Legal

Privacy Policy

Last updated: August 2026

Alex Omeyer trading as Full Stack Founder ("we", "us", "our") operates clien.ai and any associated subdomains (collectively, the "Services").

Your privacy is important to us. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Services. Please read this policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the Services.

1. Information We Collect

1.1 Information You Provide to Us

Account Information: When you register for an account, we collect your email address and name. If you sign up using Google authentication, we receive your name, email address, and profile picture from Google.

Payment Information: If you subscribe to a paid plan, our payment processor Stripe collects your payment card details. We do not store your full card number—only a reference to your Stripe customer record and the last four digits of your card for display purposes.

User Content: We collect the content you create and input into the Services, including:

  • Project names and descriptions
  • Persona configurations and details
  • Interview questions and conversations
  • Any other data you input into the Services

Communications: If you contact us directly, we may receive additional information about you such as your name, email address, and the contents of your message.

1.2 Information Collected Automatically

Usage Data: We automatically collect certain information when you access the Services, including:

  • Pages and features you access
  • Time spent on pages
  • Actions you take within the Services
  • Referring URLs

Server-side Product Analytics: For signed-in users, we send pseudonymous product-lifecycle events to PostHog's EU service. We associate these events only with your Supabase user ID. We do not send any project, research-job, persona, interview, share-link, payment, Stripe, or other database ID to PostHog. Depending on the action, an event may contain your sign-up provider; booleans; counts; duration ranges; credit costs; or controlled source, origin, outcome, plan, pack, term, and action labels. These events do not contain your name, email address, User Content, research or interview content, file contents, URLs, share tokens, payment identifiers, or authentication tokens. This server-side processing does not set a cookie and takes place independently of your browser cookie choice.

Consent-based Browser Analytics: If you accept analytics in our cookie banner, PostHog also receives page-view and page-leave events, redacted page paths and referring URLs, and technical fields added by its browser SDK (such as browser, operating-system, device, session, and library information). For signed-in users, we associate this stream with the same Supabase user ID. We disable automatic click collection, dead-click collection, session replay, and console recording. The browser SDK uses memory-only storage, so Clien.ai does not set a PostHog cookie or retain a PostHog browser identifier in local or session storage.

Device and Browser Information: We may collect information about your device, including IP address, browser type, operating system, and device identifiers.

Cookies and Similar Technologies: We use cookies and similar tracking technologies to collect information. See our Cookies Policy for more details.

2. How We Use Your Information

We use the information we collect to:

  • Provide the Services: Create and manage your account, process your transactions, and deliver the features you request
  • Improve the Services: Analyse usage patterns, diagnose technical issues, and develop new features
  • Communicate with You: Send service-related emails, respond to your enquiries, and provide customer support
  • Process Payments: Handle billing, invoicing, and subscription management
  • Ensure Security: Detect, prevent, and respond to fraud, abuse, or security incidents
  • Comply with Legal Obligations: Meet our legal and regulatory requirements

3. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

3.1 Service Providers

We share information with third-party service providers who perform services on our behalf:

ProviderPurposeData Shared
AnthropicAI persona generation and interviews (Claude)User Content for inference
GoogleAI image generation (Gemini), authenticationUser Content for inference, auth data
StripePayment processingPayment and billing information
SupabaseDatabase hosting and authenticationAll account and user data
VercelApplication hostingRequest logs, IP addresses
PostHogPseudonymous product analytics (EU service)Supabase user ID; minimized server-event fields; and, with browser consent, redacted page/referrer URLs plus browser-SDK technical fields described in Section 1.2
ResendTransactional emailEmail address, email content
ExaWeb search and retrieval for market, competitor, and audience research (US processor)Search query terms derived from your product idea (market, competitor, and role/market audience queries) — not the names or profiles of specific individuals

Exa: When we run market, competitor, and audience research for your validation reports, we send search query terms derived from your User Content to Exa (exa.ai), a US-based search provider. These query terms describe your product idea, its competitors and market, and — for audience research — the typical roles, seniority, and archetypes of the people who might use your product (for example, "the typical roles and seniority of people who would use a product for [your idea]"). The query terms we send to Exa are descriptions of roles and markets; they are not the names, dossiers, or profiles of specific individuals.

For audience research, Exa returns professional-profile data from its own index. Before that data is used, we reduce it to anonymous, count-only statistics within our own systems: we require at least ten profiles behind any figure we derive, keep only aggregate distributions (such as the mix of seniority levels across an audience), and never store or display anything that identifies a specific individual. We do not build or retain profiles of named people, and we do not use this data to contact anyone.

Unlike our AI inference providers (see Section 4.2), Exa may use the query terms we send it to improve and train its own models. Exa processes these query terms under its own privacy policy.

3.2 Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities.

3.3 Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

3.4 With Your Consent

We may share your information for other purposes with your explicit consent.

4. AI Data Processing

4.1 How AI Processes Your Data

When you use the Services, your User Content (including project details, persona configurations, and interview conversations) is sent to third-party AI providers (Anthropic and Google) for processing via their APIs.

4.2 No Training on Your Data

Your data is not used to train AI models. Both Anthropic and Google have committed to not using data submitted via their APIs for model training:

4.3 Data Retention by AI Providers

AI providers may temporarily retain data for abuse prevention and operational purposes:

  • Anthropic: May retain API inputs for up to 30 days for trust and safety purposes
  • Google: Retention periods vary; see their documentation for current policies

We encourage you to review the privacy policies of our AI providers for the most up-to-date information.

5. Data Security

We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit (TLS/HTTPS)
  • Encryption of data at rest
  • Secure authentication mechanisms
  • Regular security assessments
  • Access controls and authentication for our systems

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.

6. Data Retention

We retain your personal information for as long as necessary to:

  • Provide the Services to you
  • Comply with our legal obligations
  • Resolve disputes
  • Enforce our agreements

Account Data: Retained while your account is active and for a reasonable period thereafter to allow for reactivation.

User Content: Retained while your account is active. Upon account deletion, User Content is deleted within 60 days.

Product Analytics: PostHog events that remain linked to your Supabase user ID are retained for 12 months. We then delete them or convert them into aggregated data that no longer identifies you.

Payment Records: Retained as required by tax and accounting regulations (typically 7 years).

Shared Report Links: A validation report can have one standing “anyone with the link” share link. So that you can copy that link again at any time, we store it in a reusable form — not as a one-way hash. Anyone who obtains the link, including through a breach of our database, can read that report without signing in, so treat a share link like a password. The link does not expire; revoking it takes effect immediately and it can no longer be opened, and creating a new one issues a different link that replaces it. Links are deleted when the report is deleted or upon account deletion.

For each share link we also keep a server-side log of views and source-link clicks. These records are personal data about the people you share a report with. We use them only to measure whether shared reports are opened and read, and we retain them for as long as the report exists — they are deleted when the report is deleted or upon account deletion. We do not use them to identify individual recipients or build profiles.

Share links created before August 2026 worked differently: they were addressed to a named recipient, expired automatically, and were stored only as a one-way hash. Where any of those older links still exist, we still hold that recipient label and its hash, and we still cannot recover the link itself.

7. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States, where our service providers are located.

When we transfer personal data outside the UK/EEA, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Transfers to countries with adequate data protection laws
  • Certification mechanisms such as the EU-US Data Privacy Framework

8. Your Rights

Depending on your location, you may have the following rights regarding your personal information:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request that we correct inaccurate or incomplete information.
  • Deletion: Request that we delete your personal information, subject to certain exceptions.
  • Portability: Request a copy of your data in a structured, machine-readable format.
  • Objection: Object to our processing of your personal information in certain circumstances.
  • Restriction: Request that we restrict processing of your personal information.
  • Withdraw Consent: Where processing is based on consent, withdraw that consent at any time.

To exercise any of these rights, please contact us at alex@fullstackfounder.ai. We will respond to your request within 30 days.

If you object by email to our legitimate-interests product analytics, we will suppress future non-essential server-side analytics for your account. This does not delete or stop us keeping records needed to provide the Services or meet contractual, accounting, security, or legal obligations.

If you are in the UK or EEA, you also have the right to lodge a complaint with your local data protection authority. In the UK, this is the Information Commissioner's Office (ICO) at ico.org.uk.

9. Children's Privacy

The Services are not intended for individuals under the age of 16. We do not knowingly collect personal information from children under 16. If you become aware that a child has provided us with personal information, please contact us at alex@fullstackfounder.ai, and we will take steps to delete such information.

10. Third-Party Links

The Services may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party sites you visit.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Effective" date. Your continued use of the Services after any changes indicates your acceptance of the updated Privacy Policy.

12. Contact Us

If you have any questions, concerns, or complaints about this Privacy Policy or our data practices, please contact us:

Email: alex@fullstackfounder.ai

Alex Omeyer trading as Full Stack Founder
United Kingdom

We will endeavour to respond to your enquiry within 30 days.

13. Legal Basis for Processing (UK/EEA Users)

If you are located in the UK or European Economic Area, we process your personal data on the following legal bases:

PurposeLegal Basis
Providing the Services and delivering creditsPerformance of contract
Processing paymentsPerformance of contract
Sending service communicationsPerformance of contract
Improving the ServicesLegitimate interests
Pseudonymous product-improvement analyticsLegitimate interests
Browser page-view and page-leave analyticsConsent
Security and fraud preventionLegitimate interests
Marketing (with consent)Consent
Legal complianceLegal obligation

You may object to processing based on legitimate interests by contacting us. An objection to non-essential product analytics does not prevent you from using the Services; we will suppress future server-side analytics for your account while keeping contractual, accounting, security, and legal records where required.