Account and profile
Your email address, and your display name and avatar if you sign in with Google or GitHub or if you set them. Optionally, a headline, a short bio, and website, GitHub and LinkedIn links, which are public if you fill them in. Your plan and onboarding status. Preferences you set, including custom instructions you write for the agent, your theme and interface settings, your default model and runtime choices, your email and notification preferences, and what you told us you signed up to do. We do not ask for your employer, job title or company at signup.
Content you create in the product
Notebook cells, including code and text. Files you upload and files created inside your sandbox. Your chat with the agent, including your prompts, the agent’s replies, tool calls and their results, and the model’s intermediate reasoning. Execution records, including error messages and Python tracebacks from your own code, and execution outputs, including images, tables and charts. Notes the agent extracts and keeps as project memory, stored with a numeric embedding so it can be recalled. Research results, including the question asked and quotations from the sources retrieved.
Credentials we hold for you
Access and refresh tokens for accounts you connect, your own model provider API keys if you use bring your own key, and any headers or environment values you configure for an MCP server. Clusy API keys you create are stored only as a hash, so we cannot recover the key itself. Section 12 explains how these are protected.
Billing
Your Stripe customer and subscription identifiers, your plan and its history, invoices, and metered usage records. We never receive or store your card number. Card details go directly to Stripe.
Device, usage and logs
Product analytics events about what you do in the app, request and access logs from our servers, your IP address, a coarse city and country derived from it, your browser and device type, language and timezone. Application error reports, which include an error message, a stack trace and the identifiers of the account, project and session involved.
Security and abuse records
Signals produced by the automated checks described in section 9, including categorised detection labels and irreversible hashes of the code that triggered them, records of suspensions and appeals, and hashes of IP addresses used to detect linked accounts.
Marketing and attribution
If you arrive from a campaign link, the referring URL, landing page and campaign parameters, held against your account after you sign up. An advertising click identifier from the link you arrived on is stored in a first party cookie and in your browser, but is not sent to your account record. Clicks on our short links are logged without an account identifier, with a hashed IP and a coarse country.
Meeting bookings and support
If you book a meeting with us: your name, email, timezone, any notes you write, and the email addresses of guests you add. If you contact support: your message, your email, and basic diagnostics about the page you were on. If you use the contact form on our website: your name, email, team or company and your message. If you use the Ask feature on our documentation site, your question and the last few turns of that conversation are sent to an AI model to generate an answer, and we do not store the text of your questions.
Where it comes from
Mostly from you and from your device. Some comes from your connected accounts at your direction, some from Stripe about your payments, and some from other people: someone who adds you as a guest to a meeting gives us your email address, and a person who shares a project with you creates a record involving you.