Effective 2026-07-24

Privacy Policy

Sections are numbered so they can be cited. If you are looking for the part to show your own users, it is Part B, and Section 15 is written for them.

1. Who we are

Cluestick is a support platform for iOS applications, operated by Brogan LLC (“Cluestick”, “we”, “us”). Companies embed our Swift SDK in their own applications, the people who use those applications send support messages and files, and the company’s support staff read and answer them in the Cluestick dashboard.

This policy explains what happens to personal data in both directions. Questions about it, and any request about your own information, go to logan@brogan.io.

We have not appointed a representative under Article 27 of the GDPR or the UK GDPR, and enquiries from individuals or supervisory authorities in the European Union or the United Kingdom should be sent to logan@brogan.io.

2. The two parts of this policy

Cluestick sits in two different positions, and data protection law treats them differently.

Part A describes the information we hold in our own right — about the companies that open a Cluestick account, the people who work in those accounts, and the people who visit our website — and for that information we are the controller.

Part B describes the information that reaches us through the SDK — about the people who use our customers’ applications — and for that information we are the processor, acting for the customer whose application sent it.

If you are here because an app you use is built on Cluestick, Part B is the part that concerns you, and Section 15 tells you who to ask about your data.

3. Part A — information we collect as a controller

We do not buy personal data, and we do not enrich your account with data from brokers.

4. Part A — how we use it, and our legal bases

We use this information to provide the Service and keep you signed in, to bill you, to send transactional email — sign-in codes, verification links, invitations and notices — to keep the Service secure and prevent abuse, and to answer you when you write to us.

Our legal basis for providing, billing and supporting the Service is performance of our contract with you, or taking steps at your request before entering into it. Where we act to keep the Service secure, to prevent abuse, to keep a record of administrative actions, and to count page views in aggregate, our basis is our legitimate interest in operating and protecting the Service, weighed against your own interests and rights. Where the law requires consent, we ask for it and you can withdraw it.

We do not sell your information, we do not disclose it for cross-context behavioural advertising, and we do not use it to train machine-learning models.

5. Part A — cookies and website analytics

We set strictly necessary cookies only. The one the product depends on is the session cookie that keeps you signed in to the dashboard; the dashboard cannot work without it. We set no advertising cookies and no analytics cookies, which is why you are not asked to accept a cookie banner.

Our site loads Vercel Web Analytics on every page, including the dashboard, to count page views in aggregate. The page-view data it collects goes to Vercel, which is a subprocessor of ours for that purpose as well as for hosting, and is listed as such at /legal/subprocessors. It is the only analytics on the site, we do not use it to build a profile of you, and we do not combine it with your account.

Vercel publishes the product as cookieless, and the script sets no cookie we set or control. The script itself is served from Vercel and can change without us; what it collects is governed by Vercel’s own documentation and by our data processing agreement with Vercel, rather than by anything we can inspect in our own source.

6. Part A — error diagnostics from our own systems

When something in Cluestick fails, our servers report the error to our own Sentry account so that we find out about it. Reports carry a stack trace and identifiers for the workspace and application involved.

That reporting is deliberately narrow. We configure Sentry not to attach request bodies, headers or IP addresses, and we never send message content, attachment content or end-user personal data to it. This is our own Sentry account, which is a subprocessor for this purpose only; a Sentry account a customer connects as an integration is a different thing, described in Section 8.

7. Part B — information we process on a customer’s instructions

What reaches us depends entirely on what a customer’s application chooses to send. The SDK sends, and we store or log:

We never take an end-user identity from the body of a request. Identity comes from the signed session the SDK holds, so a caller cannot claim to be someone else by editing a payload.

8. Part B — enrichment integrations

A customer can connect RevenueCat, PostHog, Mixpanel, or its own Sentry account, so that an agent sees subscription status, product analytics or recent crashes beside a conversation.

These lookups run on credentials the customer supplies, against the customer’s own accounts with those vendors, under the customer’s agreement with them. Cluestick holds the credential, encrypted, and nothing else.

The lookups happen on demand, while an agent has the conversation open, and the responses are rendered and then discarded. They are never stored in Cluestick’s database, and no copy is written to our own records. Because nothing is retained, these four are not subprocessors of ours, and they are not on the subprocessor list in Section 11.

9. Part B — the limits of our role

We process the personal data described in Part B only on the customer’s documented instructions, as set out in the Data Processing Agreement at /legal/dpa.

The customer is the controller of that data and decides what its application sends us and why. Cluestick does not decide what is collected, does not use it for its own purposes, does not disclose it to anyone outside Section 11, and does not use it to train machine-learning models.

Our customers are responsible for having a lawful basis for what they send, and for telling their own users about it. Their privacy disclosure should identify Cluestick, operated by Brogan LLC, as a processor or service provider acting on their behalf.

10. Retention and deletion

We keep information for as long as the account it belongs to exists. Nothing that has been sent ages out on its own: a conversation from three years ago, and the files attached to it, are still in the dashboard unless someone removes them.

There is one automatic deletion, and it applies to files that were never sent. When an upload is prepared, we create the attachment record before the message exists; if the message is never sent, that file stays attached to nothing. A daily job removes any such file that has sat unattached for more than twenty-four hours, deleting the stored bytes and marking the record deleted. It touches nothing that reached a conversation.

Two controls sit in the dashboard today, available to an owner or administrator of the workspace:

An owner or administrator can also download the whole workspace as JSON from workspace settings: team, applications, conversations, knowledge base, feature board and audit log. Both exports leave out signing secrets, API key hashes and push tokens, which are credentials rather than information about a person, and neither includes attachment file content, which stays retrievable in the conversation itself.

There is no self-serve account closure today: to close an account and have everything in it deleted, write to logan@brogan.io.

Where an account is terminated, we retain the customer’s data for thirty (30) days so that it can be exported, and delete it from our production systems after that window closes. Backups age out on our providers’ ordinary schedules, so a copy can survive in backup for a period after deletion from the live systems.

11. Who we disclose information to

We disclose information to the vendors that run the Service for us. Each of them, what it does, what reaches it and where it operates, is listed at /legal/subprocessors, which is both the current public list and Annex III of the Data Processing Agreement.

We will also disclose information where we are legally compelled to, by court order, subpoena or another binding demand from a public authority. Where the law allows it, we tell the affected customer first so that it can seek protective treatment.

If Brogan LLC is involved in a merger, acquisition or sale of assets, information may transfer as part of that transaction, and this policy continues to apply to it until it is replaced by one that is at least as protective.

We do not sell information, and we disclose it to nobody for their own independent purposes.

12. International transfers

Cluestick is operated from the United States, and all processing takes place on infrastructure hosted in the United States. We do not offer regional hosting.

If you, or the people who use your application, are in the European Economic Area, the United Kingdom or Switzerland, information reaching the Service is transferred to the United States. Those transfers rest on the Standard Contractual Clauses that each of the subprocessors listed in Section 11 has entered into for its own service, together with the Data Processing Agreement between us, which includes the Clauses where they apply.

13. How we protect information

Traffic to and from the Service travels over TLS, so it is encrypted in transit. Our database and object storage providers encrypt what they hold at rest.

Integration credentials — the RevenueCat, PostHog, Mixpanel, Sentry and APNs keys a customer connects — are encrypted with AES-256-GCM before they are stored, and decrypted only for the moment they are used. That includes a customer’s APNs .p8 signing key, encrypted the same way as the enrichment-integration keys above it. The per-application secret used to sign end-user identity tokens is held the same way.

API keys are stored only as a SHA-256 hash. The key itself is shown once, when it is created, and can be revoked at any time.

Access inside the dashboard is scoped to a workspace and to a role, so an agent reaches only the workspace they belong to, and only the actions their role allows. Administrative actions are written to an audit log the workspace can read.

No system is perfectly secure, and we do not claim ours is. Report a suspected vulnerability to logan@brogan.io, as described in our disclosure policy.

14. Your rights

If you hold a Cluestick account, or have written to us, you can ask us to give you a copy of the information described in Part A, to correct it, to delete it, to restrict or object to how we use it, or to give it to you in a portable form. Where we rely on consent, you can withdraw it.

We respond to a request about your own information within thirty (30) days of receiving it at logan@brogan.io. We may need to confirm who you are before we act, and we will say so if we do.

If you are in the European Economic Area, the United Kingdom or Switzerland, you can also complain to your local supervisory authority. We would rather you told us first, so we can put it right.

15. If you use an app that uses Cluestick

If you use an application that embeds Cluestick and you want a copy of your data, or you want it deleted, contact the company that publishes that application: it is the controller of your data, and we hold that data only on its instructions.

We assist that company in answering you, and it can export or erase your data itself, from its dashboard, without waiting for us. We do not have a relationship with you directly, we cannot verify who you are, and acting on your request without the publisher’s instruction would mean acting on unverified instructions about someone else’s data.

If you cannot identify or reach the publisher, write to logan@brogan.io and we will help you work out which customer holds your data.

16. California privacy rights

For the personal information described in Part B, Cluestick is a service provider under the California Consumer Privacy Act, processing that information for and on behalf of the business — our customer — under a written contract that restricts what we may do with it.

We do not sell personal information, and we do not share it for cross-context behavioural advertising, in either part of this policy. We do not retain, use or disclose personal information for any purpose other than performing the services, except where the Act permits it.

California residents who use one of our customers’ applications should direct requests to know, delete, correct or opt out to that customer, as Section 15 describes. Californians with a Cluestick account of their own can exercise the rights in Section 14 at logan@brogan.io, and we will not discriminate against anyone for doing so.

17. Children

The Service is not directed to children, and we do not knowingly collect information from them.

Our customers must not send us data they know to be a child’s. If you believe a child’s information has reached the Service, tell us at logan@brogan.io and we will remove it and tell the customer whose application sent it.

18. Changes to this policy

We may change this policy. Where a change materially affects how we handle personal data, we will give notice by email to the address registered on the account, or through the product, before it takes effect. Corrections and clarifications take effect when they are published.

The date at the top of this page records when the current version took effect. Earlier versions are available on request at logan@brogan.io.

19. How to contact us

Write to logan@brogan.io for anything in this policy: a request about your own information, a question about how we handle data, a data processing agreement, or a supervisory authority enquiry.

Cluestick is operated by Brogan LLC. The Terms of Service govern use of the Service, the Data Processing Agreement governs our processing of the personal data in Part B, and the vendors we rely on are listed at /legal/subprocessors.