1. Scope
This Privacy Policy explains how Clyvel handles personal information when you use the website, create an account, use the hosted service, contact support or interact with Clyvel's transactional communications.
Customer-controlled prompts, model responses and operational telemetry may contain personal data. For that information, the customer generally determines the purpose of processing and Clyvel acts as a service provider or processor to the extent applicable.
2. Information we collect
- Account and profile information such as email address, display name and authentication records.
- Organization, membership, role, application, agent and configuration information.
- Gateway and product telemetry such as request timing, provider, model, token usage, cost, status and diagnostic metadata.
- Security data such as session information, access events, API-key metadata and audit records.
- Billing and subscription information supplied by the billing provider. Clyvel does not need to store full payment-card numbers.
- Support communications and information you choose to provide when contacting Clyvel.
- Basic website and device information necessary for security, operation and performance.
3. How information is used
- Provide, authenticate, operate and support the service.
- Route AI requests according to customer configuration.
- Generate observability, cost, reliability, governance and security views.
- Prevent abuse, investigate incidents and protect accounts and infrastructure.
- Process subscriptions and transactional communications.
- Improve product reliability and user experience using appropriately scoped operational information.
- Comply with legal obligations and enforce agreements.
4. How information is shared
Clyvel does not sell personal information. Information may be shared with infrastructure, authentication, email, payment and other service providers that help operate Clyvel, with customer-configured AI providers when a customer directs a request to them, or when disclosure is required by law or necessary to protect rights and security.
A current operational list is maintained on the Subprocessors page.
5. Retention
Clyvel retains information for as long as reasonably necessary to provide the service, meet contractual and legal obligations, protect security and resolve disputes. Retention periods may differ by data category, plan and customer configuration. Data that is no longer required is deleted or de-identified where reasonably practicable.
6. Security
Clyvel applies layered safeguards designed to reduce unauthorized access, disclosure, alteration and loss. These controls include tenant-scoped authorization, secure session cookies, credential hashing, encryption for stored provider credentials where configured, restricted administrative access and operational monitoring. Security measures evolve as the service changes.
7. International processing
Clyvel and its service providers may process information in countries other than your own. Where required, appropriate contractual or legal transfer mechanisms should be used. Customers with specific residency requirements should review the Subprocessors page and confirm deployment requirements before sending regulated data.
8. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to or obtain a copy of personal information. You may also have the right to lodge a complaint with a competent data-protection authority. Requests are subject to identity verification and applicable legal exceptions.
9. Cookies and local storage
Clyvel uses strictly necessary browser storage and cookies for authentication, security and user preferences. Any optional analytics or advertising technologies should be disclosed and consented to where legally required before they are enabled. See the Cookie Notice for details.
10. Children
Clyvel is designed for business and professional use and is not directed to children. Do not knowingly submit personal information of children unless you have a lawful basis and all required permissions for the relevant use case.
11. Changes and contact
This policy may be updated as the product or legal requirements change. Privacy and security questions may be sent to security@clyvel.com.