Is Cluely Safe? Data Privacy Risks for Institutions

Jul 28, ’26 | Written by Victoria

Is Cluely Safe? What Institutions Should Know About the Data Privacy Risk

Before an institution even gets to the cheating question, Cluely raises a separate one: what happens to the exam content, the audio, and the screenshots the moment a test-taker runs it during a session. That question matters to compliance officers even in the small number of cases where a school or certification body might otherwise be tempted to look past AI-assisted cheating as a minor issue.

It should not be treated as minor, and the data question is a big part of why.

What Cluely Actually Collects

Cluely operates as an invisible desktop overlay that reads on-screen content or listens through the microphone to generate real-time answers. According to Cluely's own published subprocessor list, current as of August 2025, delivering that requires routing audio, screenshots, transcripts, account data, and device information through 15 named third-party vendors during every session where it runs.

That list of data types matters because an active exam session is exactly the environment where a candidate is most likely to have it turned on. If a test-taker runs Cluely during a proctored exam, the tool is, by design, capturing a live feed of exam questions alongside personal account and device data at the same time.

Fifteen Subprocessors, Unclear Access

Cluely's disclosure names each vendor and its role: cloud hosting, speech-to-text processing, AI response generation, plus infrastructure and support vendors, totaling 15 subprocessors. Cluely discloses who each vendor is but not exactly what each one is permitted to retain, so a reasonable assumption is that at least some of them see exam content in some form, whether as raw audio, transcribed text, or a captured image of the screen.

For a corporate compliance test or an internal training exam, that is an unwanted vendor footprint spread across fifteen companies with unclear retention terms. For a certification body or university protecting a proprietary exam bank, it is closer to an open door.

Why This Matters More for Regulated Exam Content

Two groups carry the sharpest exposure.

Certification bodies and universities risk the actual exam questions themselves. Once a question has passed through Cluely's pipeline during a live session, there is no way to confirm it was not retained, logged, or exposed somewhere in that chain of fifteen subprocessors. A leaked question bank does not just cost money to rebuild. It undermines the value of every credential issued using that exam, including the ones earned honestly.

Employers running compliance or pre-employment testing face a narrower but still real exposure: candidate data, resumes, personal identifiers, and screen content, moving through a tool the candidate installed without the employer's knowledge or consent, during a session the employer assumed was private between candidate and assessment platform.

Neither group has a way to audit what happened after the fact. The tool was built to be invisible, which means the data exposure is invisible too, until something goes wrong downstream.

Where This Intersects With FERPA and GDPR

Institutions bound by FERPA are required to protect personally identifiable information within education records from exposure to unauthorized parties. An exam session where a student's audio, screen content, and device data pass unknowingly through fifteen third-party subprocessors sits well outside what most compliance officers would consider protected handling, regardless of whether the institution itself did anything wrong. The exposure happened on the student's own device, using software the institution never approved, which is precisely why detection and prevention matter more than after-the-fact cleanup.

The same logic applies under GDPR for European students and candidates, where data minimization and clear subprocessor disclosure are baseline requirements, not best practices. A tool that cannot say what each of fifteen subprocessors is allowed to do with captured audio and screenshots does not meet that bar, and an institution has no contractual relationship with Cluely to enforce one.

What a Proctoring Vendor Should Be Doing Instead

The contrast is instructive. A proctoring platform an institution actually contracts with should be able to answer, in plain terms, where session data goes, who can access it, and how long it is kept. Proctor360 operates under SOC2, GDPR, and FERPA compliance as a matter of course, with session data handled under defined institutional agreements rather than an undisclosed subprocessor chain. For sensitive, regulated exam content specifically, Proctor360 also offers hosting on AWS GovCloud, where data is processed and stored under compliance requirements few other proctoring vendors are built to meet at all.

That distinction (a named, contracted, auditable vendor versus an undisclosed subprocessor chain a candidate installed on their own device) is the entire data privacy argument in one sentence. One party is accountable. The other one is not.

Prevention Beats Cleanup

None of this is solvable after the fact. Once a question or a candidate's data has moved through Cluely's pipeline during a live session, an institution cannot retrieve it or confirm it was deleted. The only real fix is preventing the tool from running during the exam in the first place, through application-level lockdown and environmental monitoring that catches an invisible overlay even when the screen recording looks clean.

That is a detection and blocking problem as much as a compliance one, and the two are inseparable here. A proctoring platform that cannot catch Cluely running cannot protect the data exposure either.

Frequently Asked Questions

What data does Cluely actually collect during an exam session?
Per its own subprocessor disclosure, Cluely routes audio, transcripts, screenshots, account data, and device information through 15 named third-party vendors any time it is active, which for a student includes the entire duration of a proctored session where the tool is running.

Does Cluely say what its subprocessors can access?
Cluely's disclosure names each of the 15 vendors and its general function, including specific vendors for AI response generation and audio processing, but it does not publish what each one is permitted to retain, so institutions cannot verify how exam content is handled once it passes through that chain.

Is this a FERPA violation if a student uses Cluely during an exam?
It creates an exposure the institution never authorized and cannot audit, since the data moves through third-party subprocessors on the student's own device, outside any agreement the institution has in place, which is why prevention matters more than after-the-fact review.

Can an institution just add a data use policy to cover this?
A policy addresses acceptable use, but it does not stop data from moving through Cluely's subprocessors once a student runs the tool during a session. Blocking the tool from running is the only step that actually prevents the exposure.

How is a contracted proctoring vendor different from Cluely on data handling?
A proctoring vendor operating under SOC2, GDPR, and FERPA agreements is contractually accountable for where session data goes and how long it is retained. Cluely is software a candidate installs independently, with no agreement to the institution at all.

Where can an institution verify Cluely's subprocessor list itself?
Cluely publishes it directly on its own website, dated to its last update. Checking the primary source directly, rather than relying on a secondhand summary, is the more defensible step before making any compliance decision.

Protect Exam Content Before It Leaves the Room

An undisclosed subprocessor chain is not a risk most institutions can afford to shrug off. Schedule a demo to see how Proctor360's SOC2, GDPR, and FERPA-aligned platform keeps exam data, and exam integrity, inside an agreement you actually control.


Schedule A Live Demo

There is nothing quite like seeing our platform in action firsthand. Schedule a demo with one of our Proctoring Solutions Specialists by filling out this form.

Where is your organization located?

NOTE: This form should not be used to schedule an exam or to contact our support team. If you require assistance with an exam, contact our support team.

Proctor360 is a proud member of organizations dedicated to online learning and testing excellence.