Clairon — Privacy Policy

Last updated: 25 November 2025
Operated by: HDB Ventures Limited (Hong Kong)

1. Introduction
Clairon (“Clairon AI”, “we”, “us”, “our”) operates an AI-powered platform designed to analyze visibility across LLMs and GEO search environments.
We are committed to protecting your personal data and respecting your privacy.This Privacy Policy explains:
- What data we collect
- How we use it
- How we store and secure it
-Your rights under GDPR and other applicable laws
- With whom we share your data
- How long we retain it
By accessing or using Clairon, you agree to this Privacy Policy.

2. Who We Are
Clairon is currently operated by:
- HDB Ventures Limited Hong Kong SAR
A future corporate entity may be incorporated in the United States (Delaware), and this Privacy Policy will continue to apply unless otherwise updated.
For any privacy-related request:
- hugo@clairon.ai

3. Data We Collect
3.1 Data you provide voluntarily
-
Name and surname
- Email address
- Password (encrypted, never stored in cleartext)
- Company name, role, website
- Billing and invoicing data (processed securely by Stripe)
- Support messages or emails
- Content you input into the platform (keywords, prompts, URLs…)

3.2 Data collected automatically
-
IP address
- Browser and device information
- Operating system
- Usage events (clicks, pages viewed, features used)
- Logs for performance and debugging
- Cookies or analytics data (see Cookie Policy)

3.3 AI processing data
When you generate content or run analyses through Clairon:
- Prompts
- Inputs (keywords, URLs, queries)
- Temporary logs
- Model outputs
- We do not use user data to train LLMs.
We do not store prompts long-term unless necessary for troubleshooting or at your request.

3.4 Payment data
Handled entirely by Stripe.
We never store full credit card numbers.

3.5 Affiliate program data
If you join the affiliate/referral program:
- Referral link usage
- Attribution data
- Conversions
- Commission history
- Platform identifiers (PartnerStack or other providers)

4. How We Use Your Data
4.1 To provide and operate the service
-
Create and manage accounts
- Authenticate users
- Deliver and personalize features
- Analyze LLM visibility and GEO search results
- Generate reports

4.2 To improve our product
-
Understand how features are used
- Troubleshoot performance issues
- Train ranking systems (without using personal content in LLM training)
- Build new functionality

4.3 To manage billing
-
Process payments
- Handle subscription renewals
- Prevent fraudulent transactions
- Handle subscription renewals
- Prevent fraudulent transactions

4.4 For communication
-
Transactional emails
- Security alerts
- Product updates

4.5 For legal compliance
-
Tax and accounting
- Responding to valid legal requests
- Enforcing Terms of Service

5. Legal Bases for Processing (GDPR)
We process personal data on the following bases:
- Contractual necessity (to provide the service)
- Legitimate interest (product improvement, platform security)
- Consent (cookies, marketing emails)
- Compliance with legal obligations

6. How We Share Your Data
We never sell your data.
We only share it with trusted subprocessors, strictly for the functioning of the service.

6.1 Service providers (subprocessors)
- Stripe
– payment processing
- OpenAI, Anthropic, Google, Perplexity – LLM inference where applicable
- PartnerStack – affiliate program
- Email services (Postmark, SendGrid, or equivalent)
- Analytics providers (Plausible Analytics or Google Analytics)
- Cloud hosting provider (secure, accredited infrastructure)
Each provider signs a DPA and complies with security requirements.

6.2 Legal disclosure
We may disclose personal data if required:
- To comply with legal obligations
- To respond to court orders
- To enforce our Terms of Service

7. International Transfers
Your data may be processed in:
- Hong Kong (HDB Ventures Limited)
- United States (LLM providers, analytics, or hosting)
- European Union (analytics or distribution services)
Where transfers occur, we rely on:
- Standard Contractual Clauses (SCCs)
- GDPR-compliant DPAs
- Adequacy decisions where applicable

8. Data Security
We use industry-standard security measures including:
- HTTPS encryption
- Password hashing & salting
- Access control and audit logs
- Encrypted data storage
- Secure infrastructure providers
- Regular security reviews
Despite best efforts, no system is 100% secure.
If a breach occurs, we will notify affected users and regulators as required by law.

9. Data Retention
We keep personal data only as long as necessary:
- Account data: retained while the account is active
- Billing data: retained for accounting (6–10 years legal requirement)
- AI input data: temporary, unless saved by the user
- Analytics logs: 12–24 months
- Support messages: until resolved + up to 12 months
Users may request deletion at any time.

10. Your Rights (GDPR & global equivalents)
Depending on your jurisdiction, you may:
- Access your data
- Correct your data
- Delete your data
- Export your data (data portability)
- Restrict processing
- Object to processing
- Withdraw consent (cookies, emails)
Requests can be sent to:
- hugo@clairon.ai

11. Children’s Privacy
Clairon is not intended for children under 16.
We do not knowingly collect children’s data.

12. Changes to This Policy
We may update this Privacy Policy occasionally.
We will notify users of material changes via email or dashboard notification.

13. Contact
- hugo@clairon.ai