How we handle website and pilot information.
Effective July 28, 2026. This notice covers clavenar.ai, its contact and design‑partner forms, and the linked Clavenar live demo.
Who is responsible
Vanteguard Labs LLC, the company behind Clavenar, is responsible for the personal information described here. Questions or deletion requests can be sent to contact@clavenar.ai.
Information we collect
- Public form information. A business email plus fixed selections for evaluation stage, evaluation interest, or preferred contact timing. The forms have no free‑text, credential, production‑system, incident, vulnerability, personal‑data, or regulated‑data field.
- Basic website activity. The official website build does not load analytics. Plausible remains disabled unless a reviewed bounded analytics lifecycle is published first.
- Security and delivery data. IP address, request metadata, challenge results, and server logs used to deliver the site, prevent abuse, investigate faults, and protect forms.
- Live‑demo data. A scoped session token and the sample actions or ledger rows you create in that temporary session. Do not enter personal data, secrets, or production credentials into the public demo.
How we use information
- Respond to questions and evaluate design‑partner or pilot requests.
- Operate, secure, debug, and improve the website, forms, demo, and product.
- Measure aggregate interest and conversion without building advertising profiles.
- Comply with law, enforce our terms, and protect Clavenar, visitors, and third parties.
We do not sell or rent personal information, and we do not use submitted work emails for an unrelated marketing list.
Service providers and external services
We use the maintained processor inventory below. Web3Forms transmits the minimized form message to Gmail; the Clavenar contact endpoint validates the exact field shape and verifies Cloudflare Turnstile before the browser sends that fixed payload. Cloudflare Turnstile also protects live‑demo sessions from abuse. The official build disables Plausible. GitHub and other destinations apply their own privacy notices when you choose to follow an external link.
These providers may process information in countries other than your own. Their processing is governed by their terms and applicable data‑protection commitments.
| Provider | Purpose and data | Retention and deletion |
|---|---|---|
| Cloudflare Turnstile Active | Bot and abuse prevention; browser/request security signals, IP address, and challenge outcome. | Clavenar keeps only a one‑way token hash for at most 300 seconds. Cloudflare controls its security‑signal retention under its linked addendum. |
| Google Gmail Active | Receive the minimized intake message and conduct requested correspondence; business email, enum selections, and correspondence. | General‑intake copies follow the 90‑day inactive and 180‑day absolute limits below. |
| Web3Forms Active | Transmit the minimized, verified message; business email, enum selections, and fixed delivery metadata. | Web3Forms states that it does not store form submissions and deletes service logs periodically, every two months. |
| Plausible Analytics Disabled | Aggregate measurement only if a later reviewed build enables it; the official build sends no events. | Re‑enabling requires a reviewed processor inventory and bounded analytics lifecycle before publication. |
Inventory review: reviewed July 28, 2026; next review due by October 26, 2026, and at least every 90 days thereafter. The exact machine‑readable inventory is clavenar.pilot-privacy-intake/v1.
Cookies and local storage
The marketing site does not use advertising cookies. Security providers may use necessary browser data to complete an anti‑abuse challenge. The live demo uses an essential, short‑lived session credential to keep one visitor's demo rows scoped from another's.
Retention and security
We delete an inactive general inquiry within 90 days after the last substantive contact and always within 180 days after the initial submission unless a written pilot agreement takes effect. When an inquiry converts, we delete the general‑intake copy within 30 days; the written agreement governs any necessary replacement business record. Website and form security logs are kept for at most 30 days. Rate‑limit state expires within 60 seconds and the one‑way Turnstile token hash within 300 seconds.
We acknowledge a verified deletion request within seven days and complete it within 30 days. A documented legal duty or active dispute may suspend deletion only for the affected record; we delete it within 30 days after that condition ends.
We use reasonable technical and organizational safeguards, but no website, email, or storage system is guaranteed secure. Do not send secrets, private keys, regulated data, or exploit details through a general contact form.
Your choices
You may ask to access, correct, or delete information you submitted, or object to further contact. Depending on where you live, local law may provide additional rights. Email contact@clavenar.ai; we may need to verify the request before acting.
The site is intended for business users and is not directed to children. We may update this notice as the product and providers change; the effective date above will change when the update is material.