Privacy Policy. What we collect, why, and the control you have over it.
Cleyo is built for recruiters who handle other people's data every day, so we hold ourselves to a high bar.
Last updated: July 22, 2026
Overview
This Privacy Policy describes how Cleyo ("Cleyo", "we", "us", or "our") collects, uses, and protects personal data when you use our website at cleyo.io, our web application at app.cleyo.io, and the Cleyo browser extension (together, the "Services").
Cleyo is a business development platform for recruiters. We help you find companies that are hiring, identify the right people to contact, and run multi-step outreach campaigns. Because our Services involve professional contact data, we act as a data controller for the information we hold about our own users, and as a data processor for the prospect data you load into your workspace. We are committed to handling all of it in line with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
Information we collect
Account and profile data
When you create an account we collect your name, email address, password (stored only as a salted hash), company name, and the preferences you set, such as your email signature and timezone.
Connected mailbox and messaging data
When you connect a mailbox or messaging account, we store the credentials needed to send messages on your behalf. These credentials are encrypted at rest and are only used to deliver the campaigns you create. We process the content of the emails and messages you draft and send through Cleyo, along with delivery, open, and reply events.
Prospect and contact data
To run outreach you load or generate professional contact data about the decision makers you want to reach, such as names, job titles, employers, business email addresses, and LinkedIn profile URLs. Some of this is entered by you, and some is retrieved through our enrichment and search providers. You are responsible for having a lawful basis to process the prospect data you bring into Cleyo.
Calendar and meeting data
If you connect a calendar, we read your events so the product can show your schedule and know which meetings to join. If you use the meeting notetaker, we process the audio and video of that meeting, and store the transcript and the notes made from it. A recorded meeting contains the personal data of everybody on the call, not only yours, and the section below sets out how that works.
Connected applicant tracking systems
If you connect an ATS, we store the API key you generate in that system, encrypted, and we write campaign activity back to it. Your contractual relationship for the data held in that system is with its provider, not with us.
Usage and technical data
We log technical information needed to operate and secure the Services, including IP address, browser and device type, the pages and features you access, and timestamps. We keep records of security-relevant actions so we can detect and investigate abuse.
Payment data
Subscriptions and credit purchases are handled by a third-party payment provider. We do not see or store your full card number. We retain billing metadata such as plan, invoice history, and the last four digits of your card.
How we use your information
We use personal data only for the purposes below, each with a lawful basis under the GDPR:
- To provide the Services: creating your account, running searches, drafting and sending campaigns, and syncing your data (performance of our contract with you).
- To secure the Services: authentication, rate limiting, audit logging, fraud and abuse prevention (our legitimate interest in a safe product).
- To improve and support the product: diagnosing issues and responding to your requests (our legitimate interest, and your consent where required).
- To process payments and prevent billing fraud (performance of contract and legal obligation).
- To send service and transactional messages, and, only with your consent, product updates you can opt out of at any time.
We do not sell your personal data, and we do not use the content of your mailboxes, messages, or prospect lists to train machine learning models.
Meetings, calendar and recordings
Cleyo can read your calendar and join your meetings. Both are off until you connect them, and both can be switched off again at any time.
Calendar
Calendar access is read-only. We read events from yesterday to thirty days ahead, so the product can show your schedule and know which meetings carry a video link. Cleyo does not create, move or delete events. Calendars that other people have shared with you read-only, such as a colleague's calendar or a public holiday subscription, are skipped.
The meeting notetaker
The notetaker joins a meeting as a visible participant named “Cleyo Notetaker” and appears in the attendee list. It does not record silently. It records the meeting and produces a transcript and structured notes.
You decide which meetings it joins. Auto-join is a single setting in your workspace, and every individual meeting has its own switch, so you can leave auto-join on and turn off any single call.
Everyone on the call is a data subject, and you are responsible for them. Recording a conversation means processing the personal data of every participant. You are the controller for that recording, so it is your responsibility to have a lawful basis, to tell participants they are being recorded, and to obtain consent where the law of their country requires it. Cleyo makes the notetaker visible in the attendee list to help, but that visibility is not itself consent.
Meeting video is deleted automatically thirty days after the meeting. Transcripts and notes stay in your workspace until you delete them or close your account. Where you record an in-person meeting yourself, the audio file is removed once it has been transcribed.
AI processing
Cleyo uses language models to draft campaign messages, to summarise and classify the replies you receive, to produce meeting notes from transcripts, and to research companies. Depending on the feature, that means prospect names, job titles and employers, the text of replies, and meeting transcripts.
Our model providers are configured for zero data retention. Your prompts and the model's output are not stored by them, and they are contractually barred from training on your data. We do not use the content of your mailbox, your messages or your prospect lists to train any model, our own included.
One exception, stated plainly. Company research uses a web search tool, and zero-retention routing does not extend to search tools, so a research query leaves that boundary. Those queries contain company names and research questions, not the personal data of your contacts.
Cleyo has no autonomous mode. Nothing is sent that you did not create or approve, and the reply assistant drafts replies but never sends them. The current model providers are named in our Trust Center.
The Cleyo browser extension
The Cleyo browser extension keeps your Cleyo workspace in sync while you work on LinkedIn. It is optional, and you can remove it at any time from your browser. The sections below describe exactly what it does with data.
What data the extension handles
- Professional profile details you choose to save: when you are viewing a LinkedIn profile and decide to add it as a lead, the extension saves the professional details shown on that page, such as name, headline, and current company, to your Cleyo workspace.
- Sign-in information: used to keep you connected to your Cleyo workspace so the extension can sync on your behalf.
- Your LinkedIn session: LinkedIn offers no partner API for outreach, so the extension captures your LinkedIn session and keeps it in sync, which is what lets Cleyo act as you on LinkedIn. That credential is encrypted at rest with AES-256-GCM, is readable only by our backend service role and never by any user-facing interface, every write to it is recorded in our audit log, and it is deleted the moment you disconnect LinkedIn or close your account. With it Cleyo can view a profile, send a connection request, message an existing connection and send an InMail, only for people you have added to a campaign and within the daily limits you set. When somebody replies to one of those messages, the reply is matched to the conversation Cleyo started and its text is stored so it can appear in your inbox; a message in any conversation Cleyo did not start matches nothing and is discarded. It does not browse or search your LinkedIn inbox, and it does not post.
- Your settings and activity: your preferences and a short record of recent sync activity, stored locally in your browser.
The extension keeps your workspace up to date by syncing periodically in the background. It only activates on LinkedIn and only saves a profile when you ask it to.
Limited use commitment
Our use of information received from the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements:
- We only collect and use the data described above to provide and improve the Cleyo sync features you have asked for.
- We do not sell this data, and we do not transfer it to third parties except to provide the Services or for legal reasons described below.
- We do not use the data for advertising, and we do not use it to determine creditworthiness or for any lending purpose.
- No humans read your data except where you give consent, where it is necessary for security or to comply with the law, or where the data has been aggregated and anonymized.
The extension only works on LinkedIn. It does not access the pages you visit on other websites.
How we share information
We share personal data only with the categories of service providers (sub-processors) that help us run Cleyo, each bound by contract to protect it and use it only on our instructions:
- Cloud hosting and database providers, which store and run the application that powers your workspace.
- Email and messaging delivery providers, which send the messages you create through your connected accounts.
- Contact search and enrichment providers, which help you find and verify professional contact details for the prospects you research.
- AI and language model providers, which draft messages, classify replies and turn meeting transcripts into notes, as set out above.
- A meeting recording and transcription provider, which joins the meetings you ask it to and returns the recording and transcript.
- A payment provider, which processes subscriptions and billing.
Every sub-processor we use is named, with its purpose and the country it processes in, in our Trust Center. We give at least thirty days' notice before adding a new one, and you may object by writing to support@cleyo.io.
We may also disclose data when required by law, to enforce our terms, or to protect the rights, safety, and security of Cleyo and our users. If Cleyo is involved in a merger or acquisition, we will notify you before your data becomes subject to a different privacy policy.
International data transfers
Some of our providers may process data outside your country, including outside the European Economic Area. Where that happens, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses to ensure your data receives an equivalent level of protection.
Data retention
We keep personal data only for as long as we need it. The periods below are the ones the product actually enforces.
- Account, campaigns, contacts and messages: while your account is active.
- Meeting video: deleted automatically thirty days after the meeting.
- Meeting transcripts and notes: while your account is active, or until you delete them.
- In-person recording audio: deleted once it has been transcribed.
- Mailbox and LinkedIn credentials: deleted as soon as you disconnect the integration.
- Replies that do not match one of your campaigns: never stored. Incoming mail we cannot match is discarded.
- Audit logs: while your account is active, and deleted with your account.
Deleting your account from Settings is immediate and irreversible. We erase your data, cancel any scheduled notetaker, and delete the connected accounts held on your behalf at our providers. Backups roll off within thirty days. We keep records longer only where the law requires it, such as invoices held for tax purposes.
How we protect your data
Security is a core part of how Cleyo is built. We apply industry-standard safeguards, including:
- Encryption of sensitive data in transit and at rest.
- Access controls that keep each user's workspace isolated from others.
- Monitoring, logging, and rate limiting to detect and prevent abuse.
- Ongoing hardening and review of our systems.
No system is perfectly secure, but we work continuously to protect your data and to meet recognized privacy and security standards.
Your privacy rights
Depending on where you live, you have rights over your personal data. For users in the EEA and the UK, these include the right to:
- Access the personal data we hold about you.
- Correct data that is inaccurate or incomplete.
- Delete your data (the right to be forgotten).
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw consent at any time, without affecting prior processing.
You can exercise most of these rights directly from your account settings, or by contacting us at the address below. You also have the right to lodge a complaint with your local data protection authority.
Cookies and local storage
We use cookies and similar technologies that are strictly necessary to keep you signed in and to keep the Services secure. We do not use third-party advertising cookies. The browser extension stores its settings and a local activity log in your browser's local storage, which never leaves your device except as part of the sync described above.
On our public website we also measure traffic with DataFast, which is cookieless and stores nothing on your device. Two further tools load only if you allow them in the cookie banner, and you can change or withdraw that choice at any time from the link in the footer. Crisp powers the support chat. Microsoft Clarity provides product analytics and records a replay of your visit, covering the pages you view and how you move and click on them, so we can see where the site is confusing. Both set their own cookies. Neither runs inside the signed-in application, and neither runs at all until you accept.
Children
Cleyo is a professional tool intended for business use. It is not directed to children, and we do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the date at the top of this page and, where appropriate, notify you in the app or by email. Your continued use of the Services after an update means you accept the revised policy.
Contact us
If you have questions about this policy or how we handle your data, or you want to exercise your rights, contact our privacy team at:
Cleyo
support@cleyo.io