Privacy
Privacy notice
Clarity is built with a privacy-first launch posture. We use privacy-preserving Vercel page and performance measurement, but no advertising pixels, marketing cookies, or cross-site tracking. This notice explains the personal data needed to provide the assessment, saved reports, action-plan tracking, magic-link access, requested emails, and service reliability.
Controller and contact
Clarity is the controller for personal data processed through this website. For privacy requests, contact hello@getclaritycs.com.
What we collect
- Assessment answers, scores, maturity levels, and report data.
- Email address for magic-link sign-in and requested report emails.
- Profile fields such as full name, company, and role.
- Action-plan items, status, owner, due date, blocker reason, notes, and success signal when you choose to track follow-up work.
- Review request details such as name, email, company, role, and optional notes.
- Technical security data, including request identifiers derived from IP headers for rate limiting.
- Privacy-preserving page and performance measurements through Vercel, such as visited routes, referrer, approximate location, device/browser type, and Core Web Vitals.
Why we use it
- To provide the maturity assessment and saved report workbench.
- To provide action-plan tracking for report recommendations and custom follow-up actions.
- To authenticate users with Supabase magic links.
- To send requested report and maturity review emails.
- To generate optional report narrative from the deterministic report snapshot.
- To understand aggregate page usage and improve performance without advertising, marketing cookies, or cross-site tracking.
- To protect the service from abuse and operational errors.
Processors and recipients
Clarity uses Supabase for database and authentication, Resend for transactional email, OpenAI for optional report narrative enrichment, and Vercel for hosting, server logs, Web Analytics, and Speed Insights. International transfers may occur through these providers and should rely on their contractual safeguards and transfer mechanisms.
OpenAI enrichment is server-side only. Clarity sends report snapshot content, not user email or profile fields, and requests that OpenAI does not store the response input for model training by using store: false.
Retention
Saved assessments, reports, and action-plan items are retained for 24 months, then reviewed or deleted. Review requests are retained for follow-up and then reviewed or deleted. We may keep limited records longer when needed for security, legal, or operational obligations.
Your rights
You can ask to access, correct, delete, restrict, object to, or receive a portable copy of your personal data. You can also withdraw consent where consent is the relevant basis for processing, and you may lodge a complaint with your local data protection authority. Requests can be sent to hello@getclaritycs.com. We aim to respond within one month.
This product notice is provided for launch readiness and is not legal advice. Review it with counsel before broader public launch.
Read the cookie and storage notice