Privacy Policy
1. Who we are
Clarify is operated by Clarify Ltd, a company registered in England and Wales. Our service is available at getclarify.co.uk.
For the purposes of UK data protection law, Clarify Ltd is the data controller — the organisation responsible for deciding how your personal data is used.
You can contact us at any time: hello@getclarify.co.uk
2. What data we collect
Account information
When you create a Clarify account, we collect your email address and (optionally) your name. We use Clerk to handle authentication — they store your account credentials securely on our behalf.
Documents you upload
When you upload a document to Clarify, we process it to extract the text so our AI can summarise it and answer your questions. We store:
- The original document file (stored securely in Cloudflare R2)
- The extracted text content of the document
- The AI-generated summary of the document
- The questions you ask and the AI's answers
Usage data
We collect information about how you use Clarify — which features you use, how often you upload documents, and whether you encounter errors. We use PostHog for this analytics, hosted on EU servers. This helps us improve the product.
Payment information
If you subscribe to Clarify Pro or Family, your payment details are handled entirely by Stripe. We never see or store your card number, expiry date, or CVV. We receive confirmation from Stripe that payment was successful and store your subscription status.
Technical data
We automatically collect your IP address, browser type, and device type when you use Clarify. This is standard for any web service and is used for security monitoring and error tracking (via Sentry).
3. How we use your data
We use your data for the following purposes:
- To provide the service — processing your documents, generating summaries, and answering your questions
- To manage your account — authentication, subscription management, and billing
- To send you important emails — account confirmations, payment receipts, and service updates. We do not send marketing emails without your consent.
- To improve Clarify — understanding how people use the product so we can make it better
- To detect and prevent abuse — protecting the service from fraud and misuse
- To comply with legal obligations — such as keeping financial records
4. Our legal basis for processing your data
Under UK GDPR, we must have a legal basis for processing your personal data. Our bases are:
- Contract — processing your documents and managing your account is necessary to provide the service you've signed up for
- Legitimate interests — improving the product, preventing abuse, and keeping the service secure
- Legal obligation — keeping financial and tax records as required by law
- Consent — for any optional marketing communications (you can withdraw consent at any time)
5. Your documents and AI processing
When you upload a document, the text is sent to Anthropic's Claude API for processing. This means Anthropic processes the content of your document as a data processor acting on our behalf.
Anthropic's privacy policy governs their handling of data. Anthropic does not use data submitted via the API to train their models — your documents are processed and the results returned, then discarded from their systems.
We do not use your documents to train any AI models ourselves.
6. Who we share your data with
We share your data with the following third-party services, all of whom are bound by data processing agreements:
- Clerk — authentication and user account management
- Supabase — database hosting (EU region)
- Cloudflare R2 — document file storage
- Anthropic — AI processing of document content
- Stripe — payment processing
- Resend / Brevo — transactional email delivery
- PostHog — product analytics (EU hosted)
- Sentry — error monitoring
- Vercel — application hosting
We do not sell your personal data to third parties. We do not share your documents or their contents with any third party except as described above.
7. How long we keep your data
- Account data — kept for as long as your account is active, plus 30 days after deletion
- Uploaded documents — kept for as long as your account is active. Deleted within 30 days of account deletion.
- Conversation history (questions and answers) — kept with your documents, deleted on the same timeline
- Payment records — kept for 7 years as required by UK tax law
- Usage analytics — kept for 12 months then anonymised
8. Your rights under UK GDPR
You have the following rights regarding your personal data:
Right to access
You can request a copy of all personal data we hold about you.
Right to rectification
You can ask us to correct inaccurate data we hold about you.
Right to erasure
You can ask us to delete your account and all associated data.
Right to portability
You can request your data in a machine-readable format.
Right to object
You can object to processing based on legitimate interests.
Right to restrict
You can ask us to pause processing while a complaint is resolved.
To exercise any of these rights, email us at hello@getclarify.co.uk or use the "Delete my data" option in your account settings. We will respond within 30 days.
If you are unhappy with how we handle your request, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
9. Cookies
Clarify uses essential cookies only — these are required for the service to function (keeping you logged in, maintaining your session). We do not use advertising cookies or tracking cookies from third-party ad networks.
Our analytics (PostHog) uses first-party cookies to track usage within Clarify. You can disable these by contacting us, though this may affect how we can improve the product.
10. Data security
We take reasonable technical and organisational measures to protect your data:
- All data is transmitted over encrypted HTTPS connections
- Documents are stored in encrypted cloud storage
- Access to production systems is restricted to authorised personnel only
- We use Row Level Security in our database to ensure users can only access their own data
- Payment data is handled entirely by Stripe and never touches our servers
No system is 100% secure. If we become aware of a data breach that affects your rights and freedoms, we will notify you and the ICO within 72 hours as required by law.
11. International transfers
Some of our third-party providers process data outside the UK or EU. Where this happens, we ensure appropriate safeguards are in place — typically the UK International Data Transfer Agreement (IDTA) or equivalent. Anthropic, for example, is a US company — data sent to their API for processing is covered by their data processing agreement which includes appropriate transfer mechanisms.
12. Children
Clarify is not intended for use by anyone under the age of 18. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
13. Changes to this policy
We may update this privacy policy from time to time. When we make significant changes, we will notify you by email and update the "Last updated" date at the top of this page. Continued use of Clarify after changes constitutes acceptance of the updated policy.
Questions about your privacy?
We're happy to answer any questions about how we handle your data.
Email: hello@getclarify.co.uk
Response time: within 5 working days
Clarify Ltd · London, United Kingdom
Information Commissioner's Office registration: [ZC186267]