Privacy Policy
Last updated: 22 July 2026
Effective: 22 July 2026
Version 1.0
ClearAI HQ is operated from Stockholm, Sweden and is subject to the General Data Protection Regulation (GDPR) and Swedish data protection law. This policy explains what personal data we collect, why we collect it, where it is stored, and your rights as a data subject. If you have questions, contact us at
privacy@clearaihq.com.
1. Who We Are — Data Controller
ClearAI HQ ("we", "us", "our") is the data controller for personal data processed through our platform at clearaihq.com.
Kevin Babaei (sole proprietor), trading as ClearAI HQ, Stockholm, Sweden
Contact for data protection matters: privacy@clearaihq.com
2. Data We Collect
2.1 Account data
- Email address, display name, and hashed password on registration.
- Account creation date, last login timestamp, and subscription status.
2.2 Business profile data
- Business name, industry, target audience, brand voice, and goals you enter into the platform.
- This data is used to personalise AI outputs and is stored in your account.
2.3 OAuth access tokens (social media)
- When you connect a social account, we store an OAuth access token for that platform.
- Tokens are encrypted at the disk layer (database-level encryption managed by Supabase). They are used solely to publish content on your explicit instruction.
- We store tokens for: Facebook Pages, Instagram Business, LinkedIn personal profile and organisation, TikTok, and Threads.
2.4 Content and AI-generated data
- Posts, captions, campaign briefs, documents, and other content you create or save in the platform.
- Prompts you send to AI generators (these are forwarded to Anthropic or Google Gemini — see sub-processors below — but are not stored by us beyond your active session or saved content).
2.5 Usage and analytics data
- Feature usage patterns, pages visited, and interactions within the platform.
- Collected to improve the service and diagnose issues. Not sold or used for advertising profiling.
2.6 Payment data
- Billing name, last four digits of card, billing address, and invoice history.
- All payment processing is handled by Stripe. We do not store full card numbers or CVV codes on our servers.
2.7 Support and communications
- Emails and messages you send to our support team.
- Feedback you submit through the platform.
3. Legal Bases for Processing (GDPR Art. 6)
- Contract performance (Art. 6(1)(b)): Operating your account, delivering the platform features, processing subscription billing, and publishing content on your instruction.
- Legitimate interests (Art. 6(1)(f)): Security monitoring, fraud prevention, platform analytics for service improvement, and technical diagnostics. We have assessed that these interests are not overridden by your rights.
- Legal obligation (Art. 6(1)(c)): Retaining financial records as required by Swedish accounting law (Bokföringslagen) and responding to lawful requests from authorities.
- Consent (Art. 6(1)(a)): Marketing emails and optional analytics features where we ask for your consent. You may withdraw consent at any time.
4. How We Use Your Data
- To create and manage your account.
- To deliver and improve platform features.
- To publish content to connected social accounts on your explicit instruction.
- To process payments and send invoices.
- To generate AI-powered suggestions, plans, and content personalised to your business profile.
- To send transactional emails (account, billing, security alerts).
- To send marketing communications if you have opted in (you may opt out at any time).
- To comply with our legal obligations.
We do not sell personal data to third parties. We do not use your content to train AI models.
5. Storage and Data Regions
All primary user data is stored within the European Union. Certain AI processing and infrastructure services involve transfers to the United States — these are covered by Standard Contractual Clauses (see Section 7).
- Primary database & authentication: Supabase, EU-West region (Ireland — eu-west-1). This includes account data, business profiles, content, and encrypted OAuth tokens.
- AI processing: Prompts and content are processed by Anthropic (USA), Google LLC (USA), OpenAI LLC (USA), and ElevenLabs (USA). LLM prompts are not retained for training under applicable DPAs. Image generation prompts and TTS text are processed transiently.
- Payments: Stripe, with EU-based data processing where possible.
- Hosting & serverless functions: Netlify (USA), covered by SCCs.
6. Sub-Processors
We use the following sub-processors to deliver the platform. Each is bound by a data processing agreement and appropriate safeguards.
| Sub-processor |
Service |
Data involved |
Region |
Safeguard |
| Supabase Inc. |
Database, authentication, file storage |
All account, content, and profile data |
EU-West (Ireland — eu-west-1) |
DPA + SCCs |
| Anthropic PBC |
Claude AI — language model processing |
Prompts and AI outputs (not retained for training) |
USA |
DPA + SCCs |
| Google LLC |
Gemini AI — language model processing |
Prompts and AI outputs (not retained for training) |
USA |
DPA + SCCs |
| Stripe Inc. |
Payment processing and billing |
Billing name, card last-4, invoices |
EU / USA |
DPA + SCCs |
| Netlify Inc. |
Web hosting, CDN, serverless functions |
Request logs, deployed application |
USA |
DPA + SCCs |
| Resend Inc. |
Transactional email delivery |
Email address; post failure alerts, trial emails, approval notifications, status subscriber emails |
USA |
DPA + SCCs |
| OpenAI LLC |
Image generation (gpt-image-1) for social and blog content |
Image generation prompts (topic/style descriptors) |
USA |
SCCs |
| ElevenLabs Inc. |
Text-to-speech voice synthesis for chat audio output |
Text of chat replies sent for voice synthesis |
USA |
SCCs |
| Google LLC — Cloud TTS |
Google Cloud Text-to-Speech (separate service from Gemini AI) |
Text of chat replies sent for voice synthesis |
USA |
DPA + SCCs |
| Unsplash (a Getty Images company) |
Stock image retrieval for blog and social content |
Search query strings (topic keywords) |
USA |
SCCs |
| Meta Platforms (Facebook / Instagram / Threads) |
Social publishing via official API |
OAuth tokens; content published on your instruction |
USA / EEA |
Platform API Terms |
| LinkedIn Corporation |
Social publishing via official API |
OAuth tokens; content published on your instruction |
USA / EEA |
Platform API Terms |
| TikTok Inc. |
Social publishing via official API |
OAuth tokens; content published on your instruction |
Singapore / USA |
Platform API Terms + TikTok DPA |
We will notify you of any new sub-processors that materially affect the processing of your personal data by updating this page and, where required, via email.
7. International Data Transfers
Sub-processors operating in the United States include Anthropic, Google LLC, OpenAI LLC, ElevenLabs, Netlify, Stripe, Resend, and Unsplash. Transfers of personal data to these providers are safeguarded by:
- Standard Contractual Clauses (SCCs) approved by the European Commission under GDPR Article 46(2)(c).
- Where applicable, the EU–US Data Privacy Framework.
You may request a copy of the relevant transfer mechanism documentation by contacting privacy@clearaihq.com.
8. Retention Periods
- Account and profile data: Retained while your account is active. Deleted within 30 days of account deletion, except where longer retention is required by law.
- Content and AI outputs: Retained while your account is active. Deleted on account deletion.
- OAuth tokens: Deleted immediately when you disconnect a social account, or within 30 days of account deletion.
- Financial records (invoices, billing history): Retained for 7 years in accordance with Swedish accounting law (Bokföringslagen SFS 1999:1078).
- Support correspondence: Retained for up to 3 years for legal and quality purposes.
- AI prompt data: Not retained by ClearAI HQ beyond the session. Anthropic and Google confirm prompt data is not retained for model training under their enterprise agreements.
9. Your GDPR Rights
As a data subject under GDPR, you have the following rights. To exercise any of them, email privacy@clearaihq.com. We will respond within 30 days.
Right of Access (Art. 15)
Request a copy of all personal data we hold about you, including the categories processed and recipients.
Right to Rectification (Art. 16)
Request correction of inaccurate or incomplete personal data. You can update most data directly in your account settings.
Right to Erasure (Art. 17)
Request deletion of your personal data. We will comply unless we have a legal obligation to retain it (e.g. financial records).
Right to Restriction (Art. 18)
Request that we restrict processing of your data in certain circumstances, such as when you contest its accuracy.
Right to Portability (Art. 20)
Receive your personal data in a structured, machine-readable format and transmit it to another controller.
Right to Object (Art. 21)
Object to processing based on legitimate interests or direct marketing. We will stop unless we have compelling grounds.
Automated Decision-Making (Art. 22)
We do not make decisions based solely on automated processing that produce significant legal effects on you.
Withdraw Consent
Where processing is based on consent, withdraw it at any time. Withdrawal does not affect lawfulness of prior processing.
10. Social Media Integrations
When you connect a social media account, you authorise us to act on your behalf using that platform's official API. We request only the minimum permissions necessary to publish content you explicitly approve. Specifically:
- TikTok:
user.info.basic, video.upload, video.publish. We do not access your followers, inbox, or analytics without separate consent.
- Facebook & Instagram: Page publishing and content management permissions only.
- LinkedIn: Profile reading and post publishing permissions only.
- Threads & X: Publishing permissions only.
You can disconnect any social account at any time from Connected Accounts in your app settings. Upon disconnection, we delete your access token immediately.
11. Cookies and Local Storage
- Essential cookies: We use Supabase session cookies (JWT) for authentication. These are strictly necessary and cannot be disabled.
- Local storage: We store user preferences (theme, UI state) in your browser's localStorage. No personal data is stored there.
- Analytics: We use first-party analytics via Supabase. We do not use Google Analytics, Meta Pixel, or other third-party advertising trackers.
- No advertising cookies: We do not use cookies for advertising, retargeting, or cross-site tracking.
12. Security
- All connections to ClearAI HQ use HTTPS/TLS encryption.
- OAuth tokens are encrypted at the disk layer (database-level encryption managed by Supabase). There is no application-layer encryption of stored credentials.
- Passwords are hashed and never stored in plain text.
- Access to production data is restricted to authorised personnel on a need-to-know basis.
- We conduct regular reviews of our security practices.
No system is perfectly secure. If you believe there has been a security breach affecting your account, contact us immediately at privacy@clearaihq.com. We will notify affected users and the relevant supervisory authority within 72 hours of becoming aware of a breach, as required by GDPR Article 33.
13. Children's Privacy
ClearAI HQ is a business platform intended for users aged 18 and over. We do not knowingly collect personal data from children under 16. If you believe a child has created an account, please contact us and we will delete the account and associated data promptly.
14. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority. As a Sweden-based company, our lead supervisory authority is:
Integritetsskyddsmyndigheten (IMY) — Swedish Authority for Privacy Protection
Website:
imy.se · Email: imy@imy.se · Phone: +46 8 657 61 00
You may also contact the data protection authority in your country of residence.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email and/or a prominent notice in the app at least 14 days before the change takes effect. The "Last updated" date at the top reflects the most recent revision. Continued use of the platform after changes take effect constitutes acceptance.
For any privacy questions, access requests, or complaints:
- Email: privacy@clearaihq.com
- Post: Kevin Babaei (sole proprietor), trading as ClearAI HQ, Stockholm, Sweden