Skip to main content
Claro

Privacy policy

How Claro handles your information

This page explains how Claro collects, uses, and protects information across the web app and related services.

Last updated October 3, 2026
Section

What we collect

We may collect account details such as your name, email address, and sign-in method, along with the content you choose to upload, type, record, or organize inside Claro.

We may also collect basic device, browser, and usage data that helps us keep the product reliable, secure, and easier to improve over time.

Section

How we use information

We use your information to operate the product, provide note generation and search features, support authentication, sync your workspace, and respond to issues you report.

We may also use product and usage signals to improve performance, reduce abuse, and understand which parts of Claro are helping people most.

Section

Email communications

We use your email address to send account and service messages you would reasonably expect: welcome and onboarding emails, notices about your notes and recordings, billing and subscription updates, security alerts, and responses to support requests.

We may also send product updates, tips on using Claro, and occasional offers to the email address on your account. Every non-essential email includes an unsubscribe link. You can opt out at any time, and opting out does not affect your account or your ability to use Claro.

If you unsubscribe, you will still receive messages that are essential to your account — for example billing receipts, security notices, and replies to your support requests.

Section

How your content is processed

When you upload files, create notes, or ask AI questions, Claro may process that content through storage, search, and AI services so the app can generate summaries, answers, and structured outputs.

We try to keep processing limited to what is needed to provide the feature you asked for.

Section

Sharing and service providers

We work with service providers that help us run the product. Those providers process data only as needed to support the service: Google Cloud and Firebase (hosting, database, file storage, authentication); AssemblyAI (audio transcription and AI note generation, chat, and study tools through its LLM Gateway); Google Gemini API (converting note text into search embeddings); Qdrant (storing search embeddings); Supadata (fetching transcripts for video links you submit); Stripe (payments); Braintrust (monitoring the quality and reliability of AI responses, which may include the prompts and outputs of AI requests); PostHog (product analytics); Sentry (error monitoring); Loops (email delivery and product messaging, including unsubscribe management); and Cloudflare (network delivery and security).

We do not treat your notes as public content, and we do not sell your personal information in the ordinary sense of that term.

Your data is not used to train AI models. Our transcription and AI generation provider (AssemblyAI) is opted out of model training, and our embedding provider (Google Gemini API, paid tier) does not use submitted content for model training. We do not share your content with external services for their own independent use.

Section

Retention and deletion

We keep account and workspace information for as long as it is needed to operate your account, meet legal obligations, resolve disputes, and keep the service secure.

When you delete a note, it is permanently removed from our systems immediately, along with its transcript, associated storage files, processing records, translations, share link, and vector embeddings. There is no trash or recovery period — deletion is final.

Temporary audio and intermediate transcript files created during processing are automatically deleted within one day. Recordings sent to our transcription provider for file transcription are deleted from the provider once the transcript is returned.

You can delete your account and all associated data at any time from within the product. Account deletion permanently removes your notes, transcripts, folders, chats, chat messages, translations, quizzes, flashcards, uploaded files, share links, vector embeddings, and Firebase authentication record. Any active Stripe subscription is canceled immediately as part of the process, so you will not be charged again.

Limited operational records held by our monitoring providers, such as AI request logs and error reports, may persist for those providers' standard retention periods. They are used only for reliability and security and are never used to restore an account.

Claro does not retain deleted user data in active systems after deletion. Deleted data may persist in encrypted backups for up to 30 days before automatic expiry; backups are never restored to service individual accounts. If Claro receives a legal preservation request or subpoena before data is deleted, we may be required to retain that data temporarily to comply with the legal order. Once any legal hold is lifted, the data is deleted permanently.

You can also request selective data deletion with date filters, choosing to remove all data, only vector embeddings, only Firestore records, or your full account, in line with GDPR right-to-be-forgotten requirements.

Section

Security

Claro is built on Google Cloud infrastructure. Data at rest is protected with AES-256 encryption, and all connections use TLS encryption in transit.

Authentication is handled through Firebase Authentication with Application Default Credentials, meaning no service account keys are stored in or shipped with the application code.

Firestore security rules enforce that sensitive fields like subscription status, free note grants, and chat usage counters can never be written from the client. All entitlement changes go through authenticated server-side endpoints.

Every request to our servers is authenticated with a short-lived Firebase ID token that is verified server-side, and each user can only access their own notes, folders, and chats.

All user-generated content rendered in the app is sanitized through DOMPurify to prevent cross-site scripting (XSS) attacks.

AI prompts are protected against prompt injection through content delimiters and input sanitization, keeping user-supplied content separate from system instructions.

No system is perfect, so we cannot promise absolute security, but we apply industry best practices across authentication, access control, and data protection.

Section

Children's privacy

Claro is not intended for use by children under 13. We do not knowingly collect information from children under 13 years of age. If you believe a child under 13 has provided us with personal information, please contact us through the support channel in the product, and we will take steps to delete that information.

Section

Legal compliance

Claro complies with applicable data protection laws and regulations, including the General Data Protection Regulation (GDPR) for users in the European Economic Area and United Kingdom, and the California Consumer Privacy Act (CCPA) for users in California. Your rights under these laws include access to your data, correction, deletion, and withdrawal of consent.

Section

Vulnerability disclosure

We welcome responsible security research. If you believe you have found a vulnerability in Claro, please report it through the support channel in the product with details of the issue. We ask that you avoid accessing or modifying data that does not belong to you, and that you give us reasonable time to respond before any public disclosure.

Section

Contact

If you have privacy questions, concerns, or requests, contact the Claro team at [email protected].