LoginBuy now

Privacy Policy

Last updated: 28 August 2026

This is a single policy. It applies wherever you are — the European Economic Area, the United Kingdom, the United States, Hong Kong or anywhere else — and it gives everyone the same core treatment. Where a specific law grants you extra rights, those are set out in sections 12 to 15.

1. Who we are

Clodix is an AI content platform operated by AQPRO LIMITED, a company incorporated in the Hong Kong Special Administrative Region under registration number 78622410, with its registered office at Room 511, 5/F, Ming Sang Industrial Building, 19–21 Hing Yip Street, Kwun Tong, Hong Kong ("Clodix", "we", "us").

This policy explains what personal information we collect when you visit www.clodix.ai or use the Clodix service, why we collect it, who we share it with, how long we keep it and what you can require us to do about it. We process personal information lawfully, fairly and transparently under the EU General Data Protection Regulation, the UK GDPR, the California Consumer Privacy Act as amended by the CPRA, the other US state privacy laws listed in section 13, and the Hong Kong Personal Data (Privacy) Ordinance.

Questions, requests and complaints: privacy@clodix.ai.

2. Scope, and the two roles we play

This policy covers the Clodix web application, the marketing site, the onboarding quiz and site analysis, our email, and our support channels.

We are the controller (the "business", in California terms) for the personal information described in section 3 — your account, your billing record, your usage of the product, your support history and your marketing preferences. Sections 5 to 20 describe how we handle it.

We are a processor (a "service provider") for any personal information that happens to sit inside the material you put into Clodix — for example names or contact details in your website copy, brand guidelines or prompts. For that material you decide the purpose, we only act on your instructions, and section 18 sets out the terms. Business customers who need a signed data processing agreement with the EU Standard Contractual Clauses attached can request one at privacy@clodix.ai.

This policy does not cover the third-party platforms you connect to Clodix — your CMS, your social accounts, Google Search Console. Those are governed by their own terms and privacy notices, and the operators of those platforms are independent controllers of what they hold. What Clodix itself receives from those platforms — including the Google user data described in section 3 — is covered by this policy.

3. Personal information we collect

Account data. Name, email address, a hashed password, the identity of your authentication provider if you sign in with Google, account creation and last-login timestamps, and the account role you hold.

Billing data. Subscription plan and billing period, subscription status, renewal and cancellation dates, invoice history, the billing country and tax status we need in order to charge the right tax, and the last four digits and brand of your card as reported back to us by our payment processor. Full card numbers, CVCs and bank credentials never reach our servers — they are collected and stored by Stripe on Stripe's own infrastructure.

Site and brand configuration. The website address you connect, and the brand, audience, tone-of-voice, language and topic settings you provide or approve during onboarding.

Publishing credentials. Access tokens, application passwords, API keys and OAuth tokens for the platforms you connect — for example WordPress, Ghost, Shopify, Telegram, Facebook/Instagram and Google Search Console. These are encrypted at rest with AES-256-GCM under a key held only on the server, are never returned to the browser, and are deleted when you disconnect the integration.

Search Console data (Google user data). If you connect Google Search Console, we access Google user data through Google's APIs under the read-only scope webmasters.readonly — nothing broader. At the moment you connect we fetch the list of Search Console properties your Google account can read, solely to match one of them to the website you connected; we store the matched property, not the list. A daily sync then retrieves the search-performance statistics of that property — clicks, impressions, click-through rate and average position, broken down by date, by page and by search query, over a rolling window of roughly the last month — and stores them in our database. We use this data for one purpose: showing you your own site's performance in the Clodix analytics dashboard and updating the real ranking positions of the keywords you track. We do not sell Google user data, do not use it for advertising, and do not send it to the AI providers described in section 6; it is disclosed only to the infrastructure subprocessors in section 9 that host our application and database. No human reads it except with your permission, for security purposes, to comply with the law, or in aggregated, anonymised form for internal operations. The OAuth tokens are handled as described under Publishing credentials above; the synced statistics follow the retention periods in section 11 and can be deleted earlier on request under sections 12 to 15. You can stop this at any time. Disconnecting Search Console in your Clodix settings ends the sync and deletes the stored OAuth tokens; you can also revoke our access directly at myaccount.google.com/permissions, which stops any further access to your Google user data immediately.

Clodix's use and transfer of information received from Google APIs to any other application adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Content data. Keywords, topic clusters, content plans, article drafts, generated images and social posts produced for your account, together with your edits, scores and publishing history.

Marketing and lead data. If you complete the quiz or request a site analysis, we collect the email address and website you submit, the language of the request, the answers you gave, and the referral source. We use this to send you the result and, where permitted, product email you can unsubscribe from at any time.

Usage and technical data. IP address, browser and device type, pages viewed, features used, timestamps, and application and error logs.

Support data. The content of the emails and support requests you send us and our replies.

We do not intentionally collect special categories of personal data — health, biometrics, racial or ethnic origin, political or religious views, trade union membership, sex life or sexual orientation. Please do not put such data into prompts, brand settings or article content. Under California law your account log-in credentials count as "sensitive personal information"; we use them only to authenticate you and for the security of the service, which are permitted purposes, and never to infer characteristics about you.

We do not collect personal information from data brokers.

4. California notice at collection

For California residents, the table below maps what we collect to the statutory categories in Civil Code §1798.140(v), and states the source, purpose and retention for each. We disclose each category to the service providers listed in section 9, and to nobody else except as described in section 9.

CCPA categoryWhat that is hereWhere it comes fromWhyKept for
IdentifiersName, email, account ID, IP address, OAuth provider IDYou; your browser; Google sign-inRun your account, authenticate you, support, securityLife of the account + 90 days
Customer records (§1798.80(e))Billing name, billing country, card brand and last four digitsYou, via StripeTake payment, issue invoices, tax7 years (accounting law)
Commercial informationPlan, subscription status, invoices, purchase historyYou; StripeBilling, entitlement, fraud prevention7 years
Internet and network activityPages viewed, features used, application and error logsYour browser and our serversOperate, debug and secure the service12 months
Geolocation (coarse)Country inferred from IP or billing addressYour browser; StripeTax, fraud prevention, language12 months
Professional informationYour website, industry, brand and audience settingsYouGenerate content for youLife of the account + 90 days
Audio, electronic or visual informationSupport emails; content, images and drafts you createYou; generated for youSupport; deliver the service3 years (support) / life of account + 90 days (content)
InferencesTopic clusters and keyword recommendations derived from your siteDerived by usBuild your content planLife of the account + 90 days
Sensitive personal informationAccount log-in credentials (email + hashed password)YouAuthentication and account security onlyLife of the account + 90 days

We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined in the CCPA — not for money and not for anything else of value. We have not done so in the twelve months before the date at the top of this policy. We do not knowingly sell or share the personal information of anyone under 16.

5. Why we process it, and our legal basis

PurposeLegal basis (GDPR / UK GDPR Art. 6)
Creating and running your account; generating, scoring and publishing contentPerformance of a contract
Taking payment, issuing invoices, tax and accountingContract; legal obligation
Transactional email — confirmations, receipts, job status, security noticesContract
Marketing email, quiz results and product newsConsent; or legitimate interest in marketing to an existing customer about similar services, where local law allows it. Always with an unsubscribe link
Support, debugging, abuse prevention, service securityLegitimate interest in running a working and secure service
Improving the product and measuring aggregate usageLegitimate interest in developing the service
Responding to legal requests, enforcing our terms and defending claimsLegal obligation; legitimate interest in protecting our rights

Where we rely on legitimate interest, we have weighed it against your interests and rights, and you can object at any time under section 12. Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of what we did before you withdrew it.

6. AI processing

Clodix generates content using third-party large-language and image models — Anthropic (Claude, for text) and Google (Gemini, for images). To do that we send those providers the prompt material relevant to your request: your brand settings, keywords, outline and article text. We do not send them your password, your payment details, your publishing credentials, or the data we receive from Google Search Console.

Your content is not used to train third-party models. Our commercial API agreements with these providers exclude our traffic from model training, and we do not use your content, prompts or output to train models of our own.

AI output is probabilistic. It can be inaccurate, out of date, or unintentionally similar to existing material, and we do not guarantee search rankings, traffic or factual accuracy — review before you publish.

We do not make decisions about you that produce legal or similarly significant effects by automated means, within the meaning of GDPR Article 22 or the profiling provisions of the US state laws in section 13. The automated processing we do — clustering keywords, scoring drafts — affects content, not people.

7. Marketing communications

We send you transactional email because you have an account with us; you cannot opt out of security and billing notices while the account is open.

Marketing email is separate. If you are in the EEA or the UK we send it on the basis of your consent, or — where the ePrivacy rules allow it — because you bought a similar service from us and did not object at the time. In the United States we comply with the CAN-SPAM Act: every marketing message identifies us, states our postal address, and carries a working unsubscribe link that we honour within ten business days.

You can unsubscribe from the link in any marketing email or at www.clodix.ai/unsubscribe. We keep a suppression record of your address afterwards, precisely so that we do not email you again.

8. Cookies and similar technologies

We use three categories of cookies and similar technologies.

Strictly necessary. These authenticate you and keep your session secure, hold the anti-forgery state during an OAuth connection, remember which of your connected sites is active, and store your cookie-consent choice itself. Without them the application does not work, so they are set on the basis of performing our contract with you and do not require consent under the EU ePrivacy Directive or the UK PECR.

Which consent regime applies to you is decided from the country your connection reports, read from the request itself. It is not stored on your device and is never linked to an identifier.

Analytics. A first-party visitor id (clodix_session) that lets us understand how visits turn into sign-ups, and Google Analytics 4 (_ga cookies). We also use PostHog (ph_* cookies), which measures how people move through the product and records anonymised session replays — a reconstruction of the pages you saw and the actions you took, with every text you type masked and whole screens excluded, so we can see where the product confuses people. Session replay is never recorded on our administrative pages, on the forms where you enter credentials for your own website, or on our sign-in and payment screens. In the EU and the UK, PostHog runs without storing anything on your device until you accept analytics cookies. We also use Yandex.Metrika (_ym_* cookies), which counts visits and, like PostHog, records anonymised session replays; it is subject to the same route exclusions, so it never records our administrative pages, the forms where you enter credentials for your own website, or our sign-in and payment screens. We also use Vercel Web Analytics and Speed Insights, which are cookieless and store no identifier on your device — they measure aggregate page performance only.

Marketing. Ad-attribution cookies (link_slug, pixel_id) that connect a visit from one of our ads to a later purchase, and the Meta Pixel with its Conversions API (_fbc, _fbp cookies), which reports conversions to Meta so our advertising can be measured and optimised.

If you are in the EEA, the United Kingdom or Switzerland, nothing beyond the strictly necessary category runs until you choose "Accept all" in our cookie banner. Choosing "Necessary only" keeps analytics and marketing off, and removes any such cookies already set.

Everywhere else, analytics and marketing run by default on the basis of our legitimate interest in measuring and improving the service, and you can opt out at any time: choose "Necessary only" in the cookie banner. For California residents, that choice is how you exercise your right to opt out of "sale or sharing" of personal information, and we also honour the Global Privacy Control (GPC) browser signal — a GPC-enabled browser is treated as opted out of marketing unless you explicitly accept.

You can change your mind at any time by clearing our cookies in your browser — the banner will ask again on your next visit. Blocking the strictly necessary cookies will break sign-in.

9. Who we share personal information with

We disclose personal information to service providers who process it on our behalf under written data-processing terms, only for the purposes we specify, and never for their own marketing. These are our current subprocessors:

ProviderWhat they do for us
VercelApplication hosting, CDN and edge delivery
SupabaseDatabase, file storage, backups, authentication
StripePayment processing, invoicing, subscription billing, tax calculation
AnthropicText generation (Claude models)
GoogleImage generation (Gemini), and the Search Console integration you connect
DataForSEOKeyword volume, difficulty and SERP data
AhrefsBacklink and SEO metrics
ResendTransactional and marketing email delivery
CloudflareDNS and inbound email routing
PostHogProduct analytics and session replay (processed in the European Union)
YandexWebsite analytics and session replay (Yandex.Metrika)

The SEO data providers receive website addresses and keywords, not your account or billing data. These providers process data in the United States, the European Union, Hong Kong and other locations; see section 10. We keep this list current and will update it here before a new subprocessor starts processing your data.

We also disclose personal information to:

  • the platforms you connect, and only what is needed to publish on your behalf;
  • professional advisers — lawyers, auditors, accountants — under a duty of confidentiality;
  • public authorities and courts, where we are legally compelled to. We review every request, refuse those that are overbroad or unlawful, and notify you unless we are prohibited from doing so;
  • a counterparty in a merger, acquisition or sale of assets, in which case we will tell you before your data becomes subject to a different privacy policy.

10. International transfers

We are established in Hong Kong. The European Commission has not adopted an adequacy decision for Hong Kong, and neither has the UK government, so transfers of personal data from the EEA or the UK to us — and onward to our subprocessors, some of which are in the United States — need a safeguard. We rely on:

  • the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Modules Two and Three, for transfers out of the EEA;
  • the UK International Data Transfer Addendum to those clauses for transfers out of the UK;
  • the EU–US Data Privacy Framework and its UK Extension where the receiving provider is certified under it;
  • adequacy decisions where one applies to the receiving country.

On top of the contractual safeguards we apply technical measures: TLS in transit, encryption at rest, AES-256-GCM for publishing credentials, row-level isolation of every account's data, and administrative access limited to named personnel. We have assessed the laws of Hong Kong and of the other countries involved as they bear on these transfers, and we will tell you if we ever become unable to comply with the clauses.

You can request a copy of the relevant transfer safeguards from privacy@clodix.ai.

11. How long we keep data

DataRetention
Account and content dataFor the life of the account, then 90 days after closure
Billing, invoice and tax records7 years, as required by accounting and tax law
Support correspondence3 years
Security and application logs12 months
Marketing contacts and quiz leadsUntil you unsubscribe or ask for deletion, plus a permanent suppression record of your address so we do not contact you again
Publishing credentialsDeleted when you disconnect the integration or close the account
Synced Search Console statisticsFor the life of the account, then 90 days after closure

We may keep specific records for longer where we need them to establish, exercise or defend a legal claim, or where a law requires it. When a retention period ends we delete the data or irreversibly anonymise it; anonymised aggregates are not personal information and are not covered by these periods.

12. Your rights in the EEA, the UK and Switzerland

You have the right to:

  • access the personal data we hold about you and get a copy;
  • rectify data that is inaccurate or incomplete;
  • erase it ("right to be forgotten"), where one of the grounds in Article 17 applies;
  • restrict our processing while a dispute about accuracy or legitimacy is resolved;
  • object to processing based on legitimate interest, and to direct marketing at any time and without giving a reason;
  • data portability — receive the data you gave us in a structured, machine-readable format, and have it sent to another controller where technically feasible;
  • withdraw consent at any time, without affecting processing already carried out;
  • not be subject to a decision based solely on automated processing with legal or similarly significant effects — as noted in section 6, we make none.

You can also lodge a complaint with the data protection authority of the country where you live or work. Because we are not established in the EU, there is no single lead authority for us: your local authority is competent. The list of EEA authorities is published by the European Data Protection Board at edpb.europa.eu; in the UK it is the Information Commissioner's Office at ico.org.uk. We would rather you came to us first — write to privacy@clodix.ai.

13. Your rights in the United States

California (CCPA/CPRA). You have the right to know what we collect, use, disclose and sell or share about you and to receive it in a portable format; to delete it; to correct it; to opt out of sale and of sharing for cross-context behavioural advertising — we do neither, as stated in section 4; to limit the use of sensitive personal information — we use it only for the purposes that the statute permits without a limit right; and not to be discriminated against for exercising any of these. We run no financial incentive programmes. Under California's "Shine the Light" law (Civil Code §1798.83), we do not disclose personal information to third parties for their own direct marketing.

Other states. If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky or Rhode Island, your state's privacy law gives you rights to confirm and access your data, correct it, delete it, obtain a portable copy, and opt out of targeted advertising, of the sale of personal data, and of profiling that produces legal or similarly significant effects. We do not carry out any of those three activities, so there is nothing to opt out of; if that ever changes we will publish the mechanism before we start.

Nevada. We do not sell covered information as defined by NRS 603A.

How we handle requests. We respond within 45 days and may extend once by a further 45 days where the request is complex, telling you why. We may ask you to verify your identity against the information already in your account, and we will refuse a request we cannot verify. An authorised agent may act for you with written permission that we can verify.

Appeals. If we refuse your request, you may appeal by replying to our decision within 30 days or writing to privacy@clodix.ai with "Appeal" in the subject line. We will respond in writing within 45 days with our decision and reasons. If we deny the appeal you may complain to your state attorney general.

14. Hong Kong

If you are in Hong Kong, the Personal Data (Privacy) Ordinance (Cap. 486) gives you the right to ask whether we hold data about you, to a copy of it, and to correction of anything inaccurate. We may charge a reasonable fee for a copy, as the Ordinance permits, and we respond within 40 days. We do not use your personal data in direct marketing without your consent, and you may withdraw that consent at any time at no cost. Complaints can be made to the Office of the Privacy Commissioner for Personal Data at pcpd.org.hk.

15. How to exercise your rights

Write to privacy@clodix.ai from the email address on your account, and tell us which right you want to exercise. We do not charge for this unless a request is manifestly unfounded or excessive, in which case we will tell you the fee before doing the work.

You can also do a lot of it yourself, immediately: edit or delete your brand settings, articles and connected sites from within the application, disconnect any integration to erase its stored credentials, close your account from settings, and unsubscribe from marketing email from the link in any such email.

16. Security

We encrypt data in transit with TLS and at rest. Publishing credentials are additionally encrypted with AES-256-GCM under a key that exists only on the server and is never sent to a browser. Every account's rows are isolated from every other account's by database row-level security. Administrative access is limited to the people who need it and is logged. Passwords are stored hashed by our authentication provider, never in plain text.

No system is perfectly secure. If a personal data breach is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours of becoming aware of it and inform you without undue delay where the law requires it. We also comply with US state breach-notification statutes and with section 3 of the Hong Kong Ordinance.

17. Children

Clodix is a business tool. It is not directed to children, and our Terms require you to be at least 18 to hold an account. We do not knowingly collect personal information from anyone under 18, and we do not knowingly sell or share the personal information of anyone under 16 — we do neither for anyone. If you believe a child has given us personal information, write to privacy@clodix.ai and we will delete it promptly. Requests concerning a child under 13 are handled under the US Children's Online Privacy Protection Act.

18. Terms for personal data you put into Clodix

Where you use Clodix to process personal data of your own — customers, readers, contacts — you are the controller and we are your processor. In that role we:

  • process that data only on your documented instructions, which include your use of the product's features, unless a law we are subject to requires otherwise, in which case we will tell you first unless the law forbids it;
  • bind everyone who handles it to confidentiality;
  • apply the security measures in section 16;
  • use only the subprocessors listed in section 9, under equivalent written terms, and give you notice of a new one before it starts processing so you can object;
  • help you respond to data subject requests, to security incidents, and to data protection impact assessments, taking into account the nature of the processing and the information available to us;
  • delete or return that data at the end of the service, subject to the retention periods in section 11 and to any legal obligation to keep it;
  • make available the information you need to demonstrate compliance and allow audits on reasonable notice, no more than once a year unless an incident makes another one necessary.

A signed data processing agreement with the EU Standard Contractual Clauses and the UK Addendum is available on request from privacy@clodix.ai.

19. Changes to this policy

We may update this policy. Where a change is material — a new purpose, a new category of recipient, a materially different retention period — we will announce it by email or in the application at least 30 days before it takes effect, and give you the chance to close your account before it does. Other changes take effect when posted. The date at the top always shows the version in force, and we keep the previous version available on request.

20. Contact

AQPRO LIMITED

Room 511, 5/F, Ming Sang Industrial Building, 19–21 Hing Yip Street, Kwun Tong, Hong Kong

Registration number 78622410

  • Data rights, privacy questions and complaints: privacy@clodix.ai
  • Support and billing: info@clodix.ai
  • Legal notices: legal@clodix.ai
Clodix

Copyright 2026
All rights reserved

Rated 4.9, Excellent, on Trustpilot

Product

PricingFree SEO Audit

Policies

Terms of ServicePrivacy PolicyRefund Policy

Social

FacebookInstagram

Contact

business@clodix.aiinfo@clodix.ai