---
url: "https://www.clodix.ai/privacy"
title: "Privacy Policy · Clodix"
description: "How Clodix collects, uses, and protects your data."
updated: "28 August 2026"
---

# Privacy Policy

Last updated: 28 August 2026

This is a single policy. It applies wherever you are — the European Economic Area, the United
Kingdom, the United States, Hong Kong or anywhere else — and it gives everyone the same core
treatment. Where a specific law grants you extra rights, those are set out in sections 12 to 15.

## 1. Who we are

Clodix is an AI content platform operated by **AQPRO LIMITED**, a company incorporated in the
Hong Kong Special Administrative Region under registration number **78622410**, with its
registered office at **Room 511, 5/F, Ming Sang Industrial Building, 19–21 Hing Yip Street,
Kwun Tong, Hong Kong** ("Clodix", "we", "us").

This policy explains what personal information we collect when you visit
[www.clodix.ai](https://www.clodix.ai) or use the Clodix service, why we collect it, who we
share it with, how long we keep it and what you can require us to do about it. We process
personal information lawfully, fairly and transparently under the EU General Data Protection
Regulation, the UK GDPR, the California Consumer Privacy Act as amended by the CPRA, the other
US state privacy laws listed in section 13, and the Hong Kong Personal Data (Privacy) Ordinance.

Questions, requests and complaints: **privacy@clodix.ai**.

## 2. Scope, and the two roles we play

This policy covers the Clodix web application, the marketing site, the onboarding quiz and site
analysis, our email, and our support channels.

**We are the controller** (the "business", in California terms) for the personal information
described in section 3 — your account, your billing record, your usage of the product, your
support history and your marketing preferences. Sections 5 to 20 describe how we handle it.

**We are a processor** (a "service provider") for any personal information that happens to sit
inside the material you put into Clodix — for example names or contact details in your website
copy, brand guidelines or prompts. For that material you decide the purpose, we only act on your
instructions, and section 18 sets out the terms. Business customers who need a signed data
processing agreement with the EU Standard Contractual Clauses attached can request one at
privacy@clodix.ai.

This policy does **not** cover the third-party platforms you connect to Clodix — your CMS, your
social accounts, Google Search Console. Those are governed by their own terms and privacy
notices, and the operators of those platforms are independent controllers of what they hold.
What Clodix itself receives from those platforms — including the Google user data described in
section 3 — **is** covered by this policy.

## 3. Personal information we collect

**Account data.** Name, email address, a hashed password, the identity of your authentication
provider if you sign in with Google, account creation and last-login timestamps, and the account
role you hold.

**Billing data.** Subscription plan and billing period, subscription status, renewal and
cancellation dates, invoice history, the billing country and tax status we need in order to
charge the right tax, and the last four digits and brand of your card as reported back to us by
our payment processor. **Full card numbers, CVCs and bank credentials never reach our servers** —
they are collected and stored by Stripe on Stripe's own infrastructure.

**Site and brand configuration.** The website address you connect, and the brand, audience,
tone-of-voice, language and topic settings you provide or approve during onboarding.

**Publishing credentials.** Access tokens, application passwords, API keys and OAuth tokens for
the platforms you connect — for example WordPress, Ghost, Shopify, Telegram, Facebook/Instagram
and Google Search Console. These are encrypted at rest with AES-256-GCM under a key held only on
the server, are never returned to the browser, and are deleted when you disconnect the
integration.

**Search Console data (Google user data).** If you connect Google Search Console, we access
Google user data through Google's APIs under the read-only scope `webmasters.readonly` — nothing
broader. At the moment you connect we fetch the list of Search Console properties your Google
account can read, solely to match one of them to the website you connected; we store the matched
property, not the list. A daily sync then retrieves the search-performance statistics of that
property — clicks, impressions, click-through rate and average position, broken down by date, by
page and by search query, over a rolling window of roughly the last month — and stores them in
our database. We use this data for one purpose: showing you your own site's performance in the
Clodix analytics dashboard and updating the real ranking positions of the keywords you track. We
do not sell Google user data, do not use it for advertising, and do not send it to the AI
providers described in section 6; it is disclosed only to the infrastructure subprocessors in
section 9 that host our application and database. No human reads it except with your permission,
for security purposes, to comply with the law, or in aggregated, anonymised form for internal
operations. The OAuth tokens are handled as described under Publishing credentials above; the
synced statistics follow the retention periods in section 11 and can be deleted earlier on
request under sections 12 to 15. You can stop this at any time. Disconnecting Search Console in
your Clodix settings ends the sync and deletes the stored OAuth tokens; you can also revoke our
access directly at [myaccount.google.com/permissions](https://myaccount.google.com/permissions),
which stops any further access to your Google user data immediately.

Clodix's use and transfer of information received from Google APIs to any other application
adheres to the
[Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy),
including the Limited Use requirements.

**Content data.** Keywords, topic clusters, content plans, article drafts, generated images and
social posts produced for your account, together with your edits, scores and publishing history.

**Marketing and lead data.** If you complete the quiz or request a site analysis, we collect the
email address and website you submit, the language of the request, the answers you gave, and the
referral source. We use this to send you the result and, where permitted, product email you can
unsubscribe from at any time.

**Usage and technical data.** IP address, browser and device type, pages viewed, features used,
timestamps, and application and error logs.

**Support data.** The content of the emails and support requests you send us and our replies.

We do not intentionally collect special categories of personal data — health, biometrics, racial
or ethnic origin, political or religious views, trade union membership, sex life or sexual
orientation. Please do not put such data into prompts, brand settings or article content. Under
California law your account log-in credentials count as "sensitive personal information"; we use
them only to authenticate you and for the security of the service, which are permitted purposes,
and never to infer characteristics about you.

We do not collect personal information from data brokers.

## 4. California notice at collection

For California residents, the table below maps what we collect to the statutory categories in
Civil Code §1798.140(v), and states the source, purpose and retention for each. We disclose each
category to the service providers listed in section 9, and to nobody else except as described in
section 9.

| CCPA category | What that is here | Where it comes from | Why | Kept for |
| --- | --- | --- | --- | --- |
| Identifiers | Name, email, account ID, IP address, OAuth provider ID | You; your browser; Google sign-in | Run your account, authenticate you, support, security | Life of the account + 90 days |
| Customer records (§1798.80(e)) | Billing name, billing country, card brand and last four digits | You, via Stripe | Take payment, issue invoices, tax | 7 years (accounting law) |
| Commercial information | Plan, subscription status, invoices, purchase history | You; Stripe | Billing, entitlement, fraud prevention | 7 years |
| Internet and network activity | Pages viewed, features used, application and error logs | Your browser and our servers | Operate, debug and secure the service | 12 months |
| Geolocation (coarse) | Country inferred from IP or billing address | Your browser; Stripe | Tax, fraud prevention, language | 12 months |
| Professional information | Your website, industry, brand and audience settings | You | Generate content for you | Life of the account + 90 days |
| Audio, electronic or visual information | Support emails; content, images and drafts you create | You; generated for you | Support; deliver the service | 3 years (support) / life of account + 90 days (content) |
| Inferences | Topic clusters and keyword recommendations derived from your site | Derived by us | Build your content plan | Life of the account + 90 days |
| Sensitive personal information | Account log-in credentials (email + hashed password) | You | Authentication and account security only | Life of the account + 90 days |

**We do not sell personal information and we do not share it for cross-context behavioural
advertising**, as those terms are defined in the CCPA — not for money and not for anything else
of value. We have not done so in the twelve months before the date at the top of this policy. We
do not knowingly sell or share the personal information of anyone under 16.

## 5. Why we process it, and our legal basis

| Purpose | Legal basis (GDPR / UK GDPR Art. 6) |
| --- | --- |
| Creating and running your account; generating, scoring and publishing content | Performance of a contract |
| Taking payment, issuing invoices, tax and accounting | Contract; legal obligation |
| Transactional email — confirmations, receipts, job status, security notices | Contract |
| Marketing email, quiz results and product news | Consent; or legitimate interest in marketing to an existing customer about similar services, where local law allows it. Always with an unsubscribe link |
| Support, debugging, abuse prevention, service security | Legitimate interest in running a working and secure service |
| Improving the product and measuring aggregate usage | Legitimate interest in developing the service |
| Responding to legal requests, enforcing our terms and defending claims | Legal obligation; legitimate interest in protecting our rights |

Where we rely on legitimate interest, we have weighed it against your interests and rights, and
you can object at any time under section 12. Where we rely on consent, you can withdraw it at any
time without affecting the lawfulness of what we did before you withdrew it.

## 6. AI processing

Clodix generates content using third-party large-language and image models — **Anthropic**
(Claude, for text) and **Google** (Gemini, for images). To do that we send those providers the
prompt material relevant to your request: your brand settings, keywords, outline and article
text. We do **not** send them your password, your payment details, your publishing credentials,
or the data we receive from Google Search Console.

**Your content is not used to train third-party models.** Our commercial API agreements with
these providers exclude our traffic from model training, and we do not use your content, prompts
or output to train models of our own.

AI output is probabilistic. It can be inaccurate, out of date, or unintentionally similar to
existing material, and we do not guarantee search rankings, traffic or factual accuracy — review
before you publish.

We do not make decisions about you that produce legal or similarly significant effects by
automated means, within the meaning of GDPR Article 22 or the profiling provisions of the US
state laws in section 13. The automated processing we do — clustering keywords, scoring drafts —
affects content, not people.

## 7. Marketing communications

We send you transactional email because you have an account with us; you cannot opt out of
security and billing notices while the account is open.

Marketing email is separate. If you are in the EEA or the UK we send it on the basis of your
consent, or — where the ePrivacy rules allow it — because you bought a similar service from us
and did not object at the time. In the United States we comply with the CAN-SPAM Act: every
marketing message identifies us, states our postal address, and carries a working unsubscribe
link that we honour within ten business days.

You can unsubscribe from the link in any marketing email or at
[www.clodix.ai/unsubscribe](https://www.clodix.ai/unsubscribe). We keep a suppression record of
your address afterwards, precisely so that we do not email you again.

## 8. Cookies and similar technologies

We use three categories of cookies and similar technologies.

**Strictly necessary.** These authenticate you and keep your session secure, hold the
anti-forgery state during an OAuth connection, remember which of your connected sites is
active, and store your cookie-consent choice itself. Without them the application does not
work, so they are set on the basis of performing our contract with you and do not require
consent under the EU ePrivacy Directive or the UK PECR.

Which consent regime applies to you is decided from the country your connection reports, read
from the request itself. It is not stored on your device and is never linked to an identifier.

**Analytics.** A first-party visitor id (`clodix_session`) that lets us understand how visits
turn into sign-ups, and Google Analytics 4 (`_ga` cookies). We also use PostHog
(`ph_*` cookies), which measures how people move through the product and records
anonymised session replays — a reconstruction of the pages you saw and the actions you took,
with every text you type masked and whole screens excluded, so we can see where the product
confuses people. Session replay is never recorded on our administrative pages, on the forms
where you enter credentials for your own website, or on our sign-in and payment screens.
In the EU and the UK, PostHog runs without storing anything on your device until you accept
analytics cookies. We also use Yandex.Metrika (`_ym_*` cookies), which counts visits and, like
PostHog, records anonymised session replays; it is subject to the same route exclusions, so it
never records our administrative pages, the forms where you enter credentials for your own
website, or our sign-in and payment screens. We also use Vercel Web Analytics and Speed
Insights, which are cookieless and store no identifier on your device — they measure aggregate
page performance only.

**Marketing.** Ad-attribution cookies (`link_slug`, `pixel_id`) that connect a visit from one
of our ads to a later purchase, and the Meta Pixel with its Conversions API (`_fbc`, `_fbp`
cookies), which reports conversions to Meta so our advertising can be measured and optimised.

**If you are in the EEA, the United Kingdom or Switzerland**, nothing beyond the strictly
necessary category runs until you choose "Accept all" in our cookie banner. Choosing
"Necessary only" keeps analytics and marketing off, and removes any such cookies already set.

**Everywhere else**, analytics and marketing run by default on the basis of our legitimate
interest in measuring and improving the service, and you can opt out at any time: choose
"Necessary only" in the cookie banner. For California residents, that choice is how you
exercise your right to opt out of "sale or sharing" of personal information, and we also
honour the Global Privacy Control (GPC) browser signal — a GPC-enabled browser is treated as
opted out of marketing unless you explicitly accept.

You can change your mind at any time by clearing our cookies in your browser — the banner will
ask again on your next visit. Blocking the strictly necessary cookies will break sign-in.

## 9. Who we share personal information with

We disclose personal information to service providers who process it on our behalf under written
data-processing terms, only for the purposes we specify, and never for their own marketing.
These are our current subprocessors:

| Provider | What they do for us |
| --- | --- |
| Vercel | Application hosting, CDN and edge delivery |
| Supabase | Database, file storage, backups, authentication |
| Stripe | Payment processing, invoicing, subscription billing, tax calculation |
| Anthropic | Text generation (Claude models) |
| Google | Image generation (Gemini), and the Search Console integration you connect |
| DataForSEO | Keyword volume, difficulty and SERP data |
| Ahrefs | Backlink and SEO metrics |
| Resend | Transactional and marketing email delivery |
| Cloudflare | DNS and inbound email routing |
| PostHog | Product analytics and session replay (processed in the European Union) |
| Yandex | Website analytics and session replay (Yandex.Metrika) |

The SEO data providers receive website addresses and keywords, not your account or billing data.
These providers process data in the United States, the European Union, Hong Kong and other
locations; see section 10. We keep this list current and will update it here before a new
subprocessor starts processing your data.

We also disclose personal information to:

- **the platforms you connect**, and only what is needed to publish on your behalf;
- **professional advisers** — lawyers, auditors, accountants — under a duty of confidentiality;
- **public authorities and courts**, where we are legally compelled to. We review every request,
  refuse those that are overbroad or unlawful, and notify you unless we are prohibited from doing
  so;
- **a counterparty in a merger, acquisition or sale of assets**, in which case we will tell you
  before your data becomes subject to a different privacy policy.

## 10. International transfers

We are established in Hong Kong. The European Commission has not adopted an adequacy decision for
Hong Kong, and neither has the UK government, so transfers of personal data from the EEA or the
UK to us — and onward to our subprocessors, some of which are in the United States — need a
safeguard. We rely on:

- the **EU Standard Contractual Clauses** (Commission Implementing Decision (EU) 2021/914),
  Modules Two and Three, for transfers out of the EEA;
- the **UK International Data Transfer Addendum** to those clauses for transfers out of the UK;
- the **EU–US Data Privacy Framework** and its UK Extension where the receiving provider is
  certified under it;
- **adequacy decisions** where one applies to the receiving country.

On top of the contractual safeguards we apply technical measures: TLS in transit, encryption at
rest, AES-256-GCM for publishing credentials, row-level isolation of every account's data, and
administrative access limited to named personnel. We have assessed the laws of Hong Kong and of
the other countries involved as they bear on these transfers, and we will tell you if we ever
become unable to comply with the clauses.

You can request a copy of the relevant transfer safeguards from privacy@clodix.ai.

## 11. How long we keep data

| Data | Retention |
| --- | --- |
| Account and content data | For the life of the account, then 90 days after closure |
| Billing, invoice and tax records | 7 years, as required by accounting and tax law |
| Support correspondence | 3 years |
| Security and application logs | 12 months |
| Marketing contacts and quiz leads | Until you unsubscribe or ask for deletion, plus a permanent suppression record of your address so we do not contact you again |
| Publishing credentials | Deleted when you disconnect the integration or close the account |
| Synced Search Console statistics | For the life of the account, then 90 days after closure |

We may keep specific records for longer where we need them to establish, exercise or defend a
legal claim, or where a law requires it. When a retention period ends we delete the data or
irreversibly anonymise it; anonymised aggregates are not personal information and are not covered
by these periods.

## 12. Your rights in the EEA, the UK and Switzerland

You have the right to:

- **access** the personal data we hold about you and get a copy;
- **rectify** data that is inaccurate or incomplete;
- **erase** it ("right to be forgotten"), where one of the grounds in Article 17 applies;
- **restrict** our processing while a dispute about accuracy or legitimacy is resolved;
- **object** to processing based on legitimate interest, and to direct marketing at any time and
  without giving a reason;
- **data portability** — receive the data you gave us in a structured, machine-readable format,
  and have it sent to another controller where technically feasible;
- **withdraw consent** at any time, without affecting processing already carried out;
- **not be subject** to a decision based solely on automated processing with legal or similarly
  significant effects — as noted in section 6, we make none.

You can also lodge a complaint with the data protection authority of the country where you live
or work. Because we are not established in the EU, there is no single lead authority for us: your
local authority is competent. The list of EEA authorities is published by the European Data
Protection Board at [edpb.europa.eu](https://edpb.europa.eu/about-edpb/about-edpb/members_en); in
the UK it is the Information Commissioner's Office at [ico.org.uk](https://ico.org.uk). We would
rather you came to us first — write to privacy@clodix.ai.

## 13. Your rights in the United States

**California (CCPA/CPRA).** You have the right to know what we collect, use, disclose and sell or
share about you and to receive it in a portable format; to delete it; to correct it; to opt out of
sale and of sharing for cross-context behavioural advertising — we do neither, as stated in
section 4; to limit the use of sensitive personal information — we use it only for the purposes
that the statute permits without a limit right; and not to be discriminated against for
exercising any of these. We run no financial incentive programmes. Under California's "Shine the
Light" law (Civil Code §1798.83), we do not disclose personal information to third parties for
their own direct marketing.

**Other states.** If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana,
Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland,
Indiana, Kentucky or Rhode Island, your state's privacy law gives you rights to confirm and
access your data, correct it, delete it, obtain a portable copy, and opt out of targeted
advertising, of the sale of personal data, and of profiling that produces legal or similarly
significant effects. We do not carry out any of those three activities, so there is nothing to
opt out of; if that ever changes we will publish the mechanism before we start.

**Nevada.** We do not sell covered information as defined by NRS 603A.

**How we handle requests.** We respond within 45 days and may extend once by a further 45 days
where the request is complex, telling you why. We may ask you to verify your identity against the
information already in your account, and we will refuse a request we cannot verify. An authorised
agent may act for you with written permission that we can verify.

**Appeals.** If we refuse your request, you may appeal by replying to our decision within 30 days
or writing to privacy@clodix.ai with "Appeal" in the subject line. We will respond in writing
within 45 days with our decision and reasons. If we deny the appeal you may complain to your
state attorney general.

## 14. Hong Kong

If you are in Hong Kong, the Personal Data (Privacy) Ordinance (Cap. 486) gives you the right to
ask whether we hold data about you, to a copy of it, and to correction of anything inaccurate. We
may charge a reasonable fee for a copy, as the Ordinance permits, and we respond within 40 days.
We do not use your personal data in direct marketing without your consent, and you may withdraw
that consent at any time at no cost. Complaints can be made to the Office of the Privacy
Commissioner for Personal Data at [pcpd.org.hk](https://www.pcpd.org.hk).

## 15. How to exercise your rights

Write to **privacy@clodix.ai** from the email address on your account, and tell us which right
you want to exercise. We do not charge for this unless a request is manifestly unfounded or
excessive, in which case we will tell you the fee before doing the work.

You can also do a lot of it yourself, immediately: edit or delete your brand settings, articles
and connected sites from within the application, disconnect any integration to erase its stored
credentials, close your account from settings, and unsubscribe from marketing email from the link
in any such email.

## 16. Security

We encrypt data in transit with TLS and at rest. Publishing credentials are additionally
encrypted with AES-256-GCM under a key that exists only on the server and is never sent to a
browser. Every account's rows are isolated from every other account's by database row-level
security. Administrative access is limited to the people who need it and is logged. Passwords are
stored hashed by our authentication provider, never in plain text.

No system is perfectly secure. If a personal data breach is likely to result in a risk to your
rights, we will notify the competent supervisory authority within 72 hours of becoming aware of
it and inform you without undue delay where the law requires it. We also comply with US state
breach-notification statutes and with section 3 of the Hong Kong Ordinance.

## 17. Children

Clodix is a business tool. It is not directed to children, and our Terms require you to be at
least 18 to hold an account. We do not knowingly collect personal information from anyone under
18, and we do not knowingly sell or share the personal information of anyone under 16 — we do
neither for anyone. If you believe a child has given us personal information, write to
privacy@clodix.ai and we will delete it promptly. Requests concerning a child under 13 are handled
under the US Children's Online Privacy Protection Act.

## 18. Terms for personal data you put into Clodix

Where you use Clodix to process personal data of your own — customers, readers, contacts — you
are the controller and we are your processor. In that role we:

- process that data only on your documented instructions, which include your use of the product's
  features, unless a law we are subject to requires otherwise, in which case we will tell you
  first unless the law forbids it;
- bind everyone who handles it to confidentiality;
- apply the security measures in section 16;
- use only the subprocessors listed in section 9, under equivalent written terms, and give you
  notice of a new one before it starts processing so you can object;
- help you respond to data subject requests, to security incidents, and to data protection impact
  assessments, taking into account the nature of the processing and the information available to
  us;
- delete or return that data at the end of the service, subject to the retention periods in
  section 11 and to any legal obligation to keep it;
- make available the information you need to demonstrate compliance and allow audits on
  reasonable notice, no more than once a year unless an incident makes another one necessary.

A signed data processing agreement with the EU Standard Contractual Clauses and the UK Addendum
is available on request from privacy@clodix.ai.

## 19. Changes to this policy

We may update this policy. Where a change is material — a new purpose, a new category of
recipient, a materially different retention period — we will announce it by email or in the
application at least **30 days** before it takes effect, and give you the chance to close your
account before it does. Other changes take effect when posted. The date at the top always shows
the version in force, and we keep the previous version available on request.

## 20. Contact

**AQPRO LIMITED**

Room 511, 5/F, Ming Sang Industrial Building, 19–21 Hing Yip Street, Kwun Tong, Hong Kong

Registration number 78622410

- Data rights, privacy questions and complaints: **privacy@clodix.ai**
- Support and billing: **info@clodix.ai**
- Legal notices: **legal@clodix.ai**

## More

- HTML version of this page: https://www.clodix.ai/privacy
- Site brief for agents: https://www.clodix.ai/llms.txt
- [Home](https://www.clodix.ai/index.md) — what the product does, integrations, FAQ
- [Pricing](https://www.clodix.ai/pricing.md) — the plan, the three billing terms and what is included
- [Free SEO Audit](https://www.clodix.ai/free-seo-audit.md) — a free audit of any site: five real competitors, five article ideas with search volume, and the traffic they could add
- [Terms of Service](https://www.clodix.ai/terms.md) — the terms that govern use of the service
- [Refund Policy](https://www.clodix.ai/refund.md) — refund and cancellation terms
