Skip to content
ClutoRequest early access
Legal

Privacy Policy

How Cluto collects, uses, stores and protects the data you connect — including data received from Google APIs. Written to be read, not skimmed.

Effective September 11, 2026Last updated September 11, 2026Version 1.1
On this page
  1. Who we are
  2. Information we collect
  3. Google user data and Limited Use
  4. How we use information
  5. AI processing and LLM subprocessors
  6. How we share information
  7. Data retention and deletion
  8. Data security and breach notification
  9. Your rights and choices
  10. Your rights under India's DPDP Act
  11. Revoking Google access
  12. Cookies and site analytics
  13. International data transfers
  14. Children's privacy
  15. Grievance Officer
  16. Changes to this policy
  17. Contact us

This Privacy Policy explains what information Cluto collects when you use our website and product, how we use and share that information, and the choices you have. It applies to the Cluto product, our website at cluto.ai, and any related services we operate.

Cluto is a search intelligence platform for B2B SaaS companies. To do our job, we connect to your Google Search Console and Google Analytics 4 properties, and we run prompts against public AI engines to see how your brand appears in their answers. This policy describes exactly what that means for your data.

This policy is drafted to comply with India's Digital Personal Data Protection Act, 2023 (DPDP Act) as notified, the EU and UK General Data Protection Regulation (GDPR and UK GDPR), the California Consumer Privacy Act (CCPA/CPRA), and equivalent data protection laws elsewhere. Where DPDP Rules are finalised after the effective date of this policy, we will update this policy to reflect them.

01Who we are

Cluto ("we," "our," "us") operates the search intelligence platform available at cluto.ai. For the purposes of the EU GDPR, the UK GDPR, and equivalent data protection laws elsewhere, Cluto is the data controller for the personal data you provide directly to us and the data processor for the customer data you connect through Google APIs and other integrations. For the purposes of India's DPDP Act, Cluto is the Data Fiduciary for personal data you provide directly, and processes personal data of your workspace users on your instructions.

The Cluto product is operated by Ayush Verma and Co., a sole proprietorship registered in India (GST 23ATQPV0840E1ZN, MSME registered), with registered address at Coral Woods, Bhopal, Madhya Pradesh 462027, India.

02Information we collect

We collect only what we need to run the product. There are four categories.

Account information you give us

When you request access, sign up or set up a product, you give us:

  • Your work email address and name
  • Your company name and website URL
  • Rough traffic volume band and, if you share it, a short description of your search problem
  • Billing information when a paid plan is activated (processed by our payment processor — we don't store card numbers)

Data from Google APIs (Search Console and Analytics)

When you connect a Google account, you grant Cluto read-only access to specific Google APIs. See §3 for the exact scopes, the specific data we retrieve, and the Limited Use commitments we make. In summary, we retrieve:

  • From Search Console: query, page, country, device, date, impressions, clicks, CTR and average position for the properties you connect
  • From Google Analytics 4: session, user, engagement, conversion, channel, source/medium, device, geography and landing-page data for the properties you connect

AI citation data (Cluto-generated)

Cluto runs the prompts you configure against public AI engines — currently ChatGPT, Claude, Gemini, Perplexity and Google AI Overviews. We store the prompt, the engine, the timestamp, the model response, the citations extracted from the response, and the domains and pages referenced. This data is generated by Cluto's own queries; it does not come from your Google account.

Product usage data

We record how you use the product — pages viewed, features used, actions taken, session timing, IP address, browser and device information, and error diagnostics — so we can operate, secure and improve the service.

03Google user data and Limited Use

Google API Services Limited Use Disclosure

Cluto's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Consistent with those requirements, Cluto affirms that information received from Google APIs is not:

  • Used or transferred for serving advertisements, including retargeted, personalised or interest-based advertising
  • Used or transferred to determine creditworthiness or for lending purposes
  • Sold or transferred to data brokers, information resellers or any other information service providers
  • Used to train, fine-tune or otherwise improve generalised AI or machine-learning models
  • Read by humans, except (a) with your explicit consent, (b) for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data is aggregated and used for internal operations in accordance with applicable privacy and legal requirements

Scopes we request

Cluto requests only the minimum scopes needed to deliver its features. At the point of authorisation, you will see the following scopes on Google's consent screen:

  • https://www.googleapis.com/auth/webmasters.readonly — read-only access to Search Console data for the properties you select
  • https://www.googleapis.com/auth/analytics.readonly — read-only access to Google Analytics 4 reporting data for the properties you select
  • openid, email, profile — to associate the connection with your Cluto account

We do not request write access to any Google service. We cannot modify your Search Console properties, publish anything to your Analytics accounts, or change any setting in your Google account.

What we do with Google data

Data received from Google APIs is used only to power the user-facing features described in your Cluto workspace — the reports, signals, and analyses you see when you log in. Specifically:

  • We display it to you and to authorised members of your workspace
  • We join it with your AI citation data on the page URL to produce cross-source insights (this is Cluto's core function)
  • We store it so that trend, historical and comparison views work — including views that extend past Google's own 16-month retention window
  • We compute derived metrics from it (positions, gaps, coverage states, verdicts) that are shown in the product

Google data is not used for any other purpose. Where we conduct diagnostics or system-level monitoring on our infrastructure, we operate on aggregated system metrics and do not read individual customer Google data unless one of the four exceptions listed above applies.

04How we use information

We use the information we collect to:

  • Provide, operate, maintain and improve the Cluto product and the cluto.ai website
  • Authenticate you and secure your account
  • Compute the reports, signals and derived metrics that Cluto is designed to produce
  • Communicate with you about the service, including onboarding, product updates, security notices and support
  • Comply with applicable law and enforce our Terms of Service
  • Detect, prevent and address abuse, fraud or security incidents

We do not sell your personal information, and we do not use it for advertising, retargeting, credit scoring or any purpose incompatible with the specific reasons above.

05AI processing and LLM subprocessors

Cluto uses third-party large language models for two purposes, both of which are transparent, credit-metered and initiated by you.

  • Prompt tracking. The prompts you configure are executed against public AI engines (ChatGPT, Claude, Gemini, Perplexity, Google AI Overviews). The prompts themselves and the responses returned are stored in your workspace.
  • Summarize this report. When you click "Summarize" on a report, Cluto sends the report's underlying deterministic data — no raw Google user data beyond what is already shown on that report — to an LLM provider to generate a plain-English summary of what the report shows.

Our LLM subprocessors currently include OpenAI (for ChatGPT and summarisation), Anthropic (for Claude) and Google (for Gemini). Each is contractually restricted from using data we send them to train their models. We do not send data to LLMs for any purpose outside these two features, and we do not send data to LLMs in the background — every AI-processed action is initiated by an explicit click and shows a model badge on the output for transparency.

06How we share information

We share information only in the ways described here. We do not sell or rent your data.

With subprocessors we contract to operate the service

We use vetted third-party service providers to run parts of our infrastructure. These subprocessors process data only on our instructions and only to the extent needed to provide their service to us. Current subprocessors include:

CategoryProvider(s)Purpose
Cloud hosting and databaseSupabase, Amazon Web ServicesApplication hosting, database, backup, monitoring
LLM providersOpenAI, Anthropic, GooglePrompt execution and report summarisation (see §5)
Email deliveryResendTransactional email (verification, notifications, invoices)
Payment processorRazorpay (once billing is live)Subscription billing and card processing
Product analyticsPostHogAggregated usage analytics on the Cluto product itself
Error monitoringSentryDiagnosing crashes and errors in the product
Content delivery and DNSCloudflareDNS, CDN and security at the network edge

An up-to-date list of named subprocessors is maintained at cluto.ai/subprocessors and available on request to privacy@cluto.ai. We will notify existing customers by email at least 30 days in advance of adding a new subprocessor that has access to Customer Data, so that you can raise objections if needed.

With authorised users of your workspace

Data connected to a workspace is visible to other users invited into that workspace. Workspace administrators control who is invited and can remove users at any time.

For legal or safety reasons

We may disclose information when required by law, to enforce our Terms of Service, or to protect the rights, property or safety of Cluto, our users, or the public.

In connection with a business transfer

If Cluto is involved in a merger, acquisition, financing, reorganisation or sale of assets, information may be transferred as part of that transaction. If that happens, we will notify you and ensure the acquiring party is bound by protections at least as strong as those in this policy.

07Data retention and deletion

Historical depth is a feature of Cluto — it lets you see beyond Google's 16-month cap and beyond the point where a fresh install of any other tool would lose context. To make that work, we retain data as follows.

While your account is active

  • Google Search Console and Analytics data: retained for the life of the account, at daily granularity for recent windows and progressively rolled up to weekly and monthly for older windows
  • AI citation data (prompts, runs, responses, citations): retained for the life of the account
  • Account information: retained for the life of the account
  • Product usage logs: retained for 24 months, then deleted or aggregated

When you close your account

You can delete your Cluto account at any time from Settings, or by writing to privacy@cluto.ai. When you do:

  • Your OAuth grants to Google APIs are revoked from our side immediately (you can also revoke them directly with Google — see §11)
  • Account and personal data are deleted from active systems within 30 days
  • Data connected through your workspace, including Google user data, is deleted from active systems within 30 days
  • Encrypted backups may retain deleted data for up to 90 additional days before being overwritten as part of our routine backup rotation
  • Aggregated, de-identified data that no longer identifies you or your workspace may be retained for internal operations

Where we are legally required to retain certain records (for tax, accounting or fraud-prevention purposes under Indian law, the Companies Act, the GST Act, or equivalent), we do so for the period required by applicable law and then delete them.

08Data security and breach notification

We take reasonable and appropriate steps to protect the data you entrust to us. Our practices include:

  • Encryption in transit (TLS 1.2 or higher) for all connections between your browser, our servers and third-party APIs
  • Encryption at rest for stored data, including database and backup encryption
  • Access control on production systems, with the principle of least privilege and audit logging of privileged actions
  • Secret and credential management for OAuth tokens, API keys and other secrets
  • Regular security reviews of our infrastructure and code
  • Incident response procedures with defined notification obligations to affected users

No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to the rights and freedoms of affected individuals, we will notify affected customers without undue delay. Where the EU or UK GDPR applies, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR. Where India's DPDP Act applies, we will notify the Data Protection Board of India and affected Data Principals as required by the Act and its Rules.

09Your rights and choices

Depending on where you live, you have the following rights over your personal data. These rights are available to residents of the European Economic Area, the United Kingdom, California and other jurisdictions with comparable laws, and Cluto extends them to all users regardless of location.

  • Access. Request a copy of the personal data we hold about you
  • Correction. Ask us to correct inaccurate or incomplete data
  • Deletion. Ask us to delete your data (subject to legal retention obligations)
  • Portability. Receive your data in a structured, commonly used, machine-readable format
  • Restriction and objection. Restrict or object to certain uses of your data
  • Withdraw consent. Withdraw consent you have given, without affecting the lawfulness of processing before withdrawal
  • Complaint. Lodge a complaint with your local data protection authority

To exercise any of these rights, write to privacy@cluto.ai. We will respond within 30 days (or sooner where required by applicable law, including within 15 days for grievances raised by Indian Data Principals — see §15).

Our legal bases for processing personal data under the GDPR are: performance of a contract (to provide the service you signed up for); legitimate interest (to secure, operate and improve the service); consent (where you have given it); and compliance with legal obligations. Under India's DPDP Act, our lawful grounds for processing include consent (which you provide when you sign up and connect data sources) and legitimate uses as defined in the Act.

10Your rights under India's DPDP Act

If you are a Data Principal under India's Digital Personal Data Protection Act, 2023, you have the following additional rights, which Cluto honours in addition to the rights described in §9:

  • Right to information. To obtain a summary of personal data being processed, the processing activities undertaken, and the identities of any Data Fiduciaries and Data Processors with whom data has been shared
  • Right to correction, completion, updating and erasure. To have your personal data corrected, completed, updated or erased where it is no longer necessary for the purpose for which it was processed
  • Right of grievance redressal. To have grievances addressed by our Grievance Officer within 15 days (see §15)
  • Right to nominate. To nominate an individual who will exercise your DPDP rights in the event of your death or incapacity
  • Right to withdraw consent. To withdraw consent at any time, with the same ease with which it was given

To exercise any of these rights, contact our Grievance Officer at grievance@cluto.ai. Should the response you receive be unsatisfactory, you also have the right to raise a complaint with the Data Protection Board of India once it is operational.

11Revoking Google access

You can revoke Cluto's access to your Google account at any time, using either of the following methods.

From inside Cluto

Go to Settings → Connections → find the Google connection → click Disconnect. This revokes the OAuth token immediately.

From your Google account directly

Visit myaccount.google.com/permissions, find Cluto in the list of connected apps, and remove it. This revokes the OAuth token from Google's side.

Revoking access stops Cluto from retrieving new data from Google. Data already retrieved and stored in your workspace remains until you also delete the workspace or your Cluto account.

12Cookies and site analytics

The Cluto website uses a minimal set of cookies:

  • Strictly necessary cookies — for authentication, session management and basic site function. These cannot be disabled without breaking the site.
  • Analytics cookies — to understand aggregate usage of the website (which pages are visited, roughly where visitors are from). These are set only where required consent has been given through our cookie banner.

When you first visit cluto.ai, a cookie banner appears offering three choices: Accept all, Reject non-essential, and Customise. Your choice is stored for 12 months, after which the banner reappears. You can change your choice at any time via the "Cookie settings" link in the footer of every page.

We do not use third-party advertising cookies, tracking pixels for ad networks, or cross-site tracking.

13International data transfers

Cluto is based in India. Our infrastructure and subprocessors are located in multiple regions, including the United States, the European Union and India. When we transfer personal data across borders, we use appropriate safeguards:

  • For EEA and Swiss data: the Standard Contractual Clauses approved by the European Commission (Commission Implementing Decision (EU) 2021/914), using Module Two (controller-to-processor) where applicable, or Module Three (processor-to-processor) where relevant
  • For UK data: the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses
  • For Indian data: transfer to countries not restricted by the Central Government under section 16 of the DPDP Act, subject to any additional requirements notified under the DPDP Rules

We assess the destination country's laws on a case-by-case basis and, where required, apply supplementary measures such as additional encryption or access controls.

If you are in the EEA, the UK or Switzerland and would like more information about the specific transfer mechanisms we rely on, write to privacy@cluto.ai.

14Children's privacy

Cluto is a B2B product intended for business users aged 18 or older. We do not knowingly collect personal data from anyone under 18. Under India's DPDP Act, we do not process personal data of any child (defined as an individual under 18) without verifiable consent from a parent or lawful guardian. If you believe a child has provided personal information to us, contact privacy@cluto.ai and we will delete it.

15Grievance Officer

Grievance Officer — India

In compliance with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Consumer Protection (E-Commerce) Rules, 2020, and India's Digital Personal Data Protection Act, 2023, Cluto has designated the following Grievance Officer to address concerns raised by Data Principals and users.

Name
Ayush Verma
Designation
Grievance Officer, Cluto
Email
grievance@cluto.ai
Postal
Coral Woods, Bhopal, Madhya Pradesh 462027, India
Response window
Within 15 days of receipt of a grievance

We will acknowledge receipt of grievances within 48 hours and respond substantively within 15 days. If you are not satisfied with the response, you have the right to escalate the matter to the Data Protection Board of India (for DPDP-related grievances) or to your local data protection authority.

16Changes to this policy

We may update this policy from time to time. When we do, we will change the "Last updated" date at the top and, where the change is material — for example, if we begin to use your Google user data in a new way, or add a new category of subprocessor with access to personal data — we will notify you in advance and, where required, ask for your consent before making the change effective.

Prior versions of this policy are available on request.

17Contact us

Questions about this policy, or about how Cluto handles your data, can be sent to the addresses below.

Data protection

Email: privacy@cluto.ai

Grievances: grievance@cluto.ai

Phone: [+91-XXXXX-XXXXX]

Entity: Ayush Verma and Co.

Postal: Coral Woods, Bhopal, Madhya Pradesh 462027, India

GST 23ATQPV0840E1ZNMSME Registered
Cluto
AboutPrivacyTermsSubprocessors
© 2026 Ayush Verma and Co. · GST 23ATQPV0840E1ZN · Bhopal, India · Search intelligence for B2B SaaS.