Privacy Policy
Last updated: 12 September 2026
This policy explains what Clairop collects, why, who else sees it, and how to get rid of it. Clairop is operated by Pavado Technologies Inc., a company incorporated in the Province of Ontario, Canada.
Clairop handles health information, which is sensitive by definition. Symptoms, bowel movements, medications and the fact of your diagnosis are all health data, and this policy treats them that way throughout.
The short version
- Your log entries are stored against your account so they survive a new phone. Only you can read them.
- Meal photos never leave your device except at the moment you ask for one to be analysed, and they are never stored on our servers.
- When a photo or description is sent for food identification, nothing identifying you goes with it: no name, no email, no account ID, and none of your symptom history.
- Health values never enter our analytics. We record that a movement was logged, never which type. We record that a symptom entry was saved, never the score.
- We do not sell your data, and we do not advertise.
- You can export or permanently delete everything, from inside the app.
What we collect
Information you give us
- Your account.An email address, via Sign in with Apple or Sign in with Google. If you use Apple's private relay, we only ever see the relay address.
- Your health profile. Your condition, year of diagnosis, surgical history, current diet approach, medications, suspected triggers and your usual daily baseline.
- Your log entries. Bowel movements including Bristol type, urgency, blood, mucus and whether you were woken at night; symptom severities; meals and their ingredients; medication doses taken and missed; and any lab results you enter.
- Meal photos,if you take them. These are stored in your device's own storage.
Information we generate
- Activity scores and trigger analysis, calculated from the entries above.
- Usage counters, so per-day limits can be enforced.
- Product analytics:event names such as “stool_logged” with a timestamp and app version. Never the value. Server-side this is an allowlist: an event name that is not on it is discarded rather than stored.
- Error shapes,such as “the network timed out”. Never the content of an error, which could carry your data.
What we never collect
- Payment card details. Apple processes payments; we never see a card.
- Location, contacts, browsing history, or any advertising identifier.
- Audio. Voice logging transcribes speech on your device; the text is sent, the recording is not.
- Crash reports through any third-party SDK. We do not use one.
Why we are allowed to hold it
Where the UK GDPR or EU GDPR applies, health data is a special category and needs a stronger basis than ordinary data. Ours is your explicit consent under Article 9(2)(a), given when you create an account and choose to record entries. The underlying lawful basis for processing is performance of our contract with you under Article 6(1)(b), and our legitimate interest in keeping the service working and secure under Article 6(1)(f).
Where Canadian law applies, we rely on your express consent under PIPEDA, which is the standard PIPEDA expects for sensitive information.
You can withdraw consent at any time by deleting your account in the app. That is not a request we have to action; it happens immediately.
Who else receives it
These are every third party that receives any data, what they get, and why. This list mirrors what the app actually does. If it ever drifts from reality, the App Store privacy labels drift with it, so we keep it accurate.
| Who | What they receive | Why | Where |
|---|---|---|---|
| Anthropic (Claude) | Meal photos or spoken descriptions you choose to analyse. No name, email, account ID or symptom history travels with them. | Identifies the foods in a meal | United States |
| Open Food Facts | A barcode number, with nothing attached to it | Looks up the product and its ingredient list | France / European Union |
| Supabase | Your account identifier and your log entries | Hosts our database and backend | United States |
| Apple | Purchase and subscription data; your email or a private relay address if you use Sign in with Apple | Processes payments and sign-in | United States |
| Your email address and basic profile, only if you choose Sign in with Google | Signs you in | United States |
We do not sell personal information, and we do not share it for behavioural advertising. Under the CCPA and similar US state laws, we have not sold or shared personal information in the preceding twelve months.
About the AI processing
Food identification from a photo or a spoken description is performed by Anthropic's Claude models. The request contains the image or the text and nothing else. It does not contain your name, your email, your account identifier, your condition or any of your log entries, so the model has no way to associate a meal with a person.
Barcode scanning does not involve an AI service at all. A barcode number goes to Open Food Facts, and nothing is attached to it.
How long we keep it
- Log entries and your profile: until you delete them. We do not expire your health history on a timer; it is the thing you came here to keep.
- Analytics events and usage counters: deleted automatically after 90 days by a scheduled job.
- Meal photos: on your device only, until you delete them or remove the app.
- Waitlist emails: until you ask us to remove yours, or the launch email has been sent.
Your rights
Wherever you live, you can access, correct, export or delete your data. In the app: Profile → Delete Account erases your account and every entry, cached analysis, entitlement record and analytics row we hold. Profile → Reset all data clears this device and keeps the account.
If you are in the UK, EU, Canada or a US state with a comprehensive privacy law, you also have the right to object to or restrict processing, to data portability, and to complain to your regulator: the ICO in the UK, your national supervisory authority in the EU, or the Office of the Privacy Commissioner of Canada.
Email support@team.clairop.com and we will respond within 30 days.
Security
Traffic is encrypted in transit. Every backend endpoint verifies your identity before doing anything, and every database table enforces row-level security so one account cannot read another's rows. Sign-in tokens are held in the iOS Keychain.
One specific protection worth naming: if you sign in on a device where a different account was previously used, Clairopwipes the local data first. On a shared, resold or handed-down phone, that stops one person's bowel history being visible to the next.
No system is perfectly secure. If we ever suffer a breach affecting your health data, we will notify you and the relevant regulator as the law requires.
Children
Clairop is not intended for children. You must be at least 16 to create an account. We do not knowingly collect information from anyone younger; if we learn that we have, we delete it.
International transfers
Our servers and most of our processors are in the United States. If you use Clairop from the UK or the EEA, your data is transferred there under the UK Addendum and the EU Standard Contractual Clauses respectively.
Changes
If we change this policy in a way that materially affects how your health data is handled, we will tell you in the app before it takes effect rather than quietly updating the date at the top.
Contact
Pavado Technologies Inc.
Province of Ontario, Canada
support@team.clairop.com