Privacy Policy

Last updated: 3 September 2026

Protecting your personal data matters to us. This policy informs you in accordance with Art. 13 and 14 GDPR about which personal data we process when you use our website and the Claire application, for what purposes and on what legal basis. We only process the data needed to run the service.

Controller

The controller responsible for data processing within the meaning of the GDPR is:

Karsten Biedermann (sole proprietor), Herrmann-Meyer-Str. 43, 04207 Leipzig, Germany. Email: hello@weclaire.com.

Hosting and delivery

Our website and application are hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. To deliver the site, Vercel processes technical connection data (e.g. IP address, time of access, content requested) on our behalf. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure, efficient delivery). A data processing agreement is in place.

Database, authentication and storage

For our database, user accounts/authentication and file storage we use Supabase (provider: Supabase Inc., USA). Your account data and the content you create (boards, tasks, documents, messages, meeting notes) are stored and processed in the European Union, in the Supabase EU region in Frankfurt am Main, Germany. The legal basis is Art. 6(1)(b) GDPR (performance of a contract). A data processing agreement is in place. Provider privacy policy: https://supabase.com/privacy.

Email delivery

We send service and notification emails (e.g. account confirmation, notifications you opt into) via Resend, Inc. (USA). Your email address and the relevant message content are processed for this purpose. The legal basis is Art. 6(1)(b) GDPR, or Art. 6(1)(a) GDPR for optional notifications. A data processing agreement is in place.

What data we process

Account data: your name and email address provided at sign-up.

Content data: the boards, tasks, documents, messages and meeting notes you create.

Server log data: data transmitted automatically when accessing the service, such as IP address, date and time, and browser type.

Sign in with Google and Google user data

You can optionally sign up and sign in with your Google account (Google OAuth). The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The legal basis is Art. 6(1)(b) GDPR (performance of a contract).

Which Google data we access: when you sign in with Google, we only request the basic profile scopes (openid, email, profile). From these we receive your name, your email address, your Google account ID and, if available, your profile picture. We do not request access to your Gmail, Google Calendar, Google Drive, Contacts or any other Google service, and we never receive your Google password.

How we use Google user data: we use this data solely to create your Claire account, to authenticate you on subsequent sign-ins, to display your name and profile picture within your workspace to you and your team members, and to send you the service emails described above. We do not use Google user data for advertising, for profiling, to build or improve AI or machine-learning models, or for any purpose unrelated to providing and improving the Claire service. Google user data is not transmitted to the AI providers named in this policy.

With whom we share Google user data: we do not sell, rent or trade Google user data. We do not disclose it to third parties for their own purposes. It is processed only by the processors named in this policy that are technically required to run the service, on our instructions and under data processing agreements: Supabase (storage of your account in the EU region in Frankfurt am Main), Vercel (hosting and delivery) and Resend (service emails). Team members of a workspace you join can see your name and profile picture. Beyond that, we disclose data only where we are legally obliged to do so.

How we protect Google user data: all data is transmitted exclusively over TLS-encrypted connections and stored encrypted at rest in ISO 27001 / SOC 2 certified data centres in the European Union. OAuth tokens are stored server-side only, encrypted, and are never exposed to your browser or to third parties. Access to production data is restricted to the controller, protected by multi-factor authentication and limited to what is necessary for operating and supporting the service. We apply the principle of data minimisation and log security-relevant access. In the event of a personal data breach we notify the competent supervisory authority and affected users in accordance with Art. 33 and 34 GDPR.

Retention and revocation: Google user data is retained for as long as your Claire account exists. You can delete your account at any time in the app or by emailing hello@weclaire.com; your Google user data is then deleted within 30 days, except where statutory retention obligations apply. You can also revoke Claire’s access to your Google account at any time at https://myaccount.google.com/permissions.

Claire’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements (https://developers.google.com/terms/api-services-user-data-policy).

AI features

Claire offers AI-assisted features (e.g. summaries, text suggestions, meeting notes). To provide them we use the interfaces (APIs) of Anthropic Ireland, Limited, 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 TR29, Ireland (Claude models) and OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland (GPT/ChatGPT models). For customers in the EEA, these Irish companies are our contracting parties; they may involve their US parent companies (Anthropic PBC and OpenAI, L.L.C.) as sub-processors.

When you use an AI feature, the content required for that request (e.g. the text, task or document concerned, plus your prompt) is transmitted to the respective provider, processed there and the result is returned to you. We do not transmit more data than the specific request requires, and we do not transmit your account data. AI features are only triggered by your action — no content is sent automatically in the background.

The legal basis is Art. 6(1)(b) GDPR (performance of a contract), as the AI features are part of the service. Both providers act as processors on our behalf; their respective data processing addenda, including the European Commission’s Standard Contractual Clauses, form part of the commercial terms we have agreed to. Under those terms the providers do not use the transmitted content to train their models. Content is retained only for a short period (as a rule up to 30 days) for abuse monitoring and is then deleted.

Please do not enter special categories of personal data (Art. 9 GDPR) or particularly sensitive third-party information into AI features. Provider privacy policies: https://www.anthropic.com/legal/privacy and https://openai.com/policies/eu-privacy-policy.

Cookies and local storage

We do not use tracking or marketing cookies and no web analytics. For basic functionality we store settings (such as language and theme) locally in your browser (localStorage). This storage is technically necessary; the legal basis is Art. 6(1)(f) GDPR and § 25(2) TDDDG.

International data transfers

Your account and content data are stored in the EU (Supabase, Frankfurt am Main). Other providers we use (Vercel, Resend, Google, Anthropic, OpenAI) may process data in the USA, and Supabase Inc. as a US-based company may in exceptional cases access data for administration or support. Where a transfer to a third country takes place, it is based on the European Commission’s Standard Contractual Clauses (Art. 46 GDPR) and, where certified, the EU-US Data Privacy Framework.

Retention

We retain personal data only for as long as necessary for the stated purposes or while your account exists. You can delete your account at any time, which deletes your content and account data, unless statutory retention obligations apply.

Your rights

You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to object to processing (Art. 21). You may withdraw any consent at any time with effect for the future (Art. 7(3) GDPR). To exercise these rights, simply email hello@weclaire.com.

Right to lodge a complaint

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the EU Member State of your residence or the alleged infringement.

Contact

For any privacy questions, reach us at hello@weclaire.com.