This policy covers two different things that both carry the Clubria name: the marketing site you are reading now, and the platform a community runs on. They collect very different amounts of data, so they are described separately.
Who we are
Clubria is built and run by the team behind AI Builders.club, working out of Amsterdam. For questions about your data, or to exercise any of the rights below, email hello@clubria.com.
This website
clubria.com is a static site. It sets no cookies, runs no analytics or advertising trackers, and stores nothing in your browser. Reading these pages leaves no profile of you with us.
Two things on the site do send us something, and only when you choose to use them:
- The waitlist form. Your email address, plus the answers you give about how many events you run, your region and countries, your event formats, the platforms you use today, an optional link to your events page, and what you use now. The email is stored as a contact marked as a subscriber, and the answers are stored with it so we can build the product for the communities actually asking for it.
- The demo request. This opens your own mail client and sends us a normal email. Nothing is submitted to us until you press send there.
The waitlist form also runs basic anti-spam checks on the answers, which is the only automated judgement made about a submission.
The Clubria platform
If your community runs on Clubria, the platform holds what the community needs to operate:
- Account details you give us: name, email, and profile information.
- Content the community creates: events, contacts, teams, messages, invoices and files that are uploaded.
- Data from services you choose to connect, such as a calendar or an event platform.
- Basic technical logs needed to keep the service secure and working.
A community administrator can see and manage the community's data, in the same way an administrator always could. What is visible to other members depends on the role and the settings your community chose.
How we use it
- To run the community: events, scheduling, messaging, members and profiles.
- To send messages you asked for, or that relate to your own activity.
- To answer waitlist and early-access questions, and to tell you when Clubria is ready for you.
- To keep the platform secure and to fix problems.
We do not sell personal data, we do not use it for advertising, and we do not use one community's data to serve another.
Connected accounts
Connecting a third-party account is optional. Each feature asks separately for the narrowest access that makes it work, and nothing is requested until you start that feature.
- Calendar (
calendar.readonly,calendar.events): read your calendar so scheduling shows your real availability, and create or update the meetings and events you choose to add. - Contacts (
contacts.readonly): if you choose to import contacts, we read your Google contacts once to create the community contacts you select. - Drive (
drive.file): limited to the individual files you pick or that Clubria itself creates. We cannot see the rest of your Drive. - Gmail (
gmail.readonly): used only by an administrator who connects their own mailbox so replies to community mail appear in one inbox. We read message content to display those threads and never send mail from your account. - Event platforms and messaging channels, such as Luma, Meetup, Eventbrite and group chat: we read and publish the events and posts you ask us to keep in sync, under your own account there.
You can disconnect at any time from the integrations page, or from the provider's own account settings, which revokes our access. Disconnecting deletes the stored access token.
Google API Services Limited Use
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we do not transfer or use Google user data:
- for serving advertising, including retargeted, personalised or interest-based advertising,
- to sell it, or to provide it to data brokers or information resellers,
- to determine credit-worthiness or for lending purposes,
- to train or improve generalised or non-personalised AI or machine-learning models.
We transfer Google user data to others only as needed to provide the feature you asked for, to comply with law, or as part of a merger where this policy still applies. No human reads your Google data except with your explicit consent, for security, or where required by law.
How we protect your data
These are the measures actually in place, not a wish list.
- In transit: every connection to this site, to the platform and to its API is served over HTTPS, with plain HTTP permanently redirected and certificates renewed automatically.
- Access control: a role-based permission system decides what each person can read and change, scoped to the community and team they belong to.
- Connected-account tokens stay on the server: the token from a Google or other connection is never sent to your browser. The app can see only whether a connection exists and which account it belongs to.
- Sign-in flows: OAuth connections use PKCE and a single-use, short-lived state value, so a link cannot be replayed or pointed at someone else's account.
- Encrypted at rest: the secrets that would be most damaging to leak, mailbox passwords and stored API keys, are encrypted in the database with AES-256-GCM and are never returned by any query a browser can call. Other data, including community content and connected-account tokens, is stored unencrypted at the application layer and protected by the access controls above.
No system is perfectly secure, and we would rather be specific than reassuring. If you find a security problem, mail hello@clubria.com and we will treat it as urgent.
Sharing
We share data only with the service providers who help us run Clubria, for example hosting, storage and email delivery, and only so they can perform that work for us. We may disclose data where the law requires it. We do not sell personal data.
Retention and deletion
We keep your data while your account is active, and waitlist details until you ask us to remove them or Clubria stops running a waitlist. You can ask us to delete your account and its data at any time by emailing hello@clubria.com. Disconnecting a provider removes our stored access token and stops further access to it.
Your rights
Depending on where you live, you have the right to access, correct, export, or delete your personal data, and to withdraw consent. Under the GDPR you may also object to processing and complain to your local supervisory authority. Contact us and we will help.
Changes to this policy
If we change what we collect or what we do with it, we update this page and move the date at the top. Where a change materially affects how your data is used, we tell the people it affects by email rather than relying on you to re-read this page.
Contact
Questions about this policy or your data? Email hello@clubria.com.