← Clarity
Placeholder — not yet legally binding
This page is structural scaffolding only. It must be reviewed and written by a qualified lawyer before launch — do not publish or rely on it as-is. Bracketed notes mark what each section needs to cover.

Privacy Policy

How we handle the information you share with Clarity — written plainly, and held to the standard we'd want for our own.

Last updated: [DATE] · Effective: [DATE]

1. Who we are

[ TO DRAFT ] Legal entity name, registered address, and the data controller for GDPR purposes. Contact for privacy questions.

2. What data we collect

Clarity collects only what the product needs to work. In scope:

  • Your email address (when you save a free-tool result, enquire, or create an account).
  • Financial inputs you type into the tools and courses (income, spending, net worth, ages, goals).
  • Account + purchase records (which courses you own), via our auth and payment providers.
  • Basic technical/usage data if analytics are enabled (see §7).

[ TO DRAFT ] Confirm the exact fields, and whether any special-category data is ever processed (it should not be).

3. How we use it & lawful basis

[ TO DRAFT ] For each purpose (run the tools/courses, send the newsletter, fulfil purchases, support), state the GDPR lawful basis — consent, contract, or legitimate interest. Make clear financial inputs are used to generate the user's own results, not profiled or sold.

4. Who we share it with

We do not sell your data. We share it only with the processors required to run the product:

  • Supabase — authentication, database, and stored inputs.
  • Anthropic — AI categorisation, extraction, and the North coach.
  • Stripe — payment processing (Stripe receives payment data directly).
  • [Email/newsletter provider — to be added when sending launches].

[ TO DRAFT ] Confirm each sub-processor, its location, and the safeguard for any transfer outside the EEA (e.g. SCCs).

5. How long we keep it (retention)

[ TO DRAFT ] State retention periods per data type, and what happens on account deletion.

6. Your rights

Under GDPR you can request access, correction, deletion, export, restriction, and objection, and withdraw consent at any time.

[ TO DRAFT ] State how to exercise each right, our response timeframe, and the right to complain to a supervisory authority.

7. Cookies & analytics

[ TO DRAFT ] List any cookies/local storage and analytics used (or confirm none beyond what's strictly necessary for auth). If non-essential cookies/analytics are used, a consent mechanism is required.

8. Contact

Privacy questions: [privacy@oliveradan.com].