Privacy Policy — Clearune
- Effective: 15 July 2026
- Last updated: 19 July 2026
- Review status: Technical/legal draft — obtain qualified human review before the next production publication
- Controller: Joanna Szamota Blackgrain Workshop
- Address: Zachodnia 24, 05-822 Milanówek, Mazowieckie, Poland
- Tax ID (NIP): 5291840195
- REGON: 521704456
- Email:
In plain language
Clearune is designed so that the journal you save is encrypted in your browser before storage. We do not hold the key needed to read that stored journal. Readable text is processed by our server and an approved AI provider when you request an AI feature or separately opt in to automatic meaningful reflections. The When it notices something important option uses a high threshold and may occasionally create a short reflection; it does not respond to every entry. Automatic reflections are off until you opt in and can be turned off again at any time. We do not sell personal data, disclose journal text to advertisers, or build our own AI-training dataset from readable journal text. OpenAI and Google Cloud receive the request payload described below, not your encrypted archive as a whole; their own processing and retention depend on the configured business/API service, contract, and current provider terms. The public website may display Google AdSense advertising to visitors and Free-plan users; advertising code is not loaded in the private journal, archive, authentication, account, or legal-document screens.
This Policy explains what we process, why, who receives it, and the choices available to you. It applies to the Clearune website and application (the Service).
1. Who is responsible
Joanna Szamota Blackgrain Workshop, Zachodnia 24, 05-822 Milanówek, Mazowieckie, Poland, is the data controller for the Service. Contact us at .
2. Data we process
Account and contract data
We process your email address, Clerk user identifier, authentication records, account timestamps, language, plan, subscription status, and evidence that you accepted the Terms and gave any required consent. Clerk manages account authentication, sessions, verification, and account-password recovery. If you use password sign-in, Clerk receives and verifies the password; we do not receive your plaintext account password. The separate journal encryption password is processed in your browser as described below.
Optional Google sign-in data
If you choose Google sign-in, Google provides Clearune through Clerk with your email address, name, profile image, and provider account identifier. We use this information only to create and authenticate your Clearune account and associate the sign-in method with that account. We do not request access to Gmail, Google Drive, Google Contacts, calendars, files, or other Google account content. We do not sell Google user data, use it for behavioural advertising, or use it to train AI models.
Optional Apple sign-in data
If you choose Sign in with Apple, Apple provides Clearune through Clerk with a provider account identifier and either your email address or an Apple private relay address. Apple may also provide your name during the first authorisation. We use this information only to create and authenticate your Clearune account and associate the sign-in method with that account. We do not receive your Apple Account password or access iCloud, photos, contacts, files, purchases, or other Apple Account content.
Optional Facebook sign-in data
If you choose Facebook Login, Facebook provides Clearune through Clerk with the basic account information you authorise, such as your name, email address, profile image, and provider account identifier. We use it only to create and authenticate your Clearune account and associate that sign-in method with the account. We do not request access to your Facebook posts, messages, friends list, photos, pages, or advertising data.
Encryption and recovery data
Your browser creates a master encryption key. We store versions of that key wrapped under your password and recovery code, together with salts and technical key metadata. We do not store the recovery code itself. The unlocked key may be held in your browser's session storage so the journal remains open during that browser session.
Encrypted journal content
The following are encrypted in your browser before being stored in Supabase: entries and AI replies, memory summaries, moods, reflections, reports, margin notes, letters, dream readings, volume prefaces, gifts, attachment captions, and uploaded photo or audio bytes. We store ciphertext plus limited metadata needed to organise it, such as record ID, account ID, date, content type, file type, storage path, and timestamps.
Because we do not possess your unwrapped key, we cannot routinely read or recover this stored content. Encryption does not prevent temporary processing while text is decrypted in your browser and sent for an AI feature permitted by your reflection settings.
AI request content
We process relevant text and context in readable form over TLS when you explicitly request an AI response, memory question, reflection, report, mood reading, or dream reading. If you separately opt in to a scheduled-reflection mode, saving may permit the specifically described classification and reflection flow; the request-only mode makes no external AI call on save. Processing may include current writing, recent conversation, and relevant source-backed context selected locally in your browser. Clearune sends requests directly from its server to Google Cloud Vertex AI or OpenAI through the Clearune AI Gateway; it does not use an AI-model aggregator. A generation request is never sent to both providers at the same time. We do not persist readable journal text, prompts, responses, or excerpts in the journal database, operational logs, classification records, or administrator tools.
For an opted-in entry we may retain a content-free classification: entry and account identifiers, enumerated entry type and trigger reason, bounded scores, safety category, decision, confidence, model/provider, token and cost metadata, configuration version, and timestamps. It contains no journal text, excerpt, prompt, model reasoning, or readable response. An automatic response is stored only after your browser encrypts it with the journal key. We also retain your presence-mode choice, opt-in time and notice version, atomic quota reservations, and content-free interaction or feedback metadata.
Sensitive data
Journals may reveal health, racial or ethnic origin, political opinions, religion or beliefs, trade-union membership, sexuality, or other information protected as a special category under Article 9 GDPR. We do not ask you to include it. If you choose to do so, we process it only to store your encrypted journal and provide the AI features you request, on the basis of your separate explicit consent. See Section 5.
Please avoid entering another person's sensitive information unless you have a lawful reason to do so. You are responsible for the personal data about other people that you choose to include.
Embeddings and derived signals
Clearune does not request provider embeddings for memory retrieval. Relevant context is selected locally in your browser from content decrypted on your device. A long-term memory candidate is stored only after you explicitly confirm it; its text and source mapping are encrypted in your browser before database storage. Stored mood signals and other derived reflections are encrypted.
Billing data
If you buy a subscription or Ink Pack, Stripe processes your payment method, billing details, transaction, tax, invoice, and fraud-prevention information. We receive Stripe customer and subscription identifiers, plan, payment or subscription status, and renewal period. We do not receive full card numbers.
Usage, security, and diagnostics
We process response counts, token counts, plan entitlements, rate-limit records, security signals, timestamps, IP address and request/device information needed to deliver and protect the Service. Technical error reports may contain the error type, truncated message and stack trace, page path, diagnostic identifier, and browser user-agent. Error reporting is designed not to include journal text, email, or account ID.
If you report an AI reply, we receive the selected reason and any note you type. The reported reply excerpt is included only if you actively choose to share it.
Optional product analytics
With your consent, Google Analytics measures page views and a limited set of product events, and we retain a first-party copy of permitted product events such as signup, first entry, paywall display, upgrade click, personality change, or referral-link copy. Google may receive the page URL and title, timestamp, event name, limited event properties, approximate location derived from the request, and browser/device information. We do not send Google journal text, prompts, AI replies, email, name, or a Clearune account identifier. Our first-party copy may be account-linked or pseudonymous rather than anonymous.
Advertising on the public website
The public, crawlable Clearune website may load Google AdSense for signed-out visitors and signed-in Free-plan users. Active Plus, Premium, and Patron subscribers are excluded after their Stripe-synchronised plan is checked. We do not load AdSense on the private journal, journal archive, sign-in or sign-up pages, account settings, or legal documents, and we do not send journal text, AI prompts, AI replies, email addresses, or Clerk identifiers to AdSense.
Google may process the public page URL, IP address, browser and device information, consent signals, advertising cookies or local-storage identifiers, and ad impressions or interactions. Depending on your region and choices, Google may show personalised, non-personalised, or limited ads. Non-personalised ads may still use storage for purposes such as frequency capping and aggregated reporting. In the EEA, UK, and Switzerland, Google’s certified consent-management platform presents the advertising choices required for AdSense. You can revisit those choices using the privacy-options control supplied by Google on an eligible page. See Google’s advertising privacy information.
Optional weather and device permissions
If you enable real-weather ambience, your browser requests location permission and sends coordinates directly to Open-Meteo. We do not receive or store those coordinates. If you explicitly capture a weather moment in Life Context, the browser rounds the coordinates to 0.1° before the direct Open-Meteo request and stores only the minimized weather snapshot (time, condition, temperature, provider and approximate-precision label) in your encrypted account data. The snapshot is excluded from AI until you separately select it for an eligible feature. There is no background location tracking. Open-Meteo receives the network request under its own privacy terms. If you use voice input, audio is handled by your browser and encrypted attachment flow as shown in the interface; we do not use it for voice identification.
Legacy waitlist and referrals
If you previously joined a waitlist, we may hold the email address you submitted. If you arrive through a referral link, your browser temporarily stores the referral code and sends it when you create an account so the referral can be credited.
3. Why and on what legal basis we process data
| Purpose | GDPR legal basis |
|---|---|
| Create and authenticate an account; store and retrieve encrypted content; provide requested AI, export, account, and billing features | Performance of our contract, Article 6(1)(b) |
| Classify new entries and create occasional automatic meaningful reflections after you enable that optional mode | Your consent and instructions, Article 6(1)(a); explicit consent under Article 9(2)(a) where special-category data is involved |
| Process journal content that may contain special-category data | Your explicit consent, Articles 6(1)(a) and 9(2)(a) |
| Optional product analytics | Your consent, Article 6(1)(a) |
| Advertising storage, personalisation, and related measurement where consent is required | Your consent, Article 6(1)(a) |
| Security, fraud and abuse prevention, rate limiting, service diagnostics, and enforcing our Terms | Our legitimate interests in operating a secure and reliable service, Article 6(1)(f) |
| Invoices, tax records, lawful requests, and handling legal claims | Legal obligation, Article 6(1)(c), or legitimate interests, Article 6(1)(f) |
| Respond to privacy, support, and complaint requests | Contract, legal obligation, or legitimate interests, depending on the request |
Where we rely on legitimate interests, we balance those interests against your rights and limit the data to what is reasonably necessary.
4. AI processing and human review
AI requests are sent directly through the Clearune AI Gateway to Google Cloud Vertex AI or OpenAI as AI processing providers. OpenAI is the primary provider for moderation, structured safety, classification, and standard replies, and an eligible fallback for some deep features. Google Cloud Vertex AI is the primary provider for explicitly requested deep Dream Reading and Monthly Deep Report features and an eligible sequential fallback for standard replies and classifiers. A fallback is sequential and route-specific; one generation request is not sent to both providers at once.
We minimise a provider request to the inputs needed for the selected feature: relevant readable text, locally selected context, the feature and safety instructions, and technical request metadata. The application does not deliberately add your account password, billing data, advertising identifiers, or the encrypted archive as a whole. Clearune does not maintain its own training pipeline for readable journal text. The application code does not control or prove the provider's account-level logging, retention, or model-improvement settings. Provider-side processing may therefore include abuse-monitoring, security, legal retention, or other handling permitted by the configured service and contract. We do not promise zero provider retention unless the applicable provider configuration and contract support that promise. Current provider information is available in OpenAI's API data controls and Google Cloud's generative AI data-governance documentation.
Authorised personnel do not have routine access to encrypted journals. Human review is possible only for information you deliberately send outside the encrypted journal, such as a support message, a report note, or an AI excerpt you choose to include in a report.
AI outputs are generated automatically, but the Service does not make decisions that produce legal or similarly significant effects about you. The distress-language feature may display crisis resources; it does not diagnose you and we do not store a user-level record that it triggered.
5. Your explicit consent for sensitive journal data
At signup, we ask separately for explicit consent to process sensitive information you may choose to include, solely to store the encrypted journal and generate AI features you request. Automatic meaningful reflections require a further, separate opt-in in the journal settings. We record the relevant consent or opt-in time and notice version. Declining automatic reflections does not prevent writing or manually requesting an available reflection.
You may withdraw this consent at any time by deleting your account, or by contacting us. Because processing the journal is the core purpose of the Service, withdrawal means we must stop providing journal processing and erase the account, subject to legal retention exceptions. Withdrawal does not affect processing already carried out lawfully.
6. Cookies and browser storage
We use essential authentication and browser storage. Optional product analytics is off until you allow it. On the public website, AdSense may use advertising storage only for eligible visitors and in accordance with the Google advertising choices presented for the relevant region. No advertising code is loaded inside the private journal or other private product screens. You can refuse optional analytics as easily as accepting it and change that choice from Cookie preferences in the footer. Google’s advertising choices are managed separately through its consent message and privacy-options control.
See the Cookie & Storage Notice for names, purposes, and durations.
7. Who receives data
| Recipient | Purpose and data |
|---|---|
| Clerk, Inc. | Account authentication, session management, verification, password recovery, and optional connection to Google, Apple, or Facebook; account and security data |
| Google LLC / Google Analytics | Consent-based page and product measurement; page URL and title, event data, approximate network location, and browser/device information, without journal text or a Clearune account identifier supplied by us |
| Google LLC | Optional Google account authentication; basic account and profile information only when you choose Google sign-in |
| Apple Inc. and relevant affiliates | Optional Apple account authentication; provider identifier, email or private relay address, and first-authorisation name where supplied |
| Meta group companies | Optional Facebook account authentication; basic account and profile information only when you choose Facebook Login |
| Supabase, Inc. | EU-region database, database authorisation using Clerk tokens, private object storage, encrypted journal records, account and usage data |
| Netlify, Inc. | Hosting, content delivery, serverless execution, request and security logs |
| OpenAI, L.L.C. and relevant affiliates | AI processing provider for safety screening, classification, standard replies, and eligible deep fallback; readable request text, selected context, generated output, and request metadata during processing |
| Google LLC / Google Cloud | AI processing provider for explicit deep Dream Reading and Monthly Deep Report, plus eligible sequential fallback for standard replies and classifiers; readable request text, selected context, generated output, and request metadata during processing |
| Google LLC / Google AdSense | Advertising on the public website for eligible visitors and Free-plan users; public page, device, network, consent, impression, and interaction data, but no journal text or Clearune account identifier supplied by us |
| Stripe group companies | Checkout, subscriptions, payment, invoices, tax and fraud prevention when you purchase |
| Upstash, Inc., if production rate limiting is enabled | Short-lived pseudonymous rate-limit key and count; no journal content |
| Cloudflare, Inc. | Turnstile bot check only when you ask to reveal the protected contact email |
| Open-Meteo | Coordinates sent directly by your browser only when real-weather ambience is enabled or you explicitly capture a Life Context weather moment; Life Context rounds them to 0.1° before the request |
| Professional advisers and public authorities | Only where reasonably necessary for legal advice, claims, or a binding legal duty |
Our providers process data under their contracts and privacy terms. We do not sell personal data or share it for cross-context behavioural advertising.
8. International transfers
The primary Supabase project is hosted in the European Union. AI request payloads may be processed by OpenAI, Google Cloud, or their subprocessors outside the EEA; the exact location depends on the provider service, configuration, and routing in use. Other recipients, including Clerk, Apple, Meta, Netlify, Stripe, and Cloudflare, may also process data outside the EEA. Where GDPR requires it, transfers rely on an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful safeguard. You may contact us for information about the safeguard relevant to a transfer.
9. Retention
| Data | Retention |
|---|---|
| Account, encrypted journal, encrypted reflections and reports, confirmed encrypted memory, content-free classifications, preferences, attachment objects, usage and entitlement data | While the account is active; erased through account deletion, subject to the exceptions below |
| Optional analytics events | First-party events: up to 13 months; Google Analytics user-level event data: no more than 14 months under the property configuration |
| Technical error reports | Up to 30 days |
| AI response reports and voluntarily shared excerpts | Up to 12 months, or longer where needed to investigate a serious safety or legal issue |
| Readable AI request and response content at OpenAI or Google Cloud | Not retained as readable operational content by Clearune; any provider-side retention is determined by the configured business/API service, contract, abuse-monitoring and legal requirements described in Section 4, and may differ between providers |
| Rate-limit keys | Normally about 60 seconds; security logs may be retained longer by infrastructure providers |
| Referral attribution | Until signup, successful attribution, expiry, or browser-storage clearing |
| Pre-launch waitlist email | Until the related launch communication is complete or you ask us to delete it |
| Billing, invoice, tax, chargeback and fraud records | For the period required by tax, accounting, payment, and limitation laws |
| Support and legal correspondence | As long as needed to resolve the request and establish, exercise, or defend claims |
When you delete an account, we remove live account-linked data and encrypted attachment objects. Residual encrypted copies may remain temporarily in restricted disaster-recovery backups until the provider's backup cycle overwrites them. They are not used for ordinary processing. We may retain data where law requires it or where strictly necessary for legal claims, security, or fraud prevention.
10. Your rights
Subject to applicable law, you may request access, correction, erasure, restriction, portability, or objection; withdraw consent at any time; and complain to a supervisory authority. Where processing relies on consent or contract and is automated, you may request a portable copy.
The Account page provides a JSON export of written journal records and decrypted captions and lets you delete the account. Attachment metadata is included; media objects may need to be saved separately from the journal interface. For other information or rights, contact . We may need to verify your identity. GDPR requests are normally answered within one month.
You may complain to the President of the Personal Data Protection Office (UODO), ul. Stanisława Moniuszki 1A, 00-014 Warszawa, uodo.gov.pl, or to the supervisory authority where you live or work.
11. Security and the recovery-code limitation
We use browser-side AES-256-GCM encryption, TLS, access controls, private storage, row-level database security, rate limits, and restricted administrative credentials. No system is risk-free.
If you lose both your password and recovery code, the encrypted journal is permanently unrecoverable. We cannot bypass the encryption. Keep the recovery code secure and export important content periodically.
12. Children
The Service is for adults aged 18 or older. We do not knowingly offer it to children. Contact us if you believe a child has created an account.
13. Changes
We may update this Policy when the Service, providers, or law changes. We will post the updated date and give advance notice in the app or by email when a change materially affects your rights or choices. If a new purpose requires consent, we will ask before using data for that purpose.
14. Contact
Joanna Szamota Blackgrain Workshop · NIP 5291840195 · REGON 521704456
Zachodnia 24, 05-822 Milanówek, Mazowieckie, Poland