---
title: "Privacy Policy for PII Detector | ClonePartner"
description: "How PII Detector handles your data: conversation text is scanned in memory and never stored, and the only thing kept at rest is your workspace's Intercom access token."
slug: intercom-app-privacy
canonical: "https://clonepartner.com/intercom-app-privacy"
lastUpdated: 15 September 2026
---

# Privacy Policy — PII Detector

*Last updated: 15 September 2026*

This policy covers **PII Detector**, the Intercom app published by **Yin Yang Inc.** (trading as ClonePartner) on the Intercom App Store.

It sits alongside our main [Privacy Policy](/privacy), which governs the website and our migration services. That policy still applies to any dealings you have with us as a company. This page exists because the app works differently from anything described there.

## What the app does with your conversations

When one of your teammates opens a conversation with the app in the details panel, Intercom sends us the id of that conversation. We fetch that conversation from Intercom's API and scan its messages for personal data.

**That text is held in memory for the duration of the scan and is never written to disk, never logged, and never sent anywhere else.** We keep no copy of your conversations, and we do not use them to train anything.

## What the app shows on screen

The panel reports the _type_ of personal data found, how many of each, and how sensitive it is. **It never displays the matched value itself.** A card number found in a message is reported as a card number; the digits are not printed back into the panel, because doing so would defeat the purpose of the app and would leave the value sitting in a rendered panel afterwards.

## What the app stores

**One thing: your workspace's Intercom access token.** It is stored so the app can read conversations on your workspace's behalf, alongside the region your workspace is in and the date you installed. Nothing else is kept.

**Uninstalling the app ends our access immediately.** Intercom revokes the token at the moment you uninstall, so it stops working before we are involved at all — there is no window in which we could still read your conversations.

We then delete our stored copy as soon as we next see it rejected: any request that comes back unauthorized causes us to discard the token rather than retain a dead credential. Where Intercom notifies us of an uninstall directly, we delete it on the spot instead of waiting.

## What the app can access in Intercom

Intercom shows you the permissions an app asks for before you install it. This app requests four permissions that Intercom requires of every app of this kind and which cannot be reduced — reading users and companies, reading conversations, reading admins, and gathering app data — plus the permission needed to redact a message when a teammate asks it to.

We ask for nothing beyond that. The app cannot send messages, cannot change your settings, and cannot see anything outside the conversation a teammate currently has open.

## Redaction is irreversible, and only ever yours to trigger

The app never redacts anything on its own. Redaction happens only when a teammate presses the button, and it uses Intercom's own redaction feature, which removes the whole message. There is no way to remove only part of a message, and there is no undo — by us or by Intercom.

## Cookies, analytics and tracking

The app sets no cookies and includes no analytics, telemetry or tracking. It is not a web page you visit; it is a panel Intercom renders from data our server returns.

## Third parties

Your conversation data is not shared with anyone. The app talks to exactly two places: Intercom's API, to read the conversation and to redact when asked, and our own server, which runs on Cloudflare.

## Server logs

Our host records what every web server records for each request: an IP address, a timestamp, and which endpoint was called. **Conversation content is not part of that.** These logs are covered by our main [Privacy Policy](/privacy).

## Your rights

Because the only thing we hold is an access token, there is very little for a data request to reach — but you can end it at any time by uninstalling the app, which deletes the token. Rights relating to information you have given us through other channels are covered by our main [Privacy Policy](/privacy).

## Changes to this policy

If a future version of the app ever stores conversation content, or sends it anywhere, this page will be updated before that version is published. Intercom requires every change to an approved app to be re-reviewed, so such a change would also be visible in the App Store listing.

## Contact

Questions about this policy: [support@clonepartner.com](mailto:support@clonepartner.com).
