Trust & Privacy

Your mind. Your data. Your control.

Your mental-health data is some of the most personal information there is. At withClaro, protecting it isn’t a feature bolted on at the end — it’s how the app is built. You decide what you share, you can take it back anytime, and we never sell it.

Security

How we protect your data

Security isn't just a policy we point to — it's built into every layer of withClaro.

AES-256 at restTLS 1.2+ in transitiOS Keychain

Encryption at every layer

AES-256 encryption when your data is stored. TLS 1.2+ when it travels. Authentication tokens are held in the iOS Keychain — the same standards used by banks and government agencies.

Strict access controls

Role-based, least-privilege access for our team. Multi-factor authentication for admin access. Production and staging environments are fully separated.

Minimized vendor exposure

Analytics never receive health data. Notification payloads stay neutral — no medication names or health details. Our AI provider never receives your name, email, or phone number.

Accountable processing

Written data-processing agreements with every external provider. Defined retention and deletion rules. Admin access is logged and reviewed.

Transparency

What data we collect — and why

Every category maps to a specific withClaro feature. We never collect data we don't need.

What: Email address, account ID, authentication provider, session tokens, login metadata, OTP and transactional account emails.

Why: To create and secure your account, verify sign-in, and send account-related emails.

How we collect it

Directly from you

Most data comes from what you enter — check-ins, onboarding answers, medication details, notes, and optional AI chat messages.

From your device, with permission

Apple Health / HealthKit data, push notification tokens, and voice input (processed as text — we don’t retain server-side audio).

Automatically, with consent

Pseudonymous product analytics to help us improve the app. You can refuse or withdraw analytics consent at any time.

Sub-processors

Who we share data with

We work with a small number of trusted providers.

We do not sell, rent, or trade your personal data — ever.

DigitalOcean (EU/EEA hosting)

Hosting, storage, databases, backups, and infrastructure for withClaro backend systems within the EU/EEA.

OpenAI Ireland Ltd

Optional AI companion chat, AI-generated artifacts, safety classification, and report summarisation — only when you use those features. Processing may occur outside the EU/EEA under contractual safeguards.

PostHog Cloud (EU)

Optional pseudonymous product analytics for the app, hosted in the EU. Never receives health or special-category data.

Klaviyo

OTP and transactional account emails, taper protocol emails, and Ask a Psychiatrist responses. Never receives health content.

Google Tag Manager & Meta Pixel

Optional website analytics and advertising measurement on withclaro.com only, with your consent. May involve processing outside the EU/EEA.

Authentication & platform providers

Google and Apple sign-in, push notification delivery (APNs), and Apple Health / HealthKit platform interactions on your device.

RevenueCat & Apple App Store

Subscription and payment processing. withClaro does not store payment card data.

A clinician you choose

Only if you ask withClaro to transmit a doctor report to a specific recipient. We never share your data with clinicians automatically.

Internal authorized personnel

Only where access is necessary for operation, support, security, compliance, or administration.

Where your data is processed

withClaro is operated by Pink Elephant, Unipessoal Lda from Portugal. Our primary infrastructure and several processors are located in the EU/EEA and operate under written data-processing agreements that address confidentiality, security, processing instructions, and deletion.

Some providers we use — such as OpenAI, Klaviyo, Google, Apple, and Meta — may process personal data outside the EU/EEA. Where that happens, we rely on appropriate safeguards under the GDPR, such as Standard Contractual Clauses or adequacy decisions.

How long we keep it

We keep data only as long as needed — then we delete or anonymise it.

Backups may persist for limited retention periods and aren't used for live product purposes; deletion follows the applicable backup lifecycle.

  • Account & wellness dataLife of account; purged within 30 days of confirmed deletion
  • Notes & avatarDeleted immediately when you remove them, or on account deletion
  • Analytics dataUp to 24 months, then deleted or fully anonymised
  • Diagnostic & crash logs12 months from creation
  • Notification delivery logs90 days from delivery
  • Billing / tax records7 years where legally required
  • Payment card dataNever stored by withClaro

Your privacy rights

We apply GDPR-style rights to all withClaro users, wherever you live.

Access

Request a copy of the personal data we hold about you.

Correct

Update inaccurate or incomplete information.

Delete

Delete your account and associated data. Once deleted, it’s gone.

Export

Receive a portable copy of your data to use elsewhere.

Restrict

Ask us to limit how we process certain data.

Object

Object to processing based on legitimate interests.

Withdraw consent

Turn off optional features and withdraw consent at any time.

Complain

Contact a data protection authority if you believe your rights have been violated.

Exercise any of these rights by contacting [email protected]. We may need to verify your identity before responding.

Privacy by choice

These features are entirely optional. If you don't use one, we don't process the data it requires.

  • Apple Health / HealthKit integration
  • AI companion chat
  • Product analytics
  • Standalone notes
  • Voice input
  • Avatar / profile photo
  • Doctor report / clinician export
  • Push notifications
  • Medication tracking (if you choose to use it)
  • Research Programme

Privacy FAQ

Still have questions?

Reach our team anytime at [email protected].

Do you sell my data?
No. withClaro never sells personal data to advertisers, data brokers, or any third party. Your wellness data is not a product.
Is my health data encrypted?
Yes. We use AES-256 encryption for data at rest and TLS 1.2+ for data in transit. Authentication tokens are stored in the iOS Keychain.
Can I delete everything?
Yes. You can delete your account at any time. Most data is purged within 30 days of a confirmed deletion request. Notes and avatars are removed immediately when you delete them.
Does the AI see who I am?
No. We do not intentionally send your name, email address, or phone number to our AI provider. AI features receive only the feature-specific content needed to generate a response.
Do you track me for ads?
No. Optional product analytics are pseudonymous and used only to improve the app. Analytics never receive health data, chat content, medication details, or other sensitive information.
Where is my data stored?
withClaro is operated by Pink Elephant, Unipessoal Lda from Portugal. Our primary infrastructure and several processors are located in the EU/EEA under data-processing agreements. Some providers (such as OpenAI, Klaviyo, Google, Apple, and Meta) may process data outside the EU/EEA under appropriate safeguards such as Standard Contractual Clauses.

Legal documents & contact

Need the official legal language? Our full policies include plain-language summaries and detailed processing records.

Questions about your data? [email protected]