Privacy Policy

This policy explains how Clarinda handles personal data when you visit the website, join the waitlist, use the service, connect another service, or contact us.

Last updated: 30 August 2026

1. Who is responsible for your data

Clarinda is an online personal-assistant service operated from Singapore by its account owner. Clarinda is responsible for the personal data described in this policy. For privacy questions or requests, email privacy@clarinda.app.

2. Personal data we collect

3. Why we use personal data

We use personal data to review access requests; create and secure accounts; provide requested assistant features; process files and connected-service actions; operate subscriptions and credits; understand which campaigns lead to approved and paying customers; answer support requests; detect abuse; troubleshoot and improve reliability; meet legal duties; and enforce our Terms of Service. We do not sell personal data. Meta and Reddit advertising measurement runs only after your affirmative choice, with advanced matching disabled.

4. When data is shared

We share only what is reasonably needed with service providers that help operate Clarinda. These include Cloudflare for hosting, storage, security, and AI infrastructure; Resend for email delivery; Stripe for billing; Google when you connect or use its services; and configured AI providers, which currently may include MiniMax, Anthropic, Google Gemini, and Cloudflare Workers AI. If you allow optional advertising measurement, the isolated measurement frame also sends limited event names and opaque event IDs to Meta and/or Reddit. It cannot inspect your authenticated Clarinda screens, and Clarinda sends neither your email nor other personal identifier for matching. We may also disclose data when required by law, to protect users or the service, or as part of a business transfer subject to appropriate safeguards.

Connected services have their own privacy terms. Clarinda does not access a connected account until you authorize the connection, and you may disconnect it through Clarinda or the provider.

5. Google user data and permissions

Clarinda requests Google permissions when you use the related feature, not as one bundled grant:

OAuth tokens are encrypted and retained until you disconnect Google or the grant is revoked. Clarinda stores the connected account identifier, granted-scope status, and the Clarinda records or lightweight file references needed for the feature. Email attachment bytes pass through memory for delivery and are not stored in Clarinda's D1 or R2 storage.

Google user data is used only for the user-facing action you request. It is not sold, used for advertising, or used to train generalized artificial-intelligence models. When an action needs a configured service provider, Clarinda transfers only the data needed to provide that action under the safeguards described in this policy.

The use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

6. Retention and deletion

Clarinda keeps account and service records while needed to provide the service, resolve disputes, prevent abuse, maintain security and audit trails, and meet legal or accounting requirements. Pending access requests are kept while they are reviewed. A minimal record of rejected, revoked, or deleted access may be retained when necessary for security and enforcement.

Voice recordings are held only temporarily in your browser, the Clarinda request, and Cloudflare Workers AI while transcription is performed. The audio is not saved to Clarinda's database, file storage, queues, Chat history, or audit content and is deleted immediately after the transcription request finishes. The transcript remains only in the editable Chat field unless you choose to press Send; only then does the unchanged Chat pipeline store it as your message.

For uploaded files, the original binary is deleted immediately after successful processing. Unsuccessful namecard originals remain available for review and retry for seven days from upload, then are deleted. Other unsuccessful uploads are removed after 24 hours. Extracted context is kept for seven days so you can review it and ask follow-up questions. At expiry, Clarinda deletes text chunks, generated artifacts, attachment links, extraction details, summaries, source details, confidence values, storage keys, filename, file type, and size, and redacts automatic Chat messages that contained the temporary extraction. Your own Chat messages and records you deliberately save or confirm—such as contacts, receipts, or tasks—remain as separate account data until you delete them. Other content remains until you delete it, close the account, or ask us to delete it, subject to necessary security, legal, backup, and audit retention.

First-touch and last-touch campaign attribution is retained with the related access request and account for reporting. The optional-consent browser cookie lasts for up to 180 days, unless you change your choice sooner. Pending advertising event-delivery records expire after 30 days.

7. Overseas processing

Clarinda and its providers may process data outside Singapore. Where the Singapore Personal Data Protection Act applies, we take reasonable steps to use recipients that provide a comparable standard of protection.

8. Your choices and rights

You may ask to access or correct your personal data, withdraw consent, disconnect an integration, object to a use, or request account or data deletion. Optional Meta and Reddit measurement can be changed at any time through Cookie Settings on the public website; choosing Necessary only stops future optional measurement and never blocks access. Send other requests from your account email to privacy@clarinda.app. We may need to verify your identity. Withdrawing consent may prevent Clarinda from providing features that require the affected data. Some information may be retained where permitted or required by law.

9. Security and incidents

We use reasonable administrative and technical safeguards, including restricted access, authenticated sessions, encryption where appropriate, provider security controls, and anti-abuse checks. No online service can guarantee absolute security. If a data breach requires notification under applicable law, we will notify the relevant authority and affected people as required.

10. Children

Clarinda is not directed to children under 18. Do not create an account or submit another person's data unless you have the authority to do so.

11. Changes and contact

We may update this policy as Clarinda changes. Material changes will be posted here and, where appropriate, communicated through the service. Questions and privacy requests can be sent to privacy@clarinda.app. General support is available at support@clarinda.app or on the Contact page.

This Privacy Policy is also Clarinda's Privacy Notice. Joining the waitlist does not create a paid subscription. Approved users receive one 7-day, 100-credit trial when they first sign in.