Privacy Policy

Effective and last updated:

Cluster Software Inc., a Delaware corporation (“Cluster,” “we,” “us,” or “our”), explains in this Privacy Policy how we collect, use, and disclose personal information when you visit https://getcluster.ai, communicate with us, or use our software and related services (together, the “Services”).

This policy covers information we handle for our own business purposes. When we process information on behalf of a business customer, that customer determines how its information is used and its agreement with us governs our processing. For those requests, please contact the business that provided your information.

1. Information we collect

  • Information you provide. Your name, business email, company and role, account details, referral source, messages, and other information you submit when requesting a trial, booking a meeting, contacting us, or using the Services.
  • Customer content and connected services. If you use our platform, we process the records, contacts, prompts, files, campaign information, and other content you submit, as well as information you authorize us to access through connected accounts and integrations.
  • Usage and device information. IP address, browser and device type, operating system, referring pages, approximate location inferred from IP address, timestamps, pages viewed, interactions, and diagnostic data. Cookies and similar technologies may associate activity with a browser or account.
  • Information from other sources. Business contact and company information from public sources, data providers, partners, and integrations you enable, subject to the permissions and terms that apply to those sources.
  • Billing information. If you purchase paid Services, billing contacts, transaction records, and payment status. Payment providers process payment details under their own terms and privacy notices.

Please provide only information needed to use the Services. Do not submit sensitive personal information, such as health records or government identification numbers, unless we have expressly agreed to support that use.

2. How we use information

  • Provide, operate, maintain, and improve the Services.
  • Create and manage accounts, fulfill requests, run authorized workflows, process payments, and provide customer support.
  • Understand usage, troubleshoot issues, develop features, and evaluate the effectiveness of our website and communications.
  • Send service notices and respond to inquiries, trial requests, or meeting bookings; send marketing communications where permitted, subject to your choices.
  • Detect and prevent fraud, abuse, unauthorized access, and other security issues; enforce our agreements and comply with legal obligations.

3. How we share information

We may disclose information to the following recipients:

  • Service providers. Providers of hosting, storage, analytics, communications, scheduling, payments, support, and other services that help us operate our business. This includes PostHog for website analytics and RB2B for business visitor identification. Information is shared as needed for the services they provide.
  • Integrations and AI providers. Services you connect or use through our platform may receive the inputs and other information needed to complete your requests. Review their terms and privacy notices before enabling them.
  • Your organization. If you use an organization-managed account, its administrators may access and manage account information, content, and activity.
  • Professional advisers and authorities. Where reasonably necessary for advice, compliance with law or legal process, protection of rights and safety, or the investigation of fraud and security incidents.
  • Business transfers. In connection with a merger, financing, acquisition, restructuring, bankruptcy, or sale of all or part of our business, subject to applicable confidentiality and legal requirements.
  • At your direction. With other parties when you request, authorize, or consent to the disclosure.

We may also use and disclose aggregated or de-identified information that does not reasonably identify you, subject to applicable law.

4. Google user data

If you connect a Gmail account to the Services, Cluster accesses your Gmail data through Google APIs solely to provide the features you enable:

  • Sending. We send the outreach messages and follow-ups that you compose and launch, from your connected account and in your name.
  • Reading. We read incoming messages, including their headers, body, and labels, to detect replies, out-of-office notices, and delivery failures to messages you sent, so that further follow-ups stop automatically and failed addresses are suppressed, and to display those conversations in your Cluster inbox so you can respond to them.

We do not use Gmail data for advertising, for market research, or to develop, improve, or train generalized artificial intelligence or machine learning models. We do not sell Gmail data. We do not transfer it to third parties except to the service providers that operate the Services on our behalf, as necessary for security purposes or to comply with applicable law, or as part of a merger or acquisition with prior notice to you. Reply text from Gmail messages is processed by third-party AI providers solely to classify responses for you; those providers are contractually prohibited from using it to train their models. No person at Cluster reads your Gmail data unless you give explicit permission for specific messages, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and anonymized for internal operations.

Cluster's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google access credentials are stored encrypted, and synced messages are stored encrypted at rest and in transit. We retain synced Gmail messages for as long as your account remains connected and your workspace is active. You can disconnect a Gmail account at any time from your account settings or from your Google Account permissions page. When you disconnect, we stop accessing the account and delete the stored access credentials within 24 hours, and we delete the synced messages from that account within 30 days unless you ask us to keep them or the law requires retention. You can also request deletion of any Gmail data at any time by contacting us.

5. Cookies and analytics

We use cookies, local storage, and similar technologies to support functionality and understand how people use the Services. Our website uses PostHog to collect page views, interactions, and related device and usage information.

We also use RB2B to help identify businesses and visitors interested in our Services. RB2B may use cookies, device identifiers, and IP addresses to associate website activity with company or contact information, such as a name, job title, or email address, for business marketing. Its network may recognize activity across websites. See RB2B’s Privacy Policy for details and its opt-out options.

You can block or delete cookies through your browser settings. Doing so may affect functionality, and clearing cookies may reset previously saved preferences. Browser controls may not prevent every form of analytics collection.

Our website does not currently change its behavior in response to legacy browser “Do Not Track” signals. Rights associated with legally recognized opt-out preference signals, where applicable, are separate from this legacy setting.

Third-party services embedded in or linked from the Services may collect information about your activity over time and across websites when you interact with them. Their handling of that information is described in their own privacy notices.

6. Retention and security

We retain personal information for as long as reasonably necessary for the purposes described in this policy, including providing the Services, maintaining business records, complying with legal obligations, resolving disputes, and enforcing agreements. Retention depends on the type of information, our relationship with you, and applicable requirements. Customer content is also subject to the relevant customer agreement.

We use reasonable administrative, technical, and organizational measures designed to protect personal information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Deletion may be subject to legal retention requirements and routine backup cycles.

7. Your choices and privacy rights

You can unsubscribe from marketing emails using the link in those emails. We may still send transactional or service messages. You can also update account information and disconnect integrations using available account or provider settings.

Depending on where you live and which laws apply, you may have the right to request access to, correction of, deletion of, or a portable copy of your personal information; obtain information about recipients; restrict or object to certain processing; or withdraw consent. Applicable U.S. state laws may also provide rights to opt out of a sale of personal information, targeted advertising, or certain profiling, if those activities occur. These rights are subject to legal exceptions.

To make a request, contact us and describe the right you wish to exercise. We may need to verify your identity and, if you use an authorized agent, their authority. We will respond within the time required by applicable law and will not unlawfully discriminate against you for exercising your rights.

If we deny a request and you have a right to appeal, reply to our response with “Privacy appeal” and explain your concerns. You may also complain to your local data protection authority or state attorney general. If your information is controlled by one of our customers, direct your request to that customer; we will assist as required by our agreements and law.

8. International users

We are based in the United States. Your information may be processed in the United States and other countries where we or our providers operate, which may have different data protection laws from your country. Where applicable law requires safeguards for international transfers, we use the required transfer mechanisms and protections.

Where European, UK, or similar data protection laws apply, our legal bases for processing include performing a contract with you, our legitimate interests in operating and protecting our business where those interests are not overridden by your rights, compliance with legal obligations, and your consent when required. You may withdraw consent without affecting the lawfulness of processing before withdrawal.

9. Children’s privacy

The Services are intended for business users aged 18 or older and are not directed to children. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can investigate and take appropriate steps to delete it.

10. Third-party services

The Services may link to or integrate with third-party websites, data providers, scheduling tools, and other services. This policy does not govern information those third parties collect for their own purposes. Review their privacy notices to understand their practices and your available choices.

11. Changes to this policy

We may update this policy as our Services and practices evolve. We will post the updated policy here and revise the date above. For material changes, we will provide additional notice, such as an email or a prominent notice within the Services, and obtain consent where required by law.

12. Contact us

For privacy questions or requests, contact Cluster Software Inc.

For the terms governing use of the Services, please read our Terms of Service.