Privacy Policy
Effective: April 29, 2026
Cliarity ("we," "us") provides a mobile application that helps you read your own lab and imaging reports. This policy explains what information we collect, how we use it, and the choices you have.
1. Cliarity is not a healthcare provider
Cliarity is a consumer educational tool. We are not a covered entity under HIPAA. We do not provide medical advice, diagnosis, or treatment. Always discuss results with a qualified clinician.
2. Information we collect
- Account information. When you sign up, we collect your email address through Supabase authentication. We do not store your password; Supabase manages it.
- Lab and imaging report content. When you submit a report for analysis, we receive the image or text you provide. We process it to generate an analysis and immediately discard the original image or text. The structured analysis result is only saved to your account if you have explicitly enabled history during onboarding or in Settings.
- Privacy preferences. We record your medical disclaimer acknowledgment, your history opt-in choice, and your retention window. We keep an append-only consent log of these choices for audit purposes.
- Device identifiers. We generate a per-install device ID to prevent abuse of the free tier. This ID is not tied to advertising and is not shared with third parties.
- Subscription status. We receive subscription events from Apple, Google, or RevenueCat to unlock paid features. We do not receive your full payment card information; that stays with Apple or Google.
- Diagnostic logs. Server-side logs may contain timestamps, user IDs, error messages, and truncated request data for debugging. Logs are retained for up to 30 days.
3. How we use your information
- To analyze your reports and return results to you.
- To save analysis results to your account history so you can view them later.
- To enforce the free-tier limit and prevent abuse.
- To process subscriptions and unlock paid features.
- To respond to support requests.
- To investigate bugs and improve the service.
4. Service providers
We share information only with vendors that help us run the service:
- Anthropic processes report content to generate analysis. We have a Business Associate Agreement (BAA) with Anthropic. Anthropic does not retain your content beyond the duration of processing your request.
- Supabase stores your account record and saved analyses.
- Apple, Google, and RevenueCat handle subscriptions and entitlements.
- Vercel hosts our backend.
We do not sell your information. We do not share it with advertisers.
5. Data retention
Cliarity defaults to not storingyour analyses. You may explicitly opt in to history during onboarding or in Settings → Privacy. When history is enabled, you choose a retention window:
- 30 days (default and recommended).
- 90 days.
- 1 year.
- Until you delete it (no automatic expiration).
Saved analyses are automatically and permanently deleted at the end of the retention window. Disabling history at any time permanently deletes every analysis we have saved for you. Server logs are retained for up to 30 days. When you delete your account, your profile, saved analyses, and free-tier device claim are erased within 30 days. Backups may persist for up to 90 days before rotation.
6. Your rights
- Access. View your saved reports inside the Cliarity app, share them via the OS share sheet, or download them as PDFs from any results screen.
- Delete. Use Settings → Delete Account in the Cliarity app, or email [email protected].
- Export. Request a copy of your data by emailing [email protected]. We respond within 30 days.
- State privacy rights. Residents of California, Colorado, Connecticut, Virginia, Utah, and other states with comprehensive privacy laws may have additional rights, including the right to opt out of sale or sharing. We do not sell or share your information for cross-context behavioral advertising. To exercise other rights, email [email protected].
7. Children
Cliarity is rated 17+ and is not intended for users under 13. We do not knowingly collect information from children under 13. If you believe a child has provided us information, contact us and we will delete it.
8. Security
We protect your data with TLS in transit, encryption at rest where supported by our providers, and access controls limited to a small number of authorized personnel. No system is perfectly secure; we cannot guarantee that unauthorized third parties will never gain access.
9. Changes to this policy
We will post material changes to this page and update the effective date. Continued use of Cliarity after a change constitutes acceptance.
10. Contact
Email [email protected].