Privacy Policy
Last updated 21 September 2026
Summary
ClueCode is designed to collect as little as possible. Your screenshots and your Gemini API key never reach our servers. We store only what we need to run your account, your subscription, and the one-device session limit.
What we store and why
- Account: email address, display name, a salted hash of your password (never the password itself), and whether your email is verified — to sign you in.
- Sign-in sessions: session records with IP address and browser/app user agent — to keep you signed in and to detect misuse. Expire after 30 days of inactivity.
- Subscription and payments: plan status, billing period, and payment records (Razorpay payment id, amount, currency, status) — to provide access and handle refunds. We never receive or store card, UPI or bank details.
- Devices and desktop sessions: a random installation id generated by the app (not a hardware fingerprint), your computer's name, OS, CPU architecture and app version, plus session start/end times — to enforce one active session per account and to show you where you're signed in.
- Security log: events such as session started/ended/revoked, subscription changes and administrator actions, with ids and timestamps. For administrator and security-sensitive actions we also record the IP address, to investigate abuse.
- Usage counters: whether an AI request succeeded or failed, which model and mode were used, how long it took, error codes and the app version — never the screenshot, question, answer or your key. Failed sign-in attempts are counted (with an error code, not the password).
What we do not collect
- Screenshots or screen content — these are sent from your computer directly to Google, never to us, and are not written to disk by the app.
- Your Gemini API key — stored only on your computer, encrypted by your operating system.
- Prompts or AI answers.
- Advertising or cross-site tracking data.
Third parties
- Google (Gemini API): receives your screenshots and prompt when you request an answer, under your own API key and Google's terms for that key. We have no access to this traffic.
- Razorpay: processes payments and receives the details you enter at checkout.
- Hosting and database providers (e.g. Vercel, Neon) store the account data above on our behalf.
- Email provider (e.g. Resend) sends verification and password-reset emails.
Retention
Account data is kept while your account exists. Payment records are kept as required by tax and accounting law. Desktop session records, security records and usage counters are kept for up to 12 months, then deleted automatically. You can ask us to delete your account at any time; we will delete or anonymise your data except where the law requires us to keep it.
Your choices
You can view your sessions, devices and payments in the dashboard, sign out devices, cancel your subscription, and delete your account yourself (Dashboard → Settings). Deleting your account cancels any renewal, erases your name, email, password, devices and sessions, and signs out the desktop app. Payment records are kept, anonymised, where tax and accounting law requires. To export your data, contact support.
Contact
Questions about privacy: see the contact page.