Privacy Policy
Last updated: 17 July 2026
1. Overview
Clareos (“we”, “us”) provides a general wellness software platform. This Policy explains what personal information we collect, how we use it, who we share it with to run the Service, and the choices you have. We do not sell your personal information. The operator is based in Australia; the Australian Privacy Act and Australian Privacy Principles (APPs) are relevant. If you are in another country, additional laws may apply.
Important: Clareos is not a covered entity or business associate under US HIPAA solely by providing this consumer wellness app. We aim to handle health-related data carefully, but this Service should not be treated as a HIPAA-regulated medical record system unless we separately contract for that.
2. Information we collect
- Account data: name, email address, authentication identifiers (including from social sign-in providers you choose), and consent timestamps (e.g. terms acceptance, disclaimer acknowledgment).
- Profile and health-related data you provide: date of birth, biological sex, conditions, goals, allergies, medications, and similar fields you enter.
- Uploads: lab PDFs, images, and other files you upload, plus biomarkers and text extracted from them.
- Generated content: chat messages, health plans, recommendations, and related AI outputs stored in your account.
- Usage and technical data: session tokens, IP address and user agent (where collected for auth/security), notification preferences, and audit logs of certain actions.
3. How we use information
- Create and secure your account
- Provide features: storage of records, trend views, chat, plan generation, and notifications you enable
- Process content with AI to produce informational, general-wellness outputs (not medical advice)
- Improve reliability, prevent abuse, and debug issues
- Comply with law and enforce our Terms
4. Processors and where data goes
To operate the Service we use third-party infrastructure. Your data may be processed by:
- Neon (PostgreSQL): primary application database for accounts, profiles, biomarkers, plans, conversations, audit logs, and related records.
- Cloudflare R2: object storage for files you upload (e.g. lab report PDFs and images).
- Anthropic (Claude API):AI processing of prompts that may include health-related content you submit or that is derived from your records, to generate analysis and recommendations. Content sent to Anthropic is processed under Anthropic’s terms and data practices applicable to our API use.
- Novu: notification delivery (in-app, and where configured email, SMS, or push) based on your preferences and events in the product.
- Hosting / auth providers: application hosting (e.g. Vercel) and optional social identity providers (Google, GitHub, Apple) if you use those sign-in methods.
These providers may process data in regions outside Australia (including the United States). By using the Service you acknowledge that cross-border processing is required for current architecture.
5. Security
We use industry-standard protections appropriate to a software product of this type, including HTTPS in transit and access controls on application data. Database and storage providers typically offer encryption at rest; exact controls depend on provider configuration. No method of transmission or storage is perfectly secure. You are responsible for protecting your password and device access.
6. Retention and account deletion
We retain personal information while your account is active and as needed to provide the Service, resolve disputes, and meet legal obligations.
You can delete your account from Settings. When you do, we delete your account record and related application data in our database (cascading linked records such as profiles, health records, plans, and conversations). Before the account is removed, we cancel any active, trialing, or past-due Stripe subscription immediately and remove local billing records; if Stripe cancellation fails, account deletion is aborted and you will see an error so you can resolve billing first. We also attempt a best-effort cleanup of: (1) files you uploaded to Cloudflare R2 under your profile prefix, and (2) your Novu notification subscriber. Backup copies, logs, or processor-side retention may persist for a limited time according to those providers’ practices or where law requires retention. Deletion may fail if your session is not fresh enough or if billing cannot be canceled; in those cases the product surfaces the error and does not claim success.
7. Your rights
Depending on your location, you may have rights to access, correct, or delete personal information, and to complain to a regulator (in Australia, the Office of the Australian Information Commissioner). You can update much of your profile data in the app and delete your account from Settings. For other access requests, contact us.
8. Children
The Service is not directed to children under 18. We do not knowingly collect personal information from children.
9. Changes
We may update this Policy as the product and infrastructure evolve. We will revise the “Last updated” date and, for material changes, provide additional notice where appropriate.
10. Contact
Privacy questions: use the contact channel published on clareos.app when available, or in-app support.