← Back to Clint

Privacy Policy

Last updated: September 26, 2026

1. Who We Are

Clint AI is operated by Henry Raiten and Jesse Raiten (“Clint,” “we,” or “us”) in the United States. This Policy describes how we handle personal information through clint.build, including the website, free plan generator, accounts, builds, chat, hosting, support, billing, and advertising. Contact us at help@clint.build.

This Policy describes our practices; it is not a request for blanket consent. Visiting the website, accepting our Terms, or continuing to use Clint does not by itself give consent to processing for which the law requires a separate choice. Nothing here limits rights or responsibilities that applicable law does not allow us to waive.

2. Information We Collect

  • Accounts and support: name, email address, password hash, session information, preferences, and support communications. Supported external sign-in providers supply the identity information needed for sign-in.
  • Prompts and application content: ideas submitted to the free plan generator, chat messages, attachments, code, project files, database schemas, records, uploads, and other information you submit or cause an application to process. Free-plan requests are processed even without an account.
  • Integration credentials: API keys, OAuth tokens, client secrets, webhook secrets, and other configuration you supply to connect services. Do not put secrets in prompts, public pages, or client-side code.
  • Billing: plan, payment status, customer and subscription identifiers, transaction history, credits, usage, and billing or tax details supplied through checkout. Stripe collects payment-card details through its payment interfaces; Clint does not need your full card number or security code.
  • Build and service records: generated output, versions, deployment identifiers, cost records, errors, logs, and browser-test screenshots or recordings. Test artifacts may contain personal information displayed by the application being tested.
  • Device, visit, and advertising information: IP address, browser and device information, requested URLs, referrers, campaign parameters, approximate location from network headers, session identifiers, advertising click identifiers, and signup or purchase events.

Sources include you, your device, applications you operate, connected services, payment providers, and advertising partners. Provide only information necessary for your request and that you have the right to share.

3. Purposes and Legal Bases

  • Provide accounts, generate plans and applications, make requested edits, connect services, test applications, deploy projects, and provide runtime services.
  • Calculate usage, process payments, maintain billing records, and prevent unauthorized charges or abuse.
  • Answer support requests and send account, security, billing, and service communications.
  • Understand usage, diagnose problems, improve reliability, measure advertising, and send permitted promotional communications.
  • Enforce our Terms, protect people and systems, comply with legal obligations, and establish or defend legal claims.

Where the GDPR, UK GDPR, or another law requires a legal basis, the basis depends on the purpose: contract performance for requested services; legal obligations for required records or disclosures; legitimate interests for proportionate security, support, and administration where not overridden by your rights; and consent where required, including advertising storage or access technologies. Naming a basis here does not replace required consent or other legal safeguards.

Without information necessary for an account, purchase, or build, we may be unable to provide that feature. Advertising choices are separate from information necessary to provide the paid service.

4. First-Party Analytics

First-party session replay reconstructs public landing, pricing, and signup-page interactions to help us understand signup problems. It records page structure, pointer movement, clicks, scrolling, and timing. Rendered text and ordinary form entries are recorded. Passwords, payment fields, embedded media, and marked private sections are excluded. Recording stops on sign-in. Recordings are accessible only to Clint administrators and expire after 14 days. Replay respects Do Not Track and Global Privacy Control. No visitor consent popup is shown for this feature.

Clint records visits, referrers, campaign information, approximate country or region, browser and operating-system information, and a browser-session identifier. Our analytics endpoint derives a daily visitor identifier from a salted hash of the IP address and browser user-agent. This is pseudonymous, not necessarily anonymous. Signed-in analytics events may also include your Clint account identifier.

First-party visit analytics also measure visible time, active time, maximum scroll depth, and click counts. Active time pauses after 30 seconds without interaction, and hidden tabs are excluded. These aggregate measurements do not record form contents, keystrokes, or screen recordings. This first-party tracker skips collection when the browser sends Do Not Track or Global Privacy Control.

The analytics record does not store the raw IP used for that hash, but infrastructure or security logs and advertising conversion requests may separately process IP addresses. URLs and referrers can contain information put into them by you or another service; do not include secrets or sensitive information in URLs.

5. X Advertising and Conversion Measurement

Clint uses the X (formerly Twitter) advertising pixel and server-side Conversion API to attribute visits, signups, and purchases to advertisements and evaluate campaigns. The pixel can receive the page visited, browser or device information, IP address, and advertising identifiers. Where available, server-side events send X a hashed email address, X click identifier, IP address and user-agent, an event or account-linked conversion identifier, event time, and source-page URL. A hashed email is not anonymous: X can use it to match a conversion to information it already holds.

X may combine received information with other information it holds for measurement and advertising under its terms. See X's Privacy Policy. Our conversion integration is not intended to send prompts, application code, database records, passwords, or payment-card details as event fields.

We do not exchange personal information for money. Advertising disclosures of identifiers and online activity may nevertheless constitute a “sale,” “sharing,” or targeted advertising under applicable privacy laws. We do not represent that these disclosures fall outside those laws.

6. Cookies, Storage, and Tracking Choices

  • Authentication cookies: support sign-in and session security. Blocking necessary cookies may prevent account features from working.
  • Local and session storage: hold preferences, draft or pending plans, navigation state, and the analytics session identifier. Some generated applications store authentication or application state in browser storage.
  • Headline testing: a first-party cookie named clint_hero_v1 keeps a browser on the same homepage headline for up to 30 days. We measure which headline was viewed and whether a new account was created using a random browser identifier and a hashed account identifier, without recording form contents. This test does not enroll or measure browsers that send Do Not Track or Global Privacy Control.
  • X click attribution: a visit containing an X click identifier stores it in a cookie named twclid with a maximum age of 90 days. A subsequent qualifying visit may update it.
  • Advertising pixel: X's script may use cookies or similar technologies under X's policies. These are advertising technologies, not necessary authentication storage.

You can delete or restrict cookies and site storage in your browser and review advertising preferences with X. Blocking a browser pixel does not, by itself, stop server-side conversion events. To request that we stop advertising disclosures associated with your account, email help@clint.build.

Current control limitation: the website does not currently provide a site-level advertising consent banner or automated opt-out control, and its tracking code does not automatically act on Do Not Track or Global Privacy Control signals. This notice does not supply missing consent or override a legally effective opt-out. Where prior consent or recognition of a signal is required, Clint must meet that requirement. Browser settings or email requests are not substitutes for required site controls.

7. Providers and Other Recipients

Information is disclosed for the feature or purpose involved. Providers may act as processors or, for some purposes, independent controllers under their own terms.

  • AI providers: supported services include OpenAI, Anthropic, Google, and Z.ai, depending on the feature and configuration. They receive prompts, relevant conversation and project context, code, attachments, and tool results needed for a request. Tool results may include application data retrieved during a requested task.
  • Hosting and storage: Railway, Vercel, Neon, Vercel Blob, and S3-compatible storage providers process website or application files, database records, logs, uploads, and deployment configuration as applicable.
  • Payments: Stripe processes payments and related customer, subscription, transaction, and fraud-prevention information.
  • Communications: SendGrid and Twilio process recipient contact information and message content for email or SMS features that use them.
  • Advertising: X receives the information described in Section 5.
  • Connected services: OAuth and other integrations receive information needed for the operations you request. Their permissions and policies also apply.
  • Support and administration: authorized operators, contractors, and professional advisers may access information needed for support, security, operations, or legal obligations.

We may disclose information when required by law, to investigate fraud or protect rights and safety, or in a genuine business transfer subject to privacy obligations. Public application content can be accessed by other people. Providers may change; Section 15 addresses material changes.

8. AI Processing and Training

Clint does not itself use your private prompts, chat messages, code, or application records to train an AI model. Relevant information is sent to AI providers to generate and edit content, plan builds, and perform requested tasks.

Provider retention, abuse monitoring, and any permitted use for model improvement depend on the provider's terms, endpoint, and account configuration. We do not make a blanket promise that every provider has zero retention, a negotiated enterprise agreement, or identical no-training terms. If you use your own credentials, your provider agreement also matters. Contact us before submitting information requiring a particular processing location, retention limit, or contractual restriction.

9. Generated Applications, Security, and Transfers

Application operators generally determine why their users' information is collected and how it is used. Operators are responsible for accurate notices, lawful processing, required consents, appropriate access controls, and users' requests. Clint generally acts on your instructions for application hosting, database, and runtime processing. We separately determine purposes for Clint accounts, billing, security, and marketing. This does not transfer Clint's own legal duties to application operators.

Where a data-processing agreement or other safeguards are required, they must be in place before that processing. This public Policy is not a substitute for a complete Article 28 agreement or an executed transfer instrument. Contact help@clint.build to discuss requirements before using Clint for that purpose.

Information may be processed in the United States and other countries where configured providers operate. Provider selection affects the countries involved. Where required, an appropriate transfer mechanism and additional safeguards must be established. Using the website alone is not consent to a restricted transfer. We do not claim Clint is certified under the EU-U.S. Data Privacy Framework or that this Policy executes Standard Contractual Clauses.

Clint uses protections such as password hashing, credential encryption, server-side integration endpoints, access checks, and rate limits. No platform or generated application is guaranteed free of vulnerabilities, and automated testing is not a security certification. Review data handling before collecting real user information. Deployment URLs and public-URL uploads may be publicly accessible; an unlisted URL is not necessarily private.

Report security concerns to help@clint.build without sending live secrets. Applicable law determines breach-notification duties. Where Clint is a processor, this includes notifying the relevant controller without undue delay; controller notices to authorities and individuals have separate criteria and deadlines.

10. Privacy Rights and Requests

Depending on location, the information involved, and applicable law, you may have rights to access, correct, delete, or obtain a portable copy of information; restrict or object to processing; withdraw consent; opt out of sale, sharing, targeted advertising, or certain profiling; limit certain sensitive-information uses; request review of significant automated decisions; and complain to a regulator. These rights have legal exceptions, not a blanket waiver through our Terms.

Email help@clint.build with your request and the account or application involved, not your password. We may need proportionate verification for access, correction, or deletion and evidence of an agent's authority. We do not require identity verification for opt-outs where the law prohibits it. We will respond within applicable deadlines, explain denials where required, and provide an applicable appeal route. You may appeal by replying or emailing the same address. We will not unlawfully discriminate against you for exercising a right.

For information held by an application you use, contact its operator first. We can assist as required by our role. Deletion may be limited by recordkeeping obligations, security needs, disputes, or other people's rights. Automated abuse prevention and account restrictions may be reviewed by contacting support; generation itself is not a professional or eligibility determination about you.

11. California and Other U.S. State Notices

Where applicable, state-law information categories include identifiers, account credentials, commercial information, internet activity, approximate location, and submitted content. Sources and purposes appear in Sections 2–5, recipients in Section 7, and retention criteria in Section 13. Account credentials may be sensitive personal information and are used for account access and security.

Identifiers and online activity disclosed to X may fall within definitions of sale, sharing, or targeted advertising. No cash payment is needed for those definitions to apply. We do not knowingly sell or share information of people under 16 for advertising. To opt out or request a limit on qualifying uses of sensitive information, email help@clint.build.

Global Privacy Control is a legally recognized opt-out signal where applicable. Section 6 discloses our current implementation limitation; this Policy does not claim a signal-handling mechanism the website lacks. Required opt-out mechanisms and signal handling remain Clint's responsibility.

12. EEA, UK, Switzerland, and Other Locations

Where the GDPR, UK GDPR, Swiss law, or another privacy law protects you, Section 10 applies as provided by that law. You may object to legitimate-interest processing and direct marketing. Withdrawing consent does not affect earlier lawful processing. You may complain to your competent data-protection authority without first contacting us.

The operators and contact email are in Sections 1 and 16. Contact us about legal bases, recipients, transfer arrangements, or representative information applicable to your request. This Policy does not assert that a local representative has been appointed or that every jurisdiction-specific operational requirement has been completed.

13. Retention and Deletion

Retention depends on purpose and record type: active accounts or projects, restore or backup needs, investigation of errors or disputes, provider arrangements, and legal accounting, security, or recordkeeping duties. We do not promise a single deletion deadline for every system or provider.

  • Project files, databases, chat, and versions support the service and restore features. Deleted items may remain in trash, backups, logs, or external deployments until the relevant process completes.
  • Account, billing, and transaction records may be retained after cancellation for accounting, fraud prevention, disputes, or legal duties. Subscription cancellation is not account deletion.
  • Logs, test artifacts, analytics, and advertising records support their operational or measurement purposes and legal requirements. Providers apply their own retention rules to received information.
  • The first-party X click cookie has a maximum age of 90 days. Browser storage may persist until the session ends, it is cleared, or the feature removes it.

Use available project-deletion controls or contact help@clint.build for account or personal-information deletion. Applicable deadlines and exceptions apply. Copies downloaded by others and services under your own accounts may require separate action with their operators.

14. Children, Sensitive Information, and Marketing

Clint's service is not directed to children under 13, and we do not knowingly collect their personal information. Users at least 13 but below legal majority may use Clint only with a parent or guardian as required by our Terms. Report suspected collection from a child under 13 so we can investigate and take required action.

An app about families or youth sports is not automatically cleared to collect children's data. Application operators must assess applicable requirements before collecting information. Clint retains its own applicable duties; this Policy does not assign all children's privacy duties to you.

Do not submit patient records, government identifiers, raw card details, or other regulated or sensitive information unless appropriate legal, contractual, and technical safeguards have first been established. Creating an app for a regulated sector does not establish those safeguards.

To stop promotional emails, use the message's unsubscribe link or email help@clint.build. Necessary account, security, or billing messages may continue. Advertising measurement choices are separate and described in Sections 5, 6, and 11.

15. Changes

We update the date when revising this Policy. Material changes receive notice appropriate to the change and required by law, such as notice through the service or email. Where new consent is required, publication or continued use does not substitute for obtaining it. A revised notice does not retroactively authorize earlier processing.

16. Contact

Clint AI — operated by Henry Raiten and Jesse Raiten.

For privacy requests, provider or transfer questions, security concerns, or an accessible copy of this Policy, email help@clint.build.