Skip to content

Privacy Policy

Last updated: March 18, 2026

1. Information We Collect

When you use Cleya.ai, we collect information you provide directly to us, including:

  • Account information (email address, password)
  • Profile information (name, role, company, industry, skills, interests, bio, LinkedIn URL)
  • Conversation data from onboarding and AI chat interactions
  • Match preferences and feedback you provide
  • Communication preferences and notification settings

We also automatically collect usage data such as pages visited, features used, IP address, browser type, device information, and interaction patterns to improve our matching algorithms and user experience.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our AI-powered matching services
  • Generate intelligent match recommendations using our proprietary algorithms
  • Facilitate introductions between matched professionals
  • Send you notifications about matches, introductions, and platform updates
  • Analyze usage patterns to improve match accuracy and user experience
  • Communicate with you about your account and our services
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations and enforce our Terms of Service

3. AI and Data Processing

Cleya.ai uses artificial intelligence to analyze your profile data and match you with relevant professionals. This includes:

  • Generating vector embeddings from your profile information for similarity matching
  • Processing conversation data to understand your networking goals
  • Using OpenAI services to power chat interactions and generate introductions
  • Automated decision-making for match scoring (you may request human review of any match decision)

Your data is processed in accordance with our data processing agreements with third-party AI providers. We do not sell your personal data to third parties. AI outputs are suggestions only and do not constitute professional advice.

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom, we process your data under the following legal bases:

  • Contractual necessity: To provide our matching and introduction services as described in our Terms of Service.
  • Legitimate interest: To improve our algorithms, prevent fraud, and ensure platform security.
  • Consent: For optional marketing communications and non-essential analytics. You may withdraw consent at any time.
  • Legal obligation: To comply with applicable laws and regulations.

5. Data Sharing

We share your information only in the following circumstances:

  • With matched professionals: When you accept a match, your contact information is shared with the other party.
  • Service providers: We use third-party services for hosting, email delivery, analytics, and AI processing. These providers are contractually bound to protect your data.
  • Legal requirements: When required by law, subpoena, court order, or to protect our rights, safety, or property.
  • Business transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred to the successor entity.

6. Data Security

We implement industry-standard security measures including:

  • Encryption of data in transit (TLS/HTTPS) and at rest
  • Secure password hashing (bcrypt with appropriate cost factor)
  • JWT-based authentication with token expiration and CSRF protection
  • Rate limiting on authentication endpoints
  • Input validation and sanitization
  • Regular security reviews and vulnerability assessments

While we take reasonable precautions, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data.

7. Cookies and Tracking Technologies

Cleya.ai uses the following technologies:

  • Essential cookies: Required for authentication and session management. These cannot be disabled.
  • Local storage: Used to maintain your authentication session and user preferences.
  • Analytics (optional): When enabled, we use PostHog for anonymous usage analytics to improve the platform. You may opt out in Settings.

We do not use third-party advertising cookies or cross-site tracking technologies.

8. International Data Transfers

Your data may be processed in countries outside your country of residence, including the United States (for AI processing via OpenAI) and India (for hosting and operations). When we transfer data internationally, we ensure appropriate safeguards are in place, including standard contractual clauses approved by relevant data protection authorities.

9. Data Retention

We retain your data for as long as your account is active. If you deactivate your account, we retain your data for 30 days before permanent deletion, unless required by law to retain it longer. Anonymized and aggregated data may be retained indefinitely for analytical purposes. You may request immediate data deletion at any time by contacting our Data Protection Officer.

10. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Request correction of inaccurate or incomplete data.
  • Erasure: Request deletion of your personal data ("right to be forgotten").
  • Data portability: Request your data in a structured, machine-readable format (JSON or CSV).
  • Restriction: Request restriction of processing of your personal data.
  • Objection: Object to processing of your data based on legitimate interests.
  • Withdraw consent: Where processing is based on consent, withdraw it at any time.
  • Non-discrimination: Exercise your privacy rights without receiving discriminatory treatment.

To exercise any of these rights, contact our Data Protection Officer at dpo@cleya.ai. We will respond to your request within 30 days.

11. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • The right to know what personal information we collect, use, and disclose.
  • The right to request deletion of your personal information.
  • The right to opt out of the sale of your personal information (we do not sell personal data).
  • The right to non-discrimination for exercising your CCPA rights.

To submit a CCPA request, email privacy@cleya.ai with the subject "CCPA Request."

12. Indian Data Protection

Cleya.ai complies with applicable Indian data protection laws, including the Digital Personal Data Protection Act, 2023 (DPDPA). As a data fiduciary, we process your personal data only for legitimate purposes with your consent. You have the right to access, correct, and erase your data, and to nominate a representative to exercise these rights on your behalf. You may file a complaint with the Data Protection Board of India if you believe your rights have been violated.

13. Children's Privacy

Cleya.ai is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a person under 18, we will take steps to delete such information promptly. If you believe a child has provided us with personal information, please contact us immediately at privacy@cleya.ai.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on the Platform and updating the "Last updated" date. For significant changes, we will provide additional notice via email or in-app notification. Your continued use of the Platform after such changes constitutes acceptance of the updated policy.

15. Data Protection Officer

Our Data Protection Officer can be reached at:

Email: dpo@cleya.ai

For general privacy inquiries: privacy@cleya.ai