Privacy Policy
Clean, operated by Clean AI Labs, Inc. · Last updated September 1, 2026
This policy explains what data Clean collects, why we collect it, how it is stored and shared, and the controls you have. It covers three things:
- The Clean web app at www.tryclean.ai, where your workspace finds, researches, and works leads.
- The optional Gmail connection, which a workspace member can turn on to sync email threads with chosen leads into Clean. This is Google user data, and the sections below are written to comply with the Google API Services User Data Policy, including its Limited Use requirements.
- The “Clean for LinkedIn” Chrome extension, written to comply with the Chrome Web Store Limited Use and data disclosure requirements.
By using the service, connecting Gmail, or installing the extension you agree to this policy.
Who we are
Clean is a product of Clean AI Labs, Inc.. Clean is organised into workspaces: a workspace belongs to one company, and its members are the teammates that company has invited. Data a member connects to Clean lives inside that workspace and nowhere else. You can reach us any time at hello@tryclean.ai.
The Gmail connection: what it is
Connecting Gmail is optional and off until a workspace member turns it on. When they do, that member signs in with their own Google account, reviews Google's consent screen, and then picks a lead list inside Clean. Clean syncs the email threads between that Google account and the leads on the chosen list, and shows them on each lead's record as a per-lead inbox. That is the whole feature: the workspace can see the conversation history it already has with the people it is working, next to the research Clean has assembled on them.
What we request from Google
- Gmail read-only access (the
https://www.googleapis.com/auth/gmail.readonlyscope). Clean uses it to search for and read messages to or from the leads you picked. Clean never sends, drafts, modifies, labels, archives, or deletes mail, and never requests a scope that would let it. - Basic profile information from Google sign-in: the email address of the connected account, used to label the connection and to match your own address on each thread.
What we read, and what we do not
Clean reads only mail to or from the leads on the list your workspace picked. For each of those threads we store the message headers (from, to, cc, date, subject), the message text, and Google's thread and message identifiers so the inbox stays in sync and duplicates are not created. We also store the OAuth token Google issues so the sync can continue without asking you to sign in again.
Nothing else in the mailbox is fetched. Clean does not scan the whole inbox, does not read mail with people who are not on the chosen list, and does not keep anything outside the matching threads. If you change the list, Clean only ever reads threads with the leads currently on it.
How Gmail data is stored
- Encrypted. Synced messages and OAuth tokens are encrypted in transit (TLS) and at rest.
- Bounded. Storage is limited to the threads that match the chosen leads. Clean does not build a copy of your mailbox.
- Workspace-private. Gmail data is scoped to the workspace that connected it. It is never visible to any other workspace, never published, and never pooled across customers.
Who can see Gmail data
Members of your workspace. The per-lead inbox is a shared view: teammates in the same workspace can see the synced threads on the leads they are working, in the same way they can see the lead's research and notes. If you would rather not share a particular account's mail with your team, do not connect it.
Clean staff do not read your mail. No one at Clean looks at synced message content in the normal course of operating the service. Humans may access it only in the narrow cases Google's Limited Use policy allows: with your explicit permission (for example to debug a support request you raised), where necessary for security purposes such as investigating abuse, to comply with applicable law, or for internal operations where the data has been aggregated and anonymised.
Gmail data is not sold, rented, shared with advertisers or data brokers, or transferred to anyone other than the infrastructure providers that host Clean (cloud hosting and managed database providers acting as our processors under contract), and then only as needed to run the service.
How we use Gmail data
Solely to provide and improve the per-lead inbox feature you turned on: fetching the matching threads, showing them on the right lead record, and keeping them in sync. We do not use Gmail data for advertising, for profiling anyone outside your workspace's own lead list, to determine creditworthiness or for lending purposes, or to develop, improve, or train generalised artificial intelligence or machine learning models.
When Gmail data is deleted
- When you disconnect. Disconnecting Gmail in Clean revokes the token with Google and deletes every synced message and thread for that connection from live systems immediately.
- When a member leaves. If the member who connected the account leaves or is removed from the workspace, their Gmail connection is closed and its synced mail is deleted the same way.
- When a workspace is deleted. Deleting a workspace deletes every Gmail connection and all synced mail inside it.
- When you revoke from Google. You can also remove Clean's access at any time from your Google Account permissions page. Syncing stops as soon as the token is rejected, and previously synced mail is deleted when we detect the revocation or when you disconnect in Clean, whichever comes first. Emailing us also works.
Residual copies in encrypted backups expire on their normal rotation, no later than 30 days after deletion from live systems.
Google Limited Use disclosure
Clean's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The Chrome extension: what it collects
The extension has a single purpose: to securely connect, and keep connected, the user's own LinkedIn account to their own Clean account so they can read and act on their own LinkedIn data through Clean's API. To do that it handles the following data, and nothing else:
- LinkedIn session cookies. After you sign in to LinkedIn through the extension's managed-proxy connect flow, the extension reads exactly three cookies:
li_at,JSESSIONID, andli_a. These are LinkedIn session/authentication tokens. They are sent over HTTPS to your own Clean account and stored encrypted at rest (AES-256-GCM). No other cookies are read or transmitted. - LinkedIn GraphQL queryId hashes. As you browse LinkedIn normally, the extension observes the URLs of requests your own browser already sends to LinkedIn's Voyager GraphQL endpoint and extracts the rotating
queryIdidentifiers (an operation name plus a hash). This keeps Clean's server-side integration working when LinkedIn rotates those identifiers. Only the operation name and hash are recorded, never request bodies, response bodies, or query variables. - Optional interaction-timing telemetry (off by default). If, and only if, you turn on the “Human-like timing” toggle in the extension, it records anonymous interaction timing on linkedin.com: inter-keystroke intervals (the time between keystrokes, never the characters typed), paste timing markers (that a paste occurred, never its contents), scroll depth and velocity, hover dwell times, tab focus/blur events, page-type navigation (e.g. “profile”, “search”, “feed”), local hour, day of week, and viewport size. This is aggregated into session summaries and used solely to model human-like usage cadence so that activity on your own account stays within natural patterns. The toggle is off by default; turning it off immediately purges the local buffers.
- Extension settings. Your Clean API base URL, API key, and a short-lived connect-session token are stored locally in
chrome.storage.localso the multi-step connect flow can complete.
What the extension does NOT collect
- Message text, post content, or profile content.
- Search queries or GraphQL query variables.
- The actual characters you type (only keystroke timing, when telemetry is enabled).
- Passwords, payment details, or any cookies other than the three named above.
- Any data from sites other than linkedin.com and your own Clean dashboard.
How we use extension data
Session cookies are used only to operate your own LinkedIn account through Clean at your direction. queryId hashes are used only to keep the integration in sync. Optional timing telemetry, when enabled, is used only to keep automated activity on your account within human-like patterns. We do not use any of this data for advertising, profiling of other people, or any purpose unrelated to the extension's single purpose.
How we share data
We do not sell or rent your data, and we do not transfer it to third parties except as needed to run the service. Data flows only to your own Clean workspace and to the infrastructure providers that host it (e.g. cloud hosting and managed database providers) acting as our processors under contract. We may also disclose data where required by law, or to protect the security of the service and its users. We do not use or transfer your data to determine creditworthiness or for lending purposes. This use complies with the Google API Services User Data Policy and the Chrome Web Store Limited Use requirements.
Storage, security, and retention
Synced Gmail data, OAuth tokens, and LinkedIn session cookies are encrypted at rest and transmitted only over HTTPS. Telemetry and settings buffered in the browser live in chrome.storage.local on your device. We keep data only for as long as the connection that produced it is active, and delete it on disconnect as described above. You can also request deletion at any time by emailing us.
Your controls
- Disconnect Gmail from your Clean workspace settings to revoke Clean's access and delete all synced mail.
- Remove Clean's access directly from your Google Account permissions page.
- Change which lead list Gmail syncs against at any time; Clean only reads threads with the leads currently on it.
- Turn the optional timing telemetry on or off from the extension popup at any time. Turning it off purges local buffers.
- Disconnect a LinkedIn account from your Clean dashboard to revoke and delete its stored cookies.
- Uninstall the extension to stop all local collection immediately.
- Email hello@tryclean.ai to request export or deletion of your data.
Children
Clean is a business tool and is not directed to children under 16. We do not knowingly collect data from children.
Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected here with a new “Last updated” date, and where appropriate in the app, the extension, or by email to workspace administrators.
Contact
Questions about this policy or your data? Email hello@tryclean.ai. You can also visit our support page.