Privacy Policy
The short version
We collect the minimum needed to run your subscription — nothing more. ClippyAI is accessibility-tree first: most tasks send only structured UI text (visible labels, button names, coordinates), not pixels. When visual understanding is required during a task you asked for, a screenshot may be sent for that request only — never stored by us. Proactive mode (on by default, switchable off in Settings) periodically reads on-screen text so Clippy can offer tips. No analytics, no ads, no data resale. Delete your account and we delete your data.
The website (clippyai.app)
The marketing site itself collects zero personal information. There are no signup forms, no newsletter, no analytics scripts, no tracking pixels, no advertising SDKs, no localStorage, and no first-party cookies.
The only data touched when you visit is what Cloudflare (our hosting provider) logs at the edge for basic abuse prevention:
- IP address
- Browser user agent
- Requested URL and timestamp
- A short-lived Cloudflare bot-management cookie (
__cf_bm, ~30 minutes)
When you click a pricing button you leave our site and go to Stripe, which handles all payment data under Stripe's privacy policy. We never see your card number.
Your account
To run a paid subscription we store the absolute minimum:
- Email address (so we can send your license key — keys are delivered by email, never shown on screen)
- Stripe customer ID (so billing works)
- License key, plan, and subscription status
- Monthly token usage count (so we can enforce your plan's quota)
That's the entire account record, stored in Supabase. No name, no address, no phone number, no profile.
The desktop app
When you chat with Clippy, ask him to do something on your computer, or when proactive mode checks in (see below), the following is sent to our backend so the AI can respond:
- Your message — what you typed or asked
- Active window title — which app is in focus
- UI accessibility tree — structured text describing visible buttons, labels, and text fields (names and coordinates only)
- Your local Clippy profile — the name and preferences you've given Clippy, plus recent conversation history, so replies stay in context (stored on your computer — see "Local storage")
- A screenshot — only during a task you asked for, and only when the accessibility text isn't enough (see "About screenshots")
Your prompt + screen context is forwarded to our AI provider (DeepSeek) to generate a response, then discarded. We do not store conversation logs. All AI processing goes through our own backend — your license key authenticates you, and your plan's monthly token quota is enforced server-side.
If you use the "Report Issue" feature in the log viewer, your local log file is sent to our backend for debugging. Logs are stored for 30 days and then automatically deleted.
Proactive mode
Proactive mode is on by default. Every 5 minutes (adjustable), Clippy reads the active window's title and accessibility text and sends it to our backend so he can offer a relevant tip — even when you haven't asked him anything. Proactive checks never take screenshots. You can turn this off in Settings → Proactive mode (or from the tray / menu-bar menu); Clippy will then only speak when spoken to. Putting Clippy to Sleep also stops proactive checks.
Voice
Voice is optional and only active while you use it (push-to-talk, or when Clippy reads a reply aloud).
- Voice input on Windows is transcribed locally by a bundled copy of whisper.cpp. Audio never leaves your computer.
- Voice input on macOS requires your own OpenAI API key (entered in Settings, kept in your Keychain). While you hold push-to-talk, the recording is sent directly to OpenAI for transcription. Without a key, voice input is unavailable on macOS.
- Voice output uses your operating system's built-in voice by default, entirely offline. On the Max plan (premium voice), or if you pick the OpenAI voice engine with your own key, the text Clippy speaks is sent to OpenAI to generate audio.
We never record your microphone in the background, and the webcam is never used.
About screenshots
Clippy reads your screen as text via the operating system's accessibility tree — UI Automation on Windows, the Accessibility API on macOS (button names, labels, visible text — not pixels). When the accessibility tree can't describe what's on screen (e.g. canvas drawings, raster images, custom-rendered UIs), or when Clippy needs to check what a step did, he may take a screenshot of the visible desktop and forward it to the AI for that turn. Screenshots are only taken while carrying out something you asked for — never during proactive checks — and are never stored by us.
There is currently no setting that disables screenshots entirely. If you don't want Clippy to capture the screen, put him to Sleep or quit the app.
What we never collect
- ❌ Passwords, credentials, API keys, or 2FA codes (Clippy actively avoids fields containing them)
- ❌ Credit card or bank account details (Stripe handles those directly)
- ❌ Files, folders, or documents on your computer (unless you explicitly ask Clippy to read one — e.g. "summarize C:\notes.txt")
- ❌ Browser history, bookmarks, or saved passwords
- ❌ Webcam input — and microphone audio is only processed while you hold push-to-talk (see "Voice")
- ❌ Keystroke logging — we never capture keys you type outside of Clippy's bubble
- ❌ Content from windows that aren't currently visible
- ❌ Any form of device fingerprinting for tracking
- ❌ Persistent screenshots — pixels are forwarded only for the turn that needs them, never retained
Who we share data with
We use a small number of processors strictly to run the service:
- Stripe — payments and subscription management
- Cloudflare — hosting, edge, abuse prevention, and 30-day storage of "Report Issue" logs
- Supabase — database for accounts, license keys, and usage counts
- Resend — delivers your license-key and account emails
- DeepSeek — the AI model provider that generates Clippy's responses
- OpenAI, L.L.C. — voice only: premium voice output on Max, and voice input/output when you use your own OpenAI key
We do not sell, rent, or share your data with advertisers, brokers, or analytics companies. We don't have a marketing database.
How long we keep it
- Account info: for the life of your subscription, plus 90 days after cancellation (billing and tax records)
- Chat messages & screen context: processed in real time and discarded immediately — not logged
- Token usage counts: reset every billing cycle
- Diagnostic logs (submitted via "Report Issue"): 30 days, then auto-purged
Your rights
Wherever you live, you can:
- Pause Clippy — right-click the menu-bar (Mac) or system-tray (Windows) icon → Sleep. He stops reading the screen instantly.
- Quit Clippy — nothing is sent while the app is closed.
- Cancel any time from your Stripe customer portal. No questions asked.
- Access or delete your data — email [email protected] and we'll action it within 30 days.
- AI training — we never use your prompts or screen context to train models. Our AI providers process requests under their API terms; we send them only what the current request needs.
GDPR, UK GDPR, and CCPA residents have the additional rights guaranteed by those laws (rectification, portability, objection, non-discrimination). Same email reaches us.
Local storage
The desktop app stores your settings, license key, buddy name, guardrail choices, your Clippy profile and memories, conversation history, and action history locally on your computer — in %APPDATA%\clippyai on Windows, or ~/Library/Application Support/clippyai on macOS. Your profile and recent conversation are included as context when Clippy talks to the AI (see "The desktop app"); everything else never leaves your machine. All of it is deleted when you uninstall.
Children
ClippyAI is not directed at children under 13 (or 16 in the EU/UK). If you believe a child has created an account, email us and we'll remove it.
Changes
If we change this policy we'll update the date at the top and, for material changes, email active subscribers at least 7 days in advance. Continued use after the effective date means you accept the update.
Contact
Questions, deletion requests, or just want to reach a real human?