Privacy Policy
Effective 2026-10-05 · Last updated 2026-10-05
1. Who we are
ClockFlock ("we", "us") helps small businesses write social media posts in their own brand voice using AI. In the app and in our emails we are currently also called "Social Auto"; it is the same service. This policy explains what personal information we collect, why, who handles it, and what you can do about it. It covers our website and the app. We decide how and why your information is used, so we are the "controller" of it.
Today the service lets you create an account, enter your website address, get AI-written posts, and manage them in a queue. It does not take payments, does not publish to social networks (you copy the text yourself), and has no team features. If that changes, we will update this policy first.
2. What we collect
- Account: your email address, your name, and your password. We keep only a bcrypt hash of the password, never the password itself.
- Your brand: the brand name, website address, industry, voice and audience details you give us. When you enter a website address, our servers fetch that public website (text and images) to learn your brand, and we store what we need from it.
- Your posts: the topics and instructions you type, the AI-written posts, and their edit history.
- Settings and usage: your preferences, blocked words, and counters such as how many generations you have used.
- Product usage events: which pages you open and which features you use while signed in, linked to your account and kept in our own database.
- Technical logs: your IP address, browser type, the pages and API requests made, and error details, kept for security and fixing problems.
- Emails we send you: a verification email and password-reset emails, and delivery results such as bounces.
- Messages to us: anything you send to our privacy address.
Please do not put sensitive personal data (health details, government IDs, other people's private information) into the app.
3. How we use it
- To run the service: create your account, verify your email, build your brand profile and generate and store your posts.
- To keep it safe and working: prevent abuse, enforce usage limits, find and fix errors.
- To improve the product: understand which features are used, using the usage events above.
- To talk to you: send account emails and answer privacy requests.
- To meet legal duties and handle disputes.
If you are in the EU, UK or a similar region, we rely on: performing our agreement with you, our legitimate interests in running, securing and improving the service, and your consent where we ask for it. We do not use your information for advertising, and we do not sell it or share it for advertising.
4. How AI uses your content
To write posts and understand your brand, we send your brand details, text from your website, and what you type to an AI model: Anthropic's Claude models, run for us by Amazon Web Services (AWS) through its Bedrock service. The AI's output is saved as your posts.
- AWS's documentation states that model providers, including Anthropic, do not have access to the prompts and responses processed through Bedrock.
- We do not use your content to train AI models.
- AWS may keep inputs and outputs for a limited time to detect abuse, as described in AWS's own terms. We cannot control that.
- AI can be wrong or off-brand. Read every post before you use it.
7. How long we keep it, and deleting it
We keep logs only for security monitoring, finding and fixing errors, performance, preventing abuse, and meeting the rules of our providers. Each period below is the longest we keep that data; much of it is deleted sooner. When the period for logs and usage records ends, they are deleted automatically.
| What | Why we keep it | How long |
|---|---|---|
| Your account, brand, posts, edit history and settings | To run the service for you | While your account is open, and deleted within 30 days of a deletion request |
| Security and access logs (sign-ins, failed or refused requests, which address reached what) | Security monitoring and tracing unauthorised access | Up to 1 year |
| Application and API activity logs (one record per request, errors, timings) | Finding and fixing errors, performance, abuse prevention | Up to 180 days |
| Product usage events (which pages and features you use) | Understanding which features are used | Up to 90 days |
| AI usage records (count, size and cost of each AI request, never its content) | Usage limits and cost control | Up to 1 year |
| Sign-in sessions | Keeping you signed in | Until they expire (up to 30 days) or you sign out, then deleted |
| Billing and tax records | Tax and accounting law | We take no payments today. If we start, these are kept for 7 years. |
There is no "delete my account" button yet. To delete your account and everything in it, email support@clockflock.com from the address on the account.
- What happens: we confirm it is you, then within 30 days we delete your account, brands, posts, edit history, settings and AI usage records. Request records that name you are made anonymous. Logs are not searched for you; they age out on the schedule above.
- Backups: copies held by our database provider are overwritten as the backups expire, within 90 days.
- Single posts: you can delete a post yourself in the app at any time.
- What we may keep: only what the law requires us to keep.
Disposal: when data is deleted it is removed from our database, or irreversibly anonymised so it can no longer be linked to you. Deleted data cannot be restored.
8. How we protect it
- Passwords are stored only as bcrypt hashes.
- Traffic to the app is encrypted with TLS.
- Your sign-in cookie is HttpOnly, so scripts on a page cannot read it.
- Each customer's data is separated, and access is checked on every request.
- Our database and AI credentials are kept in AWS secret storage, not in our code.
No system is perfectly secure. Use a strong, unique password. If a breach affects your information, we will tell you and the regulators as the law requires.
9. Where your data goes
Our hosting, AI and email run on AWS in the United States. Our database provider, Turso, may store data in the United States or another region. If you are outside the United States, your information is transferred to and processed in the United States. Where the law requires safeguards for such transfers, such as standard contractual clauses, we rely on them. Ask us for details.
10. Your rights
Depending on where you live, you can ask us to tell you what we hold about you, give you a copy, correct it, delete it, limit or stop how we use it, or withdraw consent you gave. You will not be treated worse for asking. Email support@clockflock.com; we may ask you to confirm it is you, and we reply within 30 days. If you are not happy, you can complain to your data protection authority (in the UK, the Information Commissioner's Office). In some US states you can also appeal a refusal by replying to our answer with the word "Appeal". We do not sell personal information or share it for advertising.
11. Children
The service is for businesses and is not meant for anyone under 18. We do not knowingly collect information from children. If you think a child has given us information, email support@clockflock.com and we will delete it.
12. Changes to this policy
When we change this policy we update the "last updated" date. For material changes we will email the address on your account or show a notice in the app before they take effect.
13. Contact us
ClockFlock is operated by Priyal Hareshbhai Desai, a sole proprietor trading as Adorn By You, based in Mumbai, Maharashtra, India. Privacy questions and requests: support@clockflock.com.