Data & permissions

Your data, in plain terms.

Where your work lives, what the assistant can see and do, and what we deliberately never claim. The same answers we put in every proposal, published.

Two layers, kept separate.

Your working content stays in the systems you choose: local files, Google Workspace, Notion, or Claro Studio. The assistant reads only through connections you approve, and sends the relevant task context to the AI provider you selected.

Claro Studio holds what you build in it or deliberately bring into it: tasks, projects, records, workspace structure and activity. Claro is responsible for Claro Studio and for the assistant setup, connections and guardrails we deliver. You and your third-party providers remain responsible for your source systems, their permissions and their own terms.

What the assistant can see and do.

The assistant runs on your machines, in your own accounts. With the Claro safety hooks installed, email is draft-only and destructive actions are blocked or approval-gated; it never sends, pays, or signs on its own. Scheduled routines prepare work; nothing leaves without your approval.

We do not rely on instructions alone. Instructions help the assistant recognize risk, hard controls block dangerous actions, least-privilege access limits the blast radius, and logging plus recovery controls help us contain and repair failures.

The AI providers.

We build on the best agentic AI tools available today, currently Claude Code and Codex, running on frontier models from Anthropic and OpenAI. On Anthropic and OpenAI business and API plans, your content is not used to train models. Studio search uses OpenAI embeddings; indexed content is not used for training by default.

Every proposal names the exact runtime and account type for your setup, and includes a data-flow table filled in for the tools you actually chose.

Hosting and encryption.

Studio compute runs in the US; the database is hosted by Supabase in West EU (Ireland). The underlying disks and scheduled backups are encrypted at rest using AES-256. This is infrastructure-level encryption managed by Supabase, not end-to-end or field-level encryption. If you need EU-only processing, tell us and we scope it together.

Who can access what.

Access is workspace-based with logged activity. Infrastructure administration is separate from workspace access and restricted to named administrators at Claro.

Export and deletion.

You can export your data as a ZIP at any time. Account deletion has a 7-day hold, then soft-deleted data is retained up to 90 days before purge; encrypted backups are retained 30 days. Cancelling a subscription is not the same as deleting data, and we tell you so rather than letting you assume otherwise.

Where content ends up.

ComponentWhat it readsWhere content ends upAccess
Assistant runtime (named per proposal)Task context sent as the promptProcessed to respond; no separate Claro storeThe model provider, per its terms
Studio memory searchContent indexed into Studio memorySearch vectors in the Studio databaseSame as the Studio database
Claro Studio appWhat you create or bring into StudioStudio database (Supabase, West EU)Workspace members; infrastructure administration separate
Connector keys and OAuth tokensNothing (credentials only)Encrypted or hashed credential storeThe storing system; revocable by you
Your own accountsRead via connections you approveStay in your systemsYou; the assistant works under human review
Your computerLocal read and write under your loginYour machineYou

What we never claim.

We would rather under-claim than overpromise, so for the record: we do not claim full-EU hosting. We do not claim SOC 2 or ISO certification for Claro; our infrastructure providers’ certifications do not transfer to us. We do not claim zero retention, and we do not claim end-to-end encryption. And the honest residual risk: protections depend on the hooks and permission rules installed for each person and runtime, and prompt injection is reduced, not eliminated.

For your IT and security review.

Every Accelerator proposal ships with a half-page security sheet and a data-flow table filled in for your chosen tools. IT and security reviewers can request our security whitepaper, and setups with special requirements, such as EU-only processing, DPIAs or vendor questionnaires, are scoped together with you. Write to hello@heyclaro.ai.