Privacy Policy
Last updated: October 2026
1. Data Controller
Clonique d.o.o. is the data controller for your personal data. We are committed to protecting your privacy in compliance with the EU General Data Protection Regulation (GDPR).
Contact: dpo@clonique.ai
2. What Data We Collect
We collect the following categories of data:
- Account information (email, display name)
- Chat exports you voluntarily upload
- AI-generated personality profiles derived from your chats
- Conversations with AI clones
- Anonymous daily usage counts (for example how many clones were made or messages sent in a day, and whether the app is opened again a day, a week or a month after it was first opened): only the name of the event and a number are sent, with no account, name, content or device identifier, and the date of first opening is not sent with them. They can be turned off in Settings (Anonymous statistics).
- The number of messages and the cost of AI model calls this month and last, so the plan holds even after the app's data is deleted: kept with your account when you are signed in, otherwise with a random install id and a hash of your IP address; no message text, and older months are deleted
- Sign-in and code attempts (the email address typed and the IP address) for 30 days, to stop password guessing
- App preferences, on the device and, in the web app, in the encrypted copy on the server
- Invoices for paid plans (number, amount, plan, date and the email the invoice went to), for 11 years, as Croatian accounting law requires
- Reports of a clone’s reply: when you report a reply, that reply (for a photo or voice message only its name), the reason you pick and the app’s language are sent, with your account if you are signed in; they are kept for at most 90 days
- Our web server’s access logs (IP address, time, the address requested and the browser) for at most 15 days, for security and fixing faults
3. How We Process Chat Data
Chat exports are read and analysed on your device to build personality profiles for AI clones. In the web app, an encrypted copy of everything the app keeps (clones, conversations, settings) is also held on our server, because a browser can delete a site's data by itself (Safari after seven days without a visit); the copy is encrypted with your device's key, which the server does not store: it sits in your browser's cookie, so the copy can be opened only during a request from your browser. On the device itself the key is kept apart from the data only in the mobile app, in the system's secure storage (iOS Keychain, Android Keystore); in the browser it sits in the site's data, beside what it opens. So the encryption protects the copy on the server and, on a phone, a copy of the app's files, but not against someone with access to your unlocked device. The Android app makes no backup to Google's cloud and no transfer to a new phone, because the key cannot go with them. On plans that remember the whole chat, so that a clone can remember old conversations, the conversation is also kept on our server, in passages encrypted (AES-GCM) with a key from your device that is sent with each request; the server does not store it and can open the passages only during a request from your device. For search by meaning, the passages are sent through OpenRouter to embedding model providers (Nebius, DeepInfra, Voyage AI) that do not train on what they are sent, and their vectors stay on the server, unencrypted: they are not text, but what a passage is about can partly be inferred from them. The server also knows the clone’s name and the hours the person used to write, so the clone can write first and send a notification. To generate replies, parts of the conversation are sent to AI model providers through OpenRouter (OpenAI; Anthropic only to read the export or the description, when a clone is made or read again) over an encrypted connection (TLS); these providers are outside the EU (USA), and only providers that do not train on what they are sent are used. Data on the device is encrypted with AES-GCM, using a key created on the device that reaches the server only with the copy, and the server does not store it; this protects files and backups, but not an unlocked device. Photos, videos, GIFs, stickers and voice messages from an export with media (only those sent by the person the clone is of) are kept encrypted on your device only; the files themselves are not sent to our server, to the encrypted copy or to AI model providers. Only their list (kind, date, file name and size, and the words written around them in the chat) goes into the encrypted copy, and AI model providers get those words when the clone decides whether to send one of them. Before keeping them, the app checks on your device whether photos, videos, GIFs and stickers look sexual (a small image recognition model loaded from our server that runs only in your browser); those that do are not kept, and the clone never sends one that has not been checked yet. The check is not perfect. We do not use your chat data to train general-purpose AI models. Deleting a clone or all data also deletes the data on the server. Payments for paid plans are handled by Stripe (only Stripe sees your card details, we do not), invoices are issued by Invoxs, which fiscalises them with the Croatian Tax Administration and emails them to you (Invoxs receives that email address, the amount and the plan), and emails (address confirmation, password reset and reported replies to us) are sent by Resend; Stripe and Resend may process data in the USA.
4. Purposes and legal bases
We process data only for these purposes, each on one legal basis under the GDPR:
- Making a clone and chatting with it (the export, the personality profile, the conversations, the memory, the messages a clone writes first and sending to AI model providers): your explicit consent (Art. 6(1)(a), and for special categories of data a chat may hold, such as health, Art. 9(2)(a)). You give it when you import a chat and withdraw it by deleting the clone or all data.
- The web app’s encrypted copy, the account, sign-in, the plan and the message count that limits it: performance of the contract (Art. 6(1)(b)). Without an account, that count is kept with an install ID and a hash of the IP address, on our legitimate interest (Art. 6(1)(f)) in keeping the free plan from being abused.
- Invoices: a legal obligation (Art. 6(1)(c)).
- Sign-in attempts, limits per IP address and the server’s access logs: our legitimate interest (Art. 6(1)(f)) in a secure service and secure accounts.
- Reports of a clone’s replies: our legitimate interest (Art. 6(1)(f)) in seeing and fixing wrong or harmful replies.
- The anonymous daily usage counts are tied to no one, so they are not personal data.
Transfers of data to the USA rest on the European Commission’s standard contractual clauses (Art. 46) in the data processing agreement with OpenRouter, through which every AI model call goes, and for Stripe, Resend and Google on the EU-US Data Privacy Framework (Art. 45), under which they are certified.
5. People whose messages you import
A chat export also holds the messages of the person whose clone you make, and in a group chat those of the others in it. Those messages and the name you type are processed only so the clone can write like that person: on your device, in the encrypted copy and the memory on the server, and by the AI model providers, as described above; that person’s photos and voice messages from an export with media stay encrypted on your device only. None of it is used for any other purpose or to train models, and it is deleted with the clone. The legal basis is the legitimate interest (Art. 6(1)(f)) of the person making the clone in keeping a conversation with someone close. The messages of someone who has died are treated the same way.
Import only a chat you took part in and may share; if the person is alive, tell them. If you think someone has imported a chat with you, write to dpo@clonique.ai. We cannot see what a clone holds, because it is encrypted with a key from the device, so we delete from the server what we can link to you (such as a clone’s name); a clone on someone’s device is out of our reach.
6. Your Rights
Under GDPR, you have the following rights:
- Right of access (Art. 15): Request a copy of your data
- Right to rectification (Art. 16): Correct inaccurate data
- Right to erasure (Art. 17): Delete your data permanently
- Right to data portability (Art. 20): Export your data
- Right to restriction (Art. 18): Ask us only to keep your data
- Right to object (Art. 21): Object to processing based on legitimate interest
- Right to withdraw consent at any time
To exercise these rights, contact dpo@clonique.ai or use the in-app deletion features.
7. Data Retention
A clone's data (conversations, personality profile, chat export) is kept on the device as long as the clone exists. The encrypted copy in the web app (see above) changes along with the device; the server deletes it when you delete all data, and by itself when the browser has not asked for it for 400 days (until then the browser's cookie can bring it back). On a plan that remembers the whole conversation, the conversation is also on the server in passages for memory; the server deletes them when the plan goes back to Basic. When nobody has used a clone for a year, the server archives it: the encrypted passages stay, and search by meaning comes back when the device returns. When you delete a clone or all data, it is gone from the device at once, the clone's photos and voice messages with it, and from the server as soon as the device is online. The server's database is copied every night; those copies are kept for seven days, and copies made before a change to the server for three, so what you delete is gone from them at the latest seven days later. When you delete your account, the account, subscription and sign-in data are deleted; a paid plan, Memorial included, ends, clones go back to Basic (the last 200 exchanges) and their memory passages are deleted from the server. Payment invoices are kept for 11 years, as Croatian accounting law requires. Reports of a clone’s reply are kept for at most 90 days. The server’s access logs are deleted after at most 15 days. Clones on the device do not depend on the account; you delete them in Settings (Delete all data).
8. Contact DPO
Our Data Protection Officer can be reached at:
Email: dpo@clonique.ai
Address: Clonique d.o.o., Zagreb, Croatia
You also have the right to lodge a complaint with your local data protection authority.
9. Cookies and browser storage
The web app uses one cookie, cq_backup. Our server sets it, your browser sends it only to the address of the encrypted copy (/api/backup), scripts on the page cannot read it, and it lasts 400 days from its last use. It carries the key that opens the encrypted copy of your data (see above), so without it nobody can open the copy, us included.
In the browser's storage (localStorage) the app keeps your clones, messages and settings, encrypted, in the browser's database (IndexedDB) the clones' photos, videos, GIFs, stickers and voice messages, encrypted, and what it needs to work: your sign-in, a random install mark, the language you chose and the day it was first opened.
We use no cookies for advertising, tracking or analytics. The app's graphics engine and fallback fonts (for emoji, for example) load from Google's servers (gstatic.com), which see your IP address but set no cookies. Payment happens on Stripe's page, which sets its own cookies under Stripe's rules.
All of this is strictly necessary for the service you asked for, so it needs no consent. You delete the cookie and the app's data in Settings (Delete all data), and everything the browser keeps for this site in your browser's settings.