Privacy policy.
Last updated: June 5, 2026
The short version
CloneFlo turns a photo of you, a script you write, and a voice you pick into a video of "you" speaking that script. To do that we need to hold onto your photo, your script, your email, and the resulting video file. We use a third-party AI vendor (HeyGen) to do the actual rendering. We don't sell your data to anyone, ever. You can delete your account and all data by emailing hello@cloneflo.com.
Below: every category of data we touch, in plain English. We try hard not to write things like "we may, at our sole discretion, use…" because that style is how every privacy violation has ever been hidden.
What we collect, exactly
- Email + name. So we can email you when your clone is ready and so the Studio knows whose library to show.
- Your source photo. Uploaded to Vercel Blob storage. We hand a URL to HeyGen so they can train your avatar. We retain the photo for your account lifetime so you can re-render with the same likeness.
- Your script + voice + motion choices. Standard form data — stored with the job record so we can re-run the render if something fails.
- The rendered video file (MP4). Stored at the URL HeyGen returns. We keep these so they appear in your library; delete-on-request removes both our record and our pointer to HeyGen's file.
- Stripe payment details. We never see your card. Stripe holds it; we receive a customer ID, the plan you picked, and your trial/subscription status.
- A session cookie called
cf_session. It's HMAC-signed, httpOnly, and contains your email + plan ID + a timestamp. It exists so you don't have to retype your email every visit. Clear cookies or sign out to delete it.
Who else sees your data
- HeyGen — the underlying AI vendor that renders Avatar V Motion Engine videos. They see your photo, voice ID, script, and motion prompt. Their privacy policy is at heygen.com/policies/privacy-policy.
- Stripe — payment processing. They see your name, email, and card. Their privacy policy is at stripe.com/privacy.
- Vercel — hosting + edge functions + Blob storage + Redis (KV). Standard hosting access to logs and stored files. vercel.com/legal/privacy-policy.
- Us — the human admin reviewer. In beta, every clone is approved by a human before HeyGen renders it. That human (currently the CloneFlo team) sees your photo, your script, and your email. Once we automate this gate the human review goes away.
That's everyone. No analytics resellers, no ad networks, no email-list brokers.
What we do NOT do
- We do not sell your photo, voice, script, or video to anyone.
- We do not use your photo or video to train any AI model — not ours, not HeyGen's general model. Your data is render-only.
- We do not share your email with third-party marketers.
- We do not use cookies for behavioral advertising.
Deleting your data
Email hello@cloneflo.com from the address tied to your account and we'll wipe your photo, all your jobs, your Clone IDs, your subscription, and your email from our records within 14 days. We also flag your HeyGen-side records for deletion at the same time. Stripe records we're required by law to retain for tax/financial-reporting purposes.
Cookies, in detail
cf_session— your signed-in session. httpOnly, sameSite=lax, 90-day expiry.- No third-party analytics cookies. No ad cookies.
- If Stripe Checkout is involved, Stripe sets its own cookies on its hosted checkout domain — we don't control those, see Stripe's policy.
If you're in the EU, UK, or California
You have the right to access, correct, port, or delete your personal data. Email hello@cloneflo.com with "GDPR" or "CCPA" in the subject line and we'll respond within 30 days. We are the data controller; HeyGen, Stripe, and Vercel are sub-processors.
Contact
Any privacy concern, question, or data-deletion request: hello@cloneflo.com.