Privacy Policy
How Clairo Contracts collects, uses, shares, and protects personal information
Effective date: July 24, 2026
Last updated: July 24, 2026
Version: 1.0
Summary. Clairo Contracts is a contract-workflow platform for businesses. We handle two kinds of information: (1) account and billing data about the people who use Clairo, for which we are the responsible party; and (2) the contents of your contracts, documents, and connected email mailboxes — which may include information about your clients and counterparties — which we process on your behalf as your service provider. We do not sell or share personal information for cross-context behavioral advertising, we do not use your mailbox or contract content to train third-party AI models, and our use of Google and Microsoft mailbox data follows those providers’ API data-use policies, including Google’s Limited Use requirements.
1. Introduction and Scope
1.1 About this Policy. This Privacy Policy explains how [Clairo, Inc.] ("Clairo,""we,""us," or "our") handles personal information in connection with the Clairo Contracts platform, our websites at clairocontracts.com, and related services (together, the "Platform"). It should be read together with our Terms of Use and any Data Processing Addendum ("DPA"). This Policy addresses United States privacy law.
1.2 Who this applies to. This Policy applies to: (a) account holders and their team members who use the Platform (“Users”); (b) visitors to our websites; and (c) individuals whose information appears in Customer Content — for example, the clients, recipients, and signers our Users deal with (“Counterparties”). Section 10 explains how we handle Counterparty information.
1.3 Our two roles. For account, profile, billing, website, and product-usage data, we act as the party responsible for the information (a “business” under California law). For the contents of Users’ contracts, documents, and connected mailboxes, we act as a “service provider” that processes personal information on behalf of, and under the instructions of, the User’s Organization, which is responsible for that data. If you are a Counterparty and want to exercise rights over data in a contract or email, please contact the relevant Organization; we will support them in responding.
2. Information We Collect
We collect the categories of information below. The specific data depends on how you use the Platform. This Section also serves as our notice at collection under California law.
2.1 Information you and your Organization provide
Category
Examples
Source / provider
Account & profile
Name, email address, password or federated sign-in identifiers, authentication IDs, role (Owner/Admin/Member/Viewer).
You; our authentication provider; Google/Microsoft sign-in.
Organization & workspace
Organization name, plan tier, team membership and invitations, branding assets (logo, colors, sender name), preferences and notification settings.
You / your Organization.
Billing
Subscription plan, billing status, payment-processor customer and subscription identifiers, invoices. Payment-card details are collected and processed directly by our payment processor; we do not store full card numbers.
You; payment processor.
Support & communications
Messages, requests, and feedback you send us.
You.
2.2 Customer Content (processed on your behalf)
Category
Examples
Source / provider
Contracts & documents
Uploaded and generated templates and contracts (PDF/DOCX), document versions, field values and deal terms, signed copies.
You; Counterparties; AI generation.
Deal & Counterparty details
Counterparty and signer names and email addresses, deal descriptions, negotiation history, activity logs.
You; Counterparties.
Email mailbox data
For connected Gmail/Outlook mailboxes on tracked deal threads: message metadata (sender, subject, timestamps, thread/message IDs), message snippets and body text, and attachments — accessed to send, monitor, and classify deal-related email.
Google (Gmail API); Microsoft (Graph API), with your authorization.
Mailbox credentials
Encrypted OAuth access/refresh tokens and the connected mailbox address, used to maintain the connection.
Google/Microsoft, with your authorization.
Payment/payout tracking
Payout amounts, currencies, due dates, and status referenced in your executed contracts and detected from email confirmations. (These describe expected payments; Clairo does not move funds.)
You; AI parsing of your documents and email.
E-signature data
Signer names and emails, signing status and timestamps, signing audit records/certificates, executed documents.
You; Counterparties; e-signature provider.
2.3 Information we collect automatically
• Usage and log data: actions taken in the Platform, feature usage, AI-query counts, timestamps, error and audit logs, and activity feeds.
• Device and connection data: IP address, browser and device type, and similar technical data from your interactions with our sites and app.
• Cookies and similar technologies: session and authentication cookies and limited functional cookies necessary to operate and secure the Platform. See Section 13.
• Push-notification subscriptions: if you enable browser push notifications, the push endpoint and keys for your device/browser.
2.4 Sensitive information. Certain information we handle may qualify as “sensitive personal information” under California law — specifically, account log-in credentials, and the contents of email in a connected mailbox where Clairo is not the intended recipient of the communication. We collect and use this information only to provide the Platform’s features and for the other permitted purposes described in this Policy; we do not use it to infer characteristics about any individual. The Platform is not designed for other special categories of data (such as health, biometric, precise geolocation, or government-ID numbers), and you should not submit such data except as appropriate and lawful.
3. How We Use Information
We use information for the following business and commercial purposes:
• Provide, operate, and maintain the Platform and its features, including template creation, document generation, email sending and monitoring, negotiation, e-signature, payout tracking, and alerts;
• Run AI Features — detect fields, draft documents, classify emails, extract change requests, draft counter-proposals, and parse contract dates and payments — so we can return results to you (see Section 4);
• Authenticate users, enforce roles and plan limits, and secure the Platform;
• Process subscriptions, billing, and payments;
• Send transactional and service communications (e.g., notifications, reminders, invitations, security and account messages);
• Provide support, respond to inquiries, and maintain audit and activity logs;
• Monitor, troubleshoot, analyze, and improve reliability, safety, and performance;
• Prevent, detect, and address fraud, abuse, security incidents, and violations of our Terms; and
• Comply with legal obligations and establish, exercise, or defend legal claims.
3.1 Marketing. We may send you information about features and offers where permitted; you can opt out of non-essential marketing at any time. We do not use your connected-mailbox or contract content for marketing.
4. AI and Automated Processing
4.1 AI provider. We use a third-party artificial-intelligence provider (Anthropic’s Claude) to power the Platform’s AI Features. When you use these features, the relevant content — such as a document, template, or email thread — is sent to the AI provider to generate a result that is returned to you within the Platform.
4.2 No third-party model training on your content. We do not use your connected-mailbox content, contracts, or documents to train our own or third parties’ generally available AI models. Our agreement with our AI provider prohibits using content submitted through our account to train its models except as that agreement permits.
4.3 Human-in-the-loop; no automated legal decisions. AI outputs are suggestions for your review. We do not use AI Features to make decisions producing legal or similarly significant effects about individuals without human involvement. You remain responsible for reviewing and acting on AI output.
5. Google and Microsoft Mailbox Data — Limited Use
Google API Limited Use. Clairo’s access to, use, and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. In particular:
• We request only the Gmail permissions (OAuth scopes) needed to send, read/monitor, and manage the deal-related messages you track — for example, reading messages on tracked threads and sending on your behalf;
• We use Gmail data only to provide and improve the user-facing features you request (monitoring and classifying deal email, extracting proposed changes, sending messages);
• We do not use Gmail data for advertising, and we do not sell it;
• We do not transfer Gmail data to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger/acquisition with appropriate protections;
• We do not allow humans to read Gmail data unless (i) we have your affirmative agreement for specific messages, (ii) it is necessary for security or to comply with law, (iii) it is necessary for internal operations and the data has been aggregated/de-identified, or (iv) as otherwise permitted by the policy; and
• We do not use Gmail data to develop, improve, or train generalized/non-personalized AI or machine-learning models.
5.1 Microsoft. For Outlook/Microsoft 365 connections, we access mailbox data through the Microsoft Graph API using the permissions you grant, and use it only to provide the same deal-email features, consistent with Microsoft’s API terms.
5.2 Your control. You choose whether to connect a mailbox and can disconnect it in the Platform or revoke access at any time through your Google Account or Microsoft account security settings. Revoking access stops further sending and monitoring for that connection.
5.3 Security review. Because these are restricted scopes, our handling is subject to Google’s verification and independent security assessment (CASA) requirements.
6. How We Share Information
6.1 We do not sell or share personal information for money or for cross-context behavioral advertising, as those terms are defined under U.S. state privacy laws. We disclose information only as described in this Section.
6.2 Within your Organization. Customer Content and account data are accessible to authorized members of your Organization according to their roles and permissions.
6.3 Service providers. We disclose personal information to service providers that process it on our behalf, under written contracts that limit their use of the information to performing services for us. Rather than list every vendor, we describe the categories of service providers we rely on, with representative or material providers noted:
Category of service provider
Representative / material providers
Authentication & identity
Managed authentication provider (e.g., Clerk)
AI processing
Anthropic (Claude) — processes document, template, and email content you submit to AI Features
Email connectivity
Google (Gmail API) and Microsoft (Graph API) — to send and monitor deal email you authorize
Electronic signature
E-signature provider (e.g., DocuSign) — for documents you send for signature
Payments & billing
Payment processor (e.g., Stripe) — collects and processes your payment method
Cloud hosting, storage & infrastructure
Application hosting, database, file/object storage, and background-processing providers used to run the Platform
Transactional email delivery
Email-delivery provider for system notifications
A current, itemized list of our subprocessors is maintained and available on request at privacy@clairocontracts.com, and, for Organizations that have signed our DPA, in the subprocessor schedule to that DPA. Where required by contract, we will notify affected Organizations of material changes.
6.4 Legal and safety. We may disclose information if required by law, subpoena, or legal process, or to protect the rights, property, or safety of Clairo, our users, or others, or to enforce our Terms.
6.5 Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy or an equivalent successor policy.
6.6 With your direction. We share Customer Content with third parties (such as your Counterparties or your chosen e-signature provider) when you direct us to through your use of the Platform.
7. Where We Process Information
We are based in the United States and process information in the United States. Our service providers may process information in the United States and, in some cases, other countries where they or their subprocessors operate. In all cases we require appropriate contractual protections for the information they handle on our behalf.
8. Data Retention
We retain personal information for as long as needed to provide the Platform and for the purposes described in this Policy, then delete or de-identify it, unless a longer period is required or permitted by law (for example, for tax, accounting, security, or dispute-resolution purposes). We determine retention based on the type of information, the purpose for which we hold it, and applicable legal requirements. In general:
• Account data: for the life of your account and a reasonable period afterward.
• Customer Content (including documents and mailbox-derived data): retained per your Organization’s instructions and settings; on account closure or a verified deletion request, deleted within a commercially reasonable period, subject to backup cycles and legal holds. We target completion of deletion requests within 30 days where feasible.
• Mailbox credentials: retained while a mailbox connection is active and deleted when you disconnect or revoke access.
• Logs and backups: retained for limited periods for security, reliability, and audit purposes.
9. Security
We use technical and organizational measures designed to protect personal information, including: encryption of OAuth tokens and integration secrets at rest using AES-256-GCM; encryption in transit using TLS; access controls and role-based, organization-scoped data isolation; audit logging; and restricted administrative access. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your credentials and for configuring roles and access appropriately.
10. Your U.S. Privacy Rights and Choices
10.1 The rights. Depending on your state of residence — including California (CCPA, as amended by the CPRA), Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws — you may have some or all of the following rights, subject to conditions and exceptions:
• Know / access: to know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients, and to obtain a copy;
• Delete: to request deletion of personal information we have collected about you;
• Correct: to request correction of inaccurate personal information;
• Portability: to receive a copy in a portable format;
• Opt out: to opt out of the “sale” or “sharing” of personal information and of targeted advertising and certain profiling — although, as stated in Section 6, we do not sell or share personal information or use it for such purposes; and
• Limit sensitive information; non-discrimination: to limit the use of sensitive personal information to permitted purposes (we already restrict our use as described in Section 2.4), and to not be discriminated against for exercising your rights.
10.2 California notice. For the preceding 12 months, we have collected the following statutory categories of personal information: identifiers (e.g., name, email, IP address, account IDs); customer records and commercial information (e.g., subscription, billing, and transaction/deal information); internet or other electronic network activity (e.g., usage and log data); professional or employment-related information (e.g., role and organization); and sensitive personal information (account log-in credentials and, as a service provider, the contents of connected-mailbox email). We collect this information from the sources, and use it for the purposes, described in Sections 2 and 3, and we disclose it for business purposes to the categories of service providers listed in Section 6. We have not sold or shared personal information, and we do not offer financial incentives for personal information.
10.3 Service-provider data. Much of the information you are interested in may be Customer Content that we process as a service provider on behalf of an Organization. For that data, please direct your request to the Organization; we will assist them in responding as required by law.
10.4 How to submit a request. Submit a request at privacy@clairocontracts.com or through in-product settings where available. We will acknowledge and respond within the timeframes required by applicable law (generally 45 days, extendable as permitted). To protect your information, we will verify your identity using information associated with your account before fulfilling a request; we may decline or limit a request as permitted by law.
10.5 Authorized agents. You may use an authorized agent to submit a request on your behalf. We may require the agent to provide proof of authorization and may still verify your identity directly.
10.6 Appeals. If we decline your request and your state provides a right to appeal, you may appeal by replying to our decision or writing to privacy@clairocontracts.com with the subject “Privacy Appeal.” We will respond within the period required by your state’s law. If your appeal is denied, you may contact your state attorney general.
11. Counterparties and Non-Users
Our Users may process personal information about their clients, recipients, and signers (Counterparties) through the Platform — for example, names and email addresses, the contents of negotiation emails, and signer details. For that information, the User’s Organization is responsible as the “business,” and Clairo acts as its service provider. If you are a Counterparty and wish to access, correct, or delete your information, or to object to its processing, please contact the Organization you are dealing with. If you contact us, we will refer your request to the relevant Organization and support their response as required by law.
12. Children’s Privacy
The Platform is intended for business use by adults and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, contact privacy@clairocontracts.com and we will take appropriate steps to delete it.
13. Cookies and Similar Technologies
We use cookies and similar technologies that are strictly necessary to authenticate users, maintain sessions, secure the Platform, and remember preferences. We do not use the Platform’s core application for third-party advertising. Where required by law, we obtain consent for non-essential cookies and provide controls. You can also manage cookies through your browser settings, though disabling essential cookies may impair functionality. We honor recognized opt-out preference signals (such as Global Privacy Control) to the extent required by applicable law.
14. Third-Party Sites and Services
The Platform links to and integrates with third-party services (such as Google, Microsoft, DocuSign, and Stripe) that have their own privacy policies. This Policy does not cover those third parties, and we encourage you to review their policies. We are not responsible for their practices.
15. Changes to This Policy
We may update this Policy from time to time. We will post the updated version with a new effective date and, for material changes, provide additional notice where appropriate. Your continued use of the Platform after the changes take effect constitutes acceptance of the updated Policy.
16. Contact Us
If you have questions or concerns about this Policy or our privacy practices, contact us at privacy@clairocontracts.com