← Back to Login

Privacy Policy

AiMe — AI Marketing Manager Enterprise
Operated by ClearByte.AU · Version 1.3 · Effective: 13.07.2026 · (supersedes Version 1.2 of 12.07.2026)

This Privacy Policy explains how ClearByte.AU collects, uses, stores, and shares your personal information when you use the AiMe platform. By registering an account or using the platform, you acknowledge and agree to the practices described here.

1. Who We Are

ClearByte.AU operates the AiMe (AI Marketing Manager Enterprise) platform at aime.clearbyte.au.

ClearByte.AU
DOOLEY TWO PTY LTD
BEACON HILL NSW
ACN: 673 088 385
Email: info@clearbyte.au

For the purposes of the Australian Privacy Act 1988, the UK GDPR, and the EU GDPR, ClearByte.AU is the data controller of personal information collected through the Platform.

2. What Information We Collect

Information You Provide Directly

CategoryData PointsWhen Collected
Account DataFull name, email address, password (hashed), company nameRegistration
Billing DataPayment method (processed by Stripe — we do not store card numbers), billing addressSubscription signup
Profile DataProfile photo (optional), job title, phone number (optional), timezoneAccount settings
Brand DataBrand name, logo, colour palette, typography, brand voice, industryBrand guide setup
Content DataAll content you create, generate, upload, or publish through the PlatformPlatform use
CRM DataContact records, lead data, campaign data you manage through the PlatformCRM module use
Terms AcceptanceTimestamp and version of Terms of Service acceptedRegistration and re-acceptance

Information Collected Automatically

CategoryData PointsPurpose
Usage DataPages visited, features used, actions taken, timestampsPlatform improvement
Technical DataIP address, browser type, device type, operating systemSecurity, rate limiting
Log DataAPI requests, error logs, performance metricsDebugging, security monitoring
Cookie DataSession tokens, preference cookiesAuthentication, preferences

3. How We Use Your Information

  • Providing the Services — account management, payment processing, AI content generation, CRM, autonomous operations, publishing
  • Platform Improvement — analysing usage patterns, diagnosing issues, developing new features
  • Communications — transactional emails (receipts, alerts); marketing emails only with your consent, opt-out available at any time
  • Security and Compliance — fraud detection, Terms enforcement, legal obligations, audit logs
  • AI Processing — your content and prompts may be processed by third-party AI providers to generate outputs (see Section 6). AIME uses Google Vertex AI for primary AI text generation (Gemini), under Google's commercial Data Processing Addendum which prohibits use of customer inputs or outputs for training Google's AI models. We do not use your content to train AI models, and our AI providers are contractually bound likewise.

4. Legal Bases for Processing (GDPR)

For UK and EU users:

Processing ActivityLegal Basis
Providing Platform ServicesContract — necessary to perform our agreement
Billing and paymentContract — necessary to fulfil the subscription
Security monitoring and fraud preventionLegitimate interests
Marketing communicationsConsent — you may withdraw at any time
Legal obligationsLegal obligation
Platform improvement (aggregated)Legitimate interests

5. How We Share Your Information

We do not sell your personal data. We share your information only:

  • With your authorisation — when you connect third-party accounts or enable integrations
  • With service providers — third-party companies who help operate the Platform (acting as data processors, bound by confidentiality)
  • Within your organisation — if you operate as part of a team or enterprise account
  • Legal requirements — valid court orders, applicable law, or regulatory authority
  • Business transfers — in a merger or acquisition (we will notify you in advance)

6. Third-Party Data Processors

The table below lists the third-party services that process personal data on our behalf, grouped by purpose.

AI & Content Generation

ProviderRoleData Processed
Google (Gemini via Vertex AI)Primary AI text generation; bound by Google's commercial DPA prohibiting training on customer dataContent prompts and generated outputs
Anthropic (Claude API)Optional AI text generation, activated only when user supplies own API keyContent prompts when user key is used
OpenAI (GPT, DALL-E)Optional AI text + image generation, user API key onlyPrompts when user key is used
Stability AIOptional AI image generation, user API key onlyImage prompts when user key is used
Replicate (Flux models)Optional AI image generation, user API key onlyImage prompts when user key is used
RunwayMLAI video clip generationVideo prompts and scene descriptions
Pika LabsOptional AI video generation, user API key onlyVideo prompts when user key is used
Kling AIOptional AI video generation, user API key onlyVideo prompts when user key is used
ShotstackCloud video assembly and renderingAssembled scripts, clip URLs, render specifications
PexelsStock image searchSearch query strings

Infrastructure & Publishing

ProviderRoleData Processed
Cloudflare (CDN & Pages)Content delivery, DNS, edge security; hosting of published landing pages and websitesIP addresses, request metadata, published page content (publicly accessible once deployed)
Cloudflare (Registrar)Domain registration on your behalfRegistrant data submitted to ICANN: name, email, postal address, phone number of the registering business
Bunny.net (Bunny CDN)Video hosting and delivery for digital productsUploaded video files, viewer playback metadata
WordPress.com (Automattic)Content publishing to WordPress-hosted sitesPublished blog posts, pages, SEO metadata, site configuration
SuiteCRM (self-hosted by ClearByte; enterprise tier may use customer-hosted instance)CRM functionality, lead management, email executionContact records, lead data, campaigns, email engagement metrics

Billing & Communications

ProviderRoleData Processed
StripePayment processing and subscription managementCustomer name, email, tokenised payment method, billing address, subscription status. We do not store raw card data — Stripe handles this under PCI-DSS.
TwilioSMS verification and phone number provisioning for 2FA during social account setupPhone numbers

Authentication & User-Initiated Integrations

The integrations below are activated only when you explicitly connect the relevant account via OAuth. We receive the data scopes you authorise during the consent flow.

ProviderRoleData Processed
Google (OAuth — Sign-In)Single Sign-On (when used)Google account ID, email, profile name
Microsoft (OAuth — Sign-In)Single Sign-On (when used)Microsoft account ID, email, profile name
Google Workspace (OAuth — Integrations)Optional Gmail / Calendar integration when you connect Google WorkspaceCalendar events, email metadata, contact data within the scopes you grant. Specific OAuth scopes (e.g. gmail.send, calendar.events) are shown to you on the Google consent screen at connection time.
Microsoft Graph (OAuth — Integrations)Optional Microsoft 365 integration: Outlook calendar / mail when you connect Microsoft 365Calendar events, email metadata within the scopes you grant. Specific scopes are shown on the Microsoft consent screen.
Meta (Facebook & Instagram Graph API)Social account connection for content publishingPage access tokens, page/post engagement metrics, content you publish
LinkedIn APISocial account connection for content publishingProfile data, company page access, content you publish
Twitter / X APISocial account connection for content publishingAccount credentials (token), tweet content you publish
Webflow (OAuth — CMS Publishing)Optional Webflow CMS connection when you connect your Webflow workspace. Publishes AIME-generated content (and any media you include) into a CMS collection you select.OAuth access & refresh tokens (encrypted at rest), the email address associated with your Webflow account, the Webflow site and collection IDs you select, the field mapping you configure, and the content you publish (titles, body HTML, slugs, excerpts, author names). Featured images you publish are copied to Webflow's asset storage and become publicly retrievable from Webflow's CDN; any personal data depicted in those images (faces, identifying details) is processed and hosted by Webflow under their own terms. Images already uploaded to Webflow persist there after you disconnect from AIME — removing them requires action in your Webflow workspace. Scopes: cms:read, cms:write, sites:read, assets:write, authorized_user:read — shown on the Webflow consent screen at connection time.

User-supplied API keys: When you provide your own keys for third-party AI providers (Anthropic, OpenAI, Stability AI, Replicate, Pika Labs, Kling AI), those providers' policies govern processing of your content. We store your keys using AES-grade encryption at rest and use them solely to make API calls on your behalf.

Bespoke customer integrations: ClearByte may operate additional integrations on a per-customer basis under direct contract or DPA between ClearByte and that customer. Such integrations are not available to other customers and the relevant data flows are governed by the individual contract rather than this Policy. Current bespoke integrations are disclosed in writing to affected customers at the time of activation.

7. International Data Transfers

ClearByte.AU operates from Australia and may transfer your data to countries including the United States where our third-party providers are located. For UK/EU users, transfers are covered by Standard Contractual Clauses (SCCs). For Australian users, transfers are made under contractual arrangements requiring equivalent protection to the Australian Privacy Principles.

8. Data Retention

Data CategoryRetention Period
Account dataDuration of account + 30 days post-closure
Billing data7 years (tax and financial record obligations)
Content dataDuration of account + 30 days post-closure
Security logs12 months
Audit logs2 years
Terms acceptance records7 years (legal evidence)
Anonymised analyticsIndefinitely (no personal data)

9. Security

We implement industry-standard security measures including:

  • Encryption at rest — sensitive data encrypted using AES-grade symmetric encryption
  • Encryption in transit — all data transmitted via TLS 1.2+ (HTTPS)
  • Access controls — role-based access; database-level data isolation between users
  • Rate limiting — per-IP request limits to prevent brute-force and abuse
  • Audit logging — comprehensive, append-only audit trail of account actions

In the event of a data breach affecting your rights and freedoms, we will notify you and relevant authorities within required timeframes (72 hours under GDPR/UK GDPR).

10. Cookies and Tracking

CookieTypePurposeDuration
access_tokenEssentialAuthentication — maintains your login session30 minutes
refresh_tokenEssentialRenewing your authentication session7 days
themePreferenceStores your light/dark mode preference1 year

We do not use third-party advertising or tracking cookies and do not track your activity across other websites.

11. Your Rights

Rights Available to All Users

  • Access — request a copy of personal data we hold about you
  • Correction — request correction of inaccurate or incomplete data
  • Deletion — request deletion of your data (subject to legal retention obligations)
  • Withdrawal of consent — withdraw marketing email consent at any time

Additional Rights for UK/EU Users (UK GDPR / GDPR)

  • Restriction, Portability, Objection to legitimate interest processing, Supervisory authority complaint

Additional Rights for California Users (CCPA)

  • Know, Delete, Opt-out of sale (we do not sell personal information), Non-discrimination

Australian Users

You may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

How to Exercise Your Rights

Two routes are available:

  • Self-service (immediate, no waiting period): from your account, you can download a complete export of your personal data via Account Settings → Data & Privacy → Export My Data, or initiate account deletion via Account Settings → Data & Privacy → Delete My Account. Account deletion removes your personal data within 24 hours; rows that contributed to anonymised aggregate analytics have your user identifier removed (irreversibly anonymised) rather than the row deleted, as permitted under GDPR Recital 26.
  • Email request: privacy@clearbyte.au. We may ask you to verify your identity. We respond within 30 days for any request that cannot be fulfilled via self-service.

Facebook & Instagram (Meta) Data and Deletion

When you connect a Facebook Page or Instagram account, we store: the Facebook user ID of the connecting user; the IDs, names and (for Pages) category and profile-picture URL of the specific Pages and Instagram accounts you select; and the access tokens Meta issues for them. Access tokens are encrypted at rest. This data is used solely to display your connected accounts and to publish the content you create and schedule. We do not read other people's content, and we do not use Meta data for advertising, profiling, or resale.

You can delete this data at any time through any of these routes:

  • In-app disconnect — Social Accounts → Disconnect on the Facebook or Instagram card immediately deletes the stored tokens and connected-account records.
  • Meta Data Deletion Callback — if you remove AIME from your Facebook settings (Settings & Privacy → Apps and Websites) or delete your Facebook account, Meta sends us an automated deletion request. We then delete all stored credentials and connected-account records linked to your Facebook user ID and issue a confirmation code. You can verify completion at any time at aime.clearbyte.au/data-deletion-status using that code.
  • Email request — privacy@clearbyte.au.

LinkedIn (Profile & Company Page) Data and Deletion

When you connect LinkedIn, we store: your LinkedIn member identifier and basic profile information returned at sign-in; the IDs, names and vanity URLs of the Company Pages you explicitly select to connect (only pages you administer are ever listed); encrypted access tokens; records of the posts AIME publishes on your behalf; and, where you enable analytics, engagement metrics for your connected page's own posts. This data is used solely to display your connections, publish the content you create and schedule, and show you your own page's performance. We do not read other members' data, and we do not use LinkedIn data for advertising, profiling, resale, or AI-model training.

Deletion works the same way as for Meta data: disconnecting LinkedIn in Social Accounts immediately deletes the stored tokens and connected-account records; closing your account deletes all connected-platform data under Section 8; and you can additionally revoke AIME's access from LinkedIn's own settings at any time, after which our stored tokens cease to function and are removed. Email requests: privacy@clearbyte.au.

12. Children's Privacy

The Platform is not intended for individuals under 18. If you become aware that a person under 18 has created an account, please contact us and we will delete the account promptly.

13. AI and Automated Processing

The Platform uses AI to generate content, analyse marketing data, and make recommendations. When you enable Autonomous Operations, the Platform may take automated actions (publishing, emailing, adjusting campaigns) without real-time human intervention based on your configuration. All Autonomous Actions are logged with reasoning transparency in your audit trail. We do not use your personal data to build behavioural profiles for advertising or resale.

14. Contact and Complaints

Privacy Officer, ClearByte.AU
Email: privacy@clearbyte.au (privacy and data-rights matters)
General inquiries: info@clearbyte.au
BEACON HILL NSW

Supervisory authorities: ICO (UK) · Your local DPA (EU) · OAIC (Australia) · CPPA (California)

15. Changes to This Policy

When we make material changes, we will update the "Last Updated" date, notify you by email, and display a notice within the Platform. Continued use after the effective date constitutes acceptance.

This Privacy Policy was prepared with reference to the Australian Privacy Act 1988, UK GDPR, EU GDPR, CCPA, and PIPEDA. Users are advised to seek independent legal advice if uncertain about their obligations.

AiMe — AI Marketing Manager Enterprise | ClearByte.AU | Version 1.1