Legal · Clenta LLC

Privacy Policy

Version 0.3 Last updated: August 29, 2026 Effective: June 1, 2026

Contents

  1. Information We Collect
  2. How We Use Your Information
  3. How We Share Your Information
  4. Data Retention
  5. Benchmarking and Anonymized Analytics
  6. Cookies and Tracking Technologies
  7. Your Privacy Rights
  8. Security
  9. Children's Privacy
  10. Links to Other Websites
  11. Changes to This Policy
  12. Contact Us

Clenta LLC ("Clenta," "we," "our," or "us") operates the website at clenta.ai and the Iris mobile application (iOS and Android). This Privacy Policy explains how we collect, use, disclose, and protect personal information about you when you visit our website, join our waitlist, or use our products.

About end-client data: This policy does not cover how our business customers (retailers and operators) use Iris to manage their own client relationships. That data processing is governed by the Clenta Data Processing Agreement. Clenta processes that data as a service provider on behalf of its business customers.

Section 1 — Information We Collect

1.1 Website Visitors (clenta.ai)

When you visit clenta.ai, we may collect:

1.2 Waitlist and Access Request Submissions

When you submit your email address to join our waitlist or request early access, we collect:

This information is used solely to contact you about product updates and access. We do not sell or share it with third parties for their marketing purposes.

1.3 Account Users (Associates, Managers, Administrators)

When you create a Clenta account or are added by your employer, we collect:

1.4 Payment Information

Billing and payment are handled by Stripe. Clenta does not receive or store your credit card number or full payment card data for billing purposes. We receive transaction-level information such as invoice amounts, payment dates, and subscription status. Stripe's privacy policy is available at stripe.com/privacy.

1.5 Connected Store Data (Shopify and Other Integrations)

If your organization connects a Shopify store (or another supported point-of-sale or e-commerce platform) to Clenta, we access the following data from that platform on a read-only basis:

This data is used only to power client intelligence features inside your organization's connected Clenta workspace, such as showing an associate a client's purchase history. It is not sold, and it is not shared with third parties beyond the processing described elsewhere in this policy.

Retention and erasure for connected store data. Where a merchant connects a supported commerce platform (such as Shopify) to Clenta, the resulting order history, product references, and any client names or contact details captured from those orders are retained as part of that merchant's own business records, for the duration of the merchant's active Clenta subscription — the same retention basis as the rest of that merchant's Iris conversation and log data (Section 4). On the earlier of (a) the merchant disconnecting or uninstalling the integration, or (b) a verified written request from the merchant or its end-customer, Clenta deletes the specific data responsive to that request within 30 days. Where a connected platform sends a mandatory privacy webhook (such as Shopify's customer data request, customer data erasure, or shop data erasure notifications), Clenta acknowledges the request immediately and honors it under this same policy and timeline.

1.6 Payment card data in client records

The Services are not intended to hold payment card data, and our Terms of Service prohibit entering it. Where such data is nonetheless present in free-text fields of a connected system, we apply automated best-effort detection and redaction before that content is processed further. This detection is not guaranteed to identify every instance.

Section 2 — How We Use Your Information

We use the information we collect to:

We do not:

Section 3 — How We Share Your Information

3.1 Within your organization

If your employer has provisioned a Clenta account, your name, role, and email may be visible to your organization's administrators. Individual Iris conversations are visible only to you and your organization's administrators on applicable plans.

3.2 Service providers

We share personal information with third-party service providers who process data on our behalf under written agreements requiring appropriate data protection. Our current service providers include:

ProviderPurposeLocation
SupabaseDatabase, authentication, and infrastructureU.S. (AWS us-east-1)
AnthropicAI model powering Iris — does not use your data to train its models; inputs and outputs deleted within 30 days per its commercial API termsU.S.
Fireworks AI, Inc.AI model inference — zero data retention, no training on your data, per its Data Processing Addendum and published Zero Data Retention policyU.S.
HetznerAgent runtime infrastructureU.S. (Virginia, Ashburn); EU region available upon request
StripePayment processingU.S.
Perplexity AIWeb search and enrichment queries used by Iris; not used to train models per its API termsU.S.
Apple / Expo Application ServicesApp distribution and build infrastructureU.S.
TwilioSMS/MMS text message delivery for opted-in recipientsU.S.
Sentry (Functional Software, Inc.)Error monitoring and crash reporting across the app, onboarding site, and backend services; error reports include your account identifiers (user ID, email) and, on the mobile app, session replay and any screenshots you submit through in-app bug reportsU.S.

3.2.1 AI processing

Iris is powered by artificial intelligence. To generate Iris's responses, the information you submit in the app — your messages, the client details and notes you record, and any photos or files you attach — is sent to our AI model provider(s), which process it solely to produce Iris's replies to you. Our current AI model providers are Anthropic, PBC and Fireworks AI, Inc.; we work with our provider(s) to select the model(s) that make the most sense for our accounts and business case, and this list may change as described in Section 10.

Under Anthropic's commercial API terms, Anthropic does not use your data to train its AI models, and inputs and outputs are deleted within 30 days (retained only briefly for security and abuse monitoring). Your data is never sold or used for advertising. We obtain your explicit consent inside the app before any data is shared with Anthropic, and you can review this disclosure at any time from the Account screen.

Under Fireworks AI's Data Processing Addendum and published Zero Data Retention policy, Fireworks does not use your data to train its AI models and does not retain prompt or generation data beyond the lifecycle of each request (effective August 27, 2026). Your data is never sold or used for advertising. The same consent covers all listed AI model providers — you do not need to separately consent to each one.

3.2.2 SMS and mobile communications

If you opt in to receive text messages from a business using our Services, your phone number and opt-in consent are used solely to send you the messages you requested. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, except with service providers as necessary to deliver the messages you requested. You can opt out at any time by replying STOP to any message. See our SMS Terms for full program details.

3.3 Legal requirements

We may disclose personal information if required by law, court order, or governmental authority, or if we believe disclosure is necessary to protect rights, safety, or security.

3.4 Business transfers

If Clenta is acquired or merged with another company, your personal information may be transferred as part of that transaction. We will notify you of any such transfer and the applicable privacy policy going forward.

Section 4 — Data Retention

Data typeRetention period
Waitlist email addressesUntil you unsubscribe or request deletion, or 24 months from collection if no account is created
Account informationFor the duration of your account, plus 30 days after account closure
Iris conversation and log dataFor the duration of the organization's subscription, plus 30 days after account closure (per the DPA, Article 8)
Connected commerce data (order history, product references, and client names or contact details captured from connected platforms such as Shopify)For the duration of the merchant's active subscription; deleted within 30 days of integration disconnect or a verified deletion request (see Section 1.5)
Server access logs90 days
Payment records7 years (legal/tax obligation)
Backup copiesDeleted within 90 days of the applicable deletion trigger
Anonymized, aggregated benchmark dataRetained indefinitely; contains no personally identifiable information
De-identified service improvement dataRetained indefinitely; contains no personally identifiable information

Benchmarking and Anonymized Analytics

Clenta operates as a data platform, not only a software tool. As part of providing and improving the Services, Clenta aggregates anonymized usage data across subscribed organizations to produce industry benchmarks and platform insights.

What benchmarking data includes

Benchmarking data consists exclusively of aggregate-level, anonymized signals derived from usage patterns — for example: average number of client interactions logged per associate per week, feature adoption rates, or category-level interaction trends across organizations in a given vertical. No individual client names, contact information, purchase history, conversation content, or any other personally identifiable information is included in benchmark datasets.

What benchmarking data does not include

How benchmarks are used

Aggregated benchmark data is used to: (a) help your organization understand how your team's performance and engagement compares to anonymous industry peers; (b) inform product development and improve the Services; and (c) publish aggregate industry insights in research, reports, or marketing materials — always in fully anonymized, non-attributable form.

Opt-out

Organizations may opt out of contributing their anonymized usage data to benchmarks at any time by emailing legal@clenta.ai with "Benchmark Opt-Out" in the subject line, from an organization administrator's email address. Opting out does not affect access to any core product features. Note that opting out applies prospectively — anonymized data already incorporated into aggregate benchmarks prior to opt-out cannot be retroactively removed, as it cannot be identified within those aggregates.

Post-termination retention

Clenta retains the right to use anonymized, aggregated benchmark data derived from your organization's usage even after account termination, subject to the removal of any remaining personally identifiable information. This data, by its nature, cannot be attributed to any individual subscriber and is therefore not subject to deletion requests.

Section 5 — Cookies and Tracking Technologies

5.1 Session cookies (essential)

Clenta uses strictly necessary session cookies to keep you authenticated in the application. These cookies are essential for the application to function and cannot be disabled.

5.2 Website analytics (clenta.ai)

We use Plausible Analytics on clenta.ai. Plausible is a privacy-first analytics tool that collects no personal data, uses no cookies, and is GDPR-compliant without requiring a cookie consent banner. Data collected includes page views, referring URLs, browser type, and device type — all in aggregate, never tied to an individual visitor. No data is shared with advertising networks.

5.3 Product analytics (in-app)

We use PostHog for in-app product analytics to understand how the application is used. PostHog may set cookies to track session events and feature usage. No conversation content or client data is included in analytics events. To opt out of in-app analytics, contact privacy@clenta.ai.

5.4 What we do not use

5.5 Changes to cookie use

If Clenta introduces additional cookies or analytics tools beyond those described above, we will update this Privacy Policy with at least 30 days' notice and, where required by law, implement appropriate consent mechanisms.

Section 6 — Your Privacy Rights

6.1 All users

Regardless of your location, you may request to access, correct, delete, or export the personal information we hold about you. Contact us at privacy@clenta.ai to make a request. We will respond within 30 days.

6.2 California residents (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect and how we use it, request deletion, opt out of the "sale" or "sharing" of your personal information (we do not sell or share), and not be discriminated against for exercising your rights.

Clenta does not sell personal information. To submit a California privacy request, contact privacy@clenta.ai.

6.3 EEA, UK, and Swiss residents (GDPR / UK GDPR)

If you are located in the European Economic Area, United Kingdom, or Switzerland, you have rights under the GDPR and UK GDPR, including the right to access, rectify, erase, restrict, and port your personal data, and to object to processing based on legitimate interests.

Legal basis for processing: We process account user data on the basis of contract performance. We process waitlist data on the basis of legitimate interests. We process server logs on the basis of legitimate interests (security and debugging).

You have the right to lodge a complaint with your local data protection authority. In the UK, that is the ICO (ico.org.uk).

Where personal data is transferred from the EEA or UK to the U.S. or other third countries, such transfers are subject to Standard Contractual Clauses or other appropriate safeguards.

To exercise your GDPR rights, contact privacy@clenta.ai.

Section 7 — Security

We implement appropriate technical and organizational measures to protect your personal information, including AES-256 encryption at rest, TLS 1.2+ in transit, row-level database security isolating each organization's data, and JWT-based authentication.

No security measure is 100% effective. If you believe your account has been compromised, contact us immediately at privacy@clenta.ai.

Section 8 — Children's Privacy

The Services are not directed to individuals under the age of 16, and we do not knowingly collect personal information from anyone under 16. If we learn that we have collected personal information from a child under 16, we will delete it promptly.

Section 9 — Links to Other Websites

clenta.ai may contain links to third-party websites. This Privacy Policy does not apply to those sites. We encourage you to review the privacy policies of any third-party sites you visit.

Section 10 — Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will post the updated policy with a new "Last Updated" date and notify account users via email or in-app notification at least 30 days before material changes take effect.

Section 11 — Contact Us

For privacy-related inquiries, data access requests, or to exercise your rights:

Email: privacy@clenta.ai
Mail: Clenta LLC, 108 W. 13th Street, Suite 100, Wilmington, DE 19801

We aim to respond to all requests within 30 days.