Clarova LogoClarovaBack to home

Privacy Policy

Last updated: June 10, 2026

1. Introduction

Clarova ("we", "us", "our") is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains what data we collect, why we collect it, how it is stored and processed, and your rights under the EU General Data Protection Regulation (GDPR). This policy applies to all users of the Clarova platform.

2. Data Controller

Clarova is operated from Sweden. For all data protection matters, contact us at admin@clarova.ai.

3. Data We Collect

Account information: your email address, display name, and password (stored as a secure bcrypt hash, never in plain text). If you sign in with Google, we receive your name and email address from your Google profile.

Study content: documents you upload (PDF, DOCX, TXT files), chat conversations with the AI tutor, quiz questions and results, flashcard sets and progress, infographic data, and study activity records.

Usage data: action counts, token consumption, and timestamps used to enforce plan limits and generate your usage statistics.

Payment data: if you subscribe to a paid plan, payment is processed entirely by Stripe. Clarova does not receive, process, or store your credit card number, bank details, or other payment instruments. Stripe handles this data under their own privacy policy.

Technical data: we do not use analytics tools, tracking pixels, or fingerprinting. We do not collect IP addresses, device information, or browsing behavior for profiling purposes.

4. How We Use Your Data

We process your data solely to provide and operate the Clarova platform:

  • To authenticate your account and maintain your session
  • To process and vectorize your uploaded documents for AI-powered study features
  • To generate AI chat responses, quizzes, flashcards, and infographics from your materials
  • To track your study progress, mastery scores, and learning activity
  • To enforce usage limits according to your subscription plan
  • To process subscription payments through Stripe
  • To communicate with you about your account or important service changes

We do not use your data for advertising, behavioral profiling, or any purpose unrelated to providing the service.

5. Legal Basis for Processing (GDPR Article 6)

We process your personal data based on:

  • Contract performance: processing necessary to provide the service you signed up for
  • Legitimate interest: maintaining platform security and preventing abuse
  • Consent: which you provide by creating an account and agreeing to these terms

6. Where Your Data Is Stored

All your data — database records, uploaded files, and vector embeddings — is stored on a self-hosted server located within the European Union. Clarova does not use third-party cloud storage services (such as AWS, Google Cloud, or Azure) for storing your personal data or documents.

7. Third-Party Services

To provide AI-powered study features, Clarova sends small segments of your documents (text chunks, not complete files) and your questions to the following third-party services:

OpenAI: receives text chunks from your documents for the purpose of generating vector embeddings (numerical representations used for search). OpenAI's data processing terms apply.

DeepSeek via OpenRouter: receives text chunks and your questions for the purpose of generating AI responses, quizzes, flashcards, and infographic content. OpenRouter's and DeepSeek's data processing terms apply.

Stripe: processes your subscription payments. Stripe receives your email address and payment details. Stripe's privacy policy applies.

Google: only if you choose to sign in with Google. Google provides your name and email for authentication purposes only.

Important: these third-party AI services may process data on servers located outside the European Union. Clarova transmits only text segments and questions — never your complete documents, personal profile information, account credentials, or payment details.

8. Cookies and Authentication

Clarova uses a JSON Web Token (JWT) stored in your browser's local storage to maintain your authenticated session. This is a functional authentication mechanism, not a tracking technology. Clarova does not use advertising cookies, analytics cookies, social media cookies, or any third-party tracking technologies. No cookie consent banner is required because Clarova does not use cookies as defined under the ePrivacy Directive.

9. Data Sharing

Clarova does not sell, rent, trade, or share your personal data with third parties for marketing, advertising, or data brokerage purposes — under any circumstances. Your data is shared only with the third-party services listed in section 7, and only to the extent necessary to provide the core functionality of the platform.

10. Your Rights Under GDPR

As a user, you have the following rights under the GDPR:

  • Right of access: request a copy of all personal data we hold about you
  • Right to erasure: request permanent deletion of your account and all associated data
  • Right to rectification: correct any inaccurate personal information in your profile
  • Right to data portability: request your personal data in a structured, machine-readable format
  • Right to restrict processing: request that we limit how we use your data
  • Right to withdraw consent: you may stop using the platform and request deletion at any time
  • Right to lodge a complaint: with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se if you believe your data protection rights have been violated

To exercise any of these rights, contact us at admin@clarova.ai. We will respond to your request within 30 days as required by GDPR.

11. Data Retention and Deletion

Your data is retained for as long as your account remains active. When you request account deletion or when your account is terminated, all associated data is permanently removed from our systems. This includes: your profile and account information, all uploaded documents and their processed text, all vector embeddings in our search database, all chat conversations, quiz results, flashcard sets, infographic data, study progress records, and usage logs. Deletion is irreversible.

12. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encrypted password storage, secure authentication tokens, encrypted API key storage, and access controls limiting data access to authorized processes only.

13. Age Requirement

Clarova requires users to be at least 16 years of age, in compliance with the digital consent age under GDPR as applied in Sweden. We do not knowingly collect or process personal data from individuals under the age of 16. If we become aware that a user is under 16, their account and all associated data will be promptly deleted.

14. International Data Transfers

While your primary data is stored within the EU, text segments of your documents are transmitted to AI service providers (OpenAI, DeepSeek) that may process data in the United States or other countries outside the EU. These transfers are necessary to provide the core AI features of the platform. We rely on the service providers' own data processing agreements and safeguards for these transfers.

15. Changes to This Policy

Clarova may update this Privacy Policy to reflect changes in our practices or applicable law. Material changes will be communicated to registered users. Your continued use of the platform after changes are published constitutes acceptance of the updated policy.

16. Contact

For any privacy-related questions, concerns, or to exercise your GDPR rights, contact: admin@clarova.ai. Data Controller: Clarova, Location: Sweden.