Privacy Policy
Last updated: 2026-08-16 · Effective: 2026-08-16
The short version
Your canvas content lives in our cloud infrastructure, encrypted at rest. All AI runs on our servers, so your prompts pass through us — we don't train on them, don't mine them, and don't keep request bodies after the request finishes. We charge for the product, AI included. We read the country your connection comes from — nothing finer — to pick your currency and price. Delete your account anytime — we erase your data within 30 days; backups within 90.
1. Who we are
Clearly is an independent software product operated from the Commonwealth of Virginia, USA. It is run by a single operator rather than a corporation — that affects the paperwork, not how your data is handled.
General contact: hello@clearly.sh. Privacy + data-protection requests: privacy@clearly.sh. DMCA + IP claims: dmca@clearly.sh.
We identify ourselves in full on request. For legal service of process, a regulatory enquiry, or any matter that needs the operator's registered legal identity and address, write to legal@clearly.sh and we will provide them. The same details are on file with Stripe, which processes every payment we take.
2. What we collect
Account data: email address, display name, hashed password (if email signup) OR Google profile (if SSO). Stored in Firebase Authentication.
Canvas content: the blocks you create (text, images, brand assets, comments) live in our cloud databases (SQLite) and object storage, both with AES-256 encryption at rest. We do not read your canvas content for analytics or training.
Subscription data: tier, trial status, Stripe customer ID. Card numbers go directly to Stripe — we never see them. Payment method details (bank, wallet, voucher reference) stay with Stripe; we receive only the outcome and the amount.
Approximate location: our edge network derives a two-letter country code from your IP address on each request. We use it to decide which currency and price to show you (§5, §6) and to keep abuse records honest — it is recorded on free-preview ledger rows and public gallery entries. We do not derive city, precise location, or anything finer than country, and we do not keep a log of your IP address against your account.
Usage telemetry: page views and product events. See §8 for current and planned analytics providers.
3. AI prompts — what we DO and DON'T see
Every AI feature we currently offer runs on our servers, so your prompts pass through us. We would rather say that in one plain sentence than bury it in a table.
When you generate something — a chat reply, a vector, an image, a brand book — the text you typed and any content you attached go from your browser to our worker, and from there to the model provider that fulfils the request. We see the request in transit.
What we do with it:
- We don't train on it. Not our own models, not anyone else's.
- We don't read it for analytics or marketing. We keep aggregate counts — how many generations, what they cost — but the content itself isn't mined.
- We don't retain request bodies once the request completes. Operational logs that may contain fragments are deleted within 7 days.
- The output is stored for you. Generated files and chat history live in your workspace, and you can delete them.
- Voice (where enabled) streams audio through our worker to the provider. Transcripts land in your workspace where you can delete them; the audio stream itself is not retained.
Model providers are listed in §7. Their own terms govern what they do with a request we pass to them; we use providers that do not train on API traffic by default.
This section previously said the opposite, and the change is worth stating outright. It described a Mac daemon that sent prompts from your own machine straight to Anthropic, so that "block content and your prompt text NEVER pass through our servers". That path is not currently available, so the claim overstated your privacy. There is no AI surface in Clearly today that bypasses our servers.
4. What we DON'T collect
- Your computer's filesystem content beyond what you explicitly drag into a canvas
- Camera footage; webcam frames; biometric data
- Browsing history outside Clearly's surfaces
- Cross-site tracking — no Facebook Pixel, no Google Ads pixel, no LinkedIn Insight Tag
- Voice/microphone data outside voice-agent sessions you explicitly start
5. How we use your data
To run the product: show you your canvases, share canvases with collaborators when you opt in, deliver AI-generated results back to your workspace.
To bill you (paid tiers): we send your subscription tier + customer ID to Stripe. Stripe handles all card processing.
To price the product where you are: we choose the currency and amount from the country your connection appears to be in, so a buyer in India is shown a rupee price set for India rather than a converted dollar one. The country also decides which local payment methods appear (UPI, Pix and similar are only offered in their own currency). This is a per-request decision — see §6.
To support you: if you email us, we read the email. If we need to look at your canvas to debug, we ask first.
To improve the product: aggregate, anonymized usage patterns. Never individual content.
We do NOT: sell your personal information, train AI models on your canvas content, share your canvases with marketers, or sync data to ad networks. If our position on any of these changes in the future, we will notify you 30 days in advance and give you the option to delete your account before the change takes effect.
6. Automated decision-making (GDPR Article 22)
Clearly uses AI as a core feature — models generate code, content, designs and recommendations from what you put in. This constitutes automated processing.
However:
- No legal or significant effects without your explicit action. The AI produces drafts and suggestions; nothing is shipped or applied to the world without you clicking Approve, Send, or Deploy.
- You can decline to use AI features. Nothing generates unless you ask it to; the workspace works as an ordinary canvas and file library without ever running one.
- You can request human review. If you believe an automated decision (e.g. tier downgrade after trial expiry, account flag for abuse) has materially affected you, email privacy@clearly.sh and a human will review.
- Regional pricing is automated, and we would rather name it than leave it implied. The currency and amount you are offered are picked by our servers from the country your connection appears to be in, with no person involved. It carries no legal effect — the price is shown to you in full before you pay, and declining costs you nothing — but it does decide what you would be charged, which is worth stating plainly. If you think you were shown the wrong country's price, email privacy@clearly.sh and a human will look at it.
None of Clearly's automated processing currently produces legal effects on you (no employment decisions, no credit decisions, no insurance underwriting). If we ever add such features, we will require explicit consent + provide opt-out before activation.
7. Subprocessors + where your data lives
Third-party services we use to deliver Clearly. We have signed Data Processing Agreements with each. New subprocessors get 30-day advance notice via email (Pro+ tier) or banner (Free tier); you can object by deleting your account before the new subprocessor takes effect.
| Subprocessor | Purpose | Region(s) |
|---|---|---|
| Cloud infrastructure | Edge compute + databases + object storage + key-value store | Global edge, primary in US-East |
| Firebase Authentication (Google) | Email + Google SSO auth tokens | US, EU mirror |
| Stripe | Subscription billing, payment processing | US, EU, UK |
| Resend | Transactional email delivery | US (Vercel infra) |
| Google Cloud (Vertex AI) | Image generation, vector generation, optional voice (Gemini Live) | US |
| OpenRouter | Chat + text generation (routes to the model providers behind it) | US |
| Plausible Analytics (planned) | Cookieless page-view counts | EU |
| Sentry (planned) | Error stack traces, no canvas content | US, EU regional |
EU/UK data transfers to US-based subprocessors are covered by the EU Standard Contractual Clauses (Commission Decision 2021/914) plus supplementary measures (encryption at rest + transit).
8. Cookies + local storage
We use cookies + localStorage for:
- Authentication (HttpOnly, secure, session-only cookie) — keeps you signed in
- CSRF protection (HttpOnly cookie) — anti-forgery for state-changing requests
- UI preferences (localStorage) — theme, sidebar state, tour-seen flag, cookie consent state
No third-party tracking cookies. No advertising cookies. Our planned analytics provider (Plausible) is cookieless by design. EU/UK users see a consent banner on first visit per the ePrivacy Directive — accepting unlocks no additional tracking today, it's purely transparency.
9. Data retention
| Data category | Retention |
|---|---|
| Canvas content, brands, files | Until you delete OR account deletion + 30 days (then erased) |
| Account profile, email, settings | Until account deletion + 30 days |
| Backups of the above | Purged within 90 days of account deletion |
| Subscription + invoice records | 7 years (tax/legal requirement; in Stripe) |
| Stripe customer ID + tier (for refund/recovery) | 7 years (anonymized to email hash on account delete) |
| Cloud FAB chat request bodies | 7 days then deleted from logs |
| Error logs (Sentry, when installed) | 90 days |
| Page-view logs (Plausible, when installed) | Indefinite anonymous aggregates; no per-user records |
| Waitlist email + invite codes | Until launch + 60 days OR until you unsubscribe |
| DMCA + abuse reports | 7 years (legal hold) |
10. Your rights
Under GDPR (EU/UK), CCPA (California), and similar laws, you have the right to:
- Access (GDPR Art 15) / Know (CCPA): download all your canvases + account data via /settings → Your data → Download my data. You get a JSON archive immediately; no waiting period.
- Correction (GDPR Art 16): edit any account data at /settings.
- Deletion (GDPR Art 17) / Delete (CCPA): delete your account anytime at /settings → Delete account. We erase canvas content + account data within 30 days. Backups purge within 90 days. Anonymized billing records (email hash only) retained for 7 years per tax law.
- Portability (GDPR Art 20): same as Access — JSON export covers it.
- Object (GDPR Art 21): to any processing you don't agree with. Email privacy@clearly.sh.
- Restriction (GDPR Art 18): request we pause processing pending a dispute.
- Opt-out of automated decisions (GDPR Art 22): see §6 — none of our automated processing currently has legal/significant effects, but the right applies.
- Right to Opt-Out of Sale / Sharing (CCPA): we do NOT sell personal information or share for cross-context behavioral advertising. There is no opt-out toggle because there is nothing to opt out of.
- Non-discrimination (CCPA): exercising any of these rights does not affect your service quality or pricing.
- Complaint: to your local data-protection authority. EU users — your national DPA. UK users — the ICO. California users — the CPPA.
11. CCPA-specific disclosures (California residents)
In the prior 12 months, we have collected the categories of personal information listed in §2 above. We disclose this information to subprocessors (listed in §7) solely to provide the service. We have not sold or shared personal information for cross-context behavioral advertising. We do not have actual knowledge of selling or sharing the personal information of consumers under 16.
To exercise CCPA rights: privacy@clearly.sh. We respond within 45 days (with a possible 45-day extension if needed; we'll tell you why).
You may also designate an authorized agent to act on your behalf. The agent must provide written authorization + we may require you to verify identity directly.
12. Children + COPPA
Clearly is not directed at children under 13 (or 16 in the EU). We do not knowingly collect data from minors.
If we learn we have collected personal information from a child under the applicable age, we delete it within 30 days. Parents or guardians who believe a child has created an account can request immediate deletion + verification at privacy@clearly.sh — please include the email address used and the child's name.
13. Data breach notification
If we experience a personal data breach that is likely to result in a risk to your rights and freedoms (GDPR Art 33), we will:
- Notify the relevant supervisory authority within 72 hours of awareness
- Notify affected users without undue delay when the breach is likely to result in a high risk — via the email address on your account
- Publish a notice at /security (and at status.clearly.sh once available) describing the nature of the breach, categories of affected data, likely consequences, and steps taken to mitigate
For potential security issues, contact security@clearly.sh. Responsible disclosure welcomed.
14. Desktop app
Clearly does not currently ship a desktop app or a local daemon. Everything runs in your browser and on our servers. This section previously described a Mac daemon that held an Anthropic credential in your Keychain and kept working directories on your disk — if you installed that build at any point, those files are local to your machine and were never uploaded to us; deleting the app removes them.
If we ship a desktop app again, this section will describe exactly what it stores locally before it is available to download.
15. Hive avatar (if installed)
Hive was an optional desktop avatar bundled with the Mac app described in §14. It is not currently distributed. Where it is installed, it works entirely locally: voice playback comes from pre-rendered audio shipped with the app — no microphone capture and no cloud voice synthesis — and the lifecycle events it reacts to stay on your machine unless you opt in to telemetry, which is off by default.
16. Entity transfer + acquisition
If Clearly is acquired, merged, or undergoes a corporate restructuring, your personal information may transfer to the successor entity. We will notify you via the email address on your account at least 30 days before the transfer takes effect, with information on how to delete your account if you prefer not to continue with the new entity.
17. Changes to this policy
We'll email you about meaningful changes 30 days before they take effect. Minor edits (typos, broken links, restructuring) we just publish. The "Last updated" date at the top of this page is the source of truth.
A redline of prior versions is available on request from privacy@clearly.sh.
18. Contact
Questions about privacy or your rights? Email privacy@clearly.sh. We respond within 5 business days; statutory rights requests within 30 days (GDPR) or 45 days (CCPA).
For EU/UK GDPR data-protection requests: privacy@clearly.sh. We are not required to appoint a Data Protection Officer at our current scale (sole proprietor, < 250 employees, no large-scale processing of special-category data); the operator personally handles all privacy requests.
Legal service of process: contact legal@clearly.sh for our address on file (managed via Stripe's billing-account address record).