Clueless Creations

Legal

Privacy Policy

This policy covers the Clueless Creations marketing site, the account console, and the hosted knowledge service that AI coding agents connect to. It describes what we actually process, not what a template says we might.

Last updated

What is live today

Clueless Creations is being built in the open, and this policy is written against what is actually running, not a template of what a company like ours might eventually do. Each processing activity below carries a status and, where it switched on partway through this policy’s life, the date it did. Anything we have not built yet is simply not described here — if a future activity is marked planned, that means we have said in advance what it will do before switching it on, and we do not carry it out before then.

SurfaceWhat it doesStatus
clueless-creations.com Marketing pages and the waitlist / interest form live
mcp.clueless-creations.com Read-only knowledge service for AI coding agents, over MCP and HTTP live — private access only
app.clueless-creations.com Google sign-in, the console, API keys, and Stripe Checkout live
Product analytics PostHog — in the account console, plus one daily activity signal from the knowledge service switched on 2 September 2026

Who we are

Clueless Creations LLC (“Clueless Creations”, “we”, “us”) is the controller of the personal data described in this policy. Our postal address is 2112 Woodland Ave, Park Ridge, Illinois 60068.

For anything in this policy — a question, a rights request, or a complaint — write to privacy@clueless-creations.com. A person reads that inbox; there is no ticket queue in front of it.

EU and UK representative

We are established in the United States and have not appointed a representative under Article 27 of the GDPR or the UK GDPR. We sell subscriptions to people in the EEA and the UK, so appointing one is likely to be required. This is an open item, stated here rather than left implied.

What we process, why, and on what legal basis

“Legal basis” refers to Article 6 of the UK and EU GDPR. If you are outside those jurisdictions the same activities apply; the legal-basis column simply will not be the framework your local law uses.

Waitlist and interest form live

DataSourceWhyLegal basis
Email addressYou type itTo reach you when access opensConsent
Which plan you are interested inThe formTo size and sequence the betaConsent
Free-text note (“what are you trying to build”)You type it, optionalTo understand what people needConsent
Where you heard about us / which page you submitted fromThe formTo know which channels workConsent
Timestamps and submission countOur serverTo deduplicate repeat submissionsConsent
Browser user-agent stringYour request headersSpam and abuse triageLegitimate interests
CountryDerived by Cloudflare from your IP addressSpam triage and knowing where demand isLegitimate interests

The free-text note is exactly that — free text. Please do not put anything sensitive in it. We do not ask for and do not want health, financial, biometric, political, religious, or similar special-category information, and it is not needed to join the waitlist.

You can withdraw your consent at any time by emailing us; that removes you from the list and is as easy as joining was. Withdrawing consent does not affect processing carried out before you withdrew it.

Account and sign-in live

DataSourceWhyLegal basis
Google account identifier, email address, verified-email flag, display name, profile picture URLGoogle, when you choose “Sign in with Google”To create and identify your accountPerformance of a contract
Session cookieSet by us at sign-inTo keep you signed inStrictly necessary
API keys you createGenerated by us, stored only as a one-way hashTo authenticate your agent to the knowledge servicePerformance of a contract
Records of when your account used the service — sign-in times, when a session was last active, and when an API key was last usedOur serverAccount security, and so you can spot a key you no longer recogniseLegitimate interests
A log of significant actions on your account, such as creating or revoking a keyOur serverSo that a change to your account can be accounted forLegitimate interests

We request only three Google scopes — openid, email and profile. We do not request access to your Gmail, Drive, Calendar, Contacts, or any other Google service, and we cannot read them. The Google Data Policy sets out exactly what we do and do not do with that data, including our commitment not to sell it and not to train AI models on it.

Subscriptions and payment live

DataSourceWhyLegal basis
Name, email, billing address, countryYou, via StripeTo bill you and meet tax obligationsContract; legal obligation
Card detailsYou, entered directly into StripeTo take paymentContract
Subscription status, invoices, entitlement recordsStripeTo decide whether your account has accessContract
Card data never reaches us

Payment card numbers are collected by Stripe and never touch our servers. We see a customer identifier, subscription status, and invoice metadata. We cannot see or recover your card number, and neither can anyone we work with.

Using the knowledge service live

When your AI coding agent connects to mcp.clueless-creations.com, we process the credential it presents and the authorisation records that back it. Concretely, we store the account the credential belongs to, a SHA-256 hash of the credential, the permissions granted, and whether it has been revoked. We also apply rate limits keyed on the requesting IP address and on the account.

What we deliberately do not keep

We do not store your query history. The service records no log of which knowledge documents you or your agent requested, no request paths, and no query text, and it runs with request logging switched off. This is a design property of the service, not a promise about restraint.

It loads no analytics SDK. The one signal it sends is a single daily activity record, described in Product analytics below, which says that an account used the service on a given date and nothing about what it asked for.

Legal basis: performance of a contract for the access itself, and our legitimate interest in keeping the service secure and available for the rate limiting and abuse controls.

Product analytics switched on 2 September 2026

We use PostHog to understand which parts of the product get used and where people get stuck. It switched on for the account console, and for the knowledge service’s one daily activity signal, on 2 September 2026 — the same day we published this description of it. It works differently on our two surfaces, so they are described separately.

If you are in the EEA or the UK

We do not run analytics on requests we identify as originating in the EEA or the UK. Nothing is initialised, no identifier is stored on your device, no event is sent, and no analytics record is written on our side either — not even the internal counter that notes an account was active on a given day. The check runs before anything is captured or stored, rather than after.

To be exact about what the suppression does and does not cover, where it applies: it suppresses analytics, not the service. If you join the waitlist or hold an account, we still store what that actually requires — described elsewhere on this page, with its own retention. We are not quietly declining to serve you; we are declining to measure you.

Being straight about the limit of that: we identify origin from the country of the network connection. For an ordinary browser that is reliable. If you reach the knowledge service through an AI agent hosted elsewhere, the connection’s country is the agent’s host rather than yours.

In the account console

No analytics script runs in your browser here. The console does not load PostHog’s JavaScript, so nothing observes your clicks or the pages you view in real time, and nothing analytics-related is set in your browser — see Cookies below. Instead, our own server sends a fixed, short list of events at the moment a specific action happens:

DataSourceWhyLegal basis
That a sign-in started, completed, or failedOur server, when you use “Continue with Google”To see whether sign-in worksLegitimate interests
That an account was createdOur server, on your first sign-inTo measure activationLegitimate interests
That an API key was created or revokedOur server, when you manage keysTo see whether the console worksLegitimate interests
That the interest form was submittedOur server, when you submit it — the form is shown only when checkout is unavailable, so this event fires only thenTo see whether that flow worksLegitimate interests

Each event carries your account identifier and a small number of properties about the action itself — never a page URL, never anything you typed, and never a record of pages you merely viewed. This runs on our legitimate interest in knowing whether the console works, not on your consent, and the objection right described under “From the knowledge service” below applies to these events too.

Four things it deliberately does not do

  • No session recording. We do not replay your session or capture your screen. It is switched off in the configuration, not merely unused.
  • No automatic capture, because there is no browser script to do the capturing. Every event above is emitted by our server when the action happens; there is no client-side analytics tag in the console recording clicks, form fields, or anything else.
  • Your email address and your name are never sent. The identifier attached to analytics is your account identifier with us — not your email, not your name, not your Google account identifier. One deliberate exception, stated so you are not surprised by it: when you give us an email address, our analytics receives the domain part only — the part after the @ sign, such as example.com — so we can tell a business signup from a personal one. The address itself never leaves us.
  • PostHog does not receive your IP address from us. These events travel server-to-server: our Worker sends them directly to PostHog, so there is no browser request for PostHog to see your IP address from. We also operate a same-origin relay built for a future browser-based analytics tag; it is deployed, but nothing on the console sends traffic through it today, and if that changes this page changes first.

From the knowledge service

One event, at most once per account per day: that an account successfully used the service, the name of the AI client it connected with, and the date. It carries no query text, no document identifiers and no request paths. Alongside it we keep a short-lived key in our own storage, expiring after 48 hours, recording that the account was active that day so we do not count it twice.

The identifier is the subject on your access credential. It is pseudonymous, not anonymous: it is not your email address, but we can connect it back to your account, so this is personal data and every right described below applies to it in full. We would rather say that plainly than let “opaque identifier” imply more distance than there is.

Nothing is stored on your device for this, and no software runs on your machine for it. Legal basis: our legitimate interest in knowing whether the service is being used at all — the same basis the console events above run on. Because that basis depends on you being able to say no: email us and we will delete the analytics records we hold for your account, across both the console and the knowledge service, and stop counting it from then on. No reason needed, and it will not affect your access. Today that is something an operator does for you by request, not a self-serve toggle in the console — if that changes, this page changes first.

Cookies and similar technologies

This website sets no cookies at all. No analytics tag, no advertising pixel, no embedded third-party widget, and the fonts are served from our own domain rather than from Google. Nothing on these pages needs your consent, which is why you are not being interrupted by a banner.

The account console is different. It sets the following, and nothing else — no analytics cookie and no analytics entry in local storage, because the console loads no browser analytics script for either to belong to. If that ever changes, this page changes first.

NameTypePurpose LifetimeConsent
__Host-b2c-session Cookie Keeps you signed in 30 days, or until you sign out or it is revoked Strictly necessary — not optional
__Host-b2c-oauth-state Cookie Holds a random value for the few seconds you are mid-sign-in, so we can confirm the redirect Google sends back is the one we started 5 minutes, or until sign-in finishes Strictly necessary — not optional

Both cookies are __Host- prefixed, which forces them to be Secure, forbids a Domain attribute, and pins them to Path=/ — in practice, a browser will not send either one to any other subdomain, including this marketing site or mcp.clueless-creations.com. There is no separate CSRF cookie: the form protection the console uses is a signed value embedded in the page itself, not a second cookie.

Who else processes your data

We keep the list short on purpose. These are the only companies that process personal data on our behalf, or that we hand personal data to. We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not give it to data brokers.

CompanyWhat they do for usWhat they processStatus
Cloudflare, Inc. (US) Hosting, CDN, edge compute, and all our data storage Everything described in this policy, plus IP addresses at the network layer live
Stripe, Inc. (US) Payments, subscriptions, and the entitlement records that gate access Email, and the name, billing address, and card data you enter into Stripe; subscription and invoice records live
Google LLC (US) “Sign in with Google” Your Google account identifier, email, name and profile picture URL live
PostHog, Inc. (US) Product analytics Your account identifier, the console and knowledge-service events described above, the domain part of your email address, and nothing from your browser — no visitor identifier, no pages viewed, no feature flags, and never your email address itself, your name, or your IP address switched on 2 September 2026

A note on Google: for the sign-in itself, Google is not acting for us. Google decides on its own account how it handles your Google Account, governed by Google’s Privacy Policy. We are responsible for what we do with the data Google passes to us once you approve the sign-in, which is what our Google Data Policy describes.

We will also disclose personal data where the law requires it — a valid legal demand, or to establish or defend legal claims. If Clueless Creations is ever sold or merged, account data would transfer with the business; we would tell you before that happened and before your data became subject to a different privacy policy.

We will update this table before adding any new processor, not afterwards.

International transfers

We are based in the United States and our infrastructure providers are US companies operating globally distributed networks. If you are in the EEA, the UK, or Switzerland, your personal data will be transferred outside your country. Our analytics provider, PostHog, is on its US cloud specifically — which is one of the reasons we do not run analytics for visitors we identify as being in the EEA or the UK at all.

Those transfers rely on the Standard Contractual Clauses adopted by the European Commission (and the UK International Data Transfer Addendum where the UK GDPR applies), incorporated into our data processing agreements with each provider listed above. Some of those providers also self-certify under the EU–US Data Privacy Framework; where they do, that certification applies in addition.

What we are not claiming

Clueless Creations is not itself certified under the EU–US Data Privacy Framework, and holds no ISO 27001, SOC 2, or equivalent certification. We have not completed any of those programmes and do not claim their protections. Where this policy describes a safeguard, it describes something we actually do.

You can ask us for a copy of the transfer safeguards that apply to your data by writing to privacy@clueless-creations.com.

How long we keep things

DataKept forThen
Waitlist and interest-form entries 24 months from your last interaction with us Deleted, including the copy held in our payment provider’s records
Account record, profile, and API keys For as long as your account is open Deleted within 30 days of account closure
Invoices and payment records As long as tax and accounting law requires, typically up to seven years Deleted
Access tokens issued to your agent 10 minutes Expire automatically
Refresh tokens 7 days Expire automatically
Registered agent client records 90 days Expire automatically
Knowledge-service query history Not collected
Product analytics events No more than 12 months Deleted
The knowledge service’s daily de-duplication key 48 hours Expires automatically
Records of when your account last used the service, and of actions taken on it For as long as your account is open Deleted within 30 days of account closure

Where a longer period is needed to resolve a dispute, enforce our agreements, or meet a legal obligation, we keep only what that specific purpose requires and delete the rest.

Your rights, and how to use them

If you are in the EEA or the UK, the GDPR gives you the rights below. If you are in California, Colorado, Connecticut, Virginia, or another US state with a comprehensive privacy law, you have closely equivalent rights. We are a small company and may not meet the applicability thresholds in every one of those state laws — so rather than work out which apply to you, we extend all of these rights to everyone who contacts us, wherever you live.

  • Access — get a copy of the personal data we hold about you.
  • Correction — have inaccurate data fixed.
  • Deletion — have your data erased, subject to records we must legally keep.
  • Portability — receive the data you gave us in a structured, machine-readable file.
  • Objection — object to processing based on legitimate interests, and to direct marketing at any time and without needing a reason.
  • Restriction — ask us to pause processing while a dispute is resolved.
  • Withdraw consent — for anything we do on the basis of consent, including the waitlist. (Analytics runs on legitimate interests, not consent — see Objection above, and Product analytics.)
  • Non-discrimination — we will not degrade your service or charge you more for exercising any of these rights.

How to make a request

Email privacy@clueless-creations.com and say what you want. You do not need a particular form of words or a legal citation.

  • We reply within 30 days. If a request is genuinely complex we may extend that, and we will tell you why before the 30 days are up.
  • It is free. We will only charge for a request that is manifestly excessive or repetitive, and we would tell you first.
  • We may need to confirm you are who you say you are — usually by asking you to write from the email address on the account.
  • You may use an authorised agent; we will ask for proof of their authority.

For account holders, deleting your account from the console deletes your account data on the schedule in the retention table. You do not need to email us to do that.

If you think we have got something wrong, please tell us first — we would rather fix it. You also have the right to complain to a data protection authority: in the EEA, the supervisory authority where you live or work; in the UK, the Information Commissioner’s Office.

Security

Some concrete things rather than adjectives. All traffic is HTTPS, with HSTS preloaded. API keys are stored as one-way hashes, so a copy of our database does not yield a working credential. Access tokens live for ten minutes. The session cookie is __Host- prefixed and cannot be sent to another subdomain. Secrets are held in a dedicated secret manager and never committed to source control. The account console and the knowledge service run as separate applications so that a fault in one does not become access to the other, and the payment webhook is deliberately kept off the authorisation server.

No system is perfectly secure, and we will not pretend otherwise. If there is a breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours where the law requires it, and tell you directly without undue delay where the breach is likely to present a high risk to you.

Reporting a vulnerability or a suspected breach

Email security@clueless-creations.com, or use the contact published at /.well-known/security.txt. Please include enough detail to reproduce the issue. We will acknowledge you, and we will not pursue legal action against good-faith security research that respects user privacy and does not degrade the service.

Children

This is a developer tool and it is not for children. You must be at least 16 to use it, and at least 18 to buy paid access if we ever offer it. We do not knowingly collect personal data from children. If you believe a child has given us their data, email us and we will delete it.

Automated decisions and AI training

We do not make decisions about you by automated means that produce legal or similarly significant effects, and we do not profile you. The one automated decision in the product is whether an API key is valid and within its rate limit, which follows directly from the key record and the request count.

We do not use your personal data to train, fine-tune, or improve any machine-learning or AI model, and we do not provide it to anyone else for that purpose. The knowledge the service returns is written by us; it is not derived from customer data. This commitment is repeated, in Google’s own required terms, in our Google Data Policy.

Changes to this policy

When we change this policy we update the date at the top of the page. If a change materially affects how we handle your personal data, we will email account holders before it takes effect, and where the change requires your consent we will ask for it rather than assume it.