1. Introduction
This Privacy Policy explains how Clyona(“Clyona,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you use our websites, applications, and related services (collectively, the “Service”), including Orbit (our design canvas), project and brand tools, AI-assisted creative features, subscription and billing flows, and integrations such as LinkedIn and Shopify where enabled.
By using the Service, you agree to this Privacy Policy. If you do not agree, do not use the Service.
2. Who we are
Data controller:
Clyona14, Residency Road
Richmond Town
Bengaluru, Karnataka 560025
India
General contact: support@clyona.com
Website: https://clyona.com
If you are in the European Economic Area (EEA), UK, or Switzerland and we are required to appoint a representative, contact us at support@clyona.com or the address above for details.
3. Scope
This policy applies to information we process when you:
- Create or sign in to an account
- Use Clyona and Orbit (canvas editing, uploads, AI tools, chat, exports)
- Manage profile, subscription, credits, and usage
- Connect third-party services (e.g., LinkedIn, Shopify-related features)
- Contact support or interact with marketing pages
It does not cover third-party websites, apps, or services linked from the Service; those have their own policies.
4. Information we collect
4.1 Information you provide
- Account credentials: email and password when you register or sign in with email/password.
- Profile information: display name, profile photo/avatar (including uploads), and similar profile fields you edit in settings.
- User content: designs, canvases, scenes, text, images, videos, prompts, masks, brand kit assets (fonts, colors, logos), carousel/project data, saved posts, tasks, templates, and other content you create, upload, or store in the Service.
- Communications: messages you send to support or feedback you submit.
- Billing-related information: subscription plan and status, credit balance, and transaction references processed through our payment provider (see Section 6). We do not store full payment card numbers on our servers.
4.2 Information from authentication providers
If you sign in with Google, Facebook, Apple, or LinkedIn (or other providers we enable), we receive information from that provider as permitted by your settings, such as name, email address, profile picture, and provider account identifiers. Authentication is handled through Supabase Auth.
4.3 Information collected automatically
- Usage and log data: pages/features used, actions taken (e.g., AI tool usage that consumes credits), timestamps, IP address, browser/device type, operating system, referring URLs, and diagnostic logs.
- Session data: authentication session tokens stored in cookies (and related session metadata) to keep you signed in and secure the Service.
- Local storage:certain data may be stored in your browser's local storage (for example, unsaved Orbit canvases when not signed in, UI preferences, or temporary draft data for content generators). This stays on your device unless synced to our servers when you are signed in.
- Cookies and similar technologies: see Section 13.
4.4 Information from integrations
- LinkedIn: if you connect LinkedIn or use LinkedIn sign-in, scheduling, or analytics features, we may process LinkedIn account identifiers, tokens (stored securely), post content you schedule, and related metadata needed to publish or analyze posts you authorize.
- Shopify / Orbit commerce features: if you use Shopify listing or product sync features, we may process product data, images, listing content, and API credentials or keys needed to connect your store, as configured by you.
4.5 Information from AI and processing providers
When you use AI features (image generation, editing, upscaling, background removal, inpainting, video generation, chat, vision analysis, copywriting, web search-assisted flows, etc.), we send relevant prompts, images, masks, canvas regions, and metadata to our servers and to third-party AI/infrastructure providers to perform the requested operation. See Section 5.
5. How we use your information
We use information to:
- Provide, operate, maintain, and improve the Service
- Authenticate you and manage accounts, organizations/workspaces, and access control
- Store and sync your projects, canvases, assets, and settings
- Run AI and media processing features you request and deduct or manage credits accordingly
- Process subscriptions and payments, prevent fraud, and provide billing support
- Send service-related communications (security alerts, account notices, password reset)
- Respond to support requests and enforce our terms
- Analyze usage to improve performance, reliability, and product design (in aggregated or de-identified form where possible)
- Comply with law, protect rights, and enforce policies
We do not use your private canvas content to train public third-party foundation models unless we clearly tell you otherwise and you opt in, or unless a specific third-party's terms require it for providing the feature—in which case we rely on that provider's policies and our agreements with them.
6. AI processing and automated decision-making
Many features are automated and powered by external models and APIs, including but not limited to:
| Category | Examples (as implemented in the Service) |
|---|---|
| Large language / vision models | OpenAI, DeepSeek, Google Gemini |
| Image/video models & tools | Replicate (e.g., upscaling, background removal, inpainting, expansion, object removal, video workflows) |
| Search (where enabled) | Google Custom Search API |
| Auth, database, file storage | Supabase |
What is sent: text prompts, chat messages, images (including uploads and canvas exports), masks, selected regions, style parameters, and technical metadata needed to complete the job.
Outputs: generated or edited media and text returned to your account/canvas.
Credits: AI operations may consume account credits or require a paid plan.
Automated processing does not typically produce legal or similarly significant effects about you without human involvement; it is used to deliver creative tooling you initiate.
7. Legal bases for processing (EEA/UK users)
Where GDPR or UK GDPR applies, we rely on:
- Contract: to provide the Service you signed up for
- Legitimate interests: security, fraud prevention, improvement, and analytics (balanced against your rights)
- Consent: where required (e.g., non-essential cookies or optional marketing)
- Legal obligation: compliance with applicable law
You may withdraw consent where processing is consent-based, without affecting lawfulness before withdrawal.
9. International data transfers
We and our providers may process data in the United States and other countries. Where required, we use appropriate safeguards (e.g., Standard Contractual Clauses) for transfers from the EEA/UK.
10. Data retention
We retain information for as long as your account is active and as needed to provide the Service, resolve disputes, enforce agreements, and meet legal obligations.
Typical retention (subject to change and legal holds):
- Account and profile data: until you delete your account, plus a reasonable backup period
- User content (canvases, assets, projects): until you delete it or your account, unless longer retention is required by law
- Billing records: as required for tax and accounting (often several years)
- Logs and security data: for a limited period appropriate for security and debugging
You may request deletion as described in Section 12. Some data may persist in encrypted backups for a limited time after deletion.
11. Security
We use administrative, technical, and organizational measures appropriate to the risk, including encryption in transit, access controls, and secured credentials for service accounts. No method of transmission or storage is 100% secure; you are responsible for keeping your password confidential and using a strong, unique password.
12. Your rights and choices
Depending on your location, you may have the right to:
- Access, correct, or delete personal information
- Export portable copies of your data
- Object to or restrict certain processing
- Withdraw consent (where processing is based on consent)
- Lodge a complaint with a supervisory authority (EEA/UK)
How to exercise rights: email support@clyona.com or write to us at the address in Section 2. We may verify your identity before responding.
Account controls: update profile and avatar in app settings; sign out to end your session; use password reset on the sign-in page.
Deletion: you may request account deletion by contacting us. Deleting content in the app may not immediately remove all copies from backups or logs.
California (CCPA/CPRA):California residents may have additional rights to know, delete, correct, and opt out of certain “sharing” for cross-context behavioral advertising. We do not sell personal information as defined by the CCPA. Contact us to exercise rights.
14. Children's privacy
The Service is not directed to children under 13 (or 16 in certain jurisdictions). We do not knowingly collect personal information from children. Contact us if you believe a child has provided data and we will delete it.
15. Third-party links and fonts
The Service may load Google Fonts and other third-party resources in the browser; those providers may receive technical data (IP address, user agent) under their own policies. External links are not covered by this policy.
16. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version with a new “Last updated” date and, where required, provide additional notice (e.g., email or in-app banner). Continued use after the effective date constitutes acceptance of the updated policy.
17. Contact us
Questions about this Privacy Policy or our practices:
Email: support@clyona.com
Mail:
Clyona14, Residency Road
Richmond Town
Bengaluru, Karnataka 560025
India