Privacy Policy
CleverSets is operated by Lysmata Systems, LLC ("Lysmata," "we," "us"). This policy describes what we collect, why, and the rights you have. The short version: we collect what we need to run the service for you, we don't run ads, we don't sell or share your data for anyone else's commercial purposes, and AI processing of your content only happens if you turn it on.
What we collect
- Account info — email address, display name, optional handle.
- Content you upload — photos, videos, documents, notes, contacts, and the metadata attached to them (titles, dates, tags, locations you enter).
- Usage data — pages viewed and actions taken, used for debugging, security, and capacity planning. Never for advertising.
- Device info — browser user agent, IP address, language preference, viewport size for UI fit.
- Security event records — a record of security-relevant events on your account: sign-ins, registrations, region checks, Terms acceptance, enforcement actions taken on the account, and administrative actions. Each record includes the IP address the request came from, the approximate region, the browser user agent, and the outcome.
- Billing data — if you subscribe, our payment processor (Stripe) collects your payment details. We receive only the subscription state and a customer reference — we never see or store your full card number.
What we don't do
- No third-party tracking. We don't embed Google Analytics, Facebook Pixel, ad pixels, or equivalent. Our only telemetry is Azure Application Insights, collected through our own first-party endpoint. That operational telemetry stores a one-way hash of your IP address rather than the address itself; the address appears in readable form only in the security event records described below.
- No advertising. We don't sell ads or share your data with advertisers — including against content you publish publicly.
- No selling your data or content. To anyone, for anything.
- No AI training on your content. Your data is not used to train external AI models. AI features run inside our own Azure environment and your content stays within our trust boundary — the one narrow exception is the opt-in web-research features, which send only your search terms (never your private content) to a third-party search provider, described below.
How we use what we collect
- Operating the service — storing your content, generating thumbnails and streaming versions, fanning out shares, indexing search, computing your usage against your plan's allowances.
- Legally required scanning — every uploaded image and video is checked against an industry hash-list of known child sexual abuse material (Microsoft PhotoDNA), as US federal law (18 U.S.C. § 2258A) requires. This matching identifies only known, verified illegal material; it does not otherwise analyze private content.
- Public-content safety — content you publish to a public link is additionally scanned by an automated content-safety service for severe hate, sexual, violence, and self-harm content before it goes live.
- AI features (opt-in only) — if you enable AI assistance in Settings, your content may be processed by AI models running in our own Azure environment to produce things like captions and alt-text, recognized text (OCR), search vectors, and organization and planning suggestions. Those models are Microsoft's (Azure OpenAI) and Anthropic's (Claude), both deployed to our own Azure AI account and reached over Azure — we do not send your content to Anthropic's or OpenAI's own consumer services. This includes the conversational assistant: the messages you type to it are processed the same way — inside our environment — to answer you and to prepare the changes it proposes for your approval. You can see what was extracted per item, exclude individual items, and turning the feature off deletes the derived data.
- AI web research (opt-in, per use) — some AI features can look up information on the public web for you, such as finding prices or product options for items on a list. When you use one, only the specific search terms needed — such as the names of the items you ask us to research — are sent to a third-party search provider (Brave Search), which returns public results and handles those search terms under its own terms, not as our data processor. We don't send your photos, notes, contacts, or personal information, and we don't identify you to them; the results are public web content, shown to you to review before anything is saved. As a further check, if a search the assistant is about to run contains something that looks like personal or sensitive information — an account or card number, an address, an email address — we pause it and show you the query first. Nothing is sent until you choose to send it.
- Improving the AI assistant (only what you choose to send) — if a conversation with the assistant didn't go the way you expected, you can choose to share that conversation with us. When you do — and only then — the messages you typed, the assistant's replies, the proposals it showed you, and basic diagnostics (such as timestamps) are sent to our team to review and improve the assistant. We ask you to confirm first, it is used only for that purpose, and nothing else in your account is included.
- Security, abuse prevention, and forensics — we keep a durable record of the security-relevant events listed above, together with the IP address each request came from. We use it to investigate automated signups and account compromise, to enforce our Terms, and to be able to show afterwards that an enforcement decision was applied correctly. These records are held separately from our operational telemetry, with restricted access, and are never used for advertising, profiling, or any purpose other than security.
- Communicating with you — account email only (verification, password reset, billing receipts, urgent security or policy notices). No marketing email.
Where your data lives
CleverSets runs on Microsoft Azure in the United States. Your content is encrypted in transit and at rest; backups are co-resident in the US.
Federation (the fediverse)
If you turn on fediverse features — an optional setting that is off by default — some data intentionally leaves our servers:
- Your public posts and the public profile for your fediverse handle are delivered to independent servers (such as Mastodon) so that people there can follow you and read them. Those servers are operated by others, in their own locations, under their own policies; once data reaches them it is outside our control. Only public posts are ever sent — never private content or content shared with named people.
- When you follow an account on another server, we fetch and may cache that account's public posts and attached images so your feed loads reliably. We store those copies in the US alongside your other content and scan any cached media for CSAM, exactly as we do for uploads. If cached media matches, it is handled as the originating server's or account's content — and reported to authorities accordingly — never attributed to you for having followed them.
Turning fediverse features off stops future delivery and new fetching. Copies that have already reached other servers cannot be recalled with certainty, as explained in our Terms.
Who processes data on our behalf
We use a small set of service providers, each bound by data-protection obligations and none of whom may use your data for their own purposes:
- Microsoft Azure — hosting, storage, databases, AI services (including the Azure OpenAI and Anthropic Claude models we run on Azure AI Foundry), and transactional email delivery (Azure Communication Services).
- Stripe — payment processing for subscriptions and one-time purchases.
- Microsoft PhotoDNA service — the legally required CSAM hash-matching described above.
We also disclose data when the law requires it: court orders, subpoenas, and CyberTipline reports to the National Center for Missing & Exploited Children (NCMEC) for CSAM matches.
And of course, anything you share or publish is visible to the people (or public) you chose — that's the product working as intended.
Retention
- Account data and content — retained while your account is active; permanently purged after account deletion completes (a 14-day grace period, then the purge), subject to the exceptions below.
- Messages you sent to others — the copies already delivered to your recipients remain in their inboxes, attributed to "Deleted account," the same way an email you sent remains with its recipient.
- Your handle — permanently reserved after deletion and never reissued, so no one can impersonate the deleted identity.
- Moderation records — reports and enforcement decisions are retained as evidence of enforcement, and content quarantined by our CSAM pipeline is preserved per the CSAM entry below.
- CSAM evidence — positive hash-matches are preserved in a restricted-access vault for 90 days as federal law requires, then purged — whether the material was uploaded to CleverSets or cached from another fediverse server.
- Administrative audit logs — retained while the platform operates; personal-data fields are anonymized when your account is deleted.
- Security event records — retained for 24 months, then purged. The IP address in a record is never stored apart from that record and never outlives it. Because these records are what let us investigate abuse and evidence our enforcement decisions, they survive account deletion for the remainder of that period.
- Unsaved assistant conversations — a conversation you have not saved is kept for 30 days after you last add to it, so you can pick it back up after closing a tab, and continue it on another device. We keep your ten most recent. You can see them under "Pick up where you left off" in the assistant, and delete any of them there; saving one moves it into your own things, where it stays until you delete it. Deleting your account deletes them.
- Shared assistant conversations — a conversation you choose to share with us for review is kept only as long as we need it to review and improve the assistant, then deleted. It is held with our other feedback submissions, with restricted access, and is never used for advertising or profiling.
- Terms/Privacy acceptance records — retained while your account is active. On deletion, a single anonymized record per accepted version (hashed IP and user agent, version, date) is kept for seven years to evidence consent in case of a dispute, then purged.
- AI-derived data — deleted when you turn AI assistance off, and on account deletion.
- Billing records — retained as tax and accounting law requires.
Your rights
- Access — your content is yours to see, always.
- Correction — edit anything you've uploaded.
- Deletion — delete content individually at any time, or your entire account from Settings (app) or Profile (web). A 14-day grace period applies (sign back in to cancel); after it your account and content are permanently purged, subject to the Retention exceptions above.
- Export — bulk-export your library from Settings.
- AI opt-out — toggle AI assistance off in Settings; derived data is deleted.
We honor these rights for everyone, not just where a specific state statute requires it. Data-subject requests: support@cleversets.com.
Children
CleverSets is not directed to children under 13 and we do not knowingly collect data from them. If we learn we have, we'll delete it.
Account succession
Adult account holders can designate up to three legacy contacts (Settings → Legacy) and choose a disposition — export, memorialize, or delete after a grace period — that controls under applicable digital-assets law (RUFADAA) if you die or become incapacitated. Without a designation, we retain your content and lock the account pending lawful instructions through your estate. Memorialized accounts keep public content visible; private content stays private and is never disclosed.
Breach notification
If a breach affects your personal data, we will notify you and the relevant authorities as applicable law requires, without undue delay.
Changes to this policy
Material changes — anything that changes what we collect, how we use it, or who can see it — require your re-acceptance before you continue making changes to your data; reading your existing content is never blocked. Minor clarifications are announced with a banner. Every prior version remains publicly viewable at its own permanent link.
Contact
Privacy questions, data-subject requests, and RUFADAA-related inquiries: support@cleversets.com.
Version 10 — effective 2026-08-22. Supersedes version 9 (effective 2026-08-16).