Cleariest ("we", "our", or "us") is committed to protecting your privacy. This policy explains how we collect, use, store, and safeguard your information when you use the Cleariest application (web, Android, and iOS), visit our website at cleariest.com, or interact with our services.
1. Information We Collect
Account information
When you create a Cleariest account, we collect:
Email address (required) — to create your account, send notifications, and communicate with you
Name (required) — to display your identity in workspaces and conversations
Profile photo (optional) — uploaded or provided via your social login provider
Content you create
When you use Cleariest, we collect and store:
Messages — text messages, rich-text content (bold, italic, code blocks, lists, links), and message edits sent in channels and direct messages
Files and attachments — images, videos, documents, and other files you upload or share
Reactions — emoji reactions you add to messages
Channel and workspace information — names, descriptions, topics, and settings for workspaces and channels you create or manage
Focus sessions — data from mindfulness and focus mode features you use, including session durations and optional summaries
Technical and device information
We automatically collect:
IP address — for security, fraud prevention, and approximate geolocation
Browser and device information — browser type, operating system, device model, screen resolution, and app version
Push notification tokens — device tokens for delivering push notifications on Android and iOS (Firebase Cloud Messaging, with Apple Push Notification service on iOS) and on the web (Web Push/VAPID)
Website and web app usage data — pages visited, features used, session duration, and interaction patterns collected on Cleariest web properties. Our native iOS and Android apps do not currently include Google Analytics, Meta Pixel, or Hotjar SDKs.
Real-time connection data — connection status, typing indicators, and online/offline presence transmitted via WebSocket (SignalR)
Payment information
If you subscribe to a paid plan (Pro or Business), we collect billing information through our payment processor, Stripe. We do not store your full credit card number or payment method details on our servers. See Third-Party Services below for details.
Newsletter subscribers
If you subscribe to our newsletter on our website, we collect your email address and optionally your first name through MailerLite.
2. How We Use Your Information
We use your information to:
Provide the service — deliver messages, files, and notifications across your workspaces and channels in real time
Authenticate your identity — verify your account when you sign in and maintain your session
Send notifications — deliver push notifications (mobile and web), email notifications for mentions, invitations, and workspace activity
Process payments — manage subscriptions and billing through Stripe
Generate AI-powered summaries — when you request an AI summary of a channel, we send relevant message content to OpenAI's API to generate the summary (see AI Features below)
Display background images — fetch images from Unsplash for focus mode and workspace backgrounds
Improve the product — analyse usage patterns, diagnose bugs, and develop new features
Communicate with you — send transactional emails (invitations, password resets, email summaries) and respond to support enquiries
Ensure security — detect and prevent fraud, abuse, and unauthorised access
We will never sell, rent, or share your personal information with third parties for their own marketing purposes.
3. AI Features and OpenAI
Cleariest offers optional AI-powered channel summaries. When you request a summary:
Message content from the relevant channel and time period is sent to OpenAI's API for processing
OpenAI processes this data under their API Data Usage Policy, which states that API inputs and outputs are not used to train their models
AI summaries are cached locally on your device and are not permanently stored on our servers
You can choose not to use AI features — they are always opt-in
4. Third-Party Services
We use the following third-party services to operate Cleariest. Each service receives only the minimum data necessary for its function and is governed by its own privacy policy:
Authentication
Kinde (privacy policy) — handles user authentication, registration, and single sign-on. Receives your email, name, and login credentials. On mobile devices, authentication uses the PKCE OAuth flow via an in-app browser.
Payments
Stripe (privacy policy) — processes subscription payments for Pro and Business plans. Receives your payment method, billing address, and email. We receive only a payment confirmation and subscription status — we do not store card details.
File storage
Cloudflare R2 (privacy policy) — stores files and attachments you upload in Cleariest (images, videos, documents). Files are stored securely with presigned URLs for access control.
Push notifications
Firebase Cloud Messaging (FCM) (privacy policy) — delivers push notifications to Android and iOS devices. On iOS, FCM works with Apple Push Notification service (APNs). Firebase receives a device-specific push token and notification content such as sender name and message preview.
Web Push (VAPID) — delivers push notifications to web browsers using the standard Web Push protocol.
AI processing
OpenAI (privacy policy) — processes channel messages to generate AI-powered summaries when explicitly requested by users. See AI Features section above.
Email
Resend (privacy policy) — sends transactional emails including workspace invitations, mention notifications, and email summaries. Receives recipient email addresses and email content.
MailerLite (privacy policy) — manages our newsletter mailing list on our website. Receives your email address and name if you subscribe.
Background images
Unsplash (privacy policy) — provides background images for focus mode sessions. No personal data is shared with Unsplash; only image search queries are sent.
5. Analytics and Tracking
We use the following analytics services on our website (cleariest.com) to understand visitor behaviour and improve our marketing:
Google Analytics (privacy policy) — collects anonymised page views, traffic sources, device information, and interaction events. Uses cookies to track sessions. Google Analytics data is subject to Google's data processing terms.
Meta Pixel (Facebook) (privacy policy) — tracks page views and conversion events for advertising measurement. Uses cookies and pixel tracking. You can opt out via Facebook Ad Settings.
Hotjar by Contentsquare (privacy policy) — records anonymised session replays, heatmaps, and user interaction patterns to help us improve site usability. Hotjar does not collect passwords, payment information, or personally identifiable form inputs. You can opt out at Hotjar Do Not Track.
On Cleariest web properties, we may also record product and marketing events such as sign-ups and workspace creation. Our native Android and iOS apps do not currently ship with Google Analytics, Meta Pixel, Hotjar, or another third-party advertising or analytics SDK. If that changes, we will update this policy and the relevant app store disclosures before release.
6. Cookies and Local Storage
Our website uses cookies set by third-party analytics services (Google Analytics, Meta Pixel, Hotjar) as described above.
The Cleariest application uses browser local storage and device storage (not cookies) to store:
Authentication tokens — JWT access and refresh tokens for maintaining your login session
Cached data — AI summary caches and notification preferences for performance
Push notification state — registration status for mobile push notifications
You can clear local storage at any time through your browser or device settings. Clearing authentication tokens will sign you out.
7. Data Storage and Security
Your data is protected using the following measures:
Encryption in transit — all data transmitted between your device and our servers is encrypted using TLS/HTTPS. Real-time WebSocket connections (SignalR) are also encrypted.
Encryption at rest — our database and file storage services use encryption at rest
Access control — our database uses PostgreSQL Row Level Security (RLS) policies to ensure users can only access data within workspaces they are members of
Authentication security — we use OAuth 2.0 with PKCE flow, short-lived access tokens (1 hour), and rotating refresh tokens (7 days)
Input sanitisation — all user-generated HTML content is sanitised server-side to prevent cross-site scripting (XSS)
File access control — uploaded files use presigned URLs with time-limited access
Our servers are hosted on Railway (cloud infrastructure). Data is processed in accordance with their security and compliance practices.
8. Data Retention
We retain your data as follows:
Account data — retained for as long as your account is active
Messages — retained until you delete them individually, or until your account or workspace is deleted
Files and attachments — retained until deleted by you or a workspace administrator, or until the workspace is deleted
Payment records — retained for up to 7 years as required by tax and accounting regulations
Server logs — retained for up to 90 days for security and debugging purposes
Analytics data — retained according to the policies of each analytics provider (typically 14–26 months)
9. Account Deletion
You can delete your account at any time:
In the app — go to Settings → Account → Danger Zone → Delete Account
By email — send a deletion request to [email protected] (processed within 7 business days)
When you delete your account:
Your profile, settings, and workspace memberships are deleted immediately
Messages you sent in channels are anonymised (attributed to "Deleted User") to preserve conversation context for other members
Direct messages are deleted
Files you uploaded are deleted from our storage
Payment records are retained as required by law (up to 7 years)
Data held by third-party services (Kinde, Stripe, analytics providers) is subject to their respective retention policies
Depending on your location, you may have the following rights regarding your personal data:
Access — request a copy of the personal data we hold about you
Correction — ask us to correct inaccurate or incomplete information
Deletion — request that we delete your personal data (see Account Deletion above)
Data portability — request your data in a portable, machine-readable format
Restriction — request that we restrict processing of your data in certain circumstances
Objection — object to processing of your data for specific purposes, including direct marketing
Withdraw consent — withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing
To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days.
11. Children's Privacy
Cleariest is designed for use by businesses and teams and is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If we become aware that we have collected data from a child under 16, we will take steps to delete that information promptly. If you believe a child under 16 has provided us with personal data, please contact us at [email protected].
12. International Data Transfers
Cleariest is operated from Australia. Your data may be processed in countries outside your own, including the United States and Australia, through our third-party service providers. Where data is transferred internationally, we ensure appropriate safeguards are in place, including data processing agreements with our service providers.
13. Permissions (Mobile Apps)
The Cleariest Android and iOS apps may request the following device permissions:
Internet access — required for all core functionality (messaging, file sharing, real-time updates)
Push notifications — to deliver message notifications when the app is in the background. You can disable this in your device settings at any time.
Vibration — for haptic feedback on notifications and interactions
Camera and photo library — only when you choose to upload images or take photos to share in conversations. Access is requested at the time of use.
All permissions are optional (except internet access) and can be revoked through your device settings.
14. Changes to This Policy
We may update this privacy policy from time to time as our services evolve. Any changes will be posted on this page with an updated revision date. If we make material changes that affect how we handle your personal data, we will notify you via the app or email before the changes take effect.
15. Contact Us
If you have any questions about this privacy policy, how we handle your data, or wish to exercise your rights, please contact: