Cladior · Legal

Privacy Policy

Last updated: July 2026

Privacy Policy

Last updated: July 2026

What this policy covers

This policy describes how Cladior collects, uses, and stores personal data when you use the Cladior platform: account creation, authentication, wallet operations, session metering, developer payouts, and use of Cladior-connected apps.

Data we collect

Account data

When you create an account, we store your email address and a hashed password. We do not store plain-text passwords at any point. If you use an OAuth provider to sign in, we store your email address as received from that provider.

Usage data

When you use an app that connects through the Cladior proxy, we record a session entry containing: your user ID, the app ID, the number of kilobytes transferred, the timestamp, and the computed charge. We do not record the content of any request or response. Only the byte count is stored.

Developer data

If you register as a developer, we store your email address, the apps you create (name, rate, description, scopes), and your accumulated earnings balance. Payout requests include payment details transmitted to Flutterwave. We do not store full payment credentials ourselves.

Wallet data

Wallet top-up and charge transactions are recorded with amount, timestamp, and reference ID. These records are retained for financial record-keeping purposes.

How we use your data

We use your data solely to operate the platform: authenticating your account, processing billing, calculating developer earnings, and maintaining transaction records. We do not use your data for advertising. We do not sell your data to third parties.

Third-party processors

Supabase hosts our database and authentication infrastructure. Email addresses, user IDs, session records, and transaction data are stored in Supabase-managed infrastructure in the United States.

Cloudflare provides edge delivery and CDN services for all Cladior properties. IP addresses transit Cloudflare infrastructure but are not stored by Cladior beyond standard edge log retention.

Flutterwave processes all payment transactions. When you top up your wallet or a developer requests a payout, that transaction is handled by Flutterwave under their own privacy framework. Cladior receives a confirmation and credits the wallet or marks the payout as complete.

Developers who integrate the Cladior SDK and proxy their users' API requests through Cladior are data controllers. Cladior acts as a data processor on their behalf. The full terms of that relationship are set out in the Data Processing Agreement.

Data retention

Session records are retained for 12 months and then purged. Wallet and payout transaction records are retained for 7 years to meet financial record-keeping requirements. Account data is deleted within 30 days of account closure, except where financial records must be retained.

Your rights

You can export your session history, transaction history, and account data from your dashboard at any time. To close your account and request deletion of your data, contact privacy@cladior.com. We will confirm deletion within 14 days.

Security

All data in transit is encrypted with TLS 1.2 or higher. Passwords are hashed and never stored in recoverable form. Database tables containing personal data have row-level security enforced at the database layer. See our Security page for more detail.

Contact

For data-related questions: privacy@cladior.com.