Privacy Policy
Last updated: 25 July 2026
Who we are
Clutra (“Clutra,” “we,” “us,” or “our”) operates the website at clutra.com and the services offered there. Clutra is a done-for-you content agency: our in-house editors produce and distribute short-form content and run social accounts on behalf of our clients. As part of our services, we also operate Instagram messaging automations (for example, comment-to-DM and story-reply-to-DM flows) on behalf of clients who authorize us to do so through their own Instagram professional accounts.
This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have. It applies to visitors of our website, our business clients, and end users who interact with Instagram accounts that our clients operate through Clutra.
Information we collect and access
We collect and access the following. Sections (b), (c) and (d) describe data obtained through each platform’s official API, only after an account owner connects their account and authorizes us. Section (e) covers information that is already public.
a. Business client information
When a business signs up or works with us, we collect account and contact details such as name, email address, company name, billing information, and the details needed to deliver our services and communicate with the client.
b. Instagram data (via the Instagram Graph API)
When an account owner connects their Instagram professional account and authorizes Clutra, we access - through Meta’s official Instagram Graph API and only within the scope the owner grants - the following on that owner’s behalf:
- Instagram professional-account profile data (such as account id, username, and basic account details).
- Media and posts published by the account (posts, reels).
- Comments left on the account’s content.
- Direct messages and story replies sent to the account, which are used to trigger and deliver the automated replies the account owner has configured.
We access this data solely to operate the features the account owner has set up. We do not use the Instagram API to access data from accounts that have not authorized us.
This includes the scoped identifiers Meta issues for messaging (such as IGSID/ASID/PSID), the access tokens issued for the connection, the account’s Meta user and page identifiers, profile pictures and usernames. We refer to this collectively as Platform Data, and we Process it only as described in this policy.
c. TikTok data (via the TikTok API)
When an account owner connects their TikTok account and authorizes Clutra, we access — through TikTok’s official API and only within the scope the owner grants — their basic profile information (open ID, display name, avatar, and, where authorized, account type, follower and like counts, bio description, and their public videos). Where the owner has authorized publishing, we use the TikTok Content Posting API to upload the specific video they have approved. We process TikTok data only for the limited purpose of enabling and using the TikTok developer services within Clutra, and we do not sell it or share it with third parties without the user’s consent. Personal data is not kept for longer than necessary for that purpose.
d. YouTube and Google data (via YouTube API Services)
Clutra uses YouTube API Services. When an account owner connects their YouTube channel and authorizes Clutra, we access their channel identity and, where authorized, the ability to upload a video to that channel, along with the video and channel metadata needed to show the result back to them. We use that access solely to upload the specific video the owner has approved, with the title, description, and privacy setting they selected, and to report back on it. We store the OAuth tokens required to keep the connection active and a record of what was published through Clutra.
Clutra’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to serve advertisements, we do not sell it or transfer it to data brokers or information resellers, and we do not use it to develop, improve, or train generalized artificial-intelligence or machine-learning models. Human access to this data is limited to what is necessary to operate the service you have asked us to run, to comply with law, or with your consent.
e. Publicly available social data
To report on how a client’s content performs, we also collect information that is already public on social platforms — for example public profile details and public post or video metrics (views, likes, comments counts, captions, thumbnails) for the accounts a client asks us to track. We collect this through third-party data providers rather than through the platform APIs, we collect it only for accounts a client has asked us to track, and we use it only to produce that client’s reporting. We do not collect private messages, private posts, or any non-public information this way.
f. Usage and analytics data
Like most websites and apps, we collect standard usage and device information (such as pages viewed, actions taken, browser type, and approximate location derived from IP address) to operate, secure, and improve our services.
Cookies and similar technologies. We and our providers store and read information on your device using cookies, local storage, and similar technologies — for essential functions (such as keeping you signed in), and for product analytics and attribution. The third-party providers that may set or read such storage on our site are PostHog (product analytics), Google Analytics and Google Ads, Microsoft Advertising (UET), Customer.io (email), and Tolt (affiliate attribution). We also operate a first-party click and conversion pixel to attribute results to the content we publish for a client. We do not allow third parties to serve advertisements on our website.
How we use information
We use information to:
- Operate the services an account owner has configured - for example, automatically replying to comments and direct messages with the links and messages the owner set up.
- Report delivery, open, and click statistics back to the account owner so they can measure performance.
- Provide, maintain, secure, and improve our website and services.
- Communicate with our business clients about their accounts, billing, and support.
- Comply with legal obligations and enforce our terms.
With respect to Instagram data, Clutra acts as a processor on the account owner’s behalf. The account owner (our client) determines what automations run and what messages are sent; we carry out those instructions.
What we do not do
- We do not sell your personal data.
- We do not use Instagram data for advertising or ad targeting.
- We do not store Instagram story media - we only keep transient references needed to deliver a reply, and we do not retain the story content itself.
- We do not use Instagram data for any purpose other than operating the features the account owner authorized.
How we share information
We share information only as needed to run our services:
- Subprocessors: service providers who process data on our behalf under contract, and who may only use it to provide services to us. These currently include: Google Cloud (hosting), Supabase (database, authentication and file storage), Anthropic and Google (Gemini) (AI processing of content we edit for a client), Bright Data (collection of public social metrics), Resend (transactional email), Customer.io (email delivery), PostHog (product analytics), Stripe and Whop (payments), and Notion (client planning documents). We update this list as our providers change.
- Meta / Instagram Platform: to send messages and retrieve data through the Instagram Graph API, we exchange data with Meta as required to operate the platform integration.
- Legal: when required by law, to respond to legal process, or to protect the rights, safety, and security of Clutra, our users, or the public.
We do not sell personal data or share it with third parties for their own marketing purposes.
Data retention and deletion
We retain personal data only for as long as needed to provide our services, comply with our legal obligations, resolve disputes, and enforce our agreements. Instagram data is retained only while an account remains connected and the related automation is active; transient story references are discarded shortly after a reply is delivered.
We also delete data when it is no longer necessary for a legitimate business purpose, when we stop offering the relevant product, when the platform provider requires it, when a user requests it or no longer has an account, and when the law requires it.
Platform-specific deadlines. Where a connected account is involved, we delete the associated data on the following timelines:
- Within 7 calendar days when you disconnect the account inside Clutra, ask us to delete your data, or delete your Clutra account. We also revoke the stored token at that point.
- Within 30 calendar days when you revoke access through the platform’s own settings page (for example, the Google security settings page linked below).
- For YouTube API Services specifically, we do not retain non-analytics data obtained through the API for longer than 30 calendar days, and we re-verify at least every 30 days that our authorization to access a connected channel has not been revoked.
Who can ask. The right to request deletion is available to everyone whose data we hold — not only our paying business clients. That includes people who commented on or messaged a client’s connected account and whose interaction was processed by an automation.
You can request deletion of your data at any time. You may:
- Disconnect Clutra from within your Instagram settings (see “Revoking access” below), which stops all further data access; and/or
- Email us at privacy@clutra.com to request deletion of the data we hold about you.
Upon a verified request, we will delete the associated personal data, subject to any legal retention requirements.
Your rights
Depending on where you live, you may have rights to access, correct, or delete your personal data, to object to or restrict certain processing, and to data portability. If you are in the European Economic Area or the United Kingdom, we process data in accordance with the GDPR. If you are a California resident, we honor rights provided under the CCPA/CPRA, including the right to know, delete, and opt out of the “sale” or “sharing” of personal information - and, as noted above, we do not sell personal data.
To exercise any of these rights, contact us at privacy@clutra.com. We will respond within the timeframe required by applicable law.
Clutra is established in Sweden, so this policy is governed by Swedish and EU data-protection law. If you are in the EEA and believe we have not handled your data properly, you have the right to complain to your local supervisory authority — in Sweden this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), imy.se. We would appreciate the chance to address your concern first.
Instagram / Meta Platform compliance
Our use of information received from the Instagram Graph API adheres to the Meta Platform Terms and Developer Policies, including limitations on the use and transfer of that data. Access tokens are stored server-side, are restricted to the systems that operate your integration, are never exposed to your browser or to any other client, and are used only to operate the integration you authorized. This policy does not supersede, modify, or conflict with the Meta Platform Terms.
How we handle data on behalf of our clients
Clutra accesses and processes Platform Data on behalf of, and at the direction of, each business client — for that client’s purposes only. We do not process it for our own purposes, and we do not process one client’s data for another client’s purposes.
- Each client’s Platform Data is maintained separately from every other client’s data, enforced by a per-client access boundary in our systems.
- We share Platform Data only: with the client it belongs to; with our own service providers (hosting, database, email delivery, analytics, and AI processing) acting under contract; with a client’s service provider when that client directs us to; and where required by law.
- We maintain an up-to-date list of the clients on whose behalf we process Platform Data, and will provide it to Meta on request. A client’s access may be terminated promptly if Meta requests it.
- We will promptly notify a client of any communication we receive from Meta concerning a user request about the processing of that user’s Platform Data.
- Where consent or opt-in is required to contact someone via Instagram messaging, that consent is obtained by us or by the client on whose behalf we operate, as applicable law requires.
Revoking access
You can revoke Clutra’s access to your Instagram account at any time from your Instagram or Meta account settings - go to Settings → Apps and websites and remove Clutra. Revoking access immediately stops any further data access and automation.
TikTok compliance
When you connect a TikTok account, we receive the profile information described in section 2(c) above through TikTok Login Kit, and — where you have authorized it — we use the TikTok Content Posting API to publish the video you have approved to your own TikTok account. We access only the data needed to operate the features you have enabled, and we do not use TikTok data for advertising or sell it to third parties. Our use of TikTok data adheres to the TikTok Developer Terms of Service.
Revoking access
You can disconnect your TikTok account from within Clutra at any time, or revoke access directly in the TikTok app under Settings and privacy → Security and permissions → Apps and services. Revoking access immediately stops any further data access and prevents further posting.
YouTube and Google API compliance
Clutra uses YouTube API Services. By using the YouTube features of Clutra, you agree to be bound by the YouTube Terms of Service. Information handled by Google is also governed by the Google Privacy Policy.
What Google user data we access, use, store, and share
When you connect a YouTube channel, we request only the narrowest access needed to publish on your behalf. We access your channel identity and, where authorized, the ability to upload a video. We use that access solely to upload the specific video you have approved, with the title, description, and privacy setting you selected. We store the OAuth tokens required to keep the connection active, plus a record of the videos published through Clutra. We do not share Google user data with third parties, do not use it for advertising or to build advertising profiles, do not sell it, and do not use it to train generalized artificial-intelligence or machine-learning models.
Revoking access and deletion
You can revoke Clutra’s access to your Google account at any time via the Google security settings page at https://security.google.com/settings/security/permissions, or by disconnecting the channel from within Clutra.
If you disconnect the channel inside Clutra, or ask us directly to delete your data, we delete the associated Google user data within 7 calendar days and revoke the stored token. If you revoke access through the Google security settings page above, we delete the associated Google user data within 30 calendar days.
Children’s privacy
Our services are intended for businesses and for people aged 18 and over, and we do not knowingly collect personal data from anyone under 16. If you believe someone under 16 has provided us with personal data, contact us at privacy@clutra.com and we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above. Material changes will be communicated where appropriate.
Contact us
Questions or requests about this policy or your data? Email us at privacy@clutra.com or team@clutra.com.