Privacy Written plainly. Last changed 1 October 2026.

Privacy notice — Clavis

What this site keeps, and what it does not.

Short, because there is not much to say. Every statement here is true of the site as it is built today; when the code changes, this page changes with it.

Who runs it

Clavis, run by Mario Kaspers, who also runs the studio it was built for. Write to hello@useclavis.ai about anything on this page, including a request to delete what you gave; it reaches him, and he answers it himself. The sign-up form on the home page and Instagram, @clavis_ai, reach him just as well.

The sign-up form

It asks for an email address and/or a WhatsApp number, and a studio name if you want to give one; either contact is enough and the studio is optional. The form is handled by Netlify Forms — Netlify is the host this site runs on — and the submission is stored there. It is used for one thing: Mario replying to you, himself, by the channel you gave. There is no mailing list, no automated sequence and no account behind it.

Booking a call

The calendar on the home page is Clavis’s own booking — the same product the page is about, running on Clavis’s production stack (a database in Frankfurt, where the Clavis studio is one tenant among others, each separated from the rest by row-level security). Signing in is by email: you give a name and an email address, prove the address with a six-digit code sent to it, answer three short questions about your studio, and pick a time. What is stored: your name and email address as a member record of the Clavis studio, the three answers as a note on that record, and the booking itself. The booking is written while you wait — one request, one transaction — so the time is yours by the moment the screen says so.

The confirmation, and anything else about the call, goes to that address; the confirmation carries the call as a calendar file (an .ics attachment), and the “Add to calendar” buttons on the page write the same appointment in your browser. Nothing is sent to a calendar service on your behalf: the Google Calendar button is a link you choose to follow, and Clavis holds no calendar account of yours. The sign-in token the code issues is kept in your browser’s session storage — this tab, until you close it — and nowhere else. Deletion on request, at the address above.

The demo page

The demo is a Clavis studio of its own. Whatever you give it — the WhatsApp number or email address you type in, the messages you send, the test-card payments you make — is stored in a separate sandbox database in the EU (Supabase, Frankfurt), not in any live studio’s. Stripe runs in test mode there, so no real money moves. The sandbox can be wiped at any time.

The demo page also keeps a little in your own browser, so the account pane survives a refresh: the email address or WhatsApp number you typed, in the browser’s local storage under this site; and the framed chat keeps its own session id and sign-in token in its storage the same way. None of it is a cookie, none of it is read by anyone but that page, and clearing this site’s data in your browser removes all of it.

Instagram and WhatsApp

Clavis’s Instagram account, @clavis_ai, and its WhatsApp number reach Clavis through Meta’s own interfaces, by an app registered with Meta as “Clavis” (App ID 1081001124824384) under E-Pulsive Ltd’s Meta business account — Clavis is made by the studio that runs on it.

Instagram. When you comment on a post by @clavis_ai, Clavis stores the comment, your Instagram username and the ID Instagram gives you, when you wrote it and which post it was on, so that Mario can read it and answer it from Clavis’s own dashboard rather than from the Instagram app. If you comment the word a post asks for, Clavis may reply with one private message — Instagram allows one per comment — and tapping the button in it sends you the link. Direct messages you send to @clavis_ai are stored the same way: what you wrote, your username and ID, and the time. Mario reads and answers them. An AI assistant answers an Instagram conversation only if he switches it on for that one conversation; nothing is switched on by default. To show which post a comment belongs to, Clavis also reads @clavis_ai’s own profile and posts.

WhatsApp. Clavis’s WhatsApp number is +44 7743 277317, and today Mario answers it himself in the WhatsApp Business app. It is being connected to the demo: once it is — this page will say so, and when — a message you send it will also reach the demo’s sandbox described above, where an AI assistant answers and Mario can join the same conversation from his phone. Clavis will then store your number, what you wrote and what was sent back, and use Meta’s WhatsApp tools to manage its own number and message templates. The login codes the demo sends over WhatsApp already go through Meta’s WhatsApp Business Platform.

Where it goes. Instagram data is kept in Clavis’s production database and WhatsApp data in the demo’s sandbox — both Supabase, in Frankfurt — and the servers that handle it run in the Netherlands (Railway). Background work is scheduled by Inngest, a US company, which is sent record identifiers and, for Instagram, the ID Instagram gives you, never what you wrote. When the AI assistant answers, the conversation is sent to Anthropic, a US company, to write the reply, under commercial terms that do not allow Anthropic to train on it. Meta receives what Clavis sends through Instagram and WhatsApp, under Meta’s own terms. None of it is sold, shared for advertising, or used for anything but answering you.

Having it deleted. Write to hello@useclavis.ai with the subject “Instagram or WhatsApp data” and your Instagram username or WhatsApp number. Everything Clavis holds from you is deleted within 30 days, and you get a confirmation. Deleting a comment or a chat on Instagram or WhatsApp removes it there, but not Clavis’s copy; that needs the request.

Analytics and cookies

Nothing loads until you say yes. On a first visit this site runs no analytics and sets no cookie; a panel asks, and only Accept loads anything. Reject loads nothing and is remembered. Your answer is kept in this browser’s local storage under this site — it is not a cookie and it is not sent anywhere — and Cookie choices, in the footer of every page, reopens the panel so you can change it as easily as you gave it.

If you accept, three things load:

  • Google Analytics 4 — which pages were read, from where, and whether a call was booked. Sets the _ga cookies. Accepting also switches on Google’s advertising features for Clavis’s own ads: if you arrived from a Clavis ad on Google, the visit and a booked call are credited to that ad (the _gcl cookies), and Google may show you a Clavis ad later because you were here.
  • Meta Pixel — the same visit counted on Meta’s side, including whether you booked a call or left your contact. Sets _fbp, tells Meta you were here, and lets Clavis show you its own ads on Instagram and Facebook and count what they lead to.
  • Microsoft Clarity — this one records the session: scrolling, clicks and mouse movement, played back as a video so we can see where a page stops making sense. Typing in form fields is masked by Clarity before it leaves your browser. Sets _clck and _clsk.

Advertising, in one sentence. Saying yes covers measurement and advertising together: Clavis may advertise its own product to people who have visited, on Google and on Meta, and measure which ad led to a visit or a call. No name, email address or phone number you type here is sent to either for that, nothing is sold, and nobody else’s advertising uses it. Saying no switches all of it off, and you can turn off ad personalisation in your own Google and Meta account settings whatever you chose here.

Each of the three reports into an account of its own for this site, separate from the accounts E-Pulsive Ltd uses for its studio: nothing recorded here is mixed with the studio’s visitors, and nothing recorded there appears here. All three are US companies and the data is processed outside the UK under their own terms. None of them is needed for this site to work, which is why none of them loads on a refusal.

What the demo page keeps in your browser’s own storage is described above, and so is the booking’s sign-in token; neither is a cookie. The demo’s framed panes are other origins running under their own notices, and may set their own.

Retention and your rights

Anything you sent through the form is deleted on request — ask at the address above and it goes. Demo data is wiped with the sandbox, and can be wiped for you sooner on request the same way. A booking and the member record behind it are handled the same way: ask, and the record goes through the product’s own erasure — your name, email address and the note holding your three answers are cleared from it, your sign-in sessions are deleted, and what remains is an anonymous row of times and status with nothing on it that points back to you.

Last changed 1 October 2026.