Legal

Privacy Policy

Updated September 2026

The short version: we store what you give us and the public pages you ask us to watch, we use Claude to interpret them for your team only, we never sell your data, and you can delete everything yourself from Settings.

Who we are

Clinch (getclinch.ai) is a competitive intelligence service for B2B software teams. We monitor the public web pages of the competitors you choose, interpret what changed using AI, and deliver battlecards, briefs and a weekly digest. This policy explains what we collect, why, who processes it, and the choices you have. Questions go to hello@getclinch.ai.

What we collect

Account data. Your email address, a password (hashed and stored by Supabase Auth; we never see it), your company name and website, and your role in the workspace (owner or member).

Workspace content you enter. Competitor names and URLs, your company profile (what you sell, who you sell to, pricing, why you win and lose), notes about each rival, intelligence templates, your product documentation URL and RSS feeds, feature matrix entries, and feedback you give on our analysis.

Sales activity. If your team logs deals or competitor mentions, we store the outcome, reasons, deal size and stage, dates, the prospect company name, quotes or evidence you paste, and who on your team logged it. You control whether this includes personal data about people at your prospects; keep it to what your sales process needs.

Data we collect from the web. Text snapshots of the public pages you ask us to monitor (competitor homepages, pricing, careers, changelog, documentation, G2 and Glassdoor overview pages, press RSS feeds), the differences between snapshots, and the AI analysis of those differences. We fetch only publicly reachable pages and do not log in to anything on your behalf.

Billing data. Your Stripe customer and subscription identifiers, plan, and subscription status. Card numbers are entered on Stripe's pages and never touch our servers.

Usage and technical data. Server logs (IP address, browser, pages and API endpoints requested, errors), email delivery events (delivered, bounced, opened), public battlecard view counts, and website analytics on our marketing pages via Google Analytics.

Claude connector. If you connect Clinch to Claude, we store the OAuth client registration, access and refresh tokens, and an audit record of every write Claude makes to your workspace (tool name, arguments, result, who authorized it). What you type to Claude stays with Anthropic under your Claude account; we only receive the tool calls.

How we use it

  • To run the service: monitor pages, detect changes, generate analysis, battlecards, briefs and digests, and show them to your team.
  • To personalize AI output to your company using your profile, rivalry notes and logged deals. Your data is used only for your workspace; we do not train models on it.
  • To bill you, enforce plan limits, and send account emails (confirmation, password reset, welcome, trial reminders, payment problems, team invites).
  • To send the weekly digest to workspace members, which anyone can turn off in Settings or from the link in every digest.
  • To keep the service secure and reliable: rate limiting, abuse prevention, error monitoring and debugging.
  • To understand how the marketing site is used, in aggregate.

Who processes it

We do not sell your data. These providers process it on our behalf to run Clinch:

  • Supabase (database, authentication, file storage), hosted in the United States (us-east-1).
  • Vercel (application hosting, serverless functions, scheduled jobs, logs).
  • Anthropic (Claude models) for analysis, battlecards, briefs, digests and short classification tasks. We send the scraped page text and your workspace context needed for each task. Anthropic does not train on API inputs under its commercial terms.
  • ScrapingBee to fetch public web pages.
  • Stripe for payments, subscriptions and the billing portal.
  • Resend for account, billing and digest email, and for delivery events.
  • Google Analytics on the public marketing pages only.

If you connect Claude, Anthropic also acts as an independent controller for your Claude conversation under your agreement with them. If you install other connectors in Claude (a CRM, meeting notes, documents), that data flows between Claude and those services under their terms; Clinch receives only what Claude writes into your workspace through our tools.

We may disclose data when required by law, to protect the rights and safety of Clinch or others, or to a successor if Clinch is acquired, in which case this policy continues to apply until you are told otherwise.

Your role, our role

For your account and billing data, Clinch is the controller. For the content your team puts into a workspace, including any personal data about prospects or teammates, you are the controller and Clinch processes it on your instructions. If you need a data processing agreement or a list of subprocessors for your own compliance, email hello@getclinch.ai.

Sharing inside and outside your workspace

Everyone in your workspace can see its competitors, snapshots, analysis, battlecards, briefs, digests and logged deals. Owners manage members, billing and workspace settings.

Battlecards have a public share link. Anyone with the link can read that battlecard without an account; nothing else in your workspace is exposed by it. Links use a long random token and we count views. Regenerate or delete a battlecard to retire its link.

Retention and deletion

We keep your data while your workspace exists. Snapshots are kept as history so we can show what changed and when; that history is the point of the product.

You can leave a workspace or delete an entire workspace yourself from Settings > Workspace > Danger zone. Deleting a workspace removes its competitors, snapshots, analysis, battlecards, briefs, digests, deals, invites and connector tokens at once, and deletes the accounts of its members. Encrypted database backups may hold a copy for up to 30 days. If your subscription lapses, we stop monitoring and emailing but keep your data so you can return; email us if you want it deleted instead.

Server logs are kept for a limited period for security and debugging. Stripe keeps billing records as required by tax and accounting law.

Your rights

You can access and edit your workspace data in the app, export battlecards and briefs as PDF, turn the weekly digest off, and delete your account or workspace at any time. Depending on where you live (for example the EU, UK or California) you may also have rights to a copy of your data, correction, restriction, objection, and to complain to a data protection authority. Email hello@getclinch.ai and we will respond within 30 days. We do not sell or share personal data for advertising.

Cookies

The app uses essential cookies for sign in and session management and a browser setting for your light or dark theme. The public marketing pages use Google Analytics, which sets analytics cookies to measure visits in aggregate; you can block these with your browser or an extension without affecting the app. We do not use advertising cookies.

Security

Data is encrypted in transit and at rest. Access to each workspace is enforced in the database with row level security, so one customer cannot read another's data. Billing and plan fields can only be changed by our payment webhook, never by a user session. Claude access uses OAuth with short lived tokens that you can revoke in Claude. No system is perfectly secure; if we learn of a breach affecting your data we will tell you without undue delay.

Children and international use

Clinch is a business tool and is not directed at anyone under 16. Our servers are in the United States; if you use Clinch from elsewhere, your data is transferred there. We rely on our providers' standard contractual protections for those transfers.

Changes

When this policy changes in a way that matters, we will email workspace owners or show a notice in the app before it takes effect. The date at the top shows the current version.