Privacy Policy
The short version
- We never ask for your card number. Clariti works from which cards you hold, not from card numbers, expiry dates, or security codes. We never see them.
- Your wallet is backed up to your Clariti account so it survives a reinstall or a new phone. That account is created automatically and anonymously. There is no signup screen.
- Card reward rates ship inside the app. Recommendations are calculated on your phone, not on our servers.
- You can delete your account, and everything in it, from inside the app at any time.
- Messages you send to the AI coach are processed by a third-party AI provider on our behalf.
- We do not sell your data, we do not run ads, and we do not track you across other apps or websites.
This Privacy Policy explains what Clariti Finance (“Clariti,” “we,” “us,” or “our”) collects when you use the Clariti mobile app and claritifinance.com, why we collect it, who we share it with, and what you can do about it. Clariti Finance is a company incorporated in Ontario, Canada.
1. About the private alpha
Clariti is currently in a closed, invite-only alpha. One thing is true during this period that will not be true later, and we would rather say so plainly:
- Your usage is linked to your invite email. When you install the app you are asked to confirm the email address your invite was sent to. You can skip this. If you provide it, your analytics and crash reports are associated with that email so we can follow up on problems you personally hit, rather than staring at anonymous aggregate numbers.
When the alpha ends, the email-to-usage link is removed and the tester data described in this section is deleted. See Retention below.
2. Your Clariti account
It is created for you, anonymously
The first time you open Clariti, the app creates an account for your device automatically. There is no signup screen, no email required, and no password. It exists for one reason: so that the wallet you build does not disappear when you reinstall the app or move to a new phone.
This anonymous account is identified by a random identifier. On its own it tells us nothing about who you are.
What is stored against it
- Which cards are in your wallet, meaning the catalogue entry for each card, plus any nickname you choose to give it
- Card settings you set yourself, such as whether a card is active, whether you have autopay enabled, and whether you carry a balance on it. That last one is a genuine signal about your finances, and we use it only to avoid recommending a rewards strategy that would cost you more in interest than it earns.
- Your purchase log and the insights derived from it
- Your preferences, including country and feature settings
What is never stored, because we never ask for it
Clariti does not collect card numbers, expiry dates, or security codes, and there is nowhere in the app to enter one. The product works from which cards you hold, not from the numbers on them. If you choose to enter the last four digits of a card, it is only so you can tell two similar cards apart, and it is optional.
Reward rates, point valuations and card details ship inside the app itself, and recommendations are calculated on your device rather than on our servers.
Attaching an email, if you want to
You can optionally attach an email address, or use Sign in with Apple, to claim your anonymous account. Doing so lets you restore your wallet on a different device and lets us contact you about the product. Nothing is lost in the process: it is the same account, now with a way to identify it as yours. You are never required to do this, and the app is fully usable if you never do.
Deleting it
You can delete your account and everything stored against it from inside the app, in Settings. This is a permanent deletion, not a deactivation, and it removes the copy held on our servers. Deleting the app from your device removes the local copy. If you used Sign in with Apple, we also revoke the associated token with Apple as part of the deletion.
3. What we collect, and why
Usage and diagnostics
We collect product analytics through PostHog and crash reports through Firebase Crashlytics. This covers events such as opening the app, completing onboarding, adding a card, sending a message to the coach, confirming a purchase, searching for a merchant, and changing your country, along with the app version and build identifier. It also covers crashes, errors, and performance data.
We use this to find out what breaks, what confuses people, and what nobody uses. We do not use it to build an advertising profile.
Email address
Collected in three places, all of them optional: if you attach an email to your account as described in section 2, at the alpha invite confirmation, and any time you contact us or submit a bug report. Used to restore your account on a new device, to reach you about the product, and to answer you.
If you use Sign in with Apple and choose to hide your address, we receive only Apple's private relay address and never your real one.
Location
Only if you grant location permission. When you use nearby-store detection, your device's coordinates are sent through our backend to Google Places to identify stores around you. Coordinates are used for that lookup and are not stored against your identity. If you decline location permission, merchant search continues to work by typing a store name.
Note that if you confirm a nearby store, the name of that store is recorded in analytics so we can tell whether the recommendation was right.
Messages to the AI coach
Anything you type into the coach, including the “Can I afford this?” feature, is sent through our backend to a third-party AI provider so it can generate a reply. A summary of your wallet, meaning which card types you hold, may be included as context so the answer is relevant to you.
Please do not put account numbers, passwords, government identifiers, or anything you would not want processed by a third party into the coach.
Bug reports
When you use Report a Bug, we receive your description, your email if you provide one, the app version and build identifier, and basic device information. If you attach a screenshot, we receive that image. Photo library access is requested only for this purpose.
Bank connections
Clariti does not currently connect to your bank, and collects no banking data of any kind. The app works entirely from the cards you add yourself. If we introduce bank connections in future, we will update this policy and tell you before it happens, and it will be something you opt into rather than something that is switched on for you.
4. Who processes your data
We use a small number of service providers. Each one receives only what it needs to do its job, and none of them are permitted to use your data for their own purposes.
- PostHog (United States) — product analytics and error events
- Google Firebase Crashlytics — crash and performance reporting
- Google Places — nearby store lookup, when you grant location permission
- OpenRouter and the AI model providers it routes to — generating coach replies
- Resend — delivering bug reports and product email to us
- Supabase — storing your account and the wallet data described in section 2, and handling authentication
- Apple — only if you choose Sign in with Apple, in which case Apple provides us an identifier and, at your option, a private relay email address
- Vercel — hosting our website and backend
All API credentials for these services are held on our backend. None of them are embedded in the app you install.
5. What we do not do
- We do not sell or rent your personal information to anyone, for any price.
- We do not share your data with data brokers.
- We do not show ads, and we do not use advertising identifiers.
- We do not track you across other companies' apps or websites.
- We do not move money, make payments, or execute transactions on your behalf. Clariti is read-only.
- We are not paid by card issuers to recommend their cards, and issuer relationships do not influence the ranking the app shows you.
6. When we would disclose your information
Beyond the service providers listed above, we would disclose personal information only:
- With your consent, or at your direction
- To comply with a law, regulation, subpoena, or valid legal process
- To investigate or prevent fraud, security incidents, or abuse of the service
- In connection with a merger, acquisition, or sale of assets, in which case we will give notice before your information becomes subject to a different policy
7. Retention
- Account and wallet data is kept for as long as your account exists. When you delete your account in the app, it is removed from our systems, and from routine backups within 30 days.
- Accounts that are never used again are deleted after 24 months of inactivity, along with everything stored against them.
- The local copy on your device is removed when you uninstall the app.
- Analytics and crash data are retained for up to 12 months, then deleted or aggregated so it can no longer be tied to an individual.
- Alpha tester email links are deleted within 30 days of the alpha programme ending.
- Bug reports and support email are kept for as long as needed to resolve the issue and for a reasonable period afterwards for context, then deleted.
8. Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, obtain a portable copy, object to or restrict how we use it, and withdraw consent at any time. You also have the right not to be discriminated against for exercising these rights.
These rights are available to residents of Canada under PIPEDA and applicable provincial law, to residents of California under the CCPA and CPRA, and to residents of India under the Digital Personal Data Protection Act, among others.
The fastest way to exercise deletion is inside the app: Settings, then Delete account. That removes your account and everything stored against it without you having to write to anyone or wait for us. For access, correction, or a portable copy, or for anything else covered above, email us at the address below and we will respond within the timeframe the applicable law requires.
You can also switch off analytics collection at the operating-system level, and you can decline or revoke location and photo permissions at any time in your device settings without losing core functionality.
9. Security
We take the following concrete measures:
- All traffic between the app, our backend, and our service providers is encrypted in transit using TLS.
- Sensitive data on your device is held in the operating system's protected storage.
- Account data is protected by row-level access rules, so a given account can only ever read and write its own records.
- We never collect card numbers, expiry dates, or security codes, so there is no such data to breach.
- API keys and secrets are held server-side. None ship inside the app binary.
- Requests to our backend are authenticated, and sensitive endpoints are signed.
No system is perfectly secure, and Clariti is early-stage software in active development. We do not claim otherwise. If you discover a security issue, please email us and we will treat it as a priority.
10. Children's privacy
Clariti is not directed at children and is not intended for anyone under 18. You must be 18 or older to use the app or to hold a Clariti account. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it and the associated account.
11. International transfers
Clariti is operated from Canada and serves users in Canada, the United States, and India. The service providers listed in section 4 process data in the United States and other countries. Where information is transferred across borders, we rely on the contractual protections offered by those providers and on the safeguards permitted by applicable law. Information held in a given country may be accessible to that country's authorities under its laws.
12. Changes to this policy
We will update this policy as the product changes, and Clariti is changing quickly. Material changes will be reflected here with a new “Last updated” date, and where the change is significant we will tell you in the app or by email. Continuing to use Clariti after a change means you accept the updated policy.
13. Contact us
Questions about this policy, or want to exercise any of the rights above? Write to us and a human will answer.
Clariti Finance
Ontario, Canada
Email: hello@claritifinance.com