Privacy Policy
Last updated 25 July 2026
This explains what Clutvi does with your personal data. It's written to be readable rather than impressive. If anything here isn't clear, email getclutvi@gmail.com and ask.
1. Who's responsible for your data
Clutvi is run by Caroline Morrison, a sole trader trading as "Clutvi" in the United Kingdom. That means I'm the "data controller" for the information described here.
- Contact: getclutvi@gmail.com
- Based in Glasgow, United Kingdom. A postal address is available on request — email and we'll give you it.
2. What Clutvi collects
Your account
Your email address, and a password that's stored only as a secure hash — the actual password is never stored and can't be read, not even by me.
What you type into the tools
The text you enter, the result the AI produces, and a short preview of it are saved to your account so your history and saved items work across your devices. This is stored in a database with row-level security, meaning your rows can only ever be read by your own logged-in account.
You can delete any individual item from your history in the app at any time.
Usage counts
A count of how many generations you've run each day. This is only used to apply the trial and fair-use limits.
Billing
Your subscription status, renewal date, and the customer and subscription IDs that Stripe gives us. Clutvi never receives or stores your card number — Stripe handles that entirely.
Technical data
Standard server logs from the services below, which can include your IP address, browser type, and timestamps. These are used to keep the service running and secure.
3. Why, and the legal basis
| What for | Legal basis |
|---|---|
| Creating your account and signing you in | Performing our contract with you |
| Running the AI tools and saving your history | Performing our contract with you |
| Taking payment and managing your subscription | Performing our contract with you |
| Sending service emails (confirm your email, password resets, billing notices) | Performing our contract with you |
| Applying usage limits and preventing abuse | Our legitimate interest in keeping the service viable |
| Keeping records for tax and accounting | Legal obligation |
Clutvi doesn't send marketing emails. If that ever changes, we'll ask you to opt in first.
4. Who your data is shared with
Clutvi is a small operation built on other companies' infrastructure. These are the only organisations your data reaches, and each only gets what it needs:
| Who | What they get | Where |
|---|---|---|
| Supabase — database, login, server functions | Your account, your content history, usage counts, subscription status | EU |
| Anthropic — the Claude AI model | Only the text you enter into a tool, at the moment you run it | USA |
| Stripe — payments | Your email and payment details, which you give to Stripe directly | USA / EU |
| Resend — sending service emails | Your email address and the contents of that email | EU (Ireland) |
| Netlify — website hosting | Standard web request logs, including IP address | USA |
On the AI: when you run a tool, the text you entered is sent to Anthropic's API to generate a response. Anthropic does not use data submitted through its API to train its models. Even so, please don't paste anything genuinely sensitive or confidential into any AI tool, including this one.
This site also loads fonts from Google Fonts, which reveals your IP address to Google as it does on most websites. No account information is shared with them. Everything else the site needs — its stylesheet and code libraries — is served from clutvi.com itself, with one exception: if the app's copy of a library fails to download, it falls back to fetching the same file from jsDelivr, which would reveal your IP address to them for that one request.
Your data is never sold, and it's never shared with advertisers. It would only be disclosed otherwise if the law required it.
5. Data leaving the UK
Some of the providers above are in the United States. Those transfers are covered by the UK's approved safeguards — standard contractual clauses with the UK addendum, or the UK extension to the EU–US Data Privacy Framework — which are the mechanisms the law provides for sending data outside the UK.
6. How long it's kept
- Account and content: for as long as your account is open. Close your account and it's deleted, normally within 30 days.
- Individual history items: until you delete them, which you can do yourself in the app at any time.
- Billing records: kept for 6 years, because UK tax law requires it.
- Server logs: kept short-term by the providers above, typically days to a few weeks.
7. Security
Everything runs over HTTPS. Passwords are stored only as hashes. Database access is restricted per-user by row-level security, so one account can't read another's data. The Anthropic API key lives only on the server and never reaches your browser.
No system is perfectly secure, but if there were ever a breach affecting your data, you'd be told about it, and so would the ICO where the law requires.
8. Your rights
Under UK data protection law you can ask to:
- see a copy of the data held about you;
- have inaccurate data corrected;
- have your data deleted;
- get your data in a portable format;
- restrict or object to certain uses of it;
- withdraw any consent you've given.
Email getclutvi@gmail.com and you'll get a response within one month. There's no charge.
9. Cookies and local storage
Clutvi uses no analytics, no advertising trackers, and no third-party cookies.
The app stores three things in your browser's local storage: the login token that keeps you signed in, your light/dark theme choice, and whether you've dismissed the "new here?" tip on the dashboard. The login token is strictly necessary for the service to work and the other two are display preferences that contain no personal data, which is why you aren't asked to consent to any of them. Signing out removes the token.
Your generated content and saved posts are not kept in your browser — they're stored in the database described in section 3, so they're available on any device you sign in from.
10. Complaints
If you're unhappy with how your data has been handled, please email getclutvi@gmail.com first.
You also have the right to complain to the UK's data protection regulator:
- Information Commissioner's Office — ico.org.uk/make-a-complaint
- Helpline: 0303 123 1113
11. Changes to this policy
If this policy changes in a way that materially affects you, you'll be emailed. The date at the top always shows when it was last updated.
12. Contact
Any privacy question: getclutvi@gmail.com