Privacy Policy
Last updated: February 6, 2026
1. Introduction
Welcome to McLeuker AI (“we”, “our”, or “us”). We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our agentive AI platform and services (the “Service”). This policy is designed to comply with the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and France's Data Protection Act (Loi Informatique et Libertés, Loi n°78-17).
2. What Personal Data We Collect
We collect information necessary to provide and improve our Service. The following table describes the categories of data we process:
| Data Category | Examples | Purpose |
|---|---|---|
| Account Information | Name, email address, password | Create and manage your account |
| Profile Information | Company name, role, preferences | Personalize your experience |
| User Content | Prompts, uploaded files, content you provide to the agent | Execute your requests and provide the Service |
| Connected Account Data | Data from third-party accounts you connect (e.g., emails, calendar events) | Allow the agent to perform actions on your behalf |
| Payment Information | Billing details (processed by Stripe) | Process subscription payments |
| Usage & Telemetry Data | Pages visited, features used, agent actions, error logs | Security, debugging, improving reliability |
| Device Information | IP address, browser type, operating system | Security and analytics |
3. How We Use Your Data & Lawful Basis
Our processing of your personal data is based on the following legal grounds under GDPR Article 6:
- •Performance of a Contract (Art. 6(1)(b)): We process your Account Information, User Content, and Connected Account Data to provide the core functionality of the Service you have requested.
- •Legitimate Interests (Art. 6(1)(f)): We process Usage & Telemetry Data and Device Information for security, fraud prevention, and to analyze and improve the performance of our Service. We have conducted a balancing test to ensure our interests do not override your fundamental rights.
- •Consent (Art. 6(1)(a)): We rely on your consent for sending marketing communications and for the use of non-essential cookies and trackers.
- •Legal Obligation (Art. 6(1)(c)): We may process your data to comply with legal requirements, such as financial regulations or requests from law enforcement.
Our Policy on Model Training
We do not use your User Content, files, or Connected Account Data to train or fine-tune our foundation AI models. We may use limited, aggregated, and de-identified logs and feedback (e.g., error reports, safety flags) to improve reliability and security—without training foundation models on your content.
4. Acting on Your Behalf & Connected Accounts
When you connect a third-party account (e.g., Google, email, calendar), you authorize the Service to access and perform actions in that account strictly to provide the features you request. We do not take high-impact actions (sending messages, deleting data, purchases) without asking you to confirm.
We store access tokens securely to maintain your connection. You can revoke access at any time in the app or with the provider (e.g., Google). After revocation, we stop accessing the connected account.
If you ask the agent to email someone, we process recipients' contact details and message content as instructed by you, solely to send the communication.
5. Data Sharing & Subprocessors
We do not sell your personal data. We share information only with trusted service providers (subprocessors) who help us operate our Service under strict data processing agreements. A full list is available on our Subprocessors page.
We may also disclose your information to legal authorities when required by law, or to successors in the event of a merger or acquisition.
6. International Data Transfers
Your data may be processed outside of the European Economic Area (EEA). Where such transfers occur, we ensure they are protected by appropriate safeguards, primarily through the use of Standard Contractual Clauses (SCCs) approved by the European Commission, combined with supplementary measures where necessary.
7. Data Retention
We retain your data only for as long as necessary to fulfill the purposes described in this policy:
| Data Type | Retention Period |
|---|---|
| User Content (prompts, files) | 30 days (user can delete anytime) |
| Security & Audit Logs | 12 months |
| Account Information | Duration of account existence |
| Backups | 30 days |
When you delete your account, we will delete or anonymize your personal information within 30 days, except where retention is required by law.
8. Your Data Protection Rights
Under the GDPR, you have the following rights regarding your personal data:
- •Right of Access: Obtain a copy of the personal data we hold about you.
- •Right to Rectification: Correct any inaccurate or incomplete personal data.
- •Right to Erasure: Request deletion of your personal data.
- •Right to Restriction: Restrict the processing of your personal data.
- •Right to Data Portability: Receive your data in a structured, machine-readable format.
- •Right to Object: Object to processing based on legitimate interests.
- •Right to Withdraw Consent: Withdraw consent at any time for processing based on consent.
- •Right to Lodge a Complaint: File a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés) at www.cnil.fr.
To exercise these rights, please visit our Data Subject Request page or contact us at dpo@mcleuker.com.
9. Automated Decision-Making
Our AI agent assists you in performing tasks but does not make decisions with legal or similarly significant effects on you without your explicit confirmation. You always retain the ability to review, approve, or reject any action the agent proposes.
10. Children's Privacy
Our Service is not intended for individuals under the age of 15. In accordance with French law, users aged 15 or older may consent on their own. For users under 15, joint consent with a parent or guardian is required. We do not knowingly collect personal information from children under 15. If you believe we have collected information from a child, please contact us immediately.
11. Cookies & Trackers
We use cookies and similar tracking technologies. Non-essential cookies require your prior consent, which you can provide or refuse through our cookie banner. Refusing non-essential cookies is as easy as accepting them. For full details, please see our Cookie Policy.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the “Last updated” date. We encourage you to review this page periodically.
13. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact our Data Protection Officer:
Email: dpo@mcleuker.com
Supervisory Authority: CNIL (Commission Nationale de l'Informatique et des Libertés)