Privacy Policy

Last updated August 16, 2026

Draft for review — this document is being finalized with legal counsel.

This policy explains what personal data Claritty collects, how we use it, who we share it with, and your rights (including under the GDPR and the CCPA). It applies to the Claritty platform at claritty.ai and app.claritty.ai.

Where you use Claritty for your own purposes, we are the controller of your account data. Where your AI team processes content you connect — your documents, your customers’ messages — you are the controller and we act as your processor, handling that content only to carry out the work you ask for.

Data we process

  • Account data — your name, email, and organization, provided when you sign up. Sign-in is handled by Auth0.
  • Content you give us — the prompts and instructions you write, the apps and teams you build, and the tasks you hand your team.
  • Connected content — data we read from tools you connect (for example a Notion page, a Slack thread, a Drive document) in order to do the work you asked for, including content we index so your team can search it.
  • Credentials for connected tools — OAuth tokens and API keys, stored encrypted (see below).
  • Usage data — logs, token consumption, run history, and errors, used to operate, meter, secure, and debug the service.
  • Billing data — processed by Stripe. We do not store full card numbers.

How AI processing works

To do the work you ask for, we send the relevant content — your prompt, and the context your team needs — to the model provider that runs your plan’s model. Today those providers are Anthropic and OpenAI, and we use AWS Bedrock to turn indexed documents into embeddings so your team can search them.

We do not train foundation models on your content, and we do not permit our model providers to train on it. Content is sent to a provider to produce a result for you, and for no other purpose. If you bring your own model key (Team and Enterprise), those calls run under your own agreement with that provider and are governed by their terms.

AI output is generated, and may be wrong. We keep a record of what your team did — the run log, the tools it called, the actions it took — so that you can audit it.

Connected tools and your credentials

When you connect a tool, we store the resulting credential encrypted at rest (envelope-encrypted with a managed key) and scoped to you and the app you connected it for. Credentials are never exposed to the AI model and are never shared with other users: every call to a connected provider is brokered server-side on your behalf. Disconnecting a tool deletes the stored credential and stops any future access.

Content your team reads from a connected tool is processed to carry out your instructions, and — where you enable knowledge indexing — stored so your team can search it later. You choose which sources are indexed, and you can remove them.

The Claritty Vision browser extension

Claritty Vision is a browser extension you install yourself. It is dormant until you press Record, and it records only the tab you started in and tabs opened from it — never every tab you have open.

While you are recording, it captures the STRUCTURE of what you do rather than the content you do it with:

  • What you interacted with — the visible label, role and position of the control you clicked or typed into (“the Submit button”, “the Vendor column of a 5-column table”), the page title and path, and the shape of the region around it. The values you type are masked in the extension, before anything is sent.
  • Screenshots of the tab, taken at a few key moments so the task can be understood from what the page actually looked like. These are stored encrypted and scoped to you. This is the most revealing thing the extension captures, which is why the recorder says so on screen the whole time it is recording.
  • The address of each page you visit while recording, whole — including anything after the ?. That address is how the automation finds the page again: a list you filtered down to one batch is a different address from the unfiltered one, and without it the automation would open the unfiltered one and act on everything. A parameter carrying a token, a password or a session is dropped from it before the address leaves your browser.
  • The shape of network requests the page made — method, host, and path with identifiers removed (/api/invoices/{id}), status and content type. This is how Claritty discovers that a system has an API and can skip driving a browser. No request or response bodies, no headers, no query values, and no authentication of any kind is read or stored.
  • Anything you type into the recorder yourself — the goal you describe and the notes you add to a step. This is the one field you fill in, so treat it as you would any message to us: it is sent to a model, and personal details in it are scrubbed on arrival.

What it never captures: the values in form fields, the text of the records on a page, your passwords, or the contents of pages you visit while you are not recording. While it is recording, the extension reads one cookie — your Claritty session — so that it can talk to your own account, and no others. Connecting a site is the one other time it reads cookies, and it is described next.

A recording is processed by a model to turn it into an automation, on the same terms as everything else in this policy, and is kept with the automation it produced. Deleting the automation deletes the recording behind it. Uninstalling the extension stops all capture immediately.

Connecting a site to an automation

An automation that works a site behind a login has to be signed in to that site when it runs. Rather than ask you for the password, Claritty borrows the session you already have: you press connect this site in the extension while you are on it and signed in, and nothing happens until you do.

What is taken, when you press it: all of that site’s cookies for that host, and the values that page keeps in browser local storage — because that is where many sites hold the sign-in. This is more than the single cookie a recording reads, and it is the reason the extension asks for cookie access at all.

It is deliberately a session and not a password. A session expires on its own, it can be revoked by signing out of that site, and it is the narrowest thing that makes the automation work. We never ask for, receive, or store the password itself.

How it is held: encrypted with a key held in AWS KMS, and scoped to one user, one automation and one site. Another automation of yours cannot use it, and no other customer can resolve it. It is loaded into a Claritty-controlled browser at the moment of a run and is never written to disk there. Deleting the automation, or removing the connection from it, deletes the stored session.

Sites for which we have a real integration — Gmail, Slack, HubSpot and the rest — never use this path. They use that provider’s own authorization, described elsewhere in this policy.

Google user data (Gmail and other Google services)

When you connect a Google account to Claritty (for example, Gmail), you grant Claritty access to specific Google data through Google’s OAuth consent screen. We access this data only after you explicitly connect the integration, and only to provide the features of the Claritty app you are using.

What we access. We request the narrowest scope each app needs to function, and never more than the app you are using actually requires. Today Claritty requests permission to send email on your behalf (Gmail), to read and create calendar events (Google Calendar), and to open files you have specifically selected or that Claritty itself created (Google Drive).

Claritty does not currently request permission to read, search, label, archive or delete the messages in your mailbox. Those permissions require separate approval from Google, and if we ever offer them you would be asked to reconnect the integration and approve them yourself on Google’s consent screen. The consent screen you see when connecting is always the authoritative list of what you are granting.

How we use it. Google user data is used solely to perform the actions you or your connected app initiate (such as sending a message you approve, or adding an event to your calendar). We do not use Google user data for advertising, and we do not sell it.

How we store it. Your OAuth tokens are encrypted at rest (envelope-encrypted via a managed key) and held on the Claritty platform. Tokens are never exposed to the individual apps that use the integration — each Google API call is brokered by the platform on your behalf. You can disconnect an integration at any time, which revokes Claritty’s access and deletes the stored tokens.

How we share it. We do not transfer Google user data to third parties except as necessary to provide and secure the service (for example, our cloud infrastructure providers acting as processors under contract), to comply with applicable law, or as part of the operation you explicitly requested.

Limited Use. Claritty’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not allow humans to read your Google user data unless (a) you give explicit consent to access specific items, (b) it is necessary for security purposes (such as investigating abuse), (c) it is required to comply with applicable law, or (d) the data is aggregated and anonymized and used to improve the service in line with that policy. Google user data is never used to train AI models.

Who we share data with

We do not sell your personal data. We share it only with providers who process it on our behalf, under contract, to run the service:

  • Anthropic, OpenAI, and AWS (Bedrock) — to generate AI output and embeddings for you.
  • Amazon Web Services — hosting, databases, storage, and key management.
  • Vercel — hosting of the web application.
  • Auth0 — authentication and sign-in.
  • Stripe — payments, subscriptions, and creator payouts.
  • Tools you connect — when your team acts in them at your instruction.

We may also disclose data where required by law, to protect our rights or the safety of users, or in connection with a merger or acquisition (in which case this policy continues to apply until you are told otherwise).

Where data is processed

We process data in the United States. If you are in the EEA or the UK, this means your data is transferred internationally; we rely on the European Commission’s Standard Contractual Clauses and equivalent safeguards for those transfers.

How long we keep it

We keep your account data for as long as your account is open. Content, run history, and indexed knowledge are kept until you delete them or close your account. When you close an account we delete or de-identify your data within a reasonable period, except where we must keep records (for example invoices, or logs held for security and fraud prevention). Credentials for a connected tool are deleted when you disconnect it.

Security

We encrypt data in transit and at rest, hold connected-tool credentials under envelope encryption with a managed key, isolate every workspace’s data, and restrict internal access to those who need it to run the service. No system is perfectly secure, and we cannot guarantee absolute security.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict processing, and to withdraw consent. You can disconnect any tool at any time from your integration settings — for Google, also from your Google Account permissions. To exercise any other right, contact us and we will respond within the time the law allows. You also have the right to complain to your local data protection authority.

We do not sell or share personal information for cross-context behavioural advertising, as those terms are used under the CCPA.

Children

Claritty is not intended for anyone under 18, and we do not knowingly collect data from children.

Changes and contact

We will update this policy as the product changes, and will tell you when a change is material. Questions, or to exercise a right: privacy@claritty.ai.