Basalt Labs ("we," "us," or "our") operates the Cleo personal assistant service ("Service"). This Privacy Policy describes how we collect, use, and protect your information when you use the Service.
When you create an account, we collect:
When you choose to connect your Google account via OAuth 2.0, you grant Cleo access to:
calendargmail.modify scope. Cleo does not delete emails.We do not request access to Google Drive, Google Photos, Google Contacts, or any other Google services.
We use the information we collect solely to provide, maintain, and improve the Service:
We do not use your personal information for advertising, profiling, or any purpose unrelated to providing the Service.
Cleo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
To deliver the Service, we rely on the following third-party providers. Your data is shared with these services only to the extent necessary for Cleo to function:
Provides voice synthesis and conversational AI processing. Your voice interactions are transmitted to ElevenLabs for real-time speech-to-text and text-to-speech conversion. ElevenLabs processes this data in accordance with their Privacy Policy.
Provides large language model reasoning capabilities that power Cleo's ability to understand requests and formulate responses. Conversation content is processed by Anthropic's Claude model through ElevenLabs' agent infrastructure. Anthropic's data handling is governed by their Privacy Policy.
Provides telephony infrastructure for outbound calls and SMS messaging. Your phone number and call-related data are shared with Telnyx solely for the purpose of placing calls and delivering SMS notifications. Telnyx processes this data in accordance with their Privacy Policy.
When you connect your Google account, we use Google's OAuth 2.0 protocol to obtain a refresh token, which is stored securely and used to access your Calendar and Gmail on your behalf. We access only the scopes you explicitly authorize. Your Google data is used solely to fulfill your requests and is not shared with any other party.
Provides database infrastructure. Your account data, authentication tokens, and knowledge base entries are stored in a PostgreSQL database hosted by Supabase with row-level security policies and encryption at rest.
Provides web hosting and serverless function execution. All API requests are processed through Vercel's serverless infrastructure. Vercel processes request data in accordance with their Privacy Policy.
Each third-party service is governed by its own privacy policy. We encourage you to review their respective policies.
Your data is stored in a Supabase-hosted PostgreSQL database with Row Level Security (RLS) policies enforced. All database access is performed server-side through authenticated serverless functions using a service role key. The browser client never communicates with the database directly.
We implement the following security measures:
While we take reasonable measures to protect your information, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security.
We retain your personal data for as long as your account is active or as needed to provide the Service. Specifically:
You may request deletion of your account and all associated data at any time by contacting us at contact@basaltlabs.app. Upon receiving a verified deletion request, we will delete your user profile, knowledge base entries, OAuth tokens, and conversation data. Deletion will be completed within 30 days. Some data may be retained in infrastructure backups for a limited period, after which it will be permanently purged.
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If you are under 18, please do not use the Service or provide any personal information. If we become aware that we have collected data from a person under 18, we will take steps to delete that information promptly. If you believe a minor has provided us with personal data, please contact us at contact@basaltlabs.app.
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will update the "Effective" date at the top of this page and, where appropriate, notify you via the Service or email.
Your continued use of the Service after any changes to this Privacy Policy constitutes your acceptance of the updated terms.
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us: