1. Who we are
Clynt is operated by Clynt, the company behind clynt.ai and the Clynt Chrome extension. When this policy says “Clynt,” “we,” “us,” or “our,” it refers to that operator. When it says “you” or “your,” it refers to the attorney or law-firm staff member who creates and uses a Clynt account.
The Clynt product has two parts. The Chrome extension operates inside your authenticated ECAS browser session and reads the hearing data that session loads and, on Pro and Premium plans, the documents in your clients' case records (see §3). It syncs when you enter ECAS and at intervals while that session remains active. It never writes anything back to EOIR and never sends your ECAS cookies, session tokens, or EOIR authorization headers to Clynt. The web app at clynt.ai stores those hearings in your account and lets you manage them, export them, sync them to your calendar, and message your clients. This policy covers both.
2. Data we collect about you (the attorney)
When you create a Clynt account, we collect:
- Your email address — used to sign you in, send you product emails (see §4), and identify you to our payment processor.
- Your first name, last name, and organization — what you typed into the sign-up form. We store these on your account record.
- A password — handled and stored by Supabase, our authentication provider (see §4). We never see your password in plaintext.
When you sign in, Supabase authentication uses first-party cookies scoped to clynt.ai to maintain your session. We also use first-party browser storage for product preferences and temporary application state. See §6.
When you connect Google Calendar, Outlook Calendar, or Gmail through Clynt, we store an OAuth access token and refresh token for that connection. These tokens let Clynt act on your behalf within the scope you granted at the consent screen — nothing more. We do notstore your Google or Microsoft password. See §5 for how those tokens are protected.
When you subscribe, our payment processor Stripe collects your payment information directly through its hosted checkout. We do not see or store your card number, CVC, or billing address. Stripe shares back a customer identifier and your subscription status, which we keep so we can recognize your plan.
We do not collect your physical location, your phone number, your browsing history, or any data about how you use other websites.
3. Data you ask us to store about your clients
To do its job, Clynt stores data about the immigration clients whose hearings you track. This information is your clients' — not Clynt's. We treat it as such.
When the Chrome extension captures a hearing from your authenticated EOIR session, it sends the following fields to your Clynt account:
- The respondent's A-Number (alien registration number) and full name
- The hearing's date and time, type, and medium (in-person, video, etc.)
- The assigned immigration judge's name
- The courthouse address and EOIR location code
- On Pro and Premium plans, the documents in the case record as PDF files, with their details (see “Court documents from your clients' case records” below)
If you add your client's contact information to a hearing, we also store that contact's phone number, email address, and any notes you add. If you write notes or checklist items on a hearing, we store those exactly as you typed them.
We capture this data only from EOIR sessions you are already authenticated in, while that session is active in your browser. The Chrome extension never sees your EOIR username or password and never logs you in on your behalf. It reads hearing data and, on Pro and Premium plans, case-record documents made available through that active session. It never submits, changes, or deletes anything in EOIR. The extension does not read your email inbox to discover hearing changes.
Court documents from your clients' case records
On Pro and Premium plans, the Clynt Chrome extension also retrieves the documents in your clients' EOIR electronic Record of Proceedings (eROP) — such as hearing notices, orders, decisions, and other filings — and saves them as PDF files. It does this only through your own logged-in ECAS session: when you open a case in ECAS, after a sync detects a change to a hearing, during scheduled re-checks while your ECAS session is still active in your browser, and when you choose Refresh in Clynt. Clynt never receives your ECAS password, cookies, or session tokens.
We use these documents to confirm and keep your case details current — for example, to detect hearing cancellations and reschedules, extract dates and deadlines, and let you find and read a case's documents in Clynt.
The PDFs are kept in private storage in the United States (Supabase). Details such as the document's title, type, filing date, and the client's A-Number are stored with them. Members of your organization can see document details and summaries; the PDF file itself can be opened only by the team member whose account retrieved it.
On the Premium plan, the text of these documents is processed by our AI providers (Anthropic, with OpenAI as a fallback) to produce summaries and extract hearing details, and when you use Ask Clynt on a case. You can delete documents in Clynt. If the same document is still available in ECAS, the extension may retrieve it again on a later sync.
The extension compares later ECAS syncs with previously captured hearing data and uploads a timestamped history of detected changes. That history is available only to authorized members of your Clynt organization, subject to their account access.
Clynt uses an AI provider to power assistive features — for example, the plain-English summary of your week on the Hearings page and, on the Premium plan, document summaries and the Ask Clynt case assistant. When one of these features runs, the relevant hearing data (such as hearing dates, courts, judges, hearing types, and respondent names) and, for document features, the text of the relevant court documents is sent to our AI provider solely to generate that result for you. On the Premium plan, court documents are analyzed automatically, not only when you ask.
Depending on service configuration and availability, Clynt may process these requests through OpenAI or Anthropic. We use their business/API services rather than consumer chat products. We do not sell this data or use it for advertising. AI-generated content can be incomplete or wrong, is not legal advice, and must be verified against the official EOIR record and your case file.
4. Where your data goes
We share data only with the service providers we need to run Clynt. The principal providers are listed below with a description of what we send them and why. We do not sell your data or share it with advertisers.
- SupabaseData & auth
- Hosts the database and file storage that hold everything in §2 and §3 (including court-document PDFs), and manages your password and login sessions. Connections are encrypted in transit. Data is stored in the United States. Supabase acts as our processor.
- Stripe and Stripe TaxPayments
- Processes your subscription payments. Stripe receives your email address, the plan you choose, and the payment information you enter on Stripe's own checkout page. Stripe Tax collects address information to compute applicable tax. Stripe is independently certified at PCI Service Provider Level 1.
- Google (Calendar and Gmail) — only if you connect themOptional
- If you connect Google Calendar, Clynt uses the OAuth scope you granted to read your calendar list and to create, update, and delete calendar events for the hearings you push. If you connect Gmail, Clynt uses Gmail's send permission (
gmail.send) to send client-facing messages (such as hearing reminders) from your own Gmail address; it does not read, modify, or delete your mail. You can disconnect either at any time from the settings page in Clynt. - Microsoft (Outlook Calendar) — only if you connect itOptional
- Uses Microsoft Graph to list calendars and create, update, or delete Clynt-created hearing events on the calendars you select. Clynt does not use Outlook Mail to discover hearing changes.
- ResendEmail
- Sends transactional Clynt emails, including account messages, invitations, hearing-change alerts, weekly digests, reminders, and billing or service communications. Resend receives the destination email address and message contents.
- VercelHosting
- Hosts the clynt.ai web app and serves every page request. Vercel sees the standard request data any web host sees: your IP address, the page you requested, and your browser's user-agent string. Vercel also stores function logs that may include error messages from the application. Vercel is operated in the United States.
- OpenAI and AnthropicAI processing
- When an AI-assisted feature runs, one of these providers may receive the hearing data, court-document text, and prompt needed to produce that result (see §3). Provider selection can change for availability or service-quality reasons. Calendar and Gmail API data is not sent to these providers to train generalized AI models.
We may add or change service providers in the future. When we do, we'll update this list before the change goes live.
Google Workspace API — Limited Use
Clynt's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
Specifically, Clynt does not use, transfer, or sell Google Workspace or Google user data — including raw, aggregated, or derived data — to develop, improve, or train generalized or foundational machine-learning or artificial- intelligence models. The AI-assisted features described in §3 operate only on the hearing and case data you store in Clynt to produce a result for you; they do not send your Google Workspace data (such as Google Calendar events or Gmail messages) to any AI/ML model, and no Google user data is ever used for model training, whether by Clynt or by any third-party AI provider we use.
5. How we secure your data
All connections to clynt.ai and to our service providers use TLS encryption. Your session cookie is set withHttpOnly, Secure, and SameSite=Lax attributes.
Database rows in Supabase are protected by row-level security policies that ensure only members of your Clynt organization can read or modify your organization's data; members of the same organization share access to its hearings and case details. Server-side actions that bypass these policies (for example, processing a Stripe webhook) are limited to the narrow operations they need to perform.
OAuth tokens for Google Calendar, Outlook, and Gmail are encrypted at rest using AES-256-GCM with a key held by the Clynt application server, separate from the database itself. The plaintext tokens are decrypted in memory only when needed and are never written to logs.
No security program is perfect. We work continuously to improve ours. If you believe you have found a security issue, please email us at support@clynt.ai and we will respond promptly.
7. How long we keep data
We keep your account data for as long as your account is open. We keep the hearings, clients, and notes you store in your Clynt account so that the system is useful to you over the lifetime of each immigration case.
A few categories of data behave differently and we want you to know:
- Change history. When the extension detects a material difference between ECAS syncs, we keep a timestamped record of the prior and new values so authorized organization members have an audit trail. These records may remain after the related hearing is removed.
- Court documents. Court-document PDFs and their details are kept like the rest of your account data until you delete them. If a deleted document is still available in ECAS, the extension may retrieve it again on a later sync.
- Stripe webhook logs. For accounting and dispute resolution, we keep a copy of the subscription events Stripe sends us. These records include your account email and Stripe customer identifier and are retained indefinitely unless you ask us to delete them.
- OAuth tokens after a disconnect. When you disconnect Google Calendar, Outlook, or Gmail from Clynt, the connection is marked as removed and Clynt stops using it immediately. The encrypted token record is retained for a short period to support reconnecting without re-authorizing every scope. If you want the stored tokens deleted immediately on disconnect, please email us — see §8.
- Email delivery metadata. Resend, our email provider, retains delivery metadata about transactional emails (sent, delivered, opened) per Resend's own retention policy.
If you close your account, see §8 for how to request full deletion.
8. Your rights and how to exercise them
You have the following rights over your data. To exercise any of them, email us at privacy@clynt.ai from the email address associated with your Clynt account.
- Access. You can see all the data on your Clynt account at any time by signing in. If you need a machine-readable export, ask us and we'll send it.
- Correction. You can edit every field you control directly in the app. If you find an error in something you can't edit, ask us and we'll correct it.
- Deletion. You can ask us to delete your account and the data associated with it. We don't have a self-service delete button yet — for now, email us and we'll act on your request within 30 days. We'll also delete your customer record from Stripe. Some records (Stripe webhook events, anonymized invoices) may be retained where the law requires us to keep them.
- Portability. You can request a copy of your account data in JSON form.
- Withdraw consent. You can disconnect Google Calendar, Outlook, or Gmail at any time from the Calendar settings page. You can also revoke Clynt's access directly with Google or Microsoft.
- Complain. If you believe we've mishandled your data, you may file a complaint with your jurisdiction's data-protection authority.
9. International users
Clynt is built for U.S. immigration attorneys, and our servers are located in the United States. If you access Clynt from outside the United States, your data is transferred to and processed in the United States. If you are located in the European Economic Area, the United Kingdom, or Switzerland, we rely on the standard contractual clauses with our processors (Supabase, Stripe, Resend, Vercel, OpenAI, Anthropic) to legitimize this transfer.
10. Children
Clynt is a tool for licensed attorneys and law-firm staff. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with information, please contact us and we'll delete it.
11. Changes to this policy
We'll update this page when our practices change. Material changes (a new processor, a new category of data, a new use of your data) will be announced by email to your account address before the change takes effect. Editorial changes (clarifications, formatting) may be made without notice; the “Last updated” date at the top of this page reflects the most recent change.
12. Contact
For privacy questions or to exercise any right above, security reports, or anything else: support@clynt.ai.