Last Updated: October 8, 2025
1.1 Account Information: Email address, password (encrypted), subscription tier (Free or Pro), and payment information (processed securely by Paddle).
1.2 Usage Data: AI request counts (summaries, chat messages, writing sessions, meeting notes, quick notes), feature usage patterns, and timestamps.
1.3 Content Data: Text submitted for summarization, chat conversations, writing drafts, meeting transcripts, and quick notes you create.
1.4 Technical Data: IP address, browser type, device information, and session data for security and analytics.
2.1 Service Delivery: Process AI requests, provide chat responses, analyze text, deliver writing assistance, and generate meeting notes.
2.2 Usage Tracking: Monitor monthly request limits (100 for Free, 1000 for Pro), track feature usage, and provide analytics dashboard.
2.3 Billing: Process payments for Pro subscriptions ($20/month), manage subscriptions, and handle refunds via Paddle.
2.4 Improvements: Analyze usage patterns to improve AI models and enhance features.
2.5 Communications: Send service updates, billing notifications, and security alerts.
3.1 Groq SDK: All AI features (chat messages, writing content, meeting notes, and text summarization) are processed by Groq's Llama models (Llama 3.1 8B for chat, Llama 3.3 70B for writing, meeting notes, and summarization). Data is not stored by Groq beyond processing.
3.2 Data Retention: Your content is stored in your account. You can delete it anytime. Deleted content is removed within 30 days including backups.
4.1 Encryption: All data transmitted using TLS 1.3 encryption. Passwords hashed using bcrypt with salt rounds. Session tokens encrypted at rest.
4.2 Row Level Security: Database implements RLS policies ensuring users only access their own data. All queries are scoped to authenticated user ID.
4.3 Rate Limiting: API rate limiting (60 req/min default, 5 req/min auth, 20 req/min AI) prevents abuse. Failed login attempts trigger temporary IP blocks (15 minutes after 5 failures).
4.4 Security Headers: HSTS, CSP, X-Frame-Options (DENY), X-Content-Type-Options (nosniff), and strict Permissions-Policy implemented.
4.5 Cookie Security: HttpOnly, Secure, SameSite=Strict cookies with __Host- or __Secure- prefixes. CSRF tokens on all state-changing operations.
4.6 Monitoring: Sentry tracks errors and security incidents. Real-time alerts for suspicious activity.
5.1 Payment Processing: Paddle acts as Merchant of Record and processes all payments. For sales to US-based customers: Paddle.com Inc. For sales to UK-based customers (VAT purposes): Paddle Payments Limited. For all other customers: Paddle.com Market Limited. Paddle's privacy policy at https://paddle.com/privacy governs payment data.
5.2 Infrastructure: Supabase hosts our database. Vercel hosts our application.
5.3 Analytics: PostHog provides privacy-focused analytics. No personal data sold to third parties.
5.4 Legal Requirements: We may disclose data to comply with legal obligations or protect rights.
6.1 Access: Request copy of your personal data.
6.2 Correction: Update inaccurate information in account settings.
6.3 Deletion: Request account and data deletion (30-day retention for backups).
6.4 Portability: Export your data in machine-readable format.
6.5 Opt-Out: Unsubscribe from marketing emails anytime.
6.6 Do Not Sell: We do not sell personal information.
7.1 Essential Cookies: Authentication tokens, session management, security tokens, and CSRF protection. These cookies use __Host- or __Secure- prefixes for enhanced security.
7.2 Analytics: PostHog tracks usage patterns with privacy-focused, anonymized data. No personal information is collected.
7.3 Security Features: All cookies are HttpOnly, Secure (in production), SameSite=Strict, and have a maximum age of 7 days.
7.4 Control: Manage cookies through browser settings. Disabling essential cookies may affect functionality.
8.1 Active Accounts: Data retained while account is active.
8.2 Deleted Accounts: Data deleted within 30 days of account deletion.
8.3 Billing Records: Retained for 7 years for tax and legal compliance.
8.4 Content: Temporary content deleted after 30 days unless saved.
Our Service is not intended for users under 13. We do not knowingly collect data from children. If we discover such data, we delete it immediately.
Data may be transferred to and processed in countries outside your residence. We ensure adequate safeguards through standard contractual clauses.
We may update this policy. Material changes will be notified via email. Continued use after changes constitutes acceptance.
12.1 Service Provider: Muhammad Tanveer Abbas
12.2 Payment Processor: Paddle (Merchant of Record)
12.3 Contact Methods:
For privacy questions or to exercise your rights:
Email: privacy@clario.ai
Data Protection Officer: dpo@clario.ai
Website: https://clario.ai
12.4 Paddle Contact:
For payment-related privacy inquiries:
Paddle Privacy Policy: https://paddle.com/privacy
Paddle Legal: legal@paddle.com