Clotiv

Privacy Policy

What Clotiv collects, why, who it is shared with, how long it is kept, and the choices and rights you have over it.

Effective September 9, 2026

This Privacy Policy explains how Clotiv LLC, a Delaware limited liability company ("Clotiv", "we", "us" or "our") collects, uses, shares and protects personal information when you use clotiv.com and the features it offers — lessons, AI Help, notes, accounts and billing — and the Clotiv desktop application (the "Desktop App") connected to your account (together, the "Services").

This policy applies together with our Terms of Service. By using the Services you acknowledge that you have read it. If you do not agree with it, please do not use the Services.

In short: we collect what we need to run your account, lessons, AI features and billing; we send data to a small number of service providers (payments, AI models, web search, email, sign-in, hosting and transcription) so those features work; we do not sell your personal information and do not share it for cross-context behavioral advertising; we use no advertising cookies or third-party analytics today; and you can ask us at any time to access, correct, export or delete your information.

1. Information We Collect

We collect the following kinds of information. What we hold about you depends on which features you use.

1.1 Information You Provide

  • Account information. Your email address, and your name and profile image if you provide them or your sign-in provider supplies them. If you sign in with or connect GitHub or LinkedIn, we receive your basic profile from that provider (including your name or username there) and store the tokens it issues, encrypted, so we can keep you signed in and, only with permissions you grant, act on your behalf there; we never receive your password for that provider. You can see and remove connected accounts at any time from your account settings.
  • Lesson activity. The lessons you mark as read, and the notes you save on a lesson (each saved version is kept, so you can go back to it).
  • AI Help conversations. The questions and messages you send to AI Help, the responses you receive, and whether a question used web research.
  • API keys. The names of the API keys you create for the Desktop App. We store a hash of each key and its last four characters — never the key itself.
  • Skill files. Any "skill" files you upload to customize the Desktop App, including their names, descriptions and contents.
  • Billing information. Your customer and subscription identifiers at our payment processor, subscription status, plan and billing period, CloToken balances, and any billing-review flags. We never see or store your card number or bank details — our payment processor collects and holds them.
  • Support and contact. Your name, email address, chosen topic and message when you use the contact form, and anything you send to [email protected].
  • Waitlist. Your email address if you join a waitlist.

1.2 Information Collected Automatically

  • Usage records. For each AI or transcription request: the service and model used, token counts or audio duration, the computed cost, the CloTokens charged, the lesson involved (if any) and the time. We use these to meter CloTokens and enforce plan limits.
  • Technical data. Your IP address, browser or app identifier (user-agent), the pages and endpoints you request, and timestamps, recorded in server logs and used for security and rate limiting.
  • Session cookies. A signed session cookie that keeps you signed in, and short-lived cookies needed for sign-in to work. See Cookies and Local Storage.
  • Preferences on your device. Settings such as your theme and the size of lesson panels are kept in your browser's local storage and are not sent to us.

1.3 Desktop App Data

If you connect the Desktop App, it can capture meeting audio, produce transcripts and generate live coaching. The Desktop App sends audio to a speech-to-text provider to transcribe it (see How We Share Information) and stores in your Clotiv account the meetings it creates (title and time), transcript segments (speaker label, text and timestamp) and coaching output, along with the usage records described above. Your account may also hold a preference for which transcription provider the Desktop App uses.

You are responsible for obtaining any consent the law requires from the people you record or transcribe. Their words may appear in transcripts stored in your account; we process that content on your behalf to provide the Services.

1.4 Information From Other Sources

Sign-in providers (GitHub and LinkedIn) give us your basic profile when you sign in or connect them. Our payment processor tells us the status of your subscription and payments. If a Clotiv administrator grants your account complimentary access, we record that grant, who made it, the reason and any expiry in an administrative log.

2. How We Use Information

We use personal information to:

  • provide the Services — sign you in, show your lessons, notes and progress, run AI Help, store Desktop App meetings and transcripts, and connect the Desktop App with your API key;
  • generate AI responses, which requires sending your messages, the lesson text and any search queries to our AI and web-search providers;
  • process payments, manage plans and CloTokens, and keep billing records;
  • send transactional email such as sign-in links and account or billing notices;
  • secure the Services, prevent fraud and abuse, enforce usage limits and our Terms of Service;
  • respond to your questions and requests;
  • understand how the Services are used, fix problems, and improve lessons and features — using our own records rather than third-party analytics tools; and
  • comply with legal obligations and enforce our rights.

Legal bases (for readers in the EEA, the UK and similar jurisdictions). We process personal information: to perform our contract with you (providing the Services you signed up for); for our legitimate interests (securing and improving the Services, preventing abuse, and communicating with you), balanced against your rights; with your consent where we ask for it (for example when you connect the Desktop App or upload content), which you may withdraw at any time; and to comply with legal obligations such as tax and accounting rules.

We do not use personal information to make automated decisions that have legal or similarly significant effects on you, and we do not build advertising profiles.

3. How We Share Information

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share it only as described in this section.

3.1 Service Providers

We use the following kinds of providers to run the Services. Each receives only the information needed for its role and is bound by contract to use it only to provide services to us. We describe them by role rather than by name; a current list of our providers is available on request through the contact form.

  • Payment processor — payment processing, subscriptions and the billing portal. It receives your email address, plan and payment details; we receive identifiers and status, never card numbers.
  • AI model providers, reached through an AI model gateway — generating AI Help and other AI responses. They receive your prompts and messages, the text of the lesson you are reading, and related context.
  • Web search provider — web search when AI Help researches a question. It receives the search query.
  • Transactional email provider — sending email such as sign-in links. It receives your email address and the message.
  • GitHub and LinkedIn — sign-in and connected accounts. When you use one, that provider learns that you are signing in to Clotiv and gives us your basic profile; if you later grant additional permissions (for example to post on your behalf), that provider is told which permissions you granted.
  • Cloud hosting provider — hosting and our database, in the United States.
  • Speech-to-text providers used by the Desktop App — transcription. Audio captured by the Desktop App is sent to the provider in use to produce transcripts.

3.2 Other Sharing

  • Legal reasons. We may disclose information if we believe it is necessary to comply with the law, a subpoena or other legal process; to protect the rights, property or safety of Clotiv, our users or others; or to investigate fraud, abuse or security issues.
  • Business transfers. If Clotiv forms a new legal entity, or is involved in a merger, acquisition, financing or sale of assets, your information may be transferred to the successor, which will be bound by this policy.
  • At your direction. We share information when you ask us to.

We do not share personal information with advertisers or data brokers.

4. Security

We protect personal information with technical and organizational measures, including encryption in transit (HTTPS), hashed storage of API keys, signed session tokens, access controls that limit who at Clotiv can reach production data, and an audit log of administrative billing actions. Payment details are handled entirely by our payment processor.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Keep your sign-in links and API keys confidential, and contact us right away at [email protected] if you suspect unauthorized access to your account.

5. Your Rights and Choices

Wherever you live, you can ask us to:

  • access the personal information we hold about you;
  • correct information that is inaccurate or incomplete;
  • delete your account and personal information (see Account Deletion);
  • export a copy of your information in a portable format;
  • object to or restrict certain processing, including processing based on our legitimate interests; and
  • withdraw consent where processing is based on consent, without affecting processing that happened before you withdrew it.

To exercise a right, use the contact form (choose the topic "Privacy request") or email [email protected] from the address on your account. We will verify your identity — usually by confirming that you control the account email — before acting, and we may ask for more information if needed. An authorized agent may make a request on your behalf if the agent provides your written permission and we can verify your identity. We will not discriminate against you for exercising your rights.

You can also manage some information yourself: edit your notes, revoke API keys, manage your plan on your billing page, and change the preferences stored on your device. If we have not resolved a concern, you may also have the right to complain to a data-protection authority where you live.

6. Cookies and Local Storage

We use only cookies that are necessary for the Services to work:

  • a session cookie that keeps you signed in for a limited time after you sign in; and
  • short-lived cookies used during sign-in to protect against forged requests.

We also keep preferences such as your theme and panel sizes in your browser's local storage; they stay on your device.

We do not use advertising cookies, third-party analytics or tracking pixels. If we add any in the future, we will update this policy and, where the law requires, ask for your consent first.

Do Not Track and opt-out signals. Some browsers send a "Do Not Track" signal. Because there is no common standard for responding to it, the Services do not respond to it. Because we do not sell or share personal information, an opt-out preference signal such as Global Privacy Control has nothing to switch off; we do not currently detect such signals.

7. Account Deletion

You can ask us to delete your account at any time through the contact form (topic "Privacy request") or by emailing [email protected] from the address on your account. Self-service deletion is not yet available in the app; until it is, we handle every request by hand and confirm when it is done.

When we delete your account we remove your profile, sign-in connections, API keys, lesson progress, notes, AI Help conversations, skill files, and Desktop App meetings and transcripts. We keep what the law requires us to keep — chiefly billing and tax records and audit records of billing actions — and may retain a minimal record that the account was deleted. Cancel any active paid plan first; deleting an account does not by itself refund a purchase.

8. Children

The Services are for adults preparing for job interviews. You must be at least 18 years old to create an account, and we do not knowingly collect personal information from anyone under that age. In particular, we do not knowingly collect information from children under 13, as defined by the US Children's Online Privacy Protection Act (COPPA). If you believe a child has provided us with personal information, contact us at [email protected] and we will delete it.

9. Data Retention

  • Account data — profile, sign-in connections, API keys, progress, notes, conversations and Desktop App data — is kept while your account exists and deleted when you delete your account, except as described below.
  • Usage and billing records — usage logs, CloToken ledger entries, subscription history and audit logs — are kept as long as needed for metering, resolving disputes, and tax and accounting obligations.
  • Server logs containing IP addresses and request data are short-lived and rotated automatically.
  • Contact-form messages and support email are kept as long as needed to resolve your request and for a reasonable period afterwards.
  • Waitlist entries are kept until you are admitted or ask to be removed.

Backups may retain copies for a limited time after deletion. When information is no longer needed, we delete or anonymize it.

10. California Privacy Rights

This section applies to California residents under the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the "CCPA"). It supplements the rest of this policy.

10.1 Categories of Personal Information

In the last 12 months we have collected the following categories of personal information, as the CCPA defines them:

  • Identifiers — name, email address, profile image, account and API-key identifiers, IP address.
  • Commercial information — plan, subscription status, purchase and top-up history, CloToken balances.
  • Internet or other electronic network activity — lesson progress, notes, AI Help conversations and usage records, pages and endpoints requested, browser or app identifiers.
  • Audio, electronic or similar information — if you use the Desktop App: meeting audio (processed by a transcription provider, not stored by us), transcripts and coaching output.
  • Inferences — none. We do not build profiles about your preferences or characteristics.
  • Sensitive personal information — none beyond your account log-in credentials (hashed API keys and the tokens issued by your sign-in provider). We use them only to provide the Services and do not disclose them for any other purpose.

10.2 Sources and Purposes

We collect these categories directly from you, automatically when you use the Services, from your sign-in provider and from our payment processor, for the purposes described in How We Use Information. We retain them as described in Data Retention.

10.3 Disclosures, Sales and Sharing

We disclose the categories above to the service providers listed in How We Share Information for business purposes. We do not sell personal information and do not share it for cross-context behavioral advertising, and we have not done so in the preceding 12 months. We have no actual knowledge that we sell or share the personal information of consumers under 16.

10.4 Your Rights Under the CCPA

  • Know what personal information we collect, use, disclose, sell or share, and receive a copy of the specific pieces.
  • Delete personal information we collected from you, subject to the CCPA's exceptions.
  • Correct inaccurate personal information.
  • Limit the use of sensitive personal information (we already use it only to provide the Services).
  • Opt out of sale or sharing (we do neither).
  • Non-discrimination for exercising any of these rights.

10.5 How to Submit a Request

Submit a request through the contact form (topic "Privacy request") or by emailing [email protected]. We will confirm receipt within 10 business days and verify your request by confirming that you control the email address on your account; we may ask for more information if needed. An authorized agent may submit a request for you with your signed permission, and we may still ask you to verify your identity directly. We will respond within 45 days, and may extend that by up to 45 more days with notice.

11. Other US State Privacy Rights

Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, New Jersey, New Hampshire and others — may have the right to confirm whether we process their personal data; to access, correct, delete and obtain a copy of it; and to opt out of targeted advertising, the sale of personal data, and profiling for decisions with legal or similarly significant effects. We do not engage in targeted advertising, sales or such profiling.

Exercise any of these rights through the contact form or at [email protected]. If we deny a request, you may appeal by replying to our decision; if we deny the appeal, we will tell you how to contact your state's attorney general.

12. Users Outside the United States

Clotiv operates from the United States, and our hosting and database are in the United States. If you use the Services from elsewhere, your personal information is transferred to, stored and processed in the United States, where privacy laws may differ from those of your country. We protect it wherever it is processed as described in Security.

If you are in the European Economic Area, the United Kingdom or Switzerland: Clotiv is the controller of your personal information; the legal bases in How We Use Information apply; you have the rights in Your Rights and Choices; and you may lodge a complaint with your local supervisory authority.

13. Changes to This Policy

We may update this policy as the Services change. The effective date at the top of this page shows when it last changed. For material changes, we will notify you before the change takes effect — by email to the address on your account or by a notice in the Services. Your continued use of the Services after that date means the updated policy applies.

14. Contact Us

Questions or requests about privacy? Use the contact form or email us at [email protected]. We aim to respond promptly.