Privacy Policy

Effective date: July 24, 2026

Clio is operated by Clio Assistant LLC, a Wyoming limited liability company. Clio (“we,” “our,” or “us”) provides an AI-powered booking receptionist for appointment-based service businesses. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data — including data accessed through Google APIs.

1. Who this policy covers

This policy applies to two groups:

  • Business owners — individuals who sign up for a Clio account to run their booking receptionist.
  • Widget visitors — customers who interact with a Clio-powered chat widget embedded on a business owner’s website.

2. Data we collect from business owners

  • Account data: name, email address, and password (hashed; we never store plaintext passwords).
  • Business profile: business name, service area, services offered, pricing, hours, and widget configuration.
  • Google Calendar data: see Section 4 for full detail.
  • Payment data: billing is handled entirely by Stripe. We store only a Stripe customer ID — we never see or store raw card numbers.

3. Data we collect from widget visitors

  • Name, phone number, email address, and service address — only when voluntarily provided during a booking conversation.
  • Conversation content. Chat messages are used to conduct the booking conversation. When a booking is made, we store a summary of the conversation — which may include the name, phone, email, service address, requested service, and preferred time — in the business owner’s account, so they have a record of the booking. This summary is retained with the booking record (see Section 7).
  • Approximate IP address, used to operate and secure the service, including abuse prevention and rate limiting.
  • Basic device and usage information collected through cookies and similar technologies (see Section 6a).

Widget visitor data is collected on behalf of, and stored in, the business owner’s Clio account. For that data the business owner is the controller and is responsible for their own privacy practices toward their customers; Clio acts as a service provider/processor. For the analytics and security data described in Section 6a, Clio acts as the controller.

4. Google Calendar access

When a business owner connects their Google Calendar, Clio requests the following OAuth scopes:

  • calendar.readonly — We read your calendar to identify which time slots are already occupied, so the booking widget never offers a time when you are already busy. We do not read the title, description, attendees, or any other content of your existing events — only their start and end times.
  • calendar.events — We create a calendar event when a customer books an appointment through your widget. We update or delete that event if the booking is changed or cancelled.

We do not use Google Calendar data for advertising, analytics, or any purpose beyond providing the scheduling features described above. We do not share your Google data with any third party, train AI models on it, or retain it after your account is deleted.

You can revoke Clio’s access to your Google Calendar at any time by visiting myaccount.google.com/permissions and removing Clio, or by disconnecting from your Clio account settings.

Clio’s use of Google API data complies with the Google API Services User Data Policy, including the Limited Use requirements.

5. AI processing

Booking conversations are processed by Claude (Anthropic) to generate responses and extract booking details. Messages are sent to Anthropic’s API over an encrypted connection. Anthropic’s data handling is governed by their Privacy Policy. We do not use conversation content to train or fine-tune AI models.

6. Third-party services

  • Supabase — database and authentication. Data is stored in the United States.
  • Stripe — payment processing for subscriptions. Stripe’s privacy policy governs payment data.
  • Resend — email delivery (booking confirmations, account and reminder emails). Email content is transmitted to Resend for delivery only.
  • Anthropic — AI processing of booking conversations (see Section 5).
  • PostHog — product analytics: how visitors and business owners use the app, including pageviews and feature usage. May process approximate IP and device information.
  • Sentry — error monitoring, to detect and diagnose faults. Receives technical error data; we configure it to redact sensitive fields.
  • Upstash — rate-limiting infrastructure that temporarily stores request counts keyed to an approximate IP and session identifier.
  • Vercel — application hosting and infrastructure.

6a. Cookies and analytics

We use cookies and similar technologies for two purposes: (1) strictly necessary cookies set by Supabase to keep business owners signed in, and (2) analytics cookies set by PostHog to understand product usage. We do not use advertising or cross-site tracking cookies, and we do not sell personal information. You can block or delete cookies through your browser settings; strictly necessary cookies are required for the dashboard to function.

7. Data retention

  • Business owner accounts and associated data are retained for as long as the account is active. You may request deletion at any time by emailing us; we will delete or de-identify your data within a reasonable period after your request.
  • Widget visitor booking data — including the conversation summary described in Section 3 — is retained in the business owner’s account until they delete it or close their account.
  • Google OAuth tokens are stored encrypted (AES-256-GCM) and are deleted when you disconnect your calendar or delete your account.
  • Rate-limiting records (Upstash) are short-lived and expire automatically.

8. Security

All data is transmitted over TLS. Sensitive values (Google refresh tokens) are encrypted at rest with AES-256-GCM before being written to the database. Passwords are never stored in plaintext.

9. Your rights

Depending on your location, you may have the right to access, correct, export, or delete your personal data. To exercise any of these rights, contact us at the address below. We will respond within 30 days.

9a. Children’s privacy

Clio is a business tool and is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us at the address below and we will delete it.

10. Changes to this policy

We may update this policy from time to time. Material changes will be communicated by email to registered business owners at least 14 days before they take effect. The effective date at the top of this page reflects the most recent revision.

11. Contact

Questions about this policy or requests regarding your data: support@clioassistant.dev