Data Protection

Privacy Policy

Last Updated: September 6, 2026

Submit privacy request

This Privacy Policy explains how eLearning Company, Inc. collects, protects, uses, and discloses personal information across the Cluelabs platform, Content Studio, and cloud services.

Introduction & Roles

1. Overview and Scope

eLearning Company, Inc. ("eLearning Company", "Cluelabs", "we", "us", or "our"), a New York corporation, is committed to safeguarding the privacy and security of your personal information. This Privacy Policy ("Policy") explains how we collect, use, store, disclose, and protect information when you visit the cluelabs.com website, use the Cluelabs platform, author courseware through Content Studio, deploy conversational AI interactions, access our Model Context Protocol (MCP) endpoints or APIs, or utilize our cloud data and analytics tools (collectively, the "Platform" or "Services").

This Policy applies to individuals and organizations who register for an account, access our website, or interact directly with our services. To understand our practices fully, please note the fundamental distinction between our operational roles under global data protection laws (such as the EU/UK General Data Protection Regulation and the California Consumer Privacy Act):

  • Cluelabs as a Data Controller: We act as a Data Controller with respect to the personal information of our direct registered users, account administrators, website visitors, and billing contacts. This includes information collected during account creation, subscription management, platform configuration, direct customer support communications, and website telemetry.
  • Cluelabs as a Data Processor / Service Provider: We act as a Data Processor (or Service Provider under California law) on behalf of our enterprise customers (who act as Data Controllers) with respect to end-user and learner data processed through our course widgets, embeds, and tracking endpoints. When a customer integrates our xAPI Learning Record Store (LRS), User Flow Analytics, Data Cloud, Google Sheets sync, PDF Maker, or conversational AI role-plays into an elearning course, any learner personal data transmitted through those tools is processed strictly in accordance with the customer's instructions and our Data Processing Addendum (DPA).

Back to top

AI Data Commitments

2. Zero AI Model Training Guarantee

We recognize that instructional materials, enterprise training curricula, corporate source documents, and learner interaction logs represent confidential, proprietary business assets. We maintain a strict and verifiable policy regarding generative artificial intelligence:

We do not use your proprietary content, source documents, prompts, scripts, generated media, or learner interaction data to train, retrain, or fine-tune public foundation models, proprietary artificial intelligence models, or third-party commercial algorithms.

When you utilize our generative AI capabilities—including Content Studio storyboarding, scriptwriting, voiceover generation, image synthesis, or conversational role-plays—your inputs are processed via secure enterprise API endpoints with our authorized foundation model providers (such as Google Cloud Vertex AI and OpenAI). Under our commercial enterprise agreements with these providers:

  • Your inputs (prompts, source files, reference images) and outputs (scripts, storyboards, audio, graphics) are not retained by the model providers for model training or machine learning improvements.
  • All data in transit to and from AI inference endpoints is encrypted using high-grade TLS protocols.
  • Model processing occurs transiently in-memory to generate the requested response, after which persistent assets are stored exclusively in your designated project repository.

Back to top

Data Collection

3. Information We Collect

We collect information across several categories depending on how you interact with the Platform:

Information You Provide Directly

  • Account and Profile Information: When you create an account, we collect your full name, professional email address, organization name, job title, and password hash.
  • Billing and Payment Information: When you purchase a paid subscription, add credits, or enable auto-refill, transaction details are collected directly by our payment processor, Stripe, Inc. We store transaction history, billing addresses, tax identifiers, and the last four digits and expiration date of your payment card for administrative and invoicing purposes; we never store raw credit card numbers or security codes on our servers.
  • Project and Authoring Content: In Content Studio and our authoring tools, you provide course topics, target audience profiles, uploaded source documents (Word, PDF, text), slide titles, narration scripts, custom variables, reference imagery, sound effect prompts, and custom developer instructions.
  • Support and Inquiries: When you submit support tickets, feature requests, or inquiries via our contact page or community forum, we collect your contact details, correspondence history, and attached diagnostic files.

Information Collected Automatically

  • Technical Telemetry: When you access the Platform, our servers automatically log technical information transmitted by your web browser, development environment, or MCP client, including Internet Protocol (IP) address, operating system, browser type and version, language preferences, hardware characteristics, and referring URLs.
  • Platform Usage and Performance Data: We collect aggregated metrics regarding page load times, API response latency, feature engagement, error stack traces, and workflow completion to maintain system reliability and optimize performance.
  • Cookies and Session Identifiers: We use essential and functional cookies to maintain authenticated sessions, preserve security tokens, and record workspace preferences.

Information Processed on Behalf of Customers (Processor Role)

When you deploy our widgets into courses hosted on external LMS platforms or web servers, the tools collect learner data strictly as configured by you:

  • xAPI Learning Record Store (LRS): Actor identifiers (learner email or account hash), activity URIs, completion statuses, scores, and timestamped behavioral statements.
  • User Flow Analytics: Anonymous or pseudonymous learner slide transitions, dwell time, and interaction drop-off patterns.
  • Data Cloud and Google Sheets Sync: Course variables, learner reflection responses, quiz scores, and state data saved by learners during course completion.
  • PDF Maker: Form fields, learner names, completion dates, and scores passed dynamically into certificate and report templates.
  • AI Interactions: Learner text or voice responses submitted during simulated conversational practice and automated rubric evaluation.

Back to top

Data Usage

4. How We Use Collected Information

We use the personal information we collect for the following specific business and operational purposes:

  • Service Delivery and Operation: To create and maintain your account, authenticate authorized users and AI agents, process project files, generate storyboards, render synthesized voiceover audio, produce synchronized captions, and serve cloud data widgets.
  • Billing and Account Administration: To process subscription payments, calculate credit consumption, manage automated credit refills, issue tax-compliant invoices, and prevent fraudulent billing activity.
  • Communication and Support: To deliver essential transactional emails, service alerts, security advisories, billing receipts, and administrative notices, and to respond to technical support inquiries.
  • System Security and Integrity: To monitor API and MCP endpoint traffic, detect and prevent malicious attacks, enforce rate limits, investigate suspicious activity, and maintain the security of our infrastructure.
  • Product Enhancement and Reliability: To identify software bugs, analyze aggregated platform usage trends, optimize server capacity, and refine platform workflows without using your private course content for public model training.
  • Legal Compliance: To comply with applicable statutory obligations, tax regulations, law enforcement subpoenas, and court orders, and to enforce our Terms of Service.

Back to top

Subprocessor Transparency

5. Authorized Subprocessors

We engage trusted third-party service providers ("Subprocessors") to perform specialized infrastructure, data storage, payment processing, and artificial intelligence functions. Each Subprocessor is vetted for rigorous security standards and is bound by written data protection agreements that restrict data processing strictly to our instructions:

Subprocessor Category & Function Processing Scope & Data Handled Location
Google Cloud Platform (Google LLC) Cloud Infrastructure, Hosting, Database, Gemini/Vertex AI, TTS, Translation Core platform hosting, compute, Firestore database, file storage, AI model inference, voiceover generation, translation. Applies to all platform users. Global (Customer-selectable regions)
OpenAI, L.L.C. Artificial Intelligence & Large Language Models Natural language processing, instructional script drafting, slide generation, Whisper audio transcription. Applies to AI-assisted authoring and interactions. United States
ElevenLabs, Inc. High-Fidelity Voice Synthesis Text-to-speech voiceover synthesis, custom speech rendering. Applies to voiceover narration generation in Content Studio. United States / European Union
Amazon Web Services, Inc. (AWS) Cloud Messaging & Communications Transactional email delivery (Amazon SES), notification routing, and automated system alerts. Applies to account notifications. United States
Stripe, Inc. Payment Processing & Billing Secure payment gateway, recurring subscription billing, fraud detection, credit purchase processing. Applies to paying customers. United States
Zendesk, Inc. Customer Support & Helpdesk Support ticket tracking, customer correspondence, and inquiry resolution. Applies to users submitting support tickets. United States
The Rocket Science Group LLC (Mailchimp) Marketing & Communications Distribution of optional educational newsletters, product updates, and platform guides. Applies only to opt-in subscribers. United States

We will notify registered account administrators of any material additions or replacements to our Subprocessor list prior to authorizing the new Subprocessor to process customer personal data.

Back to top

Data Residency

6. Regional Data Storage Options

We recognize that organizations operating in regulated industries, government sectors, or specific jurisdictions must adhere to strict data sovereignty and residency rules. For our persistent data services, Cluelabs provides customers with the capability to select their preferred primary data storage region.

Supported Persistent Offerings

When you configure any of the following offerings, you are presented with options to select the geographic region where your project assets, learner records, and database entries are stored:

  • Content Studio: Storyboard databases, project files, generated audio clips, captions, and graphics.
  • xAPI Learning Record Store (LRS): Complete xAPI statement streams and learning analytics data.
  • User Flow Analytics: Learner slide transition logs and session drop-off analytics.
  • Data Cloud: Persistent learner course variables and cloud database records.
  • Translation: Stored multi-language translation dictionaries and localized strings.
  • PDF Maker (Stored Templates): Stored DOCX templates and generated document repositories.

We currently offer data storage options across more than 40 certified data centers on 6 continents, including dedicated regions in the United States, European Union, United Kingdom, Canada, and Asia-Pacific.

Stateless and Pass-Through Services

Certain platform widgets operate as stateless pass-through utilities that do not store learner records, transactional inputs, or personal data on our servers. These include:

  • Closed Captioning: Converts audio tracks directly to timed captions in real time without storing media copies.
  • Two-Way Google Sheets Sync: Authenticates and routes data directly between course instances and your Google Sheets spreadsheet without intermediate storage or logging.
  • Dynamic PDF Generation: Compiles and outputs personalized PDF documents dynamically to the learner's browser without retaining generated copies.
  • Timers and Progress Bars: Run entirely client-side in the learner's browser without transmitting learner identity or state back to our servers.

Back to top

Data Sharing & Sale

7. Sale and Sharing of Personal Information

We do not sell your personal information, customer materials, or learner data to third parties under any circumstances.

Furthermore, we do not share, disclose, or transfer personal information to third parties for cross-context behavioral advertising, targeted promotional campaigns, or third-party marketing purposes. We do not maintain any marketing data-broker partnerships or affiliate monetization networks.

We disclose personal data only under the following limited circumstances:

  • Authorized Subprocessors: To our contracted Subprocessors strictly as necessary to deliver platform infrastructure, compute power, payment processing, and customer support.
  • Customer Direction: To third-party platforms, databases, or external services (such as your Google Sheets account, external LRS, or LMS) when explicitly configured and directed by you.
  • Legal Mandates: When required to do so by applicable law, search warrant, subpoena, court order, or formal regulatory investigation, provided we notify you in advance where legally permissible.
  • Corporate Restructuring: In connection with, or during negotiations of, any merger, acquisition, sale of corporate assets, financing, or corporate restructuring, in which customer accounts and data assets are transferred as part of the business assets, subject to continuing confidentiality obligations.

Back to top

Data Retention

8. Data Retention and Account Deletion

We retain personal information and project data only for as long as necessary to fulfill the operational purposes for which it was collected, maintain your account in good standing, satisfy legal, tax, and accounting requirements, and resolve potential disputes.

  • Active Account Data: Project files, storyboards, uploaded media, and generated assets are retained for the active lifecycle of your account.
  • Learner Records (Processor Data): xAPI statements, User Flow logs, and Data Cloud records are retained according to the retention window or storage tier selected by the customer in their account settings.
  • Billing Records: Transaction history, invoices, and payment receipts are retained for a minimum of seven (7) years to comply with statutory accounting and tax audit regulations.
  • Server and Diagnostic Logs: Network access logs, API telemetry, and diagnostic logs are retained on a rolling cycle, typically between thirty (30) and ninety (90) days, after which they are permanently deleted or anonymized.

Account Termination and Erasure

You may request the deletion of your account and associated personal data at any time by contacting us through our contact page. Upon receiving a verified deletion request:

  • Your user account will be deactivated and inaccessible.
  • Your project files, customer materials, storyboards, and custom variables will be removed from our primary production databases.
  • Backups and disaster recovery snapshots will overwrite and purge deleted records in accordance with standard backup rotation schedules (typically within 30 to 90 days).

Back to top

European Rights

9. European Data Protection Rights (GDPR & UK GDPR)

If you are a resident of the European Union, European Economic Area (EEA), or United Kingdom, your personal data is protected under the General Data Protection Regulation (EU GDPR) or the UK GDPR.

Legal Bases for Processing

We process personal data as a Data Controller only when we have a recognized legal basis under Article 6 of the GDPR:

  • Contractual Necessity (Art. 6(1)(b)): Processing necessary to register your account, provide platform access, process subscription fees, and deliver requested services.
  • Legitimate Interests (Art. 6(1)(f)): Processing necessary for our legitimate commercial interests, such as securing our network, preventing fraud, analyzing aggregate performance, and improving platform reliability, provided such interests are not overridden by your fundamental rights.
  • Legal Obligation (Art. 6(1)(c)): Processing necessary to comply with applicable statutory laws, tax reporting, financial auditing, and court orders.
  • Consent (Art. 6(1)(a)): Processing based on your explicit consent, such as opting into educational marketing newsletters or optional research studies, which consent you may withdraw at any time.

Your Data Subject Rights

Subject to statutory conditions and exceptions, European residents possess the following legal rights regarding their personal data:

  • Right of Access (Art. 15): The right to obtain confirmation as to whether your personal data is being processed, and to receive a copy of such data.
  • Right to Rectification (Art. 16): The right to request the correction of inaccurate or incomplete personal data.
  • Right to Erasure / "To Be Forgotten" (Art. 17): The right to request the permanent deletion of your personal data where retention is no longer justified.
  • Right to Restriction of Processing (Art. 18): The right to restrict the processing of your data under specific contested circumstances.
  • Right to Data Portability (Art. 20): The right to receive your personal data in a structured, commonly used, and machine-readable format, or have it transmitted directly to another controller where technically feasible.
  • Right to Object (Art. 21): The right to object at any time to processing based on legitimate interests, and an absolute right to object to direct marketing communications.
  • Right to Withdraw Consent: The right to withdraw consent at any time without affecting the lawfulness of processing conducted prior to withdrawal.

To exercise any of these rights, please submit a request through our contact page or email our Data Protection Officer at dpo@cluelabs.com. We respond to all verified requests within thirty (30) days without charge.

You also have the right to lodge a formal complaint with an appropriate data protection supervisory authority in the EU Member State of your habitual residence, place of work, or place of alleged infringement.

Back to top

California Rights

10. United States State Privacy Disclosures (CCPA/CPRA)

This Section applies solely to residents of California and other United States jurisdictions with comprehensive consumer privacy laws (including Virginia, Colorado, Connecticut, and Texas). This disclosure describes our practices regarding the collection, use, and disclosure of Personal Information in accordance with the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, "CCPA").

Notice at Collection: Categories of Personal Information Collected

In the preceding twelve (12) months, we have collected the following categories of personal information for business purposes:

  • Identifiers: Real name, professional email address, account password hash, IP address, unique online identifiers, and API tokens.
  • Commercial and Financial Information: Records of products purchased, subscription tiers, credit package transactions, billing address, and payment card metadata (last four digits and expiration).
  • Internet and Electronic Network Activity: Browser type, operating system, page interactions, referring URLs, API endpoint request logs, and platform telemetry.
  • Professional or Employment-Related Information: Job title, department, employer or educational institution name provided during account setup.
  • Geolocation Data: General geographic location derived from IP address (country and city level).
  • Audio and Visual Materials: Narration voice recordings, synthesized speech audio files, custom avatar prompts, and reference graphics submitted to Content Studio.

We collect these categories directly from you, automatically via your device, and from our payment processor, Stripe. We use these categories for the business purposes described in Section 4 of this Policy.

Sale and Sharing of Personal Information

In the preceding twelve (12) months, Cluelabs has not sold personal information and has not shared personal information for cross-context behavioral advertising. We have no actual knowledge of selling or sharing personal information of consumers under sixteen (16) years of age.

California Consumer Rights

As a California resident, you possess the following rights under the CCPA:

  • Right to Know and Access: The right to request disclosure of the specific pieces and categories of personal information collected, the sources of collection, the business purpose for collection, and the categories of third parties with whom data is shared.
  • Right to Delete: The right to request the deletion of personal information collected from you, subject to statutory retention exceptions.
  • Right to Correct: The right to request the correction of inaccurate personal information maintained in your profile.
  • Right to Opt-Out of Sale / Sharing: Although we do not sell or share personal information, you maintain the right to register your opt-out preference. We recognize the Global Privacy Control (GPC) signal transmitted by compatible web browsers.
  • Right to Non-Discrimination: We will not discriminate against you in pricing, service level, or platform availability for exercising any statutory privacy rights.

To exercise your California privacy rights, please submit a verifiable consumer request via our contact page or email privacy@cluelabs.com.

Back to top

Cross-Border Transfers

11. International Data Transfers

Cluelabs is operated by eLearning Company, Inc., located in the United States. If you access the Platform from outside the United States, your personal data may be transferred to, stored, and processed in the United States or other jurisdictions where our cloud infrastructure providers maintain operations.

When we transfer personal data originating from the European Economic Area, United Kingdom, or Switzerland to countries that have not received an adequacy decision from the European Commission, we implement recognized cross-border transfer safeguards, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission pursuant to Commission Implementing Decision (EU) 2021/914;
  • The International Data Transfer Addendum issued by the UK Information Commissioner's Office (ICO); and
  • Technical, organizational, and physical encryption safeguards applied to data during transit and storage.

Where customers utilize our regional storage options, persistent project data remains localized within the chosen geographic zone.

Back to top

Security Safeguards

12. Information Security and Breach Notification

We maintain comprehensive administrative, technical, and physical safeguards engineered to protect personal information against unauthorized access, destruction, loss, alteration, or disclosure. Our security controls include:

  • Encryption: All web traffic and API calls are secured using Transport Layer Security (TLS 1.3/HTTPS). Stored project assets, databases, and backup files are encrypted at rest using industry-standard AES-256 encryption algorithms.
  • Access Control: Platform infrastructure and internal databases operate under strict role-based access control (RBAC), multi-factor authentication (MFA), and the principle of least privilege.
  • Network Security: Virtual private cloud (VPC) isolation, web application firewalls (WAF), automated distributed denial-of-service (DDoS) mitigation, and continuous intrusion monitoring.

Data Breach Notification

In the event of a confirmed security incident resulting in the unauthorized access, disclosure, or destruction of personal data under our custody, we will take immediate remediation steps to contain the incident. If the breach presents a risk to the rights and freedoms of individuals, we will notify affected account holders and relevant regulatory authorities without undue delay and within the timeframes mandated by applicable law (including 72-hour notification where required under GDPR).

Back to top

Minor Protection

13. Children's Privacy

The Platform is an authoring, development, and administrative platform intended strictly for adult professionals, corporate training personnel, and instructional designers. The Platform is not directed to children under the age of thirteen (13), and we do not knowingly collect personal information from children under thirteen (13) years of age (or under sixteen (16) in jurisdictions governed by the GDPR).

If you are under the age of eighteen (18), you are not permitted to register for an account or submit personal information on the Platform. If we discover that a child under thirteen (13) has submitted personal information to our Platform without verified parental consent, we will promptly delete such information. If you believe we might have collected information from a child, please contact us immediately.

Back to top

Tracking & Cookies

14. Cookies and Tracking Technologies

We use cookies and similar browser storage technologies to operate the Platform securely and efficiently:

  • Strictly Necessary Cookies: Essential for platform functionality, user authentication, session security, CSRF protection, and load balancing. These cookies cannot be disabled without disabling access to the Platform.
  • Functional Cookies: Remember your interface preferences, such as selected language locale, active workspace views, and regional data storage defaults.
  • Performance and Analytics: Collect aggregated, anonymized metrics regarding page response times, navigation patterns, and application errors. We do not use third-party behavioral tracking cookies or advertising pixels.

You can configure your browser settings to reject or delete cookies. However, if you disable all cookies, you will not be able to log in, authenticate, or access core features of the Platform.

Back to top

External Links

15. Third-Party Websites and External Content

The Platform may contain links to external websites, authoring software repositories, online documentation, or partner platforms that are not operated or controlled by Cluelabs. We are not responsible for the privacy practices, content, or security standards of any third-party website. We encourage you to review the privacy policies of any third-party service you access through links on our Platform.

Back to top

Policy Updates

16. Changes to this Privacy Policy

We reserve the right to revise, modify, or update this Privacy Policy at our discretion to reflect platform enhancements, operational changes, subprocessor updates, or evolving legal requirements. When modifications are made, we will update the "Last Updated" date at the top of this Policy and publish the revised version on the Platform.

For material modifications that significantly alter how we process your personal data, we will provide reasonable advance notice through an in-app banner or an electronic communication delivered to your registered email address. Your continued access to or use of the Platform following the effective date of the updated Policy constitutes your acknowledgment and acceptance of the revised terms.

Back to top

Inquiries & DPO

17. Contacting Us and Data Subject Requests

If you have questions, comments, or concerns regarding this Privacy Policy, or if you wish to exercise your statutory privacy rights, please contact our Data Protection Officer and privacy team:

eLearning Company, Inc.
Attention: Data Protection Officer / Privacy Department
New York, NY, United States
Website Contact Form: cluelabs.com/contact
Direct Privacy Inquiries: privacy@cluelabs.com
Data Protection Officer: dpo@cluelabs.com
Support Portal: Support Forum

Back to top

Data Requests

Have Questions About Your Privacy?

Contact our Data Protection Officer or submit a verified data subject access request at any time.

Contact DPO