Privacy Policy
Last updated: January 2026
1. Introduction
Clario ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our email workflow and task management service. Please read this policy carefully.
2. What Data We Collect
We collect information in the following categories:
- Account Information: Name, email address, company name (if applicable), and role/title when provided.
- Integration Data: When you connect Gmail or Outlook, we access email metadata (subject, sender, date) and content as needed for task suggestions. We also access calendar events for scheduling features.
- Usage Analytics: Page views, feature usage patterns, and error logs to improve service quality.
- Support Requests: Information you provide when contacting support or submitting feedback.
3. How We Use Your Data
We use collected information to:
- Provide core services including email-to-task suggestions and calendar-aware planning
- Improve product performance, reliability, and security
- Provide customer support and manage your account
- Process subscription requests and billing inquiries
- Send service-related communications (not marketing, unless opted in)
4. AI Processing & User Responsibility
Clario uses AI to generate task suggestions and productivity insights. Here's how we handle your data:
- We send only the minimum necessary content for AI processing (subject, snippet, last message).
- Attachments are excluded by default and are not sent to AI services.
- AI services are used for transient processing only — they are not our data store.
- When using paid API services, customer data is not used to train AI models.
- Sensitive patterns (API keys, tokens, phone numbers, emails) are automatically sanitized before processing.
- Nothing is executed without your confirmation. AI suggestions are advisory only.
Important Disclaimers:
- Clario is a productivity tool, not a decision-maker. Users are responsible for reviewing all actions before confirmation.
- AI outputs may be incomplete, incorrect, or outdated. Users must verify information before acting.
- Users remain solely responsible for communications sent, tasks created, and calendar changes made through the Service.
- Clario shall not be liable for any damages resulting from reliance on AI-generated suggestions.
5. Data Sharing
We may share your information with:
- Service Providers: Hosting, analytics, and email delivery services that help us operate Clario.
- OAuth Providers: Google and Microsoft for authentication and integration purposes (you control these connections).
- Legal Requirements: When required by law or to protect our rights.
We do not sell your personal data.
6. Data Retention
- Account data is retained while your account is active.
- AI outputs are retained for up to 90 days for service improvement.
- Audit logs are retained for up to 365 days for security purposes.
- Raw AI request content is not stored beyond transient processing.
- You can disconnect integrations at any time, which stops data sync.
- You may request full account deletion by contacting support.
7. Security
We implement robust security measures to protect your data:
- Encryption in Transit: All data is transmitted over HTTPS.
- Token Security: OAuth refresh tokens are encrypted using AES-256-GCM and stored securely on the backend only.
- Access Controls: Role-Based Access Control (RBAC) ensures users only access authorized data.
- Audit Logging: Sensitive actions are logged for security and accountability.
- Password Security: Passwords are hashed using bcrypt with appropriate cost factors.
8. International Transfers & Data Residency
Clario aims to support Saudi Arabia and GCC data residency requirements. We can host data within Saudi Arabia for Enterprise clients when configured.
Please note that third-party integrations and API providers (such as Google, Microsoft, and AI services) may process data outside the Kingdom of Saudi Arabia according to their own privacy policies.
9. Regional Compliance (NCA KSA)
For users in the Kingdom of Saudi Arabia, we are committed to aligning with the National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC):
- Data Residency: Local hosting options available for Enterprise clients.
- Access Control: Strict RBAC enforcement across all user levels.
- Audit Trails: Comprehensive logging of security-relevant events.
- Data Minimization: Only essential data is collected and processed.
10. Your Rights
You have the right to:
- Access: Request a copy of your personal data.
- Correction: Update inaccurate or incomplete information.
- Deletion: Request deletion of your account and associated data.
- Export: Request an export of your data in a portable format.
- Opt-Out: Disable optional analytics where applicable.
- Disconnect: Revoke integration access at any time from Settings.
11. Contact Us
For privacy-related inquiries, please contact us:
This Privacy Policy may be updated from time to time. We will notify you of any material changes by posting the new policy on this page with an updated "Last updated" date.