Personalization

Combine product context, user preferences and explicitly shared Clone context.

Three levels of context

  1. Product context: recent conversation, current selection and known artifact text. Available without a Clone user account.
  2. Product-owned preferences: explicitly permitted, current preferences supplied in user_preferences. Keep these scoped to the authenticated user and increment context revision when they change.
  3. Optional Connect Clone: the user signs in and selects synced profile paragraphs and Goals to share with this app. Store the resulting connection per authenticated user.

A company app registration or card does not grant access to a user's private Clone context. Never map an email address to a Clone identity or automatically include all synced data. Raw personal history is not a public export endpoint.

Connect flow

Your backend starts /v1/connections with user_id, the exact registered redirect_uri, random state and a PKCE code_challenge. Keep the verifier and flow in that user's server-side session. Open the returned authorization URL; the user reviews and selects sources.

On callback, check the same authenticated user, state, request ID, expiry and one-time use. Exchange through /v1/connections/exchange with the verifier. Store the returned connection_id per user and include it in later prediction requests. The SDK's CloneClient.connect and exchange implement the wire steps. See the full integration guide.

Change or disconnect

Settings must make the selected connection and disconnect action visible. On disconnect, revoke through the API, clear candidates and discard late results. Future new requests may use product context. Do not retry a revoked or mismatched connected request silently as a new basic prediction.

When selected sources change, reconnect so the user reviews the new grant. Advance the local context revision on user preference changes. Keep machine-generated, accepted and edited text distinguished from independently human-authored corrections; generated sends are not new evidence of personal preference.

API and SDK parity

The same optional connection works through direct HTTP and the SDK. The server checks app, subject, selected source revisions and revocation on predictions and replays. The SDK handles local invalidation; a custom client must implement that check too. No automatic sending follows from connecting personal context.