Privacy Policy
Last updated: August 13, 2026
1. Introduction
ClioIQ ("we", "our", or "us") is a product of CognixAI Hub. This Privacy Policy explains how we collect, use, and safeguard information when you or your organization use ClioIQ — including the calls, transcripts, and CRM data the platform captures.
2. Information We Collect
- Account information: Name, work email, company name, and phone number provided when you request a demo, start a trial, or sign up.
- Call recordings & transcripts: Audio recordings, transcripts, summaries, and derived data (risk scores, sentiment, coaching metrics) from meetings captured through the AI Notetaker or built-in video calling.
- CRM & deal data: Leads, contacts, accounts, deals, and related fields you enter directly or that ClioIQ extracts from a call and files automatically.
- Integration data: Credentials and configuration details for connected services (Salesforce, HubSpot, Zoho, Zoom, Google Calendar, Outlook & Teams), stored encrypted at rest.
- Usage data: Interactions with the platform, feature usage, and login activity.
- Communications: Messages sent to us via email, the demo request form, or support channels.
3. How We Use Your Information
- To provide the core product: capturing calls, generating transcripts and summaries, scoring deal risk, and filing data to your CRM.
- To power Clio AI's answers, always cited back to the specific call they came from.
- To communicate with you about your account, service updates, and support requests.
- To monitor system performance and diagnose technical issues.
- To comply with legal and regulatory obligations, including record-keeping requirements applicable to your industry.
4. Call Recording & Consent
ClioIQ opens every call with a disclosed recording notice before capture starts — consent is never assumed. Your organization is responsible for ensuring recording is lawful in the jurisdictions where your calls take place and for obtaining any additional consent required by applicable law beyond the in-call disclosure ClioIQ provides. We do not use your call content, transcripts, or calendar data to develop, improve, or train generalised artificial intelligence or machine learning models, and we do not share it with any third party for that purpose.
5. Data Security
Call recordings, transcripts, and CRM data are encrypted at rest and in transit. Access is restricted to authorized personnel. We do not sell your data or share it with third parties for marketing purposes.
6. Third-Party Integrations
When you connect Salesforce, HubSpot, Zoho, Zoom, Google Calendar, or Outlook & Teams, data flows between those services and ClioIQ solely to run the features you've enabled — syncing CRM records, joining calls, or reading calendar events. We do not retain this data beyond what's needed for that purpose.
7. Google User Data
ClioIQ offers two optional Google integrations — calendar and mailbox. Each is connected separately, by you, and each can be disconnected independently. Scheduling meetings and sending email are additional permissions, requested separately again and only at the point you first use those features. If you only use ClioIQ to capture meetings and email, you are never asked for them.
Google Calendar — reading. When you connect Google Calendar, ClioIQ reads your events using the calendar.events.readonly scope. We use this data only to display your upcoming meetings inside ClioIQ, prepare briefing material from records already stored in your own workspace, and detect video-conference links so you can choose to have the AI Notetaker join and transcribe a meeting.
Attendee email addresses from calendar events are never stored — at sync time they are reduced to a single indicator of whether a meeting has an external participant. Event descriptions and locations are scanned for a conference link and then discarded.
Google Calendar — scheduling. If you schedule a meeting from within ClioIQ, we ask separately for the calendar.events scope. We use it to create that meeting on your primary calendar with a video conference attached, and to remove it again if the meeting is cancelled. We only create or delete events that ClioIQ itself scheduled — we never modify events you created elsewhere. Provider-side invitation emails are suppressed so that attendees receive one invitation from ClioIQ, carrying the join link and a calendar attachment, rather than two competing invitations for the same meeting.
Gmail — capture. When you connect a Gmail mailbox, ClioIQ reads messages using the gmail.readonly scope in order to capture your customer conversations. We do not ingest your mailbox. The sync fetches message metadata for a bounded window — 30 days of history by default — matches every sender and recipient address against the contacts and leads in your own organization, and only then fetches and stores the message body and any attachments. A message that does not involve a known contact or lead is dropped: no record, no snippet, no search index entry. Your personal mail is never stored.
Captured threads are indexed so Clio AI can answer questions about a customer's history, and the date of the most recent reply feeds deal-risk scoring.
Gmail — sending. If you choose to reply to a customer from within ClioIQ, we ask separately for the gmail.send scope, so the message goes out from your own address and the customer's reply comes back to you. We only send messages you have reviewed and clicked Send on. No automated or background process sends mail on your behalf. This scope permits sending only — it grants no ability to read, modify, label, or delete mail.
ClioIQ's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We do not use Google user data to develop, improve, or train generalised artificial intelligence or machine learning models. We do not sell Google user data, transfer it for advertising, or use it for any purpose other than providing the features described above.
You can disconnect either integration at any time from Settings, and you can withdraw the scheduling and sending permissions without disconnecting. Disconnecting your calendar immediately and permanently deletes all synced calendar events and the stored authorization credentials for that connection; where you chose to record a meeting, the event title remains part of that meeting's record in your workspace and is deleted when you delete the meeting. Disconnecting a mailbox immediately and permanently deletes the captured threads, messages and attachments for that connection, along with its stored authorization credentials. Meetings ClioIQ created on your calendar are not deleted when you disconnect — they remain yours, on your calendar, and you can remove them there.
8. AI Processing & Service Providers
For meetings you choose to record, ClioIQ sends the meeting transcript, together with the calendar event title and start time, to Google's Gemini API to generate your meeting summary, action items, and coaching feedback. This is per-user processing carried out to deliver the product to you. Under Google's paid-tier terms, data submitted through the Gemini API is not used to train or improve Google's models.
Captured email threads that matched a contact or lead are converted into numerical embeddings by Jina AI so that Clio AI can search them. Message content is sent to that provider for this purpose only, and is not used to train its models. Calendar data is not embedded.
The AI Notetaker runs on ClioIQ's own infrastructure. Meeting audio it captures is not sent to a third-party meeting-bot service.
We use the following service providers to operate the platform. Each processes data only on our instructions, and only for the purpose listed:
- Google (Gemini API) — AI meeting intelligence
- Google Cloud Platform — hosting, storage, and database
- Jina AI — text embeddings for semantic search
- Deepgram — speech-to-text transcription
- LiveKit — real-time calls and recording
- Brevo — transactional email, including meeting invitations and follow-ups
- Razorpay — payment processing
- Sentry — error monitoring
9. Data Retention
Call recordings and transcripts are retained for as long as your account is active. Disconnecting an integration immediately deletes the data synced through it. Archived CRM records are permanently purged 15 days after archival. You may request deletion of your organization's data at any time, and we will action the request within 30 days.
10. Your Rights
You have the right to access, correct, or request deletion of your personal data. To exercise these rights or for privacy-related questions, contact us at support@clioiq.com.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated date. Continued use of ClioIQ after changes take effect constitutes acceptance of the revised policy.