Privacy Policy
Last updated: August 11, 2026
The short version
Clario finds school, sports and family events in the emails you forward to your private Clario address, and puts them on your calendar. That is how Clario works for everyone by default — it does not read your mailbox. A small invited group is separately testing a direct Gmail connection; if that's you, you connected it yourself and can disconnect it at any time. We never sell your information and we never use it for ads. Forwarded emails are kept for 90 days so you can look back at where an event came from, then deleted automatically. You can delete your account at any time.
What we collect
- Your email address and display name (from sign-in)
- Family member names you add (including children's first names)
- Calendar events and to-dos extracted from the emails you forward — or, for testers with a connected inbox, from Gmail (titles, locations, notes, and to-do text are encrypted at rest)
- OAuth tokens, only for testers who have connected a Gmail account (encrypted at rest)
- Basic usage info such as last sign-in time and when we last processed an email for you
- The content of emails you forward to your Clario address, encrypted, kept for 90 days and then deleted automatically
We do not collect your contacts, and we do not copy your mailbox. By default Clario receives only the individual messages you forward. We keep those messages, encrypted, for 90 days so you can see where an event came from, along with the event details we pull out of them.
How we use your email
Emails you forward. When you forward an email to your private Clario address, we send the parts we need — the subject, the message text, and any attached file such as a photographed school flyer or a PDF calendar or handbook — to Anthropic Claude, which finds the events, dates and locations. We keep the event details it finds, and we keep the forwarded message itself, encrypted, for 90 days so you can tell where an event came from. We do not keep the attachments themselves: they are read once and discarded.
Connected Gmail (invited testers only). Clario is testing a direct Gmail connection with a small invited group. It is off for everyone else and cannot be switched on from inside the app. If you have connected Gmail, Clario looks at recent messages and sends the same parts to Anthropic. We do not copy your mailbox; the original messages stay on Google's servers.
Anthropic only processes this to give you that feature. It does not keep your email and does not use it to train its models.
Where the Gmail connection is enabled, Clario asks Google for read-only access — the https://www.googleapis.com/auth/gmail.readonly permission. Read-only means exactly that: Clario cannot send, delete or change anything in your email, and it cannot write to your account.
Google Limited Use disclosure: Clario's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Gmail data for advertising, do not sell it, and do not allow humans to read it except with your explicit consent (see below), where necessary for security, or to comply with applicable law.
Support access: If you choose to share data with our support team to help troubleshoot a problem, you must explicitly opt in first. Support access is limited to the data you choose to share, is logged, and can be revoked at any time. We never access your content for support purposes without this consent.
Sub-processors
We use the following service providers to operate Clario:
- Anthropic — reads email text and attached files (flyer photos, PDF calendars and handbooks) to find events. Anthropic does not retain or train on data sent through their API.
- Supabase — Database, authentication, and file hosting. SOC 2 Type II certified.
- Vercel — Web application hosting and CDN.
- Google — Gmail data source, for testers who have connected an inbox. Clario does not use Google as a sign-in method.
Data retention
- Account data: kept while your account is active
- Email scan logs: 90 days, then automatically deleted
- Emails you forward to Clario: 90 days, then permanently deleted
- Forwarded mail held for review — sent from an address you haven't approved yet: 90 days, then permanently deleted
- Parsed event metadata: 180 days, then automatically deleted
- Deleted events: permanently removed 30 days after you delete them
- Usage analytics: 12 months, then automatically deleted
- OAuth tokens: deleted when you disconnect a connected inbox or close your account
- Account deletion: your data is removed from our live systems immediately. Encrypted backups are retained for up to 7 days as part of normal disaster recovery, after which those copies expire too.
Your rights
You can see, correct or delete your information at any time from Settings inside the app. Deleting your account also disconnects any connected inbox and tells Google to cancel Clario's access, and it stops your forwarding address working — mail sent to it afterwards is discarded without being stored. If you want a copy of your data, email privacy@clarioaiplanner.com and we will send it to you within 30 days.
California residents (CCPA/CPRA): You have the right to know, delete, correct, and opt out of the sale of personal information. We do not sell personal information.
EU/UK residents (GDPR): You have the rights to access, rectification, erasure, restriction, portability, and objection. Our legal basis for processing is your consent and contract performance.
Children's information
Clario is intended for adults managing family schedules. We store only the first names of children, supplied by a parent or guardian, for the purpose of organizing the family calendar. We do not knowingly collect any other information from or about children under 13.
If we learn that we have collected personal information from a child under 13 other than as described above, we will delete it promptly. If you believe a child has provided us information directly, contact privacy@clarioaiplanner.com.
Security
OAuth tokens are encrypted with AES-256-GCM before being stored. The sensitive content we extract — event titles, locations, notes, and to-do text — is additionally encrypted at rest with a key unique to your family. We can decrypt it only on our servers, and our team accesses your content only with your explicit, logged consent — for example when you ask support for help. All traffic uses TLS 1.2 or higher, and database access is restricted by row-level security policies. Read more on our Security page.
Changes to this policy
If we make material changes, we will notify connected users by email at least 14 days before the changes take effect.
Contact
Clario is operated by The Clario Group LLC, the data controller responsible for your information. The fastest way to reach us is by email at the addresses below.
Privacy questions: privacy@clarioaiplanner.com
Security concerns: security@clarioaiplanner.com
General support: support@clarioaiplanner.com