Legal

Privacy

What cleap collects, what it keeps, who else touches it, and how to get rid of it. Written to be read, not to be scrolled past.

1. The short version

cleap reads your code to build a map of it, keeps the map rather than the code, and never writes anything back.

Everything below expands on that. If you want the mechanics rather than the policy, the data page walks through the same ground in order, with the specific permissions and vendors named.

2. What we collect

Your account details, the repositories you connect, and the map built from them.

Account. Your email address, your name if you give one, and the workspace and products you create. If you sign in with Google, we receive your email address, name and profile picture from Google, and nothing else.

Repositories. When you connect a repository through the cleap-ingest GitHub App, we read its files, its structure and its commit history to build the map. The App has no write permission of any kind.

The map. What we store is the map: the files and symbols that exist, how they refer to one another, plain-English labels, and signals like how often a file changes. Your source files are not stored in our database. When you open a file's code in the app, that file is fetched from GitHub at that moment.

Usage. Ordinary server logs. cleap runs no third-party analytics or tracking scripts.

3. What we use it for

Running the product for you, and nothing else.

We use what we collect to build and update your map, to answer your questions about it, to keep your account working, and to contact you about the service. We do not sell your data, and we do not share it with anyone except the providers listed below, who process it on our behalf in order to run the service.

4. Where AI is involved

Model providers see slices of your map, and the code excerpt in question when you ask a code-level question.

Plain-English labels and answers in Ask cleap are produced by Anthropic's Claude models, given the relevant slice of the map, and for a code-level question the excerpt in question. Anthropic's API terms do not permit training on it.

Your code is never used to train a model, by us or by anyone else.

5. Who can see it

The people in your workspace, and nobody else.

A map is scoped to the workspace that created it. Members you invite can see it; nobody outside it can. A document you deliberately share by link is the one exception, and only for as long as that link exists.

A repository added to the public showcase gallery is a curated open-source repository we have chosen. Your repositories are never added to it.

6. Who processes it for us

Seven companies, each for one purpose.

Accounts and maps are stored in Supabase, on Postgres hosted in AWS us-east-1. The service that reads repositories runs on Railway. The site itself is served by Vercel. Model calls go to Anthropic. Repository access is through GitHub. Firecrawl reads a public link you paste as document context, and nothing else. Resend delivers invitation and account email. Each is used only for the purpose described here, and the security page says what each one can see.

This means your data is processed in the United States as well as in the United Kingdom. Those transfers rely on the standard contractual clauses in each provider's own data processing terms. If that matters to your organisation, ask us and we will tell you exactly what is stored where.

7. How long we keep it

Until you delete it.

Disconnecting a source deletes its map. Deleting a workspace deletes everything in it, including its products, members, invites and GitHub connections. Revoking the GitHub App on GitHub stops all reads immediately, even before you delete anything here.

Deleting your account removes your profile, your workspace memberships, your comments and pins, your saved views and renamed nodes, and any API keys you created. Maps and documents in a workspace other people keep using stay, without your name attached. A workspace you own alone has to be handed to someone else or deleted first, because a workspace with no owner cannot be reached by anyone left in it.

8. Your rights over it

You can see it, correct it, export it or have it deleted, by asking.

Most of this you can do yourself in the app, including closing your account: Account settings has a Delete your account section that removes your sign-in and everything that is yours alone, with no grace period and no way back. For anything you cannot do yourself, email hello@cleap.dev and we will do it. Depending on where you live you may have specific statutory rights over your personal data, including access, correction, deletion and portability. We honour those requests regardless of where you live.

9. How it is protected

Encrypted in transit and at rest, with access limited to what running the service requires.

We do not claim any certification we do not hold. If your organisation needs a security review before connecting a repository, ask and we will answer specific questions honestly, including the ones where the answer is that we do not do that yet.

If a breach ever affects your personal data, we will tell you and the relevant authority within 72 hours of becoming aware of it.

10. Cookies and browser storage

No analytics or tracking cookies. Browser storage is used to keep you signed in.

cleap sets no advertising or analytics cookies, and runs no third-party tracking scripts. Your session is held in your browser's own storage so you stay signed in, and a few small preferences, such as which panels you last had open, are kept the same way. Clearing your browser storage signs you out and resets those preferences.

11. Children

cleap is not for anyone under 16.

We do not knowingly collect personal data from children under 16. If you believe we have, email us and we will delete it.

12. Changes to this policy

We will tell you before a change that materially affects you takes effect.

The date at the bottom of this page is when the current version took effect. Continuing to use cleap after a change means you accept the updated policy.

13. Who we are

cleap is a product of Movemoni Ltd, registered in England and Wales, Company No. 16851668.

Movemoni Ltd is the data controller responsible for your personal data. For data protection questions specifically, you can also reach the company's data protection contact at dpo@myclariti.com, which covers all of the company's products.

If you are in the UK or the EU you have the right to complain to your data protection authority. In the UK that is the Information Commissioner's Office.

14. Contact

hello@cleap.dev.

A real person reads it. If something on this page does not match what you actually see in the product, that is a bug in the page and we want to know.

In effect from 9 September 2026.Questions, or something here that does not match what you see? Tell us