Privacy Policy

Version 2026-09-28 · Last updated 28 September 2026

Clardentity is built on the idea that you should be able to see what an answer rests on. The same applies to what we hold about you. This policy says what we collect, why we collect it, who else sees it and how to make us delete it - in plain words, with the specifics rather than the usual hedging.

1. Who we are

Clardentity ("we", "us") provides an AI companion that answers questions and shows the sources behind each claim. For the purposes of the UK and EU General Data Protection Regulation and India's Digital Personal Data Protection Act 2023, we are the data controller for the information described here.

Questions, requests, or complaints: hello@clardentity.ai.

2. What we collect

WhatExamplesWhy
Account detailsEmail address, password (stored only as a one-way hash), display name if you give one, the date you accepted these termsTo create and secure your account
What you writeYour questions, the answers, any follow-up answers you give, and chat namesTo answer you, and to keep your conversations so you can come back to them
Files you attachPDFs, Word, Excel, PowerPoint, text files, images; their extracted text and the numeric embeddings made from itTo answer questions about them and cite them
VoiceAudio you record in the composer, and its transcriptTo turn speech into the question you asked
Approximate locationCity and country, derived from your IP address at sign-in. We do not store the IP address itself or any coordinatesSo regional questions get regional answers (prices, rules, weather)
Language and time zoneThe language preferences and time zone your browser already reports, sent when you start a voice call. Not storedSo the voice speaks your language the way it is spoken where you are, rather than with an accent laid over it
Technical recordsServer logs with timestamps, endpoints, error traces and per-request timingsTo keep the service running and diagnose faults
Product analyticsNamed events such as “a question was asked in Finder mode”, with no content in them - see section 7To learn which features are used and where people get stuck

We do not ask for, and ask that you do not send, government identifiers, payment card numbers, or health records. We do not knowingly collect anything from children under 16.

3. Why we are allowed to (legal bases)

Under the GDPR we rely on: performance of a contract for everything needed to run your account and answer your questions; legitimate interests for keeping the service secure and diagnosing faults; and consentfor product analytics, which you can give or refuse in the banner and change at any time. Under India's DPDP Act we rely on the consent you give when you create an account and on the legitimate uses that Act permits for providing a service you asked for.

4. Where your questions go

Answering a question means sending it to other companies. This is the part most policies are vague about, so here is the actual list. Each is bound by a contract that restricts what it may do with the data.

ProcessorWhat it receivesWhere
AnthropicYour question, the recent conversation, any attached text, to generate an answerUnited States
OpenAIThe same, when used as a fallback; audio for transcription; text for embeddingsUnited States
TavilySearch queries derived from your question - not the question verbatimUnited States
SupabaseThe database: accounts, conversations, documents, claimsConfigured region
RenderThe application servers that process every requestUnited States
VercelServes the web app; sees requests for pages, not your conversationsGlobal edge
UpstashRate-limit counters and background job queue - identifiers, not contentConfigured region
ResendYour email address, to send password resets and welcome mailUnited States
PostHogAnalytics events with no content, only if you consent (section 7)European Union

Anthropic and OpenAI do not use business API data to train their models under their standard API terms. We do not sell your data, and we do not share it for advertising.

5. International transfers

Some of the processors above are outside the UK, EU and India. Where personal data leaves those areas we rely on the transfer mechanisms our providers offer - Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.

6. How long we keep it

Your account, conversations and files stay until you delete them. Deleting a chat removes its messages, claims and citations. Deleting your account (Profile → delete account) removes the account, its workspaces, conversations, documents, uploaded files and memory - immediately and irreversibly. Server logs are kept for up to 30 days. Analytics events, if you consented, are kept for up to 12 months.

7. Analytics and cookies

We store one thing on your device without asking: the tokens that keep you signed in. Without them the app cannot work, so they are strictly necessary and carry no consent requirement.

Product analytics are different, and are off until you say yes. If you accept, we record named events - a question was asked, in which mode, whether a file was attached, roughly how long the answer took - through PostHog on its European servers. These events never contain your questions, your answers, chat names, file names or your email address; you appear as a random account identifier. Session recording and automatic click-capture are switched off in our code, not merely in a setting. You can change your mind at any time from the link in the footer of the banner or by clearing site data.

8. Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or hand it to another provider. Two of these you can do yourself, immediately: export any conversation from the chat menu, and delete your account from your profile. For anything else, write to hello@clardentity.ai and we will respond within 30 days.

If you think we have handled your data badly, you may complain to your local supervisory authority - the Information Commissioner's Office in the UK, your national authority in the EU, or the Data Protection Board of India.

9. Security

Traffic is encrypted in transit. Passwords are stored as one-way hashes and never in readable form. Access to the production database is limited to the people who operate the service. No system is perfect: if a breach affects your data we will tell you and the relevant authority within the timeframes the law sets.

10. Changes

If we change this policy materially we will raise the version number, show the change when you next sign in, and ask you to accept it again where the law requires. The version you accepted is recorded against your account.

See also our Terms of Service.