Privacy Policy

Effective date: August 9, 2026

1. Who We Are and What This Policy Covers

Clevifai, Inc., a Delaware corporation doing business as Anystart ("Anystart," "we," "us," or "our"), provides the Anystart website, desktop application, cloud services, public Marketplace and creator profiles, and related support and communications (collectively, the "Services"). Clevifai, Inc. is the controller of personal information covered by this Privacy Policy.

This Policy explains what personal information we collect, how we use and disclose it, how long we retain it, and the choices and rights available to you. It applies when you visit our website, create or use an account, use the desktop application or cloud Services, publish or report a creator profile, join a Team, subscribe to communications, or contact us.

This Policy does not govern third-party websites, AI providers, MCP connectors, plugins, or other services that you choose to access through Anystart. Those parties process information under their own terms and privacy notices.

2. Information We Collect

Information You Provide

  • Account and authentication information: name, email address, password credential or password hash, email-verification status, account identifiers, profile avatar, authentication records, and the versions, time, and account-creation method associated with acceptance of our Terms and acknowledgment of this Policy.
  • Social sign-in information: if you choose Google sign-in, we receive your Google account identifier and limited profile information needed to authenticate and secure your account. We may receive a profile image but do not save it as your Anystart avatar. We do not receive your Google password.
  • Workspace and agent content: workspace names and settings, instructions, memory entries, prompts, chat messages, assistant responses, reasoning and tool records, search text, feedback, and other content you submit or generate through the Services.
  • Files and device content you direct us to process: files, file excerpts, attachments, local paths, command output, tool results, and other information that you or the agent choose to include in a task. Anystart does not automatically upload an entire working folder, but content read or produced during a task may be sent to our cloud Services and selected providers and may be stored in the related chat transcript.
  • Generated media: image and video prompts, request settings, generated assets, technical metadata, and billing or lifecycle records associated with managed media generation.
  • Team information: Team name, membership, role, active-Team selection, invitation recipient email, invitation status and expiration, and related administrative actions. Teams do not make personal workspaces, chats, memory, files, connectors, quotas, or subscriptions available to other Team members.
  • Creator profile information: if you opt in, your creator display name, public handle, biography, source language, Anystart-managed avatar and cover images, approved external links, publication state, prior handles, terms acceptance, and timestamps.
  • Marketplace publishing information: private listing drafts, stable slugs, names, descriptions, categories, keywords, source language, support and policy links, plugin archive contents and hashes, file and capability inventories, connector endpoints and declarations, required credential variable names, upload and scan evidence, release and submission history, publisher-agreement acceptance, review decisions and notes, publication and revocation state, and timestamps. Do not put credential values, passwords, access tokens, private keys, or unnecessary personal information in a listing or archive.
  • Reports and moderation information: report category and optional details, report status, moderation actions and reasons, appeals, and trust-and-safety audit records.
  • Billing information: selected plan, Stripe customer and subscription identifiers, subscription status, billing period, trial and cancellation status, and payment-related events. Stripe collects and processes payment-card and other payment details; Anystart does not receive full card numbers.
  • Communications: support requests, privacy or legal requests, survey or feedback responses, an optional screenshot you choose to attach to product feedback, newsletter preferences, waitlist information, and other messages you send us.

Please do not provide sensitive personal information unless it is necessary for your task and you have the right to provide and process it.

Information Collected Automatically

  • Device and application information: operating system, app and browser version, locale, screen or display characteristics, app installation identifier, configuration state, and update status.
  • Network and security information: IP address, request identifiers, timestamps, authentication and session events, update-check and download requests, rate-limit signals, and security or fraud indicators.
  • Usage and billing-metering information: plan tier, selected model, token and credit usage, request counts, feature and tool categories, workspace and session identifiers, durations, outcome categories, and other content-minimized product events.
  • Diagnostics: crash reports, error messages, stack traces, performance spans, request and provider metadata, and sanitized tool or agent diagnostics. Our normal diagnostics exclude raw prompts, outputs, file contents, tool arguments and results, secrets, and full local paths. In controlled diagnostic modes, limited input or output content may be captured when needed to investigate a reliability or support issue, subject to restricted access and retention.
  • Website activity: pages viewed, referring page, permitted campaign parameters, clicks and interactions, device and browser details, cookie or local-storage identifiers, analytics choices, a coarse country-derived analytics regime, and, only after you separately and affirmatively consent and diagnostic replay is sampled, a masked representation of website interactions. Sentry Replay masks text and blocks media; sensitive Team-invitation routes are excluded.

For creator-profile reports, we combine an HMAC-pseudonymous representation of the client IP with the profile handle to enforce a short-lived rate limit in Redis. We do not store the raw client IP in the Postgres creator-report record.

Plugin reports use the same approach with the listing slug. Public Website analytics for creator profiles and plugins is content-minimized and does not include handles, slugs, listing text, report reasons or detail, archive contents or hashes, connector endpoints, credentials, reviewer notes, or internal publisher, release, submission, and report identifiers.

Information Stored Locally on Your Device

The desktop application stores certain information locally, including its authentication token, account and workspace settings, working-folder path, local generated files, pending chat-write outbox entries, cached or extracted plugins, permission and audit records, an analytics preference and installation identifier, and MCP configuration and OAuth credentials. MCP credentials use operating-system encryption when available and may otherwise be stored locally in plaintext with a warning in application logs.

Local files remain on your device unless you direct Anystart or an enabled tool to read, modify, transmit, upload, or otherwise process them. Signing out, switching accounts, deleting an Anystart account, or uninstalling the application does not necessarily remove files or retained caches from the device. You are responsible for removing local data and generated files you no longer want.

3. Sources of Information

We obtain personal information:

  • directly from you;
  • automatically from your browser, device, and use of the Services;
  • from Google when you choose Google sign-in;
  • from Stripe regarding subscription and payment status;
  • from Team members who invite you;
  • from users who submit creator-profile or plugin reports or rights complaints;
  • from service providers that help us operate, secure, and support the Services; and
  • from public sources or third-party services that you ask the agent, Browser, web tools, plugins, or connectors to access.

4. How We Use Information and Our Legal Bases

We use personal information for the following purposes:

  • Provide and perform the Services: authenticate users; operate workspaces, chats, memory, tools, connectors, Teams, generated media, creator profiles, and downloads; route requests to AI and web providers; save and synchronize cloud data; meter credits; and provide support. Where applicable, the legal basis is performance of our contract with you.
  • Process subscriptions and transactions: create checkout and billing-portal sessions, administer trials and renewals, verify payment events, prevent duplicate charges, and maintain accounting records. The legal bases are contract performance, legal obligations, and our legitimate interests in administering the Services.
  • Secure and maintain the Services: prevent abuse, fraud, impersonation, unauthorized access, and unsafe activity; enforce rate limits and permissions; diagnose errors; maintain audit trails; and protect users, Anystart, and the public. The legal basis is our legitimate interests and, where applicable, legal obligations.
  • Improve and understand the Services: measure content-free product usage, test reliability, evaluate feature performance, and improve usability. We rely on consent where required and otherwise on our legitimate interests. We do not use your content to train our own foundation models.
  • Communicate with you: send verification, password-reset, Team invitation, billing, security, service, support, newsletter, and product-update messages. The legal bases are contract performance, legitimate interests, legal obligations, or consent, depending on the communication.
  • Operate public creator profiles, Marketplace publishing, and trust and safety: publish fields and approved listing disclosures you intentionally activate; store, inspect, scan, review, distribute, restore, update, moderate, or revoke submitted releases; maintain old-handle redirects and reserved slugs; include active public content in discovery surfaces; review reports and appeals; prevent reuse, impersonation, fraud, and unsafe packages; and enforce our Terms. The legal bases are contract performance, legitimate interests, consent where applicable, and legal obligations.
  • Comply with law and protect rights: respond to lawful requests, establish or defend legal claims, enforce our agreements, and conduct corporate transactions. The legal bases are legal obligations and legitimate interests.

Where we rely on legitimate interests, we consider the impact on your rights and use personal information only where those interests are not overridden by your interests or fundamental rights. Where we rely on consent, you may withdraw it at any time without affecting prior lawful processing.

5. AI, Agent, Browser, and Connector Processing

Anystart's agent loop runs on your device, but model inference is provided through our cloud API. Prompts, relevant conversation history, tool definitions, selected file content, and tool results needed for a request are sent through Vercel AI Gateway to the selected AI provider. The current catalog may include models from Alibaba, Anthropic, ByteDance, DeepSeek, Google, OpenAI, and xAI. Provider availability and routes may change.

Managed image and video requests set a Gateway routing preference asking that their prompts not be used for provider training. That preference is not the same as zero data retention, does not establish the serving provider's enforcement, and is not currently applied by Anystart to ordinary text-model requests. Gateway routing and fallback can cause the same model name to be served by different providers, whose retention, review, training, and privacy terms vary. We do not promise zero data retention or one fixed serving provider for a request. Do not submit content to a model if you are not authorized to disclose it or if the applicable processing is unsuitable for its sensitivity.

If you use web search or extraction, we send queries, URLs, and related options to Tavily. If you use the built-in Browser, visited sites receive ordinary browser and network information and may collect information under their own policies. By default, the Browser uses a fresh application-owned profile and does not reuse your personal browser profile. If you explicitly choose My Chrome, then after a fresh Anystart permission and Chrome's native approval, the agent may control your already-running Chrome instance and access its tabs, including private or authenticated content. Content used to perform your task is processed like other agent and tool content: it may be sent to the selected model provider and stored in the related chat transcript. My Chrome keeps Chrome's ordinary network access and does not use the default Browser's public-only network filtering. Detaching Anystart does not close Chrome, delete its profile, sign you out, or disable Chrome's remote-debugging setting.

If you install or enable an MCP connector, plugin, skill, or other third-party integration, the agent may send the information needed to perform the requested action to that third party. Connector OAuth credentials are stored locally, but the connector provider receives requests and content you authorize. Review the provider's terms and privacy notice before enabling an integration.

6. How We Disclose Information

We may disclose personal information as follows:

  • Infrastructure and operations providers: Railway for application hosting and managed databases; Cloudflare for DNS, CDN, and object storage; GitHub for release distribution and software operations; and Sanity for website content operations.
  • AI and web providers: Vercel AI Gateway and the selected model providers described above, and Tavily for web search and extraction.
  • Payments and communications: Stripe for checkout, payments, subscriptions, and fraud prevention; and Resend for transactional email, contact preferences, and newsletters.
  • Analytics and diagnostics: PostHog for product analytics and Sentry for errors, performance monitoring, and masked website replay. Basic PostHog website analytics operates according to the regional default and choices described below. Sentry Replay requires a separate affirmative choice and is suppressed by recognized browser privacy signals. Ordinary Sentry error and performance monitoring is separate from Replay. Desktop optional analytics can be disabled, although minimized operational telemetry required for security, billing, updates, error diagnosis, and core reliability may continue.
  • Authentication providers: Google when you choose Google sign-in.
  • Integrations and third parties you direct: MCP servers, plugins, websites, and other services you ask Anystart to use.
  • Public users and search engines: information in an active creator profile and approved public Marketplace listing, including creator attribution and reviewed capability and connector disclosures. Draft, hidden, suspended, removed, and otherwise ineligible profiles or listings are not intentionally listed publicly. Private archives, review notes, reports, and credential values are not intentionally disclosed publicly.
  • Legal, safety, and rights recipients: courts, regulators, law enforcement, affected parties, or advisers when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or establish or defend claims.
  • Corporate transaction recipients: prospective or actual purchasers, investors, lenders, advisers, and successors in connection with a financing, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality safeguards.

We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising, and we do not use personal information for targeted advertising.

7. Cookies, Local Storage, Analytics, and Choices

We use cookies and similar storage for authentication, security, language and theme preferences, billing or OAuth return flows, and analytics preferences. Some are necessary for the Services to function.

For visitors in the European Economic Area and United Kingdom, and when coarse country information is missing or cannot be classified, basic PostHog website analytics starts off until you opt in. For visitors classified outside those regions, basic analytics starts on, subject to your right to opt out. We derive this default from a coarse country code supplied at the website edge and store only an opt-in or opt-out regime cookie for this purpose, not the country code itself. An explicit basic-analytics choice overrides the regional default. When basic analytics is on, PostHog uses local storage and cookies and collects content-minimized pageviews and interactions.

Sentry Replay is a separate choice everywhere and is not installed or started before affirmative consent. If you enable it, Sentry may sample 10% of eligible website sessions and may capture a masked Replay when an error occurs, outside excluded sensitive routes. Disabling Replay stops future recording; a client-side withdrawal cannot retrieve a Replay already sent to Sentry. Global Privacy Control and Do Not Track signals suppress Replay even if a grant was previously stored, but do not by themselves disable basic first-party analytics. We do not sell or share personal information for cross-context behavioral advertising.

You can independently change basic analytics and Replay at any time through “Privacy choices” in the website footer. Choosing “Use required only” disables both optional purposes.

New desktop installations default to basic, content-free product analytics unless a local opt-out signal is present. You can change the desktop telemetry preference in the application. Required operational events may continue after optional analytics is disabled, but they are minimized and marked separately.

PostHog session recording is disabled. Sentry may sample masked website Replay for reliability and error diagnosis only after the separate affirmative choice described above.

8. Data Retention

We retain personal information for no longer than reasonably necessary for the purposes described in this Policy, including providing the Services, maintaining security, resolving disputes, enforcing agreements, and meeting legal, tax, accounting, and regulatory obligations. Retention depends on the type of information:

  • Active cloud chat sessions, messages, workspaces, and memory are generally retained while the owning account and workspace exist.
  • Deleting a chat is a soft deletion. It is hidden immediately and is ordinarily eligible for permanent purge after 30 days. Related private transcript and generated-media objects are then deleted on a best-effort basis.
  • Account or workspace deletion removes associated cloud records through database deletion rules and triggers best-effort deletion of private transcript payloads, avatars, and generated image and video objects. Provider backups, logs, or objects whose deletion temporarily fails may persist for a limited period until overwritten or cleanup succeeds.
  • If you delete an account with a creator profile, we make the profile unavailable, revoke public media access, scrub public profile content, and mark owned media for deletion. We may retain the non-reassignable creator identity, current and historical handles, a deletion tombstone, reports, and moderation history as needed to prevent impersonation and handle reuse, address abuse and appeals, resolve disputes, and comply with law.
  • If you publish Marketplace plugins, we may retain reserved slugs, publisher-agreement acknowledgements, immutable submitted and approved releases, archive hashes and security evidence, review and moderation history, reports, and limited listing metadata for existing-install restoration, update and revocation safety, abuse prevention, audit, disputes, rights claims, and legal obligations. Normal unpublishing stops discovery and new installs but does not delete installed device-local copies. Private abandoned or failed-upload objects are eligible for best-effort cleanup under operational retention rules.
  • Content made public may remain in search-engine caches, third-party archives, or copies made by others after it is removed from Anystart; we do not control those copies.
  • Subscription, transaction, tax, fraud-prevention, and accounting records are retained as required by law and legitimate business needs. Stripe may retain payment information under its own policy.
  • Security logs, analytics, diagnostics, rate-limit records, and support communications are retained for periods appropriate to their operational or legal purpose and are then deleted or de-identified.
  • Newsletter and marketing-contact information is retained until you unsubscribe, request deletion, or it is no longer needed.
  • Device-local files, caches, credentials, settings, and generated files remain until you or the operating system removes them.

We may retain de-identified or aggregated information that cannot reasonably be linked to you.

9. Security

We use administrative, technical, and organizational safeguards designed to protect personal information, including transport encryption, access controls, environment separation, private object storage, short-lived signed asset URLs, credential isolation, rate limiting, and security monitoring. No system is completely secure, and we cannot guarantee that information will never be accessed, used, or disclosed improperly. You are responsible for protecting your account credentials, device, working folders, connector credentials, and copies of data you export or save.

10. International Data Transfers

Anystart is operated by a United States company and uses providers that may process information in the United States and other countries. Those countries may have privacy laws different from those where you live. Provider terms and data-processing addenda may make contractual transfer protections available where applicable. The mechanism and processing location can vary by provider, service, and route; this Policy does not promise that information remains in one country or region.

11. Your Rights and Choices

Depending on where you live, you may have the right to:

  • request access to and a copy of your personal information;
  • correct inaccurate personal information;
  • request deletion of personal information;
  • obtain certain information in a portable format;
  • object to or restrict certain processing;
  • withdraw consent;
  • opt out of the sale, sharing, or targeted advertising use of personal information;
  • limit certain uses of sensitive personal information; and
  • appeal our refusal of a privacy request.

We do not sell or share personal information for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes that require a right to limit under California law.

You can edit certain account, workspace, memory, analytics, and creator-profile information in the Services. You can unsubscribe from marketing email using the link in the message. To exercise other rights, email [email protected]. Please describe your request and the account email involved. We may verify your identity and authority before completing a request. An authorized agent may submit a request where permitted by law, but we may require proof of authorization and direct identity verification. We will not discriminate against you for exercising a privacy right.

Rights are subject to exceptions. For example, we may retain information needed for security, fraud prevention, billing, legal compliance, disputes, and creator-handle integrity. If we deny a request, you may appeal by replying to our decision or emailing [email protected] with the subject “Privacy Appeal.”

You may also complain to the data-protection authority in your country or region. European Economic Area and United Kingdom residents may contact their local supervisory authority.

12. California Notice at Collection

In the preceding 12 months, we may have collected the following categories of personal information described by California law: identifiers; customer-record information; commercial information; internet or other electronic-network activity; geolocation derived approximately from IP address; audio, visual, or similar information in content you provide or generate; professional or employment-related information you choose to include; and inferences drawn from usage or preferences. Account credentials and the contents of communications may be sensitive personal information under California law.

We collect these categories from the sources in Section 3, use them for the purposes in Section 4, and disclose them to the recipients in Section 6. We retain them as described in Section 8. We do not sell these categories or share them for cross-context behavioral advertising.

13. Children

The Services are not directed to anyone under 18, and you must be at least 18 or the age of legal majority where you live to create an account. We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact [email protected] so we can investigate and take appropriate action.

14. Changes to This Policy

We may update this Policy to reflect changes in the Services, law, or our practices. We will post the updated Policy and effective date here. If a change materially affects your rights or how we use personal information, we will provide additional notice when required, such as by email or in-product notice. Your continued use after the effective date is subject to the updated Policy, but we will obtain consent when law requires it.

15. Contact Us

For privacy questions, requests, or complaints, contact:

Clevifai, Inc. (Anystart)

1111B S Governors Ave, Suite 45725, Dover, DE 19904 United States

Email: [email protected]

We have not appointed a Data Protection Officer or an EU or UK privacy representative. Contact Clevifai, Inc. directly at the address or email above.

For creator-profile moderation appeals or intellectual-property and other legal notices, email [email protected].