cleat.

Last updated September 11, 2026

Privacy Policy

Hyppe Tech LLC runs Cleat. This policy explains what we collect, why, who sees it and how long we keep it. We don’t sell your data, and we don’t use advertising or tracking cookies.

What we collect

  • Account: your name, email address and password. Passwords are stored only as a one-way hash.
  • Identity verification: your ID document and selfie go to Stripe, which checks them. We receive the outcome and a reference to the check, not copies of your ID or selfie.
  • Payments: Stripe handles your card. We keep a Stripe customer reference and each line’s subscription status.
  • Texts your lines receive: the sender, the message, when it arrived and any code we detect in it.
  • Settings and teams: email-forwarding choice, your Telegram chat if you connect one, webhook URLs, API key names (keys themselves are stored only as hashes), workspace members and invite emails.
  • Security data: to stop abuse we count requests per IP address and account. These counters store only one-way hashes and are deleted when their time window ends. Our hosting providers also keep standard request logs.
  • Waitlist: your email, if you ask to hear about Cleat Full.

How we use it

  • to run Cleat: set up lines, show your texts and deliver them where you ask;
  • to verify identities and prevent fraud and abuse;
  • to bill you;
  • to send account email, such as password resets, security notices and team invites;
  • to meet legal obligations.

Who we share it with

Only the providers that help us run Cleat, each for its part:

  • Stripe: payments and identity verification.
  • Resend: sending email, including texts you choose to forward by email.
  • Telegram: texts you choose to forward there.
  • Telecommunications partners: they provide the numbers and route texts sent to them to us.
  • Database and hosting providers: they store and serve Cleat’s data for us.

Texts also go wherever you point them: your teammates, your webhook endpoints and apps using your API keys. We may disclose information when the law requires it, to protect people or Cleat from harm, or to a company that takes over Cleat, which would stay bound by this policy.

How long we keep it

  • Account data and texts are kept until you delete the workspace or your account.
  • Password-reset links expire after an hour; abuse counters are deleted when their window ends.
  • Billing records are kept as long as tax and accounting law requires.
  • Backups held by our providers can persist for a limited time after deletion.

Cookies

We use two cookies, both needed for Cleat to work: one keeps you signed in, and one remembers which workspace you’re viewing. There are no analytics, advertising or tracking cookies.

Your choices and rights

  • Update your name, turn email forwarding off, disconnect Telegram or revoke API keys in Settings.
  • Delete your account in Settings; it removes the workspaces you own and their texts.
  • Ask for a copy of your data, a correction or a deletion by writing to contact@cleat.so. Depending on where you live, for example California, the EU or the UK, you may have further rights, and we’ll honour them as the law requires.

Security

Connections are encrypted, passwords and keys are hashed, webhooks are signed, and texts are visible only to members of the workspace that owns the line. No system is perfectly secure; if we learn of a breach that affects you, we’ll tell you as the law requires.

Children, location and changes

Cleat isn’t for anyone under 18. We process data in the United States. If we change this policy in a meaningful way, we’ll tell you by email or in the app first. The Terms of Service also apply.

Contact

Questions or requests about privacy: contact@cleat.so.