Where your data lives, and how we protect it

Hosted in the EU. Your data is stored in a European data center. Content sent for AI processing may be used to train or improve AI models. Encrypted in transit (TLS). Passwords hashed, stored API keys encrypted at rest. Public report links are revocable instantly, at any time.

Hosting and data location

Clairo runs on infrastructure operated by Contabo GmbH (a German provider) in a data center located in France, inside the European Union. Application data, project content, and backups of the application database reside on this EU infrastructure.

AI processing: how your content may be used

When you run an AI action (extraction, Q&A, report generation), the relevant text is sent to our AI subprocessor, Mistral AI (France), to process that request and return a result. Under our current Mistral account data-sharing settings, this content may also be used by Mistral to train or improve their AI models. AI output is generated automatically and can be inaccurate or incomplete. It is provided as a starting point, not as advice. You are responsible for reviewing AI output before relying on it or sharing it.

Encryption and credentials

All traffic between your browser and Clairo is encrypted with TLS. Account passwords are hashed with bcrypt. We cannot see or recover your password. If you connect your own AI API key, it is encrypted at rest before storage. Payment card details are collected and processed entirely by Polar, our merchant of record. Card data never reaches Clairo servers.

Access control and sharing

Project access follows three roles: Owner, Editor, and Viewer. Role checks are enforced server-side on every API endpoint, not just hidden in the interface. Team invitations are only claimed after the invitee verifies ownership of the invited email address. Public report links use long, unguessable tokens. Anyone with the link can read that report until you revoke it. Revoking is instant. Each project's private email-in address accepts mail only from the project owner's or an editor member's verified account email. All other senders are rejected automatically. The Chrome extension reads only the Google Chat conversation visible on your screen, and only when you click.

Retention, export, and deletion

Your data is retained while your account is active. You can delete individual inputs, items, and reports in-app at any time. Paid plans can delete entire projects. Reports can be exported as PDF or DOCX at any time. You can request full account deletion or a copy of your data via the contact form. We action such requests promptly and confirm when complete. Revoked share links and deleted content stop being publicly accessible immediately.

Subprocessors

We use a small number of service providers to run Clairo:

Your responsibilities

Clairo is a tool. What goes into it, and what is done with what comes out of it, is decided and controlled by you. By using Clairo you accept that: You are responsible for the content you submit, including having the right to share it. Do not paste material you are not authorized to process (for example, third-party confidential information or personal data you have no lawful basis to handle). You are responsible for reviewing AI-generated output before acting on it or sharing it. AI output can contain errors, omissions, or misinterpretations. You are responsible for all decisions, actions, and communications made based on Clairo's output, including reports shared with clients or stakeholders. You are responsible for who you invite to projects, the roles you grant them, and any public share links you create and distribute. You are responsible for complying with your own organization's policies and all laws that apply to you and your data.

Something doesn't look right? Talk to us first

If anything on this page, in the product, or in how your data is handled seems wrong, outdated, or concerning, contact us and ask. We will correct, change, or remove it promptly, and removal or deletion requests are honored without argument. By using Clairo you agree to raise any concern, complaint, or dispute with us first and give us 30 days to resolve it in good faith before initiating any formal or legal proceeding. In our experience every issue so far has been resolved this way, faster and at no cost to anyone. Nothing in this section limits rights that applicable law does not allow to be limited, such as your right to complain to a data protection authority.

Disclaimer and limitation of liability

Clairo is provided on an "as is" and "as available" basis, without warranties of any kind, whether express or implied, including fitness for a particular purpose, accuracy of output, or uninterrupted availability. Clairo does not provide legal, financial, medical, or other professional advice. To the maximum extent permitted by applicable law, Clairo and SmartToolHQ disclaim all liability for any loss or damage arising from your use of the service, including decisions made in reliance on AI-generated output, content you submit, content you share with others, or access you grant to other people. Your sole and exclusive remedy for dissatisfaction with the service is to stop using it and delete your data.

For your security and procurement team

Need paperwork for an internal review? Our privacy policy and a Data Processing Agreement (DPA) template are available here. To execute the DPA: fill in your company details, sign it, and email the signed copy to support@smarttoolhq.com — we counter-sign and return it within 2 business days.

Responsible disclosure

Found a security issue? Please report it through the contact form with the subject "Security". We investigate every report and respond within 2 business days. Please do not access other users' data or disrupt the service while testing.