation form — you enter your email yourself and click a labelled button to send it.
You can refuse the widget by not opening it. Nothing about the widget loads a session, sets a cookie, or contacts our servers until you open it and send a first turn.
Your rights
You can, at any time, email support@clue2app.ai to:
- Ask for a copy of the transcripts tied to your session id or email.
- Ask us to delete a transcript, or all transcripts tied to an email.
- Ask what the model was told about you (the system prompt is document-grounded, not personal-data-grounded, but we will show you the answer if asked).
- Object to any of the processing described above.
We respond inside 30 days.
Safety and abuse
We review a small sample of transcripts each week to spot prompt injection attempts, jailbreaks, and abuse. Reviewers see the transcript and the IP hash — never the raw IP or any information not listed above. Confirmed abuse can be rate-limited, blocked, or reported to law enforcement where required.
Contact form
When you submit the contact form (with or without the widget), we receive your name, email, message body, and the page you sent it from. The form uses the same anti-abuse checks as the chat (Turnstile + honeypot + minimum-time-to-submit).
We use the message to answer you and, if you ask a sales question, to follow up. We do not add you to newsletters or marketing lists without a second, explicit opt-in.
Cookies
We use one strictly-necessary cookie for the marketing site's theme
choice (light/dark). The website chatbot uses sessionStorage — not a
cookie — to keep your conversation grouped inside a single tab, and
only after you open the widget. Closing the tab clears it.
Contact
- Email: support@clue2app.ai
- Postal address: available on request; we are a small US-based company. Give us a heads-up by email first so the right person opens the envelope.
Changes to this page
We date the top of this page each time it changes. Material changes (new vendors added, retention lengthened, new categories collected) are noted in the platform's release notes.