Skip to content
Clairitea home

Privacy Policy

Draft · Version 1.0

This version is a draft and may change before it is final.

Fair question: what do they keep on me? Here’s the answer.

What we keep, what we never keep, and how to get yours deleted.

On this page
  1. 1The short version
  2. 2Information we collect
  3. 3How we use information
  4. 4How we share information
  5. 5AI checks, automated checks and biometrics
  6. 6How long we keep information
  7. 7Your choices and rights
  8. 8California privacy rights
  9. 9Other U.S. state privacy rights
  10. 10If you are named in a post
  11. 11Children
  12. 12Security
  13. 13United States only
  14. 14Changes to this Policy
  15. 15Contact us

This Privacy Policy explains how [FOUNDER: company legal name] ("Clairitea", "we", "us" or "our") collects, uses, shares and protects personal information when you use the Clairitea iOS app, the website at clairitea.com, and related services (the "Service"). It also explains your choices and rights, including if you are a person that other users have posted about.

1The short version

  • Clairitea is for adults 18 and over, in the United States only. We do not knowingly collect information from anyone under 18.
  • Other users and the people you post about never see your name, phone number, email address or account.
  • We know which account made each post. We disclose it only when the law requires it (Section 4).
  • Our app database does not store your phone number, ID documents, selfies, your contacts, your precise location or voice recordings. Where we need to recognize a phone number or sign-in account, we store a keyed one-way hash of it.
  • Voice notes are turned into text on your phone. Audio is never uploaded.
  • We remove location and other metadata from every photo before we store it.
  • We do not use face recognition.
  • AI checks run on your posts, photos and screenshots only if you turn them on. You can turn them off at any time.
  • We do not sell your personal information, share it for targeted advertising, show ads, or use advertising identifiers.
  • You can download your data and delete your account in the app.

2Information we collect

2.1Information you give us

Account and sign-in. When you sign in with Apple or Google, that provider gives us an account identifier for you and, if you allow it, an email address. Google may also share your name and profile photo. Our sign-in system stores what the provider shares. We do not show it to anyone. When you sign in with a phone number, you give us that number and the one-time code we send to it. Section 2.4 explains where these are kept.

Age confirmation. You confirm that you are 18 or older on the sign-in screen, and we record that you did, along with which version of the Terms and other documents you accepted.

Your area. The city or metro area you choose.

Posts and other content. Posts, questions, comments, replies, reactions, flags and reason labels, optional ratings, the relationship and "where you met" details you choose, the name, city and approximate age you give for the person you post about, photos, and screenshots ("receipts"), plus drafts and scheduled posts. Content you post may include information about you, such as your dating life, and information about the person you post about.

Screenshots. You choose what to cover up in a screenshot before you send it. We keep the original screenshot, with its metadata removed, privately, so that the redaction can be re-applied if you edit it and checked by our reviewers. Other users only ever see the redacted version.

Watches and settings. People and names you choose to watch, your notification settings, whether you have turned on AI checks (and which version of the AI Disclosure you agreed to), and your other settings.

Reports, appeals and requests. Reports you file (the reason and any details you add), blocks, appeals, support messages and their attachments, disputes, and privacy requests. If you give us your name or an email address with a support message or privacy request, we store the email address encrypted.

Optional questions. Your answer to "How did you hear about Clairitea?", the invite code you signed up with, and your answers to occasional check-in questions in the app.

Web purchases. If you buy Clairitea Plus on clairitea.com, you give your email address and payment details to RevenueCat and Stripe, our payment providers (Section 4). They may share your email address with us so we can help with your subscription. We never receive your full card number.

2.2Information collected automatically

Device and security information. The platform (iOS or web), app version, language, time zone, and a push notification token if you allow notifications. On iPhone, Apple's App Attest creates a key on your device that proves requests come from the genuine app. We store a hash of the key's identifier and its public key. When you use the app without signing in, it sends a random device identifier, and we store a keyed hash of it to apply free limits. On the website, Cloudflare Turnstile checks that you are a person when you sign in, and we set a random security cookie and store a keyed hash of it (see the Cookie Policy).

IP address. We use your IP address when you connect, to apply rate limits and prevent abuse. We do not store it in our app database. Our hosting and network providers' request logs record it (Section 6).

Activity on the Service. The pages you open (to count your free lookups and show you your history), which feed items were shown to you (for 7 days, so we do not show them again), your reactions and watches, and product usage events such as which screen you viewed and which feature you used. Usage events do not include the text of posts, the names of people or phone numbers.

Searches. We use what you type to run the search. We do not keep a search history on our servers. If you search with a screenshot of a profile, the app reads the text on your phone and sends us only the text, not the image.

Purchases. Whether you have an active Clairitea Plus subscription, where you bought it, the plan, renewal and expiry dates, and store transaction identifiers.

Safety signals. We keep a record of each account's rule violations, strikes and suspensions, and signals that help us detect fake accounts, repeated accounts, coordinated fake posts or ratings, and scraping. These signals are never shown to other users.

2.3Information from other people and companies

Posts about you. If other users post about you, we hold what they submit: your first and last name as they enter it, nicknames, city, an approximate age, photos, and their posts, ratings and flags. Pages and search results show your first name and last initial only. Section 10 explains your rights.

Sign-in and service providers. Apple or Google (your account identifier, and your email, name or photo if shared), Twilio (whether a phone number is a mobile line), and Apple, RevenueCat and Stripe (subscription and payment status).

Clairitea does not buy information about people from data brokers, and does not build pages from public records or by collecting information from social networks. Every page on Clairitea exists because a user posted about that person. If we ever change this, we will update this Policy first.

2.4What we do not collect or keep

  • Phone numbers. Our app database stores only a keyed hash (HMAC-SHA-256) of your phone number. Your number itself is kept only by our sign-in system, so that it can send you codes and sign you in, and is shared with Twilio to send the code and check the line type.
  • Sign-in accounts. Our app database stores only a keyed hash of the account identifier from Apple or Google. The identifier itself, and anything else the provider shares, are kept only by our sign-in system.
  • Contacts. We do not access your contacts.
  • Precise location. We do not collect it. We remove location data from photos before storage and check the stored file to confirm it is gone.
  • ID documents, selfies and liveness video. We do not ask for them.
  • Audio. Voice notes are transcribed on your phone with Apple's on-device speech recognition. Only the text is sent.
  • Biometric information. See Section 5.
  • Advertising identifiers. We do not collect your device's advertising identifier, we do not track you across other companies' apps and websites, and we do not show ads.
  • Payment card details. Handled by Apple (App Store) or Stripe (web).

3How we use information

We use personal information to:

  • Provide the Service: create and secure your account, sign you in, show pages, posts and feeds, count free lookups, deliver notifications you have asked for, and provide Clairitea Plus.
  • Keep people safe and enforce our rules: check content against the House Rules with automated rules and, if you have turned them on, AI checks; hold content for review by a person; handle reports, blocks, appeals, disputes and requests from people who are posted about; remove intimate images and stop them being uploaded again; detect fake accounts, repeated accounts, coordinated fake posts or ratings and scraping; and apply warnings, strikes and suspensions.
  • Communicate with you: send the push notifications and in-app activity you have turned on, and emails only about your data export, your account deletion, replies to your support messages, the outcome of a dispute you filed, and your web subscription. We do not send marketing emails or marketing texts. If we ever do, we will ask first where the law requires it, and every marketing email will have an unsubscribe link.
  • Improve the Service: understand which features are used and fix problems, using usage events and error reports that have personal information removed.
  • Meet legal obligations and protect rights: comply with law and legal process, respond to lawful requests, remove intimate images and child sexual abuse material and report the latter as the law requires, and establish or defend legal claims.

We do not use your information for targeted advertising, and we do not sell it.

4How we share information

With other users. Your posts, comments, ratings, reactions, photos and redacted screenshots are shown to other users of the Service, without your identity. Some posts or parts of posts are shown only to signed-in or paying users. Public pages on clairitea.com show a person's first name and city and invite people to sign in. They ask search engines not to index them.

With the person you post about. They can see what you posted about them, but not who you are.

With service providers. We share information with companies that process it for us, under contracts that limit their use of it to providing services to us:

ProviderWhat they do for usWhat they receive
RailwayHosting for our servers, database, sign-in system, file storage and background jobs (we run the open-source Supabase software on Railway)All account data and content we hold
CloudflareNetwork delivery and security, and Turnstile bot checks on the websiteRequests to our website and API, including IP address and browser signals
TwilioSending sign-in codes by SMS; checking a number is a mobile lineYour phone number
AppleSign in with Apple, App Attest, push notifications, App Store payments, Apple PaySign-in and device data, push content, purchases
GoogleSign-in, if you choose itSign-in data
RevenueCatManaging subscriptions in the app and on the webYour Clairitea account ID, purchase and renewal data, and your email address for web purchases
StripeProcessing web paymentsYour payment details, email address and billing information
Amazon Web Services (Rekognition)Checking photos and screenshots for prohibited content, and reading text in screenshots, only if you turned on AI checksYour photos and screenshots
AnthropicAI checks of the text you post, only if you turned on AI checks and we have switched this check onThe text you post
ResendSending the emails listed in Section 3Your email address and the message
PostHogProduct usage analytics and error reportsYour Clairitea account ID or a random installation ID, usage events, your plan and metro area, and your IP address unless we have turned that off [FOUNDER: confirm PostHog "discard client IP" setting]

For legal reasons. We disclose information when we believe in good faith that the law, a subpoena, court order, search warrant or other legal process requires it; to protect anyone from death or serious physical injury; to report child sexual abuse material to the National Center for Missing & Exploited Children as federal law requires; or to protect the rights, property and safety of Clairitea, our users or others. Our Law Enforcement Guidelines explain what process we require, and that we notify users before we disclose their information unless the law forbids it.

Business transfers. If Clairitea is involved in a merger, acquisition, financing, reorganization, bankruptcy or sale of assets, information may be transferred as part of that transaction, subject to this Policy.

With your consent. We share information in other ways when you ask us to or agree.

Aggregated information. We may share statistics that do not identify anyone.

5AI checks, automated checks and biometrics

Every post, comment and reply is checked by automated rules when you submit it. If you turn on "AI checks my posts and photos" in Settings, Privacy, your photos and screenshots are also checked by Amazon Rekognition, and your text may be checked by an AI model from Anthropic when we have that check switched on. Without your consent, none of your content is sent to an AI provider, and a person on our team reviews your photos and screenshots before they appear. The AI Disclosure explains this in detail.

No face recognition. We do not use face recognition or face matching, and we do not create or store face geometry, faceprints or any other biometric identifier from photos. Our image checks look for prohibited content (such as nudity or violence) and read text. They do not identify people. The image fingerprints we keep to stop intimate images being uploaded again are made from the whole image, not from a face. If you turn on the app lock, Face ID runs on your iPhone. We never receive Face ID data.

6How long we keep information

We keep personal information only as long as we need it for the purposes in this Policy. The periods below are what our systems do automatically.

InformationHow long we keep it
Your account, settings and consentsWhile your account exists
Live posts, comments, ratings and reactionsUntil you delete them, we remove them, or you delete your account
Removed or blocked posts and comments90 days after removal (for appeals and safety), then the text is replaced by a one-way hash and the photos and screenshots are deleted
Removed or blocked photos and screenshots90 days after removal, then deleted
Fingerprints of removed intimate imagesAs long as needed to stop the image being uploaded again. We keep the fingerprint only, never the image
Uploads while they are processedDeleted as soon as processing finishes (at most about 1 hour after a failed upload)
Drafts30 days
Record of pages you opened90 days (we keep only totals after that)
Feed items shown to you7 days
In-app notifications30 days
Activity items180 days
Your data export file7 days
Payment provider event records30 days (we keep a minimal record to prevent duplicates)
Support messagesUntil you delete your account. Messages sent without an account: [FOUNDER: retention period; nothing deletes them automatically yet]
Keyed hashes of your phone number and sign-in account, device keys and your rule-violation record, after you delete your account90 days, then deleted
Your sign-in record in our sign-in system, after you delete your accountUp to 90 days, then deleted
Server and network logsUp to 30 days
Product usage events and error reports in PostHog[FOUNDER: PostHog region and retention period]
Records of moderation and staff actions2 years
Privacy requests and our responses24 months after the request is closed

We may keep information longer when the law requires it, when it is subject to a legal hold or legal process, or when we need it to establish, exercise or defend legal claims, and only for as long as that need lasts.

When you delete your account, we sign you out everywhere, remove your posts, comments and ratings from the Service, and delete your account data, watches, support messages and unlocks. Reports and disputes you filed are kept without your identity or the details you wrote, because they are part of someone else's case. Our payment providers keep their own records of web purchases as the law requires.

7Your choices and rights

7.1In the app

  • Download my data (Settings, Privacy): a file with your posts, comments, ratings, reactions, watches, name watches, settings, subscription and unlock history, and your activity from the last 90 days. The file is available for 7 days. You can ask for one export every 24 hours.
  • Delete account (Settings): deletes your account as described in Section 6.
  • AI checks my posts and photos (Settings, Privacy): turn AI checks on or off at any time.
  • Notifications: choose which notifications you get, in the app and in iPhone Settings.
  • Edit or delete your posts and comments.
  • Blocked people: manage who you have blocked.

7.2Requests to us

You can ask us to tell you what personal information we hold about you and give you a copy, correct it, or delete it. Account holders can do most of this in the app (Section 7.1). You, or someone you have authorized, can also email support@clairitea.com. If you are named in a post, use the process in Section 10.

To protect you, we verify every request. For an account holder, we ask you to confirm from the phone number or sign-in account on the account. For anyone else, we send a confirmation link to the email address you give us, and we may ask for more information that shows the request is about you. An authorized agent must give us your signed permission, and we may ask you to confirm it directly. We respond within 45 days, and aim to respond within 30. If we need longer, we will tell you why, as the law allows.

If we decline your request, we explain why. If you live in a state that gives you the right to appeal our decision, reply to our response to appeal, and we will respond within the time your state's law requires. If you disagree with the outcome of an appeal, you may contact your state's Attorney General.

We will not discriminate against you for using your privacy rights.

8California privacy rights

This section applies to California residents under the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA").

Categories of personal information. In the last 12 months we have collected these categories of personal information, from the sources, for the purposes, and disclosed for business purposes to the recipients described in Sections 2 to 4:

CCPA categoryExamplesDisclosed to
IdentifiersAccount ID; keyed hashes of your phone number, sign-in account and device; push token; email address if you give it or your sign-in provider shares it; phone number (held by our sign-in system); IP address (used, not stored in our app database)Service providers
Customer records (Cal. Civ. Code § 1798.80(e))Name, phone number, email address; for web purchases, billing information held by StripeService providers
Characteristics of protected classificationsThat you are 18 or older; anything you choose to include in a postService providers; other users, for what you post
Commercial informationSubscription plan and status, free lookups, unlocksService providers
Internet or network activityPages opened, feed items shown, usage events, device informationService providers
Geolocation dataThe metro area you choose only (not precise location)Service providers
Audio, electronic or visual informationPhotos and screenshots you uploadService providers; other users, for what you post
InferencesSafety and abuse signalsService providers
Sensitive personal informationYour sign-in account used with a one-time code; information about your sex life, sexual orientation or health, if you include it in a postService providers; other users, for what you post

Sensitive personal information. We use and disclose sensitive personal information only to provide the Service, to keep it secure and safe, to comply with law, and for the other purposes that California regulations permit without offering a right to limit. We do not use it to infer characteristics about you.

No sale or sharing. We do not sell personal information, and we do not share it for cross-context behavioral advertising, as the CCPA defines those terms, and we have not done so in the last 12 months. We have no actual knowledge of selling or sharing personal information of anyone under 16. Because we do not sell or share, we honor Global Privacy Control signals automatically.

Retention. Section 6 sets out how long we keep each category.

Your rights. You have the right to know what personal information we collect, use and disclose, and to get a copy of it; to delete it; to correct it; to opt out of sale or sharing (which we do not do); to limit the use of sensitive personal information (which we use only as permitted); and not to be discriminated against for using these rights. Use the methods in Section 7.

Free speech. The CCPA does not require us to delete information needed to exercise free speech or to ensure another person's right to free speech. A post in which another user describes their own experience may fall within that exception. We still review every deletion request about such a post against the House Rules (Section 10).

Shine the Light. We do not disclose personal information to third parties for their own direct marketing purposes.

9Other U.S. state privacy rights

Depending on where you live (for example Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah or Virginia), you may have the right to confirm whether we process your personal data, access it, correct it, delete it, get a portable copy, and opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects. We do not sell personal data, use it for targeted advertising, or use it for that kind of profiling. To use your rights, or to appeal a decision, follow Section 7.

Consumer health data. We do not ask for health information. If you choose to include health information in a post, or a user includes it in a post about you, we use it only to provide the Service and to moderate content, we do not sell it, and the rights in Sections 7 and 10 apply, including under Washington's My Health My Data Act and similar laws in Nevada and Connecticut. Posts that say someone has a sexually transmitted infection are held for review by a person before they appear.

Nevada. We do not sell covered information as Nevada law defines it.

10If you are named in a post

If users have posted about you, you have choices even if you do not use Clairitea.

What we hold about you. The information in Section 2.3: the name, nicknames, city and approximate age users entered, photos, and their posts, ratings and flags. Pages and search results show your first name and last initial only. We do not hold your phone number, address or other contact details, and our rules prohibit users from posting them. We do not allow pages about anyone under 18.

Ask us to review a post. Use the "A post about you?" form on your page on clairitea.com, or at clairitea.com/support, or email safety@clairitea.com with a link to the page. You do not need an account. Tell us which post, and whether it is not true, not you, shares private information, is harassment, or something else. We send a link to confirm your email address. Once you confirm, we aim to review the request within 48 hours, and we tell you the outcome.

What we do. We remove content that breaks the House Rules, including private information, threats, harassment, content about the wrong person, and sexual content. Content that does not break our rules may stay up, because it is another person's account of their own experience. We do not tell you who wrote a post, except as Section 4 allows. We never remove or change content in exchange for payment.

Intimate images. If a post includes an intimate image of you shared without your consent, including a fake or AI-generated one, we remove it within 48 hours of a valid request. The Safety Center explains how to make one.

Access and correction. You can ask for a copy of the information on a page about you, or ask us to correct information, using the same process.

If you use Clairitea. You can also report a post in the app with "This is me", "This isn't true" or another reason. Your identity is never shown to the person who posted.

11Children

Clairitea is only for adults 18 and over. We do not knowingly collect personal information from anyone under 18, and we do not allow pages or content about anyone under 18. If we learn that we have collected information from someone under 18, we delete it and close the account. If you believe a child is using Clairitea or appears in content, report it in the app with "Someone under 18" or email safety@clairitea.com.

12Security

We protect personal information with measures that include encryption in transit, private storage that can only be read through short-lived links after a permission check, database access rules on every table, keyed hashing of phone numbers and sign-in identifiers, removal of photo metadata, device attestation, and restricted, logged staff access. No system is completely secure, and we cannot guarantee the security of information. If a breach affects your personal information, we will notify you and the authorities as the law requires.

13United States only

We offer the Service only in the United States. We and our service providers process and store information in the United States [FOUNDER: confirm that Railway, PostHog and every other provider store data in U.S. regions]. The Service is not directed to people in the European Union, the United Kingdom or other countries, and we do not offer it there.

14Changes to this Policy

We may update this Policy. If we make a material change, we will tell you in the app before it takes effect. The version and effective date are shown at the top of this Policy.

15Contact us

[FOUNDER: company legal name], [FOUNDER: mailing address for legal notices]. Privacy questions and requests: support@clairitea.com. Posts about you and safety: safety@clairitea.com. Legal process: legal@clairitea.com.