Last Updated: September 29, 2026 Effective Date: September 29, 2026
This Privacy Policy explains how Clone Holdings, Inc. ("Clone Holdings," "we," "our," or "us"), the developer and operator of Clone.Me (also referred to as Clone Studio, Clone.org CloneForce, and the Clone.Me platform), collects, accesses, uses, stores, shares, protects, retains, and deletes information when you use our website at https://clone.me, our web application at https://studio.cloneforce.com, and related applications, integrations, and services (collectively, the "Services").
Clone.Me is an agentic AI platform that lets individuals and organizations create AI digital teammates ("Clones") that perform work on the user's behalf — for example, reading and drafting email, managing calendar events, organizing files, preparing documents, joining meetings, and automating workflows across the business tools the user chooses to connect.
Section 5 ("Google User Data") specifically describes how Clone.Me handles data received from Google APIs. If you connect a Google Account, Section 5 controls over any more general statement in this policy.
────────────────────────────────────────
1. Scope of This Policy
This policy applies to personal information we process as a controller when you visit our website, create an account, connect third-party services, or use Clone.Me.
When an organization (such as your employer) purchases Clone.Me and administers your account, we may process data on that organization's behalf under our customer agreement. In those cases the organization's own privacy practices also apply. Regardless of who administers your account, Google user data is always handled in accordance with Section 5 of this policy.
────────────────────────────────────────
2. Information We Collect
2.1 Information You Provide
- Account information: name, email address, company, job title, password or single sign-on credentials, and billing details (payment card data is processed by our payment processor; we do not store full card numbers).
- Clone configuration: the name, role, instructions, persona, and preferences you set for your Clones.
- User content: prompts, messages, files, documents, images, audio, and other material you upload or submit to the Services.
- Likeness and voice materials (optional): if you choose to create a Clone that uses your appearance or voice, the photos, video, and voice recordings you provide for that purpose (see Section 6).
- Communications: information you provide when you contact support, book a demo, respond to surveys, or attend events.
- Phone numbers: if you provide a mobile number, we use it only for service-related messages you request or that relate to your use of the Services.
2.2 Information Collected Automatically
- Log and device data: IP address, browser type, operating system, device identifiers, time zone, and dates/times of access.
- Usage data: features used, actions taken, and performance and error diagnostics.
- Approximate location: derived from IP address for security (for example, detecting unusual sign-ins) and to set time zones.
- Cookies and similar technologies: used to keep you signed in, remember preferences, secure the Services, and understand website traffic. You can control cookies through your browser settings.
2.3 Information From Connected Third-Party Services
When you choose to connect a third-party service (such as Google, Microsoft, Salesforce, Slack, HubSpot, Zendesk, or others), we access only the data needed for the features you enable, using the permissions you grant on that service's authorization screen. Google data is described in detail in Section 5.
────────────────────────────────────────
3. How We Use Information
We use information to:
- Provide, operate, and maintain the Services, including performing the tasks you direct your Clones to perform;
- Authenticate you and secure your account;
- Personalize your own Clones using the knowledge, preferences, and context you provide;
- Provide customer support and respond to your requests;
- Send service, security, billing, and administrative communications;
- Send product updates and marketing communications (you may opt out at any time; Google user data is never used for marketing);
- Monitor, investigate, and prevent fraud, abuse, security incidents, and violations of our terms;
- Improve the reliability, performance, and usability of the Services using aggregated or de-identified operational metrics; and
- Comply with legal obligations and enforce our agreements.
We do not sell personal information. We do not use personal information for cross-context behavioral advertising or targeted advertising.
AI model training. We do not use your user content, or any data from connected third-party services, to train or improve generalized, foundational, or non-personalized AI or machine-learning models. Clone.Me uses third-party large language model providers under agreements that prohibit those providers from using data we send to train their models. Google user data is subject to the additional restrictions in Section 5.
────────────────────────────────────────
4. How We Share Information
We share information only as described below:
- Service providers (subprocessors): hosting and cloud infrastructure, AI model inference providers, customer support, email delivery, payment processing, and security vendors that process data only on our instructions, under confidentiality and data protection obligations, and only as needed to provide the Services.
- At your direction: when you instruct a Clone to send an email, share a file, post a message, or connect to another application, we transmit the relevant information to the recipient or service you designate.
- Your organization: if your account is administered by an organization, its authorized administrators may access account information and usage logs as permitted by our customer agreement.
- Legal and safety: when required by law, subpoena, or court order, or when necessary to protect the rights, safety, or security of our users, the public, or Clone Holdings, or to investigate abuse.
- Business transfers: in connection with a merger, acquisition, or sale of assets, subject to Section 5.6 for Google user data.
We do not sell, rent, or trade personal information, and we do not share it with advertising networks, data brokers, or information resellers.
────────────────────────────────────────
5. Google User Data
This section describes how Clone.Me accesses, uses, stores, shares, protects, retains, and deletes data received from Google APIs ("Google user data"). Clone.Me only accesses Google user data after you sign in with Google or choose to connect a Google Account and explicitly grant permission on Google's consent screen. You can choose which Google services to connect, and you can disconnect at any time.
5.1 Limited Use Disclosure
Clone.Me's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Clone.Me's use of information received from Google Workspace APIs also adheres to the Google Workspace API User Data and Developer Policy.
5.2 Google User Data We Access
We request only the permissions ("scopes") needed for the features you choose to use. Depending on which features you enable, Clone.Me may access:
Google Sign-In (Basic Profile)
Data Accessed: Name, email address, profile picture
Why Clone.Me Accesses It: To create and sign in to your Clone.Me account and display your identity in the app.
Gmail
Data Accessed: Email messages, threads, labels, attachments, and metadata; ability to compose, send, draft, and label messages
Why Clone.Me Accesses It: So your Clone can search, read, summarize, and triage your email, draft and send replies you request, and organize your inbox.
Google Calendar
Data Accessed: Calendars, events, attendees, availability, and conferencing links
Why Clone.Me Accesses It: So your Clone can show your schedule, check availability, book, update, or cancel meetings you request, and prepare meeting briefings.
Google Drive
Data Accessed: Files and folders and their metadata and sharing permissions
Why Clone.Me Accesses It: So your Clone can find, read, upload, organize, and share files you direct it to work with.
Google Docs, Sheets, Slides, and Forms
Data Accessed: Document, spreadsheet, presentation, and form content and form responses
Why Clone.Me Accesses It: So your Clone can read, create, and edit documents, spreadsheets, presentations, and forms at your request.
Google Meet
Data Accessed: Meeting spaces, participant lists, recordings, transcripts, and meeting artifacts
Why Clone.Me Accesses It: So your Clone can create meetings, attend meetings you invite it to, and generate summaries, notes, and action items for you.
YouTube
Data Accessed: Channel information, video metadata, playlists, comments, and analytics; ability to upload or update videos
Why Clone.Me Accesses It: So your Clone can manage your channel, upload videos you create, and report on your channel's performance.
We do not request access to Google services you have not chosen to connect, and we do not request permissions for features that are not yet available.
5.3 How We Use Google User Data
We use Google user data only to provide and improve the user-facing features that are visible and prominent in the Clone.Me interface and that you have requested, as described in the table above. Specifically:
- Google user data is used to perform actions you initiate or authorize (for example, "summarize my unread email," "schedule a meeting with Sarah," or "create a report in Google Docs").
- Google user data may be processed by an AI model solely to generate the output you requested, in real time, within your own account.
- Google user data may be stored in your private, account-scoped knowledge and memory so your own Clone can use that context for you. This personalized context is isolated to your account (or your organization's tenant) and is never combined with other users' or organizations' data.
We do not:
- Use Google user data to develop, improve, or train generalized, foundational, or non-personalized AI or machine-learning models, and we do not store Google user data in conjunction with any such model;
- Transfer Google user data to any AI model provider for the purpose of training that provider's models;
- Use Google user data for advertising, including targeted, personalized, retargeted, or interest-based advertising;
- Sell Google user data, or transfer it to advertising platforms, data brokers, or information resellers;
- Use Google user data to determine creditworthiness or for lending purposes;
- Use Google user data to create databases or profiles unrelated to the features you requested, or for surveillance;
- Use Google user data to create, edit, or distribute sexually explicit, intimate, or non-consensual imagery of any person, or any synthetic ("deepfake") depiction of a person (see Section 6).
5.4 How We Store Google User Data
- Google user data is stored on secured cloud infrastructure located in the United States.
- OAuth access tokens and refresh tokens are encrypted at rest and stored separately from other data. Encryption keys are managed in a dedicated cloud key management system.
- Google user data stored for your account (such as knowledge files or conversation context you have asked your Clone to retain) is encrypted at rest and logically isolated to your account or your organization's tenant.
- Data retrieved only to complete a single task is held only as long as necessary to complete that task.
5.5 Human Access to Google User Data
Clone Holdings personnel do not read your Google user data, except:
- With your explicit, documented permission for specific messages, files, or data (for example, when you ask our support team to troubleshoot a particular item);
- When necessary for security purposes, such as investigating a bug, abuse, or a security incident;
- When necessary to comply with applicable law; or
- When the data (including derivations) has been aggregated and anonymized and is used for internal operations in accordance with applicable law.
Access is limited to authorized personnel on a need-to-know basis and is logged.
5.6 How We Share, Transfer, or Disclose Google User Data
We do not share, transfer, or disclose Google user data to third parties except:
- To provide the user-facing features you request, with your consent — for example, sending an email you asked your Clone to send, or transmitting content to an AI inference provider solely to generate the response you requested. Such providers act as our subprocessors, are contractually prohibited from using the data for any other purpose (including model training), and must protect it at least as strictly as this policy requires;
- For security purposes, such as investigating abuse or a security incident;
- To comply with applicable law, regulation, legal process, or enforceable government request; or
- As part of a merger, acquisition, or sale of assets of Clone Holdings, only after obtaining your explicit prior consent.
Non-public Google user data is never exposed to other users or third parties without your explicit opt-in consent. Our employees, agents, contractors, and successors are required to comply with the Google API Services User Data Policy.
5.7 How We Protect Google User Data
We implement administrative, technical, and physical safeguards designed to protect Google user data against unauthorized or unlawful access, use, alteration, loss, destruction, or disclosure, including:
- Encryption of all data in transit using TLS (HTTPS) and encryption of data at rest using industry-standard encryption (AES-256 or equivalent);
- Encryption of OAuth tokens at rest and management of keys in a dedicated key management system;
- Tenant isolation, role-based access controls, single sign-on, and least-privilege access for personnel;
- Audit logging of access to systems that process Google user data;
- Protections against prompt injection and other AI-specific attacks on tools and agents that act on Google data;
- Requiring your confirmation before a Clone takes sensitive actions on your behalf where appropriate;
- Vulnerability management, security testing, and ongoing monitoring; and
- A security program aligned with SOC 2 (Type II audit in progress) and, where required, completion of Google's Cloud Application Security Assessment (CASA).
If we become aware of unauthorized access to Google user data, we will notify affected users and Google as required by law and Google's policies.
5.8 Retention and Deletion of Google User Data
- We retain Google user data only as long as needed to provide the features you have requested.
- Disconnecting Google: You can disconnect your Google Account at any time in Clone.Me account settings. When you do, we immediately stop accessing your Google data, revoke and delete the associated OAuth tokens, and delete Google user data we have stored for that connection within 30 days, except data you have explicitly saved into your Clone's knowledge base, which you can delete separately at any time.
- Revoking through Google: You can also revoke Clone.Me's access at any time at https://myaccount.google.com/permissions. We treat revocation the same as disconnecting.
- Deleting your account: If you delete your Clone.Me account, we delete your Google user data and associated personal data within 30 days. Residual copies in encrypted backups are overwritten within 90 days.
- Requesting deletion: You can request deletion of your Google user data at any time by emailing support@clone.me. We will confirm deletion once complete.
- We may retain limited information longer only where required by law or to resolve disputes, in which case it remains protected by this policy and is deleted when no longer required.
5.9 Your Controls
- Choose which Google services to connect and grant only the permissions you want.
- Review, export, or delete content stored in your Clone's knowledge and memory at any time.
- Disconnect Google in account settings or at https://myaccount.google.com/permissions.
- Export your data by contacting support@clone.me; we will provide it in a commonly used, machine-readable format.
────────────────────────────────────────
6. Digital Likeness, Voice, and Responsible AI
Some Clone.Me features let you create a Clone that uses your own appearance (avatar image or video) or your own voice.
- Consent-based only. You may only create a likeness or voice Clone of yourself, or of another person who has given you express, documented permission. We may require verification.
- Biometric information. Photos, video, and voice recordings you provide for likeness or voice features may be considered biometric information under some laws. We use them solely to generate the likeness or voice Clone you requested, do not sell them, do not use them for identification or surveillance, and delete them within 30 days after you delete the likeness/voice Clone or your account, or earlier if required by law.
- Prohibited content. Clone.Me strictly prohibits using the Services to create, edit, or distribute sexually explicit or intimate imagery of any person, non-consensual intimate imagery (NCII) — including AI-generated or synthetic "deepfake" imagery — child sexual abuse material, or deceptive impersonations of any person. We use automated safeguards and human review to prevent and respond to such misuse, remove violating content, terminate violating accounts, and report illegal content to authorities where required.
- Google APIs are never used for these purposes. Clone.Me does not use any Google API or Google user data to generate, edit, store, or distribute AI-generated intimate imagery, NCII, or synthetic depictions of real people.
- Reporting. To report misuse of your likeness or suspected NCII, email support@clone.me with the subject line "Likeness Report." We prioritize and act on these reports promptly.
────────────────────────────────────────
7. Data Retention (General)
Apart from the specific periods in Sections 5.8 and 6, we retain personal information only as long as necessary for the purposes described in this policy — for example, for as long as your account is active and as needed to provide the Services — and as needed to comply with legal obligations, resolve disputes, and enforce our agreements. When information is no longer needed, we delete or de-identify it.
────────────────────────────────────────
8. Security (General)
We protect all personal information using the safeguards described in Section 5.7, including encryption in transit and at rest, access controls, and monitoring. No method of transmission or storage is completely secure, but we work continuously to protect your information and to notify you of any breach as required by law.
────────────────────────────────────────
9. Your Privacy Rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you and receive a portable copy;
- Correct inaccurate personal information;
- Delete your personal information;
- Restrict or object to certain processing;
- Withdraw consent at any time, where processing is based on consent;
- Opt out of marketing communications; and
- Appeal a decision we make about your request, and lodge a complaint with your data protection authority.
To exercise these rights, email support@clone.me. We will verify your identity before completing requests and will not discriminate against you for exercising your rights. You may use an authorized agent, who must provide signed written permission.
U.S. state privacy disclosures: In the past 12 months we have collected identifiers, account and commercial information, internet and network activity, approximate geolocation, user content, and (only if you choose likeness or voice features) biometric information, for the purposes described in Section 3, and disclosed them to the categories of recipients in Section 4. We do not sell or "share" personal information (as those terms are defined under California law) and do not use sensitive personal information to infer characteristics about you.
International users: We are based in the United States and process data in the United States. Where required, we transfer personal information using legally recognized transfer mechanisms, such as Standard Contractual Clauses.
────────────────────────────────────────
10. Children's Privacy
Clone.Me is a business productivity service and is not directed to children. We do not knowingly collect personal information from children under 13 (or under 16 where required by local law), and users must be at least 18 years old to create an account. If you believe a child has provided us personal information, contact support@clone.me and we will delete it.
────────────────────────────────────────
11. Third-Party Services
When you connect third-party services or direct a Clone to share information with others, those parties' own terms and privacy policies govern their handling of the information. We encourage you to review them. Clone.Me is not affiliated with, endorsed by, or sponsored by Google or any other third-party service we integrate with.
────────────────────────────────────────
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page with a new "Last Updated" date and, for material changes, notify you by email or in the app. If we change how Clone.Me uses Google user data, we will notify you and obtain your consent before using your Google user data in a new way or for a new purpose.
────────────────────────────────────────
13. Contact Us
Clone Holdings, Inc. Developer of Clone.Me - Email: support@clone.me - Website: https://clone.me
────────────────────────────────────────