Privacy Policy

How we collect, use, and protect your information.

Last updated July 26, 2026

This explains what Clampdown collects, why, and who else sees it. It covers the marketing site, the free tools, and the product.

What we collect

  • Account details. Your name and email address, and your password stored only as a salted hash. If you're part of a team, we also store which organisation you belong to and your role in it.
  • Session records. When you sign in we store a session token along with the IP address and browser user-agent it was created from, so we can expire sessions and spot suspicious sign-ins.
  • What you ask us to protect. Titles and details of your work, plus the findings our scans produce — URLs, the sites they sit on, classifications, and the notices we send about them.
  • Free audit submissions. The audit tool takes the type of work, its title, the creator name, an optional email address, and an optional price. Price is used only to estimate revenue loss. If you give us an email, we use it to send you the result and to follow up about Clampdown; you can tell us to stop.
  • Messages you send us. Support and sales email, and anything you tell us on a call you book.
  • Error and performance telemetry. When something breaks we collect a diagnostic report — the page, the error, browser and timing data. Session replay is configured to mask all text and form inputs and to block media, so replays show layout and interactions rather than content.

We don't run advertising or analytics trackers on this site, and we don't buy personal data from anyone.

How we use it

To run the service: scan for copies of your work, produce findings, send removal notices as your agent, and show you what happened. To keep accounts secure and stop abuse of the public tools. To bill you. To answer you when you get in touch, and to tell you about changes that affect your account. To fix crashes and make the product faster.

Takedown notices are not private

Worth reading twice: a removal notice has to identify the work and the person claiming it. When we send one on your behalf, the recipient — a host, a platform, a search engine — sees your name or your organisation's name, the work, and the URLs complained about. Some recipients pass notices to the uploader, and some publish them to public transparency archives. We can't pull that back once a notice is sent. Tell us before we file if you need a particular name used.

Who we share it with

We don't sell your data. We use these providers to run the service, and they only get what they need for their part:

  • Cloudflare — hosting, the D1 database your data lives in, transactional email, and the bot check on the audit form.
  • Apify — runs the scans that search public sources. It receives the search terms derived from the title you asked us to protect.
  • Sentry — error and performance monitoring, with the masking described above.
  • Cal.com — the booking page. If you book a call, they handle your name, email, and the times you pick.
  • Hosts, platforms, and search engines — the recipients of the notices you ask us to send.

We'll also disclose data if the law requires it, and if the business is ever sold or reorganised your data may transfer with it — you'd be told first.

Where it's processed

The service runs on Cloudflare's global network, and the providers above operate internationally, so your data may be processed outside your country.

How long we keep it

Account and organisation records: while your account is open, then deleted or anonymised after closure. Findings and notice history: kept while the account is open, since you may need the record of what was sent. Free audit submissions: kept so the result stays retrievable, and deleted on request. Diagnostic telemetry: kept for the limited window Sentry retains it. Anything we're required to keep for tax or legal reasons is kept for that period.

Your rights

Ask us and we'll give you a copy of your data, correct it, delete it, or stop using it for follow-up email. Write to privacy@clampdown.ai and we'll answer within 30 days. Depending on where you live you may also have the right to complain to a data protection authority.

Cookies

We set a cookie to keep you signed in, and store your light/dark preference in your browser. That's it — no advertising or cross-site tracking cookies, which is why this site has no cookie banner. Blocking the session cookie means you can't sign in.

Children

Clampdown isn't intended for children, and we don't knowingly collect their data. If you think a child has given us information, email us and we'll remove it.

Changes to this policy

When this changes, the date at the top changes with it. If a change materially affects how we use your data, we'll email account holders.

Contact

Questions about this policy? Reach us at privacy@clampdown.ai.