Draft — to be reviewed by a lawyer before launch.
Privacy Policy
Last updated: September 29, 2026
This policy explains what personal data Clozr collects, why, who we share it with and the choices you have. It covers our website, the Clozr app and the AI setter service we run on Instagram for our customers.
1. Who we are
Clozr ("Clozr", "we", "us") provides an AI setter for fitness coaches: software that answers Instagram direct messages on a coach's behalf, qualifies leads and books calls. You can reach us at support@clozr.com.
We deal with three groups of people:
- Visitors to our website, including people who request a Lost Leads Audit.
- Customers: coaches and their team members who use Clozr.
- Leads: people who send a direct message to a customer's Instagram account.
For leads' data, the customer (the coach) decides why and how their Instagram conversations are handled, and we process that data on their behalf and on their instructions. For visitor and customer data, we decide how it is used.
2. What we collect
Website visitors
- Audit form: your answers (DMs per month, what you sell, price range), name, email, Instagram handle and WhatsApp number.
- Attribution: the page you came from, campaign tags in the link (UTM parameters) and Meta advertising identifiers stored in cookies (
_fbp,_fbc). - Booking details: if you book a call, the time and the details you give in the scheduling tool.
- Usage data: pages viewed, device and browser information, collected through the Meta Pixel and Google Analytics 4 (see Cookies below).
Customers
- Account data: name, email, business name, and your alert phone number if you turn on WhatsApp alerts.
- Billing data: handled by Stripe. We receive your plan, invoice history and the last four digits of your card; we never see or store full card numbers.
- Instagram connection: when you connect through Instagram Login, Meta gives us your Instagram professional account ID, username and an access token for the permissions you approve (
instagram_business_basicandinstagram_business_manage_messages). The token is stored encrypted. We never receive your password. - Setup material: past messages and captions you share so we can model your voice, your sales script, offer details, prices, red lines and booking link.
- Calendar connection: if you connect Calendly, booking events for calls booked through Clozr.
Leads (people who message our customers)
- Instagram-scoped user ID, username and display name as provided by Meta's API.
- The content of messages exchanged with the customer's account, including replies drafted or sent by Clozr.
- Information the lead chooses to share in the conversation (for example goals, timeline, budget) and any call they book.
3. How we use it
- To provide the service: receive a customer's Instagram messages, draft and send replies in their voice, qualify leads, send booking links and record booked calls.
- To keep the customer in control: approval queues, takeover, alerts on hot leads and weekly reports.
- Quality control: our team reviews conversations the AI flags (for example low confidence, or a lead asking for a human) to fix the customer's script.
- To run audits and demos you request, and to contact you about them by email or WhatsApp.
- Billing, support, security, fraud and abuse prevention, and meeting legal obligations.
- Measuring our own marketing (which ads and pages lead to audit requests and booked calls).
We do not sell personal data. We do not use Instagram data from our customers' accounts for advertising, and we do not use it to train general-purpose AI models. A customer's conversations are used only to run and improve that customer's own setter. See our AI & Data Policy for details.
4. Legal bases (UK, EEA and similar laws)
- Contract: to provide the service to customers and to run the audit you asked for.
- Legitimate interests: security, quality control, improving our service and measuring our marketing, balanced against your rights.
- Consent: for non-essential cookies and advertising pixels where the law requires it.
- Legal obligation: tax, accounting and responding to lawful requests.
5. Who we share it with
We share data only with service providers that help us run Clozr, under contracts that limit their use of it:
| Provider | Purpose |
|---|---|
| Meta Platforms | Instagram API (receiving and sending messages); Meta Pixel and Conversions API on our website |
| Anthropic | AI model that drafts replies and classifies conversations |
| Supabase | Database, authentication and file storage (United States) |
| Stripe | Subscription billing and payments |
| Twilio | WhatsApp alerts to customers (optional) |
| Calendly | Booking audit calls and customers' sales calls |
| Google Analytics 4 on our website; business email | |
| Our hosting provider | Serving the website and app |
We may also disclose data if required by law, to protect our rights or users' safety, or as part of a merger or acquisition (in which case this policy continues to apply).
6. International transfers
Our database is hosted in the United States and some providers process data in other countries. Where UK or EEA data is transferred, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK Addendum.
7. How long we keep it
- Customer account, conversation and setup data: while the account is active. After cancellation or a deletion request we delete it within 30 days.
- Instagram access tokens: deleted as soon as you disconnect Instagram or remove our app.
- Audit requests from visitors who don't become customers: up to 24 months, or sooner on request.
- Billing records: as long as tax and accounting law requires (typically up to 7 years).
- Backups roll over on their normal cycle and are not restored except for disaster recovery.
8. Security
We use encryption in transit (HTTPS) and encrypt Instagram access tokens at rest. Access to customer data is restricted by account, by database-level access rules and to team members who need it. No system is perfectly secure; if a breach affects your data we will tell you as the law requires.
9. Your rights
Depending on where you live (for example the UK, EEA, California or other US states, Canada or Australia), you may have the right to access, correct, delete or export your data, to object to or restrict certain uses, to withdraw consent, and to opt out of "sale" or "sharing" for targeted advertising. We will not treat you differently for using these rights.
To use them, email support@clozr.com. We may need to verify your identity. If you are a lead who messaged one of our customers, you can also contact that coach directly; we will help them respond. You can also complain to your local data protection authority.
To delete your data, see our Data Deletion page.
10. Cookies and tracking
Our website uses the Meta Pixel and Google Analytics 4 to measure visits and ad performance, and first-party storage to remember the campaign you arrived from. You can block or delete cookies in your browser, opt out of Google Analytics with Google's browser add-on, and manage ad preferences in your Meta account settings. The logged-in app uses only cookies needed to keep you signed in.
11. Children
Clozr is a business service and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe we have, contact us and we will delete it.
12. Changes
We will update this page when our practices change and change the "Last updated" date above. For material changes we will notify customers by email before they take effect.
13. Contact
Questions or requests: support@clozr.com.
