AIClue Privacy Policy
Effective date: August 27, 2026
AIClue is a local file management tool for personal computers. We care about your privacy and file safety. This Policy explains what information AIClue may access, store, use, or transmit when providing file scanning, search, preview, filtering, project workspace, duplicate file detection, account and feature access, software updates, and related features, and how you can manage that information.
This Policy applies to the AIClue desktop app distributed through Microsoft Store or other official channels.
1. How We Handle Your Files
AIClue's core file management capabilities are local-first. After you add scan directories, AIClue reads file information on your device and creates local data for search, filtering, and preview.
During everyday scanning, search, filtering, preview, and project workspace use:
- AIClue does not upload your original files because you add scan directories.
- AIClue does not automatically upload file content because you run local search or preview.
- AIClue does not actively modify, move, copy, or delete your source files in the background.
- Operations that may affect real files or local records, such as deleting duplicates or clearing data, show a prompt or confirmation before execution.
If you choose to open a file with the system default app, subsequent handling is performed by that external app and is subject to that app's own rules.
2. Information We May Process
Depending on the features you use, AIClue may process the following information.
2.1 Local File and Directory Information
To provide file lists, search, filtering, preview, project workspaces, and duplicate detection, AIClue saves information related to scanned files on your device, including:
- Scan directory paths you add;
- File name, file path, extension, file type, file size, created time, modified time, and other file attributes;
- Processed text from readable files for local content search;
- File tags, classifications, extension mappings, and filter relationships;
- Project workspace names, states, and files associated with projects;
- Auxiliary data needed to find duplicate files, such as records used to determine whether file content is identical;
- Search history for search suggestions;
- App settings, such as language, theme, startup, tray, performance, privacy, dictionaries, file types, and exclusion rules.
This information is mainly stored on your local device so that AIClue can perform search, filtering, preview, duplicate detection, and workspace management locally.
2.2 Account and Feature Access Information
If you register, log in, or sync feature access, AIClue may process and transmit the following information:
- Email address;
- Password or information required for authentication requests;
- User ID, device ID, login state, and sync time;
- Device display name, operating system, app version, device identifier, or derived values;
- Trial state, feature access, entitlement plan, entitlement validity period, and related information;
- Tokens used to maintain login state and sync entitlements.
This information is used to create and log in to accounts, identify the current device, sync available features, determine trial or feature access state, and keep account services operating normally.
AIClue does not upload your local source files as part of account login or entitlement synchronization.
2.3 Behavior Logging Information
If you enable behavior logging in Settings, AIClue may save some usage behavior on your device to improve recent files, Workbench cards, or related feature effects. Depending on the level you choose, this may include:
- File click or open records inside the app;
- Drag-and-drop target app name;
- External window title;
- Related time, session identifiers, interaction counts, and additional state information.
You can adjust the behavior logging level or turn it off in Settings > Privacy Settings. You can also use the app blacklist to exclude apps you do not want recorded.
2.4 Update and Network Request Information
If automatic update checks are enabled, AIClue may access official release addresses or update services to check for new versions and download update packages when needed. These requests usually contain technical information required for network communication, such as IP address, request time, app version, and operating system type.
If you register, log in, sync entitlements, or log out, AIClue communicates with the account service to complete the corresponding feature.
2.5 Anonymous Website Analytics
When you visit the official AIClue website, we use a self-hosted Umami service to understand aggregate page traffic and the effectiveness of download entry points. The data includes sanitized page paths; marketing attribution parameters limited to utm_source, utm_medium, utm_campaign, utm_content, and utm_term; referrer pages with query strings and fragments removed; browser, operating system, device type, language, coarse country or region; and the placement and page language of download clicks.
This analytics service does not use cookies, invoke user identification, associate data with an AIClue account, device ID, or local client files, or enable session replay, heatmaps, or performance collection. Request IP addresses are used only to generate anonymous sessions and coarse location information and are not stored in their original form. When Do Not Track is enabled in the browser, the website tracker does not send analytics events. Marketing links must not place email addresses, account identifiers, tokens, or other sensitive values in the permitted UTM fields.
2.6 User Feedback and Optional Diagnostic Information
Redacted and scope-limited diagnostic material is uploaded only when you actively submit feedback and select the diagnostic data option. Diagnostic material does not include account credentials, tokens, user names, host names, raw databases, search indexes, hardware serial numbers, MAC addresses, or local absolute paths. The text you enter and images you select are handled as content you actively submit and are used only for issue analysis.
2.7 Desktop Activity Analytics
While the AIClue process is running, it automatically reports daily activity to calculate DAU, rolling 30-day MAU, and the latest 30-day trend. Signed-out activity is counted by anonymous installation, while signed-in activity is counted by account using the existing login credential. Activity before and after sign-in may be counted separately, so the total is not a strictly deduplicated person count. Each identity type is recorded successfully at most once per UTC date. This analytics behavior is enabled automatically and has no off switch.
To distinguish signed-out installations, AIClue keeps a randomly generated anonymous number in its local database. Clear all data inside the app preserves this number. When signed in, the service keeps only the internal account ID, UTC activity date, and receipt time. When signed out, it keeps only a further-anonymized installation number, UTC activity date, and receipt time. The report does not include the app version, operating system, host name, user name, email address, files, paths, search content, feature clicks, usage duration, hardware identifiers, or other usage behavior. It does not save the received anonymous number or IP address. The IP address is used only at request time to limit abnormal repeated submissions.
3. How We Use This Information
We use the information above to:
- Display file lists, search results, filter results, and file previews;
- Create and maintain local search data;
- Manage scan directories, exclusion rules, tags, classifications, and project workspaces;
- Find duplicate files and help users confirm cleanup targets;
- Save user settings, search history, and local usage state;
- Provide account login, registration, anonymous trial, feature access checks, and entitlement synchronization;
- Check, download, and install software updates;
- Measure total, account, and signed-out desktop activity DAU, rolling 30-day MAU, and short-term trends;
- Improve in-app experience and feature recommendation effects;
- Troubleshoot issues, protect service security, and prevent abuse.
Unless you actively use account features, entitlement synchronization, update checks, or another feature that clearly requires network access, AIClue's file scanning, content reading, regular search, and preview are mainly completed on your device.
4. Storage and Protection
AIClue stores local data on your device, such as in the app data directory, database files, search data files, or configuration files. The exact storage location may vary by installation method, operating system, and app version.
We take reasonable measures to protect related information, including:
- Saving file records, search data, settings, and workspace data locally on your device;
- Using account tokens and entitlement state only to maintain login and feature access;
- Using network communication only for corresponding features such as account, entitlement, and update functions;
- Showing confirmations or prompts before important operations such as clearing data or deleting duplicate files.
Please note that no software or network transmission method can be guaranteed to be absolutely secure. You should also protect your device, system account, disk permissions, and AIClue account password.
5. Sharing and Disclosure
We do not sell your personal information.
We may share or disclose necessary information in the following circumstances:
- To transmit necessary information to relevant service providers for account, feature access, update downloads, software distribution, hosting, or technical support;
- To comply with applicable laws, regulations, regulatory requirements, legal process, or lawful government requests;
- To protect the lawful rights, safety, and property of AIClue, users, or the public;
- In connection with a merger, division, acquisition, asset transfer, or similar transaction, as required by applicable law.
When you download, install, or update AIClue through Microsoft Store, Microsoft may process information related to Store download, installation, purchase, review, crash reporting, or device environment under its own policies. Such processing is not controlled by AIClue. Please also review Microsoft's privacy statements.
6. Your Choices and Controls
You can manage information use in AIClue in the following ways:
- If you do not add a directory, AIClue will not scan that directory;
- Remove a directory in Directory Management to delete records related to that directory from AIClue;
- Use exclusion rules to skip directories, paths, or file types you do not want scanned;
- Delete search history items you no longer need from search suggestions;
- Adjust or turn off behavior logging in Settings > Privacy Settings;
- Clear AI analysis results, clear the file index, or clear all data in Settings > Privacy Settings > Data Management;
- Turn off automatic update checks in Settings;
- Log out in Account Center;
- Choose whether to share diagnostic data when submitting a problem or suggestion;
- Desktop activity analytics is an automatic network behavior and has no off switch. Clear all data inside the app does not change the anonymous installation number used for signed-out analytics;
- To access, correct, or delete account-related information, contact us using the method at the end of this Policy.
Clearing local data does not actively delete source files on disk. Delete operations on the duplicate detection page affect real files and move selected files to the system recycle bin. Please confirm carefully before execution.
7. Data Retention
Local file records, search data, project workspaces, settings, behavior logs, and search history are usually kept on your device until you clear them in the app, remove directories, reset data, or uninstall/delete related local data.
Account, feature access, and entitlement synchronization information is retained as needed by the account service for login, trial, feature access, device management, and security auditing. You may contact us to request handling of account-related information.
Images and diagnostic attachments submitted with feedback are automatically deleted 30 days after the feedback enters the resolved or closed state. Other than your description, environment summaries and other analytical information exist only inside the diagnostic attachment and are not retained as separate fields. Feedback text, processing status, and attachment inventory remain available for support records, security auditing, and service improvement.
Desktop installation and account activity details retain only the current server UTC date and the preceding 59 dates, for a total of 60 date buckets. The server maintenance process deletes activity details outside that range, and account deletion also removes the related activity details. This analytics feature does not create a separate long-term installation profile, account behavior profile, or a record for every process start.
Anonymous website analytics is self-hosted and retained only for as long as needed to analyze website use and download effectiveness. We do not currently promise a fixed automatic deletion or backup-retention period. We periodically review whether this data is still needed and delete it when it is no longer required. You may also contact us using the method at the end of this Policy to request handling of related analytics data. We will update this Policy when fixed lifecycle controls are introduced.
8. Children's Privacy
AIClue is intended for general personal computer users and is not specifically directed to children. If you are a minor, please use this software under the guidance of a guardian. If a guardian believes that a minor has provided information that should not have been provided, please contact us.
9. International Transfers
Depending on the deployment of account services, update services, software distribution, or hosting services, your account and network request information may be transferred to servers outside your region. We will take reasonable measures to protect related information as required by applicable law.
Local file scanning, content reading, regular search, and preview are mainly completed on your device and do not automatically upload original files because you add directories or run local searches.
10. Third-Party Services
AIClue may rely on the following third-party or external services for some features:
- Microsoft Store, for app distribution, installation, updates, and Store-related services;
- Official release or update hosting services, for checking and downloading new versions;
- Account and feature access services, for registration, login, anonymous trial, entitlement synchronization, and device state management;
- System default apps or file managers that you actively invoke, for opening, editing, or locating files.
Third-party services process related information under their own privacy policies. Please read those policies when using the corresponding services.
11. Policy Updates
We may update this Policy based on product features, laws and regulations, or service methods. After the Policy is updated, we will notify you through the app, official website, Microsoft Store page, or other reasonable methods. The updated Policy takes effect from the publication date or the stated effective date.
12. Contact Us
If you have any questions, requests, or complaints about this Policy or personal information processing, you can contact us through:
- Developer: AIClue Team
- Contact email: aiclue@boxai365.com
To protect account and data security, we may need to verify your identity before handling access, correction, deletion, or other privacy-related requests.