← Back

Privacy Policy

Version 1.0.1. Effective August 4, 2026.

Framework Films, LLC, doing business as clearlabel (“we”, “us”) operates the clearlabel web and mobile application (the “Service”). This policy explains what we collect, who we send it to, how long we keep it, and what you can do about it.

clearlabel collects health information. It does not provide medical advice. Both of those are true at the same time. See the Medical Disclaimer for the second one.

The short version. We collect the food you log, the symptoms you log, and the profile you set, and we run statistics over them to show you patterns in your own data. We do not sell your personal data. Your individual profile is never shared. What you type to Claire, our assistant, is sent to Anthropic to generate a reply. You can export everything we hold or delete your account from Settings, at any time.

1. What we collect

Information you give us.

  • Food and drink logs. Meals, products scanned, ingredients, portions, timestamps, and any notes you add.
  • Symptom logs. Symptoms you select, severity, when you felt them, and any notes you add.
  • Your profile. Dietary preferences, sensitivities and their severity, diagnosed conditions you choose to enter, allergies, and demographics you choose to provide.
  • Context you log. Medications, supplements, alcohol, and similar entries you add so the analysis can account for them.
  • Conversations with Claire. Everything you type or say to the assistant.
  • Photos. Product labels, dish photos, and screenshots you upload.
  • Account information. Your email address and the sign-in method you chose.

Some of this is data concerning health, which is a special category of personal data under the UK and EU GDPR and consumer health data under several US state laws. We process it on the basis of your consent, which you give at signup and can withdraw at any time by deleting your account.

Information we generate. Clear Scores, personal scores, statistical correlations between ingredients and your symptoms, forecasts, and the tier labels attached to them. These are derived from your logs.

Information collected automatically. Device class (mobile or desktop), browser and operating system class, pages viewed, and error diagnostics. We do not track your precise location. Where you allow it, we record the approximate region of a scan.

2. Voice

If you speak to Claire, the recording is sent over an encrypted Cloudflare tunnel to a server we operate and control ourselves, transcribed there by a speech model running on that machine, and discarded. It is not sent to a third-party transcription service. We do not store the audio. We keep the transcript, because it is the message you sent and it appears in your conversation history. Spoken replies from Claire are synthesised on that same server on request and streamed to you; they are not stored either. See section 4 for what happens to the transcript afterwards.

3. What we do with it

  • Score products against your profile.
  • Find statistical associations between what you log and how you report feeling, and show them to you.
  • Generate replies from Claire.
  • Send notifications you have turned on.
  • Operate, secure, and debug the Service.
  • Improve the Service, including our scoring and analysis, using your data in aggregate.

We do not use your health data for advertising, and we do not sell it. We do not sell any personal data, to anyone, including data brokers.

4. Who we send it to

We use the following processors. They may only use your data to provide their service to us.

Processors that receive health-related data:

Anthropic
The full text of your conversations with Claire, including symptoms, foods, and notes, and any photos you send it
Railway
All API traffic, which includes your logs in transit
Timescale Cloud
Everything we store, at rest
Vercel
Web hosting, and the photos you upload
Cloudflare (tunnel)
Voice recordings and spoken replies, in transit only. Cloudflare carries the connection between the app and our own speech server; it is the network path, not the destination, and the audio is not stored there

Processors that do not receive health data:

Clerk
Your email address and sign-in method
Stripe
Billing details, on the checkout page only
Sentry
Error diagnostics. Request bodies, cookies, headers, and query strings are stripped before an error is sent
PostHog
Product events, such as "completed onboarding". No free text and no health data
Cloudflare (Turnstile)
Bot protection on sign-in. A separate service from the Cloudflare tunnel listed above, which is why Cloudflare appears in both lists
Open Food Facts
Barcodes we look up. Photos you choose to contribute

About Anthropic specifically. Claire is powered by a third-party large language model. What you type to Claire is transmitted to Anthropic to generate a reply. Anthropic's commercial API terms state that inputs and outputs are not used to train its models. We have not negotiated a zero-retention agreement beyond those standard terms. If you would rather a third party did not receive something, do not type it into Claire; the rest of the app works without it.

About voice specifically. When you speak to Claire, the recording is sent over an encrypted Cloudflare tunnel to a server that we operate and control ourselves. It is transcribed there by a speech model running on that machine, and the recording is discarded once it has been transcribed. It is not sent to a third-party transcription service, and no such service is configured in the product. Claire's spoken reply is synthesised on that same server. The transcribed text is then handled exactly like anything else you type to Claire, which means it does go to Anthropic to generate a reply, as described above.

Aggregated data. We may share aggregated or anonymised patterns, which cannot reasonably be used to identify you, with research and institutional partners. Your individual profile is not shared. You control this in Settings, under community data sharing.

Legal requests. We may disclose information where we are legally required to. We will narrow or resist requests we consider overbroad, and we will tell you about a request for your data where we are permitted to.

5. How long we keep it

  • Your logs and profile: for as long as your account exists.
  • Conversations with Claire: for as long as your account exists, or until you delete them.
  • Voice recordings: not retained.
  • Error diagnostics: 90 days.
  • Backups: purged within 90 days of deletion from our live systems.

After you delete your account we do not keep your logs. We may retain a minimal record of the deletion itself, and information we are required to keep for tax, accounting, or legal reasons.

6. Your choices

Export. Settings, then Privacy, then Download my data. You get one JSON file containing every record we hold for your profile: food logs, symptom history, conversations, scans, settings, and derived statistics.

Delete. Settings, then Privacy, then Delete my account. Deletion begins immediately. Your records are removed from our live systems as part of that request, and from backups within 90 days. It cannot be undone, and once it has run we cannot recover your data or provide you with a copy. Export first if you want one.

Correct, restrict, object. Contact privacy@clearlabel.ai.

Withdraw consent. Deleting your account withdraws your consent to health data processing. You can also turn off community data sharing in Settings at any time without deleting anything.

Notifications and marketing. Turn them off in Settings.

Depending on where you live you may have additional rights, including access, portability, correction, erasure, restriction, objection, and the right to complain to a supervisory authority. We respond to requests within the time limits set by the applicable law. We do not discriminate against you for exercising these rights.

7. Children

The Service is for adults. You must be 18 or older to create an account, and we ask you to confirm this at signup. Accounts for children under 13 exist only as profiles managed by a parent, who provides consent and controls the data. We do not knowingly collect personal information from a child under 13 outside of a managed profile. If you believe we have, contact privacy@clearlabel.ai.

8. Security

Access is authenticated, data is encrypted in transit, and user data is isolated at the database level so one account cannot read another's. Our staff access your data only where it is needed to operate or support the Service. No system is perfectly secure, and we cannot guarantee that a determined attacker will never defeat these measures.

9. Where your data is processed

We are based in the United States and our infrastructure is in the United States. If you use the Service from outside the United States, your information is transferred to and processed in the United States.

We are not currently set up to accept users in the European Economic Area or the United Kingdom, and the Service is not offered to them. If that changes we will put the required transfer safeguards in place first, and we will say so here before we open the Service to those regions.

10. Cookies and local storage

Sign-in uses cookies set by Clerk. The checkout page loads Stripe, which sets two fraud-prevention cookies; no other page loads Stripe. We store your preferences and some draft state in your browser's local storage. We do not use advertising cookies. A full inventory is in our Cookie and Storage Disclosure.

11. Changes

We may update this policy. The version and effective date at the top will change. If a change is material we will notify you in the app or by email before it takes effect.

12. Contact

privacy@clearlabel.ai

Framework Films, LLC, doing business as clearlabel

Washington Health Data