Legal
Privacy Policy
What we collect, why, how long we keep it, and how to get it deleted. The short version: we hold your photos privately, publish only a smaller copy, never train AI on them, and never sell them.
1. Who is responsible for your data
Clunny (entity to be incorporated) is the controller of the personal data described here. Write to privacy@clunny.com with any question or request.
2. What we collect
Everyone with an account:
- Your email address, and a password we never see in readable form. It is hashed by our authentication provider.
- If you sign in with Google instead of a password: your email address, your name and your profile picture, as Google gives them to us, and the fact that Google is how you sign in. We never receive your Google password, and we ask Google for nothing else: no contacts, no calendar, no files.
- Whether you are a creator or a licensee, and whether you have enabled two-factor authentication.
- When you signed up, and when you last changed something.
Creators, in addition:
- Your display name, profile address, biography, category and industry.
- Your first and last name, your date of birth, and your gender and pronoun. These are not shown on your public profile. We ask for your date of birth because nobody under 18 may license their likeness here and because it goes on your contract, and for your pronoun so that we address you the way you asked to be addressed.
- The country you are based in, and the territories you will license.
- Your licensing terms and prices.
- Photographs of your face, and a record of which version of the consent wording you agreed to when you uploaded each one.
- Social account handles you choose to list. If you prove an Instagram account by sending us a message, Meta delivers that message to us. We use the sender and whether the text contains the phrase we issued. We do not keep the message text.
- If you set up payouts: the identifier of your Stripe connected account, whether Stripe says that account can receive payouts, and Stripe's own reason code if it cannot. Stripe collects your identity documents and bank details on their pages. We do not store those documents or bank details. If the date of birth you gave us does not match the date of birth Stripe has for that payout account, we email a founder the two dates so they can look. We do not change your listing and we do not stop payouts because of that mismatch.
- Once your profile is live, any change you make to these details is kept separately until one of us has checked it. Your public page carries on showing the details we already checked. We keep what you proposed, when you proposed it, whether we accepted it, and, if we did not, the reason we gave you. You can cancel a change you have sent us at any time, from your dashboard.
Licensees, in addition:
- The name you license under, your date of birth, and the country you live in. Your website if you give us one, and the outcome of our verification check. We ask for your date of birth because nobody under 18 may buy a licence here and because it goes on your contract. These details are not shown on any public page. A creator who receives a request from you sees your name, and your website if you gave us one.
Everyone, as a result of using the service:
- Licence requests you send or receive, the scope they cover, and any counter-offers.
- Messages you write to the other side of a deal, and when you wrote them.
- Whether you blocked or unblocked the other person in a conversation, and when.
- Every version of the draft agreement either of you proposes, who proposed it, what it said, and who agreed to it and when.
- When you last opened a conversation. We use it to decide whether to email you about a new message, to count what you have not read, and to show you where you left off. It is never shown to the other side — nobody here learns when you were reading.
- A record of every change to a request: what changed, when, and who did it.
- A record of the notification emails we queued and whether they were delivered. When the mail provider tells us an address bounced or marked a message as spam, we record that address so we stop sending to it. Otherwise the app reports success and nothing arrives.
- Counts of certain actions, per email address and per internet connection, used to limit how often they can be repeated.
- A security record of signing in, signing out, failing to sign in, signing up, asking for a password reset, changing a password, and entering a two-factor code correctly or incorrectly, with the time, the internet address it came from, and which browser was used.
That security record exists so that a break-in can be noticed and investigated. Without it, an account being taken over would leave no trace at all. If someone tries to sign in to an address that has no account here, we count the attempt but do not keep the address. We have no reason to hold details about people who are not our users.
We measure how the site is used and how fast it is, through Vercel, who host it. That means a count of which pages were opened, roughly where in the world from, on what kind of device, and how long each page took to appear. It sets no cookie and creates no identifier that outlives your visit, so these counts cannot be joined together into a picture of one person, and they are never combined with your account.
We run no advertising trackers, we do not track you across other websites, and we do not buy data about you from anyone.
3. Your photographs, specifically
Face photographs get separate treatment because they deserve it.
The original is stored in a private bucket. It is not publicly reachable. Clunny staff reviewing your profile can open it through a link that stops working after ten minutes. Every time one of us does that we record who opened it and when, so the access can be accounted for afterwards. A licensee never receives the original.
What appears on your public profile is one photograph, the profile picture you chose, as a resized, re-encoded copy at a lower quality than the file you sent us. Your other photographs are not published; a licensee sees them once a licence between you is signed. We strip the embedded metadata, including any location the camera recorded, before storing anything.
We do not create a face scan, face template, faceprint or any other biometric identifier from your photographs, and we do not run face recognition or face matching over them.
We do not use your photographs to train AI models, ours or anyone else's, and we do not license them to anyone for that purpose. What a licensee may do is set by the licence you agree, and Clunny itself never generates AI content.
4. Why we are allowed to hold it
If you are in the UK or the European Economic Area, the legal bases we rely on are:
- Performing our contract with you: running your account, showing your listing, carrying requests between you and the other side, and taking payment.
- Your consent, for holding and publishing your face photographs. You can withdraw it at any time by deleting them.
- Our legitimate interests: keeping the service secure, preventing abuse and impersonation, and keeping a record of what was agreed. We think these do not override your rights, and you can object.
- Legal obligation: tax, accounting, and responding to lawful requests.
5. Who else sees it
Other users, in the way you would expect:
- Anyone can see a listed creator's public profile: the name, biography, terms, prices where you make them public, and the public copy of your profile picture.
- A licensee you are in a conversation with sees your name and the details of that conversation.
- A creator sees the name of a licensee that contacts them, and a website if that licensee gave us one.
- The two sides of a deal see everything in that deal: the messages, every version of the draft agreement, and when each of you opened it.
Clunny staff can read a deal conversation and its draft agreement. We do that to answer support questions and to sort out disagreements about what was agreed, and we do not do it casually. If one of us is going to write in your conversation, we press a button that says so, and both of you are emailed at that moment. A message from us appears under Clunny’s name and never under a personal one. Reading it still does not notify you, but it is no longer invisible to us either: whenever one of us opens a conversation we are not part of, that is written to our own internal record, naming who opened it and when, so the access can be accounted for.
Companies that run parts of the service for us:
- Supabase: our database, file storage and authentication, hosted in the European Union.
- Vercel: our web hosting. Our server code runs in Frankfurt.
- Resend: sends our notification emails, from a server in Ireland.
- Sentry: tells us when something in the site breaks, from a server in Germany. See below for what it does and does not receive.
- Stripe: card payments from licensees, and payouts to creators. Card details never reach our servers. For Connect payouts, Stripe collects identity and bank details on their own pages.
- Meta: Instagram Login, and the delivery of a proof message you send to our Instagram account. Meta acts under its own terms for that delivery. We receive the sender and the text only to check the phrase.
If you choose to sign in with Google, Google learns that you signed in to Clunny and when. That is Google acting for itself under its own privacy policy, not for us. We cannot see or control it, and it is the trade you are making by using the button. Signing up with an email address and password avoids it entirely, and both routes give you the same account.
Each of them acts on our instructions and is bound to keep your data confidential. We do not sell your personal data, and we do not share it for anyone else's advertising.
We will disclose data where the law requires it, and we will tell you when we are permitted to.
6. When something breaks
When the site fails, whether that is a page that will not load or a button that does nothing, a report is sent to Sentry so we find out and fix it. Without that, a fault only reaches us if someone tells us.
The report contains what went wrong and where. It does not contain:
- Your photographs. Images are never captured.
- Your name, email address, or anything you typed. Text is removed before the report leaves your browser.
- Your password, or any link from an email we sent you.
- Your IP address.
Sentry does record the country and city the report came from. That is worked out from the network connection at their end rather than from anything we send. We do not send your IP address and it is not stored against the report. We keep this: knowing that a fault only happens in one country is often the whole diagnosis, and a city is not enough to identify anyone.
If an error happens we also keep a short recording of the moments before it, covering which parts of the page you clicked and in what order, so the fault can be reproduced. Images are blocked from that recording and all text in it is masked, so it shows the shape of the page rather than its contents. Nothing is recorded during an ordinary visit where nothing goes wrong.
We identify these reports by your account's internal reference only, so we can tell that one person hit the same fault repeatedly rather than many people hitting it once.
7. Where it is held
In the European Union. If you are outside the EU, in the United States, Israel or Colombia for example, your data is transferred there and held under EU data protection standards.
8. How long we keep it
- Face photographs: while your profile exists, and up to 3 years after your last activity, whichever comes first. When an account closes during an active licence, every original and public copy is deleted immediately. Approved private angle previews stay available only to the active licensee until that licence ends, then they are deleted.
- Account and profile data: while your account is open.
- Licence requests and the record of what was agreed: while either side may still need them, and after that for as long as the licence itself may matter.
- Deal conversations, their messages and every version of the draft agreement: kept as a permanent shared history for both of you. A request ending does not close its conversation. Neither side can delete the other’s messages or rewrite a version the two of you agreed. Blocking someone pauses new messages and leaves the full history in place. Closing an account does not remove the messages you wrote from the other party’s inbox.
- Our internal record of changes: kept after an account closes. It records that an action happened and by whom, which is what makes a licence defensible years later, and it cannot be selectively rewritten without destroying that.
- The security record described in section 2, including the internet addresses it holds: kept in the same way and for the same reason. A record of who signed in that can be deleted by whoever signed in is not a security record.
9. Deleting your data
You can delete an individual photograph at any time from your dashboard. It is removed from storage, not just hidden.
You can delete your whole account. If there is no active licence, we remove your stored files first and your account second. If the files cannot be removed, we stop and change nothing.
Shared licence requests, contracts, payment records and messages stay after the login closes. We replace the profile with a deleted-account record and remove the personal details those shared records do not need.
If a licence is active, its licensee keeps access to the approved private angle previews until the licence ends. Every original and public copy is deleted when the account closes. The retained previews are deleted after the final active licence ends.
Messages you sent in a conversation stay visible to the other people in it after your account is closed. They are not attached to your account in the database, so deleting you does not delete what you said to them. That is a gap, not a feature, and it is listed for counsel rather than papered over here.
Deleting your data does not cancel a licence already in force.
10. Your rights
You can ask us to:
- Give you a copy of your data.
- Correct it if it is wrong.
- Delete it.
- Stop or limit a particular use of it.
- Send it to you, or to someone else, in a portable form.
- Withdraw a consent you gave, at any time.
Write to privacy@clunny.com. We will not charge you or make it difficult, and asking will never affect how we treat you.
If you are in the UK or EEA and think we have got something wrong, you can complain to your national data protection authority. We would rather you told us first, but you do not have to.
11. Cookies
We set cookies to keep you signed in and to keep your session secure. That is all they do. There are no advertising cookies, and the usage measurement described in section 2 sets no cookie of any kind, which is why there is no banner here asking you to accept anything.
12. Security
Access to your data is restricted at the database itself, not only in our application, so a mistake in one screen cannot expose rows you should not see. Private files are reachable only through short-lived links. We offer two-factor authentication and recommend turning it on.
No service is perfectly secure. If a breach affects your data we will tell you and the relevant authority, within the time the law sets.
13. Children
Clunny is for people 18 and over. We do not knowingly hold data about anyone younger, and we license no minor's likeness under any circumstances. If you believe we have such data, tell us and we will delete it.
14. Changes
If we change this policy materially we will tell you before it takes effect. Where a change affects how we use your photographs, we will ask for your consent again rather than assume it.