Privacy Policy
Last updated: 27 August 2026
This policy explains what we collect when you use Cleonhill, why we collect it, and the choices you have. We keep it plain so you can actually read it.
1. Who we are
Cleonhill is operated by Cleonhill Proprietary Limited, a private company registered in Botswana and based in Gaborone. For data protection law we are the responsible party under Botswana's Data Protection Act, and we aim to meet GDPR standards for users in the EU and UK. You can reach us at [email protected].
2. What this policy covers
This covers the Cleonhill website and the builder you use to create WhatsApp bots. It does not cover the bots you build and run yourself once they are exported, or the third-party services you choose to connect them to. Those run under their own terms.
3. Information we collect
- Account details, such as your email address, handled through our auth provider. Building requires an account.
- The prompts and messages you send to the builder, and the bot code the AI generates in response.
- Build activity and logs we use to keep the service working and to improve it.
- Your credit balance and usage.
- API keys you paste to connect a third-party service to your bot. These are stored so your bot can run, and are never shown to the AI model or printed in the chat.
- Basic technical data such as IP address and browser type.
4. How we use your information
- To run the builder, which includes sending your prompt and the current state of your bot to our AI model provider so it can write and test your bot.
- To store and show your projects.
- To meter credits and prevent abuse of the service.
- To keep the platform secure and to fix problems.
- To improve the product, using activity data.
- To meet our legal obligations.
5. The AI model
Building a bot means sending your prompt and build context to our AI provider, OpenRouter, which routes it to one of several AI models, so it can generate and fix your code. We do not sell your data and we do not use it to train third-party AI models. Please do not paste passwords or sensitive personal data into the chat that you would not want processed by an AI model.
6. Who we share data with
We share only what each provider needs to run the platform:
- Supabase, for accounts, database, and file storage.
- OpenRouter, for the AI model that builds your bot.
- OpenSandbox, which runs generated bots during a build so you can test them.
- Network and hosting providers that deliver the site.
- Legal authorities, where the law requires it.
- A successor, if the business or its assets are transferred.
7. Keys for connected services
When you connect a third-party service to your bot by pasting an API key, we store that key so your bot can use it, and inject it into your bot at runtime. It is never sent to the AI model and never displayed back in the chat. You can remove a connected key at any time.
8. International transfers
Some of the providers above operate outside your country. Where data crosses borders we rely on lawful transfer safeguards and standard contractual clauses.
9. Your rights
You can ask to access, correct, delete, or export your data, object to a use, or withdraw consent. Email [email protected] and we will respond within 30 days. You also have the right to complain to your data protection regulator.
10. How long we keep it
We keep your projects and their build logs while your account is active, and delete them on request. Projects are removed after a long period of inactivity. Credit and billing records are kept as long as we need them for accounting.
11. Security
We encrypt data in transit, restrict access to it, keep our application tables off the public data API, and never send your secrets to the AI model. No system is perfectly secure, so we cannot promise absolute protection, but we work to keep your data safe.
12. Cookies
We use cookies only to sign you in and keep you signed in: a session cookie and a refresh cookie once you sign in, plus two short-lived ones that confirm a sign-in started in the same browser that finished it — one during e-mail confirmation, one during Google sign-in. They are all necessary for the service to work. Nothing is set until you begin signing up or signing in, we do not use advertising cookies, and we do not sell tracking data.
13. Children
Cleonhill is not directed at people under 18. If we learn we have collected data from a child, we delete it.
14. Changes to this policy
If we make a material change we will post the new version here and update the date above. Continued use after a change means you accept it.
15. Photography and attribution
The business photographs on our site are provided by their photographers through Unsplash and used under the Unsplash License.
16. Contact
Questions about this policy or your data can go to [email protected].