Privacy Policy
Last updated: August 2026
The Short Version
Public charts, app evidence, and short clone-plan previews are open to browse. When verified access is enabled, we use a requested email verification message and an essential secure session to unlock full clone-plan reveal, copy, and generation, and to generate or download Build Kits. Verified visitors receive a small free Build Kit allowance; an optional paid Pro plan, billed by Stripe, removes the per-kit limit. The session remembers that browser and renews during validated active use. That service verification is separate from optional marketing email. Your Spotlight saves remain in your browser.
Information We Collect
Information You Provide
Depending on the features you use, you may provide:
- Service-access email: When verified access is enabled, an email address is required only to reveal, copy, or generate a full clone plan, or to generate and download a Build Kit. We use it to send the verification link you request.
- Optional marketing choice: You may separately opt in to Weekly Build Ideas. Leaving that option clear does not prevent service access.
Email verification shows that someone could receive and act on a message at that mailbox at that time. It does not establish a legal name or prove real-world identity.
Automatically Collected Information
Like most websites, our servers automatically log:
- IP addresses (for security and abuse prevention)
- Browser type and version
- Pages visited and timestamps
- Referring URLs
These logs are used for debugging, security, and aggregate analytics. We do not use this data to identify individuals.
Local Storage
Your browser stores:
- Saved apps: Apps you save for later are stored in your browser's localStorage
- Recent clone activity: App identifiers added locally after a successful chart-side clone action
We do not intentionally put your raw email address in localStorage, analytics events, affiliate links, or the verification URL.
Verified Access & Email Use
For verified service access, we may store or process:
- Your email address
- Verification and session records, such as token hashes and issue, use, and expiry times
- Security and delivery metadata needed for rate limiting, deduplication, failure handling, and abuse prevention
- Build Kit unlock records and your free-kit allowance, and for Pro subscribers the plan status, all keyed by a pseudonymous identity reference derived from your email rather than by the address itself
- Your separate marketing consent and preferences, only if you choose them
Shared workspace and connected AI tools
When you are signed in, new saved apps and Remix drafts can be stored with your account. Drafts include your selected apps and features, source-kit versions, titles, exclusions, and product notes. Existing browser saves are copied only when you choose to import them. Do not include passwords or sensitive personal information in a brief.
When you approve a connected AI tool, it can read and edit this workspace and, with active Pro access, retrieve kit files and Remix exports. Material you request through that tool is also processed under its provider's policies. We store connection metadata, hashed credentials, expiry information, and aggregate usage counts. We do not include your notes, tool arguments, or file contents in analytics.
You can disconnect tools from your workspace. Disconnecting stops future access but does not remove material already retrieved by the tool. You can clear saved workspace content from the account page or request deletion through support.
How We Use Your Email
- Requested service verification: Sending a short-lived, one-time link so you can establish an essential access session. The message does not contain the clone plan itself.
- Optional weekly email: Sending Weekly Build Ideas only when you separately opt in, subject to its preference and unsubscribe controls.
Asking for service access is not consent to receive marketing. Existing or legacy subscriber records are not automatically promoted to verified service identities or treated as fresh marketing consent for this feature.
What We Do Not Do
- Sell your email: We do not sell or rent your email address to third parties for their marketing
- Share for ads: Your email is not shared with advertisers or ad networks
- Disposable-address screening upload: We do not upload your address to an outside disposable-email validation service. Mailbox control is checked by delivery and use of the requested verification link.
Your Controls
- Marketing preferences and unsubscribe: The optional weekly email includes links to change preferences or stop future marketing messages.
- Service session: You can end local access by signing out or clearing the essential session cookie. A different browser or device must be verified separately. Verification messages are sent only in response to an access request.
- Billing: Anyone with a Stripe customer record, active or lapsed, can update their payment method or cancel at any time from the Stripe billing portal linked on the app page's Build Kit zone. Cancellation stops future renewals; access continues through the paid period.
- Access or deletion request: Contact [email protected]. We may retain limited suppression, consent, security, billing, or legal records where reasonably necessary.
Paid Plans & Payments
When the Pro plan is enabled, payments are processed by Stripe on Stripe's hosted checkout and billing pages. CloneChart never sees or stores card numbers. Stripe collects the email address, payment method, and billing details you enter there under Stripe's privacy policy, and acts as our payment processor.
To connect a payment to your verified access without sharing your email with our own billing records, we send Stripe the pseudonymous identity reference described above as checkout metadata. That means the Stripe account holder can relate a Stripe customer record to that reference. In our database we keep only that reference, Stripe's customer and subscription identifiers, the plan and its status, the renewal date, your Build Kit unlock records, and short webhook receipts. We do not store card data, billing names, or billing addresses.
Billing records can outlive the verified email row, which is deleted after the inactivity horizon described below, and they re-attach automatically if the same mailbox is verified again. A different email address is a different customer.
How We Use Information
The limited data we collect is used to:
- Operate and maintain the Service
- Understand aggregate usage patterns
- Prevent abuse and security threats
- Improve the platform
We do not sell, rent, or share your personal information with third parties for marketing purposes.
Third-Party Services
Analytics
When analytics is enabled we may use Google Analytics 4 and PostHog (US cloud) to understand how the site is used, including how visitors move from browsing to verifying access and to Build Kits. Both are configured to minimize data collection: no session recording, no automatic click capture, no heatmaps or surveys, page addresses reduced to their path, and campaign parameters and referring pages removed before anything is sent. A browser Do Not Track or Global Privacy Control signal prevents either from loading at all. PostHog events are anonymous: we do not identify people to it and never send email addresses, identity references, or verification links.
Payment Processing
Stripe processes Pro subscription payments on its own hosted pages and sends us signed notifications about subscription status. See Paid Plans & Payments above for what we store.
Transactional Email Delivery
When you request verification, our configured transactional email provider may process your address, the verification message, and delivery metadata on our behalf. We do not send production verification email or upload a subscriber list to a provider until that delivery configuration has been explicitly approved.
Verification alone never subscribes you to anything. If you also tick the optional Weekly Build Ideas box while verifying, we record that consent and activate the subscription when you click the sign-in link; that click is its confirmation, and every issue carries an unsubscribe link.
Affiliate Links
When you click links to partner platforms (Rork, Cursor, etc.), those services have their own privacy policies. We recommend reviewing them before using their services.
For affiliate reporting, we record the partner, timestamp, and optional app or page-source context. We do not put your email address in affiliate tracking URLs or include it in new affiliate click records. This change does not delete any historical records that may already exist.
Advertisements
If we display ads, they are developer-focused and non-tracking where possible. We avoid invasive ad networks.
Cookies
CloneChart.io uses minimal cookies:
- Essential cookies: When verified access is enabled, a secure, HTTP-only, host-only session cookie remembers that the mailbox was verified in that browser. Its current configured horizon is at most 400 days. Validated active use can renew that horizon no more than once per 30-day renewal window; clearing cookies, signing out, changing browsers or devices, or more than 400 days without use requires another verification.
- Preference cookies: Remember your settings (if any)
- Analytics storage: When analytics is enabled, PostHog keeps an anonymous device identifier in this browser's localStorage rather than in a cookie, and it is not created at all when your browser sends a Do Not Track or Global Privacy Control signal.
We do not use tracking cookies or share cookie data with advertisers.
Data Retention
Server logs are retained for a limited period based on operational, security, and applicable policy needs, then deleted or de-identified where appropriate.
Verification links and access sessions expire according to the service's configured time limits. Access sessions currently expire after at most 400 days without validated use and can be revoked sooner. The associated verified service email is scheduled for database TTL deletion after the same inactivity horizon; database cleanup is asynchronous. Active use may renew both deadlines at a bounded interval. We keep delivery, consent, suppression, and security records only as long as reasonably needed to provide the feature, honor preferences and suppression, resolve delivery issues, prevent abuse, and meet applicable obligations.
Billing records (plan status, Stripe customer and subscription identifiers, and Build Kit unlock records, all keyed by the pseudonymous identity reference) are kept while a plan may be renewed or reactivated and for as long as reasonably necessary for accounting, tax, dispute, and fraud-prevention purposes. Stripe webhook receipts are scheduled for database TTL deletion 180 days after receipt, and the daily counters that limit free-kit abuse (a keyed one-way digest of the requesting network address for the current day, never the address itself) two days after their day ends; as with the verified email, database cleanup is asynchronous.
Saved-app and recent clone-activity markers persist in localStorage until you clear browser data or remove saved items. Raw email addresses are not intentionally stored there.
Your Rights
Depending on where you live, you may have rights concerning personal information we hold. You can:
- Clear your saved apps by removing items or clearing browser data
- Use browser privacy features (private browsing, ad blockers)
- Use the links in optional marketing email to unsubscribe or change preferences
- Contact us to request access to or deletion of personal information associated with your email, subject to applicable exceptions
Children's Privacy
CloneChart.io is not directed at children under 13. We do not knowingly collect information from children.
Changes to This Policy
We may update this Privacy Policy occasionally. We'll note the "Last updated" date at the top when changes are made.
Contact Us
Questions about privacy? Contact us at [email protected]