Privacy Policy

Last updated: July 23, 2026

Clara helps licensed clinicians capture, transcribe, and organize their therapy sessions. This Privacy Policy explains how we handle personal information when you use Clara and its related services (collectively, the "Services").

Data Controller

For therapist account data and any other personal data for which Clara acts as a controller, the data controller is LOW TIDE STUDIO, SOCIEDAD LIMITADA, with registered office at Calle Bassols, 17, 1, 08026 Barcelona, Barcelona, Spain, and CIF/NIF B26920223. For privacy questions or to exercise your data protection rights, you can contact us at privacy@heyclara.app.

Data Protection Contact

You can contact Clara's Data Protection Officer at privacy@heyclara.app.

Roles and Lawful Bases

Clara has different GDPR roles depending on the type of data involved. For therapist account and business-relationship data, Clara acts as a data controller. For patient data that clinicians record, upload, or generate through the Services, the clinician remains the data controller and Clara acts as a data processor under the Data Processing Agreement.

  • Therapist and business-relationship data: For therapist account, authentication, billing, support, and service-security data, Clara relies primarily on performance of a contract under Article 6(1)(b) GDPR. Where required, Clara may also process certain data to comply with legal obligations under Article 6(1)(c) and to pursue legitimate interests under Article 6(1)(f), such as keeping the Services secure, reliable, and protected against abuse.
  • Patient data processed on behalf of clinicians: When Clara records sessions, stores patient information, generates transcripts, or creates clinical documentation for a clinician, Clara processes that data only on the clinician's documented instructions and under the Data Processing Agreement. The clinician is responsible for identifying the applicable legal basis under Article 6 GDPR and, for special-category health data, the applicable condition under Article 9 GDPR, including where relevant explicit consent under Article 9(2)(a) or the provision of health care under Article 9(2)(h).

Information We Collect

  • Account and authentication data: Contact details, credentials, access tokens, and security settings required to create and maintain your Clara account.
  • Patient data: Information you choose to store in Clara about the patients you work with, including demographics, treatment history, and appointment metadata. Patient consent data: responses entered by patients or guardians, selected consent statements, notes, typed signatures, signature dates, consent status and timestamps, and consent PDF documents generated from the submission.
  • Session recordings and transcripts: Audio captured through Clara's web recorder, plus derived artifacts such as transcripts, notes, and AI summaries. Recordings only begin when you explicitly start them and end when you stop them or leave the recording flow.
  • Browser-local recovery data: If a browser recording is interrupted, Clara may temporarily store audio chunks and minimal recovery metadata in IndexedDB on the clinician's device. This metadata can include the session ID, patient ID or patient name, session type, scheduled session ID, and timing information needed to recover the recording.
  • Clara subscription and billing data: When you choose a paid plan, Stripe collects and processes the information needed for checkout, VAT or tax ID collection, recurring billing, invoices, payment recovery, and customer portal access. Clara stores related subscription records such as your plan, billing cycle, trial and period dates, payment status, Stripe customer and subscription identifiers, checkout session and price identifiers, and referral or billing-credit records. Clara does not store full card numbers or payment method details.
  • Usage, diagnostics, and analytics data: Device information, browser events, recorder diagnostics, limited product interaction data, and technical identifiers linked to the account, recording, session, or patient context used for diagnostics help us secure the platform, troubleshoot issues, understand feature adoption, and support the web recorder. Clara uses PostHog for this limited analytics and troubleshooting telemetry. During browser recordings, Clara may also use limited session replay for troubleshooting. Replay is configured so sensitive inputs are masked and recording surfaces that may contain patient details or notes are blocked from capture, so that sensitive content cannot be read in replay. We do not track unrelated browsing activity.
  • Google Calendar data: If you connect Google Calendar, we collect selected calendar IDs, display names, primary or access-role status, event dates, times, titles, attendee email addresses, and technical sync metadata such as per-calendar sync tokens and webhook identifiers or expiration timestamps. This Google User Data is used exclusively to sync your appointments with the Clara dashboard and maintain multi-calendar sync.

How We Use Information

  • Authenticate clinicians and authorize platform access.
  • Provide recording, transcription, patient management, and clinical documentation capabilities.
  • Collect, validate, generate, store, and retrieve consent evidence on a clinician's documented instructions.
  • Support recovery of interrupted browser recordings from the clinician's device.
  • Sync selected Google calendars and related metadata at your request.
  • Create and manage Clara subscriptions, trials, invoices, VAT or tax handling, payment recovery, cancellation, and referral billing credits through Stripe.
  • Deliver customer support, product updates, and security notifications.
  • Maintain the safety, integrity, and availability of our infrastructure.
  • Operate limited PostHog analytics, recorder diagnostics, technical telemetry, and troubleshooting workflows, including session replay during browser recordings.
  • Comply with legal obligations and enforce our agreements.

How We Share Information

We never sell personal information. We share data only with:

  • Service providers that host, store, or process data on our behalf, including Microsoft Azure for infrastructure, database, and file storage; Stripe for Clara subscription checkout, VAT or tax ID collection, payment processing, invoices, and customer portal services; PostHog for limited analytics, recorder diagnostics, related technical identifiers, and session replay during browser recordings; and Resend. Resend provides transactional delivery for consent, invoice, account, and clinician-notification email. Stripe is used for Clara subscription billing only and not for patient payments or clinical records. If you want to object to analytics or troubleshooting processing, contact us at privacy@heyclara.app. These partners are contractually obligated to safeguard the information they handle.
  • Regulators or law enforcement when required by applicable law or to protect rights, safety, or property.

Data Retention

We apply the following retention periods:

  • Server-side session audio: 14 days after processing, then deleted.
  • Browser-local recovery copies: Interrupted browser-recording audio chunks and related recovery metadata stored in IndexedDB on the clinician's device are kept for up to 7 days, or deleted sooner if the recording is recovered or the local copy is manually removed.
  • Transcripts, clinical notes, and patient records stored in Clara: For the duration of the account and up to 30 days after account deletion or closure, unless a longer retention period is legally required.
  • Therapist account data: Up to 30 days after account closure, except where we must retain limited information for legal, tax, security, or billing reasons.
  • Clara subscription and payment records: Subscription records, invoices, tax records, payment status, billing credits, and Stripe identifiers are retained while your account is active and for as long as needed for tax, accounting, legal, security, billing-dispute, payment-recovery, and fraud-prevention purposes. Payment method data is managed by Stripe.
  • Recorder diagnostic logs and analytics data: Recorder logs stored in Clara systems and related PostHog analytics, session replay, and troubleshooting data are retained for up to 30 days.
  • Consent evidence: Consent status and timestamps, submitted responses and signatures, and generated consent documents are retained for the duration of the clinician's processing relationship and then for five years when the clinician instructs Clara to preserve proof of lawful basis, unless a longer legal hold applies.
  • Google Calendar connection data: Selected calendar configuration and technical sync metadata are retained while Google Calendar remains connected and are deleted when you disconnect the integration or delete your account.

Therapists in Spain may be subject to separate legal obligations to retain clinical records for at least 5 years under Ley 41/2002. Clara's account retention settings do not replace that professional obligation.

Security

We apply technical, administrative, and physical safeguards such as encryption in transit and at rest, role-based access controls, logging, and regular reviews of our infrastructure. No system is completely secure, so we encourage users to keep credentials confidential.

Your Data Protection Rights

  • Access (Art. 15 GDPR): you can request confirmation of whether we process your personal data and receive a copy of that data together with related information about the processing.
  • Rectification (Art. 16 GDPR): you can request correction of inaccurate personal data and completion of incomplete personal data.
  • Erasure (Art. 17 GDPR): you can request deletion of your personal data where the GDPR permits it.
  • Restriction (Art. 18 GDPR): you can request that we limit processing of your personal data in certain circumstances.
  • Portability (Art. 20 GDPR): you can request a copy of the personal data you have provided to us in a structured, commonly used, machine-readable format and, where technically feasible, ask us to transmit it to another controller.
  • Objection (Art. 21 GDPR): you can object to certain processing, particularly where we rely on legitimate interests as the legal basis, including our limited analytics and troubleshooting telemetry, by contacting privacy@heyclara.app.
  • Automated decision-making (Art. 22 GDPR): you can request information about decisions based solely on automated processing and, where applicable, not be subject to them if they produce legal effects or similarly significant effects.

Complaints and Supervisory Authority

If you believe that Clara's processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es.

International Use

Clara is operated from the European Union. Our primary application infrastructure and service data are hosted within the EU. If a service provider processes limited support, analytics, or troubleshooting data outside the EU/EEA, we rely on the contractual and legal safeguards required by applicable data protection law.

Contact Us

If you have questions about this Privacy Policy or how Clara handles personal information, please contact us at privacy@heyclara.app.