Privacy Policy
What happens to the chat export you upload, who processes it, how long we keep it, and how to delete it
Who is responsible for your data
Clark Reads is operated by one person, not a company. The details below are the ones a data protection authority would ask for.
- Data controller
- [operator name — confirm before launch]
- Contact email
- support@clarkread.com
- Country or region
- [country or region — confirm before launch]
- Payment processing
- Stripe, as an independent controller for payment data. We never see your card details.
- Report generation
- [primary model provider — name it before launch] (primary) and [fallback model provider — name it before launch] (fallback)
- Email delivery
- [email provider — name it before launch]
The short version
You upload a chat export so that a report can be written from it. We keep the text for the retention window below and then delete it, we never train models on it, we never sell it, and you can delete a report — or your whole account — yourself at any time. The rest of this page is the detail behind those four sentences.
What we collect
The conversation text. When you upload a WhatsApp export, the file is unzipped in your browser and photos, videos and voice notes are removed before anything is transmitted. What reaches us is the text of the conversation. The same applies to a plain-text iMessage export.
What you tell us about it. The chat type, the source platform, the report language, the participant names you confirm, and which participant is you.
Your email address. Collected in the last step of the wizard, used to deliver the report and to contact you about it. There is no password to store.
Payment data. If you unlock a report, the payment is processed by Stripe. Stripe is an independent controller for that data; we receive the outcome of the payment and an identifier, never your card number.
Technical data. Ordinary server logs, as on any website: IP address, user agent, timestamps.
Why we process it
Each kind of data is used for one purpose, and the legal basis for it:
| Data | Purpose | Legal basis |
|---|---|---|
| Conversation text | Writing the report you asked for | Performance of a contract |
| Email address | Delivering the report, contacting you about it | Performance of a contract |
| Payment data | Taking the payment, keeping records for tax law | Contract, and legal obligation |
| Technical logs | Keeping the service secure and working | Legitimate interests |
We do not use your data for profiling, advertising, or any purpose other than the ones in this table. If we need it for a new purpose, this page changes first.
Uploading happens before you sign up
The upload step comes before the step that asks for your email address. The text of your conversation therefore reaches our servers while you are still anonymous, whether or not you go on to create an account and whether or not you ever pay.
Your browser holds a random anonymous token that identifies that upload. If you never finish the wizard, the conversation is deleted on the schedule below and the token becomes unusable. Finish the wizard in one browser: the token lives in that browser rather than on an account, so another device cannot pick up where you left off.
Who the text is sent to
The report is written by a third-party AI model provider. We name our providers instead of calling them "third-party service providers" — the names are in the disclosure block at the top of this page.
Model providers. The text of your conversation is sent to them so that the report can be written. Under contract they process it only for that purpose, only for the time needed, and may not train on it.
Email delivery. Transactional email is sent through the provider named above, solely to deliver messages to you.
Payments. Stripe processes the payment as an independent controller; Stripe's own privacy policy governs the payment data it holds.
Infrastructure. The service runs on Cloudflare Workers, with Cloudflare D1 for the database, R2 for object storage and KV for cache.
Some of these providers may process data outside your country or region. Where that happens, transfers rely on the safeguards required by applicable law — for EU users, the European Commission's standard contractual clauses.
How long we keep it
The cleanup runs once an hour, so every window below is closed within the hour that follows it.
| Data | Retention |
|---|---|
| A conversation with no report ordered | Deleted 48 hours after upload, record included |
| A conversation whose report was never unlocked | Original text deleted 48 hours after upload; the report and its free preview stay |
| A conversation whose report was unlocked | Original text deleted 7 days after the report was written |
| Reports | Kept until you delete them |
| Payment records | Kept as long as tax rules and Stripe require |
| Technical and security logs | Deleted after 90 days unless a law or an incident requires us to keep them longer |
| Your account | Deleted in one click, with everything in it |
Deleting a report, or your whole account, is always available to you in the app. A conversation that has no report yet is discarded when you upload a different file in its place; if you want one removed sooner than that, write to support@clarkread.com and we delete it.
What we never do
- We do not use your conversation to train AI models, ours or anyone else's.
- We do not sell your data, and we do not share it for advertising.
- We do not use your conversation as marketing material or as a sample report. Sample reports are written from invented conversations.
- We do not read your conversation by hand, except to answer a support request you sent us.
How we protect it
Your conversation travels to us over an encrypted connection and is encrypted where it is stored. Access to it is limited to what is needed to generate and deliver your report, and the original text is deleted automatically on the schedule above.
No online service can promise absolute security, and we do not claim to. What we can promise is that the exposure is small by design: the text is anonymous while you are in the wizard, it is deleted on a schedule that runs hourly, and no human reads it unless you ask us to.
Your rights
Write to support@clarkread.com to access, correct, export, restrict or delete the data we hold about you, or to object to a specific processing purpose. You can also delete individual reports, and your whole account, inside the app without contacting us.
If you are in the EU, the UK or another jurisdiction with an equivalent regime, you have the right to lodge a complaint with your supervisory authority — for EU users, the data protection authority in your country of residence. We answer data protection requests within 30 days.
Cookies and analytics
The service needs one cookie: the session cookie that holds your anonymous upload, and then your account session once you sign in. Nothing else is required for it to work.
If a measurement ID was configured when the site was deployed, we also load Google Analytics 4 to count visits and see which pages are used. The full list, including the other analytics providers that can be switched on this way and the support chat widget, is in the Cookie Policy. None of them are given your conversation: they see page views and button clicks, not chat text or report content.
Changes to this policy
If we change how data is handled we update this page and change the date above. Continuing to use the service after a change means you accept the updated version. Material changes are announced by email to registered users.
Contact
support@clarkread.com — the operator's name and country are stated in the disclosure block at the top of this page.