Privacy Policy
Last updated: September 2026
Privacy Policy
Last updated: September 2026
What this policy covers
This policy describes how Cladior collects, uses, and stores personal data when you use the Cladior platform: account creation, authentication, credit purchases and renewal, session metering, developer payouts, and use of Cladior-connected apps.
Cladior Technologies is the data controller for that data. Questions, requests, and complaints go to privacy@cladior.com.
What this policy does not cover. When you connect to a developer's app, that developer decides what they do with data you give them directly. They are their own data controller and their own privacy policy applies. Cladior tells them only that you are authenticated and hold a balance, plus any permission you explicitly approved on the consent screen. We never pass on your card details, because we never hold them.
Data we collect
Account data
When you create an account, we store your email address and a hashed password. We do not store plain-text passwords at any point. If you use an OAuth provider to sign in, we store your email address as received from that provider.
Signing in with Google
If you sign in with Google, Cladior asks Google for three things: openid, email and profile. Google classes all three as non-sensitive. We do not ask for access to Gmail, Drive, Calendar, Contacts or any other Google service, and we cannot read them.
What we receive. Your Google account email address, your name, your profile picture URL, and the account identifier Google uses for you.
What we do with it. We create your Cladior account and sign you in. The email address identifies the account and is where we send anything you ask us to send. The name and picture appear on your Cladior profile. That is the whole of it.
Who we share it with. Supabase, which hosts our authentication and our database, and nobody else. We do not sell this data. It is not used for advertising, and it is not used to train machine learning or artificial intelligence models. It is not passed to the developers whose apps you connect to: they are told you are authenticated and hold a balance, and nothing further.
How it is protected. Encrypted in transit with TLS 1.2 or higher. Held at rest in Supabase behind row-level security enforced at the database layer, so a row is readable only by the account it belongs to.
How long we keep it. For as long as your account is open. Close the account and it is deleted within 30 days. You can withdraw Cladior's access at any time from your Google account permissions page, which stops Google sending us anything further.
Limited Use. Cladior's use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.
Usage data
When you use an app that connects through the Cladior proxy, we record a session entry containing: your user ID, the app ID, the number of kilobytes transferred, the timestamp, and the computed charge. We do not record the content of any request or response. Only the byte count is stored.
Developer data
If you register as a developer, we store your email address, the apps you create (name, rate, description, scopes), and your accumulated earnings balance. To be paid you open a Stripe connected account. Stripe collects your bank details and identity documents; we store only the identifier of that account, so we never hold your banking credentials.
Credit and payment data
Credit purchases and usage charges are recorded with amount, timestamp, and reference ID. These records are retained for financial record-keeping purposes.
Where automatic renewal is enabled, we store a payment token issued by Stripe, together with the customer record Stripe holds for you, the card's last four digits, its brand, and the billing email address Stripe associated with it. The token is a reference that only Stripe can redeem, and only against our account. It is never the card number, which we do not receive.
We never receive or store your full card number, expiry date, or security code. Removing your saved card, or disabling automatic renewal, deletes the token from your account.
How we use your data
We use your data solely to operate the platform: authenticating your account, processing billing, calculating developer earnings, and maintaining transaction records. We do not use your data for advertising. We do not sell your data to third parties.
Third-party processors
Supabase hosts our database and authentication infrastructure. Email addresses, user IDs, session records, and transaction data are stored in Supabase-managed infrastructure in the United States.
Cloudflare provides edge delivery and CDN services for all Cladior properties. IP addresses transit Cloudflare infrastructure but are not stored by Cladior beyond standard edge log retention.
Stripe processes payments into your account. When you buy credit, and when your credit renews automatically, that transaction is handled by Stripe under their own privacy framework. Cladior receives a confirmation and credits the account. Stripe holds the card details behind the payment token described above; the card number never reaches Cladior.
Developer payouts run through Stripe as well. A developer who wants to be paid opens a Stripe connected account, and Stripe collects their bank details and identity documents directly. Cladior never sees them and cannot send a transfer until Stripe reports the account able to receive one.
Flutterwave processed payments before September 2026. It no longer takes payments and no longer sends payouts. Payments taken through it may still settle or be refunded against it, so it remains a processor of record for those earlier transactions.
Developers who integrate the Cladior SDK and proxy their users' API requests through Cladior are data controllers. Cladior acts as a data processor on their behalf. The full terms of that relationship are set out in the Data Processing Agreement.
Data retention
Session records are retained for 12 months and then purged. Credit, charge, and payout records are retained for 7 years to meet financial record-keeping requirements. Account data is deleted within 30 days of account closure, except where financial records must be retained.
Legal bases for processing
Where the GDPR or the Nigeria Data Protection Act 2023 applies, we rely on:
- Performance of a contract for the data needed to run your account, hold your credit, route your API calls, and bill correctly. Without it the service cannot function.
- Legal obligation for transaction records we are required to retain, and for responding to lawful requests.
- Legitimate interests for security, fraud and laundering prevention, and keeping the service working. We do not use your data for advertising or sell it to anyone.
- Consent for anything optional, such as non-essential cookies. You can withdraw consent at any time without affecting processing already carried out.
International data transfers
Our infrastructure providers store data in the United States. If you are in the European Economic Area, the United Kingdom, or Nigeria, using Cladior involves transferring your personal data outside your country.
We rely on the contractual protections offered by those providers, including Standard Contractual Clauses where applicable, and on the safeguards permitted under section 41 of the Nigeria Data Protection Act 2023. You can request details of the safeguards in place by writing to privacy@cladior.com.
Your rights
Depending on where you live, you have some or all of the following rights over your personal data:
- Access. A copy of the data we hold about you.
- Rectification. Correction of anything inaccurate or incomplete.
- Erasure. Deletion, where we have no overriding legal obligation to keep it. Transaction records are the usual exception, since financial records must be retained.
- Restriction. Ask us to stop processing while a dispute about accuracy or lawfulness is resolved.
- Portability. Receive your data in a machine-readable format, or have it sent to another provider where technically feasible.
- Objection. Object to processing carried out on the basis of legitimate interests.
- Withdraw consent. Where processing relies on consent.
You can export your session history, transaction history, and account data from your dashboard at any time. For anything else, contact privacy@cladior.com. We respond within 30 days, and will tell you if we need longer and why. To close your account and request deletion, use the same address. We confirm deletion within 14 days.
We do not charge for these requests unless one is manifestly unfounded or excessive, and we will say so before doing anything.
Complaints
If you think we have handled your data improperly, tell us first at privacy@cladior.com so we can put it right.
You also have the right to complain to a supervisory authority. In Nigeria that is the Nigeria Data Protection Commission. In the EEA it is the authority in your country of residence, and in the UK it is the Information Commissioner's Office.
Automated decision-making
We do not make decisions producing legal or similarly significant effects about you by automated means alone.
Fraud and laundering signals are scored automatically, but a score never blocks a payout or closes an account on its own; it flags activity for a person to review. You can ask for that review, and for the reasoning behind any decision, at privacy@cladior.com.
Children
Cladior is not intended for anyone under 18 and we do not knowingly collect data from children. If you believe a child has created an account, contact privacy@cladior.com and we will delete it.
Security
All data in transit is encrypted with TLS 1.2 or higher. Passwords are hashed and never stored in recoverable form. Database tables containing personal data have row-level security enforced at the database layer. See our Security page for more detail.
Contact
For data-related questions: privacy@cladior.com.