Privacy Policy
This policy describes how ClaroFlux handles your information. It reflects how the product is actually built — what we collect, why, where it lives, and the control you have over it.
01Overview
ClaroFlux (“ClaroFlux”, “we”, “us”) is an AI-assisted study dashboard that helps you log study sessions, manage tasks, and receive automated insights and coaching. This Privacy Policy explains exactly what data we collect, why we collect it, where it is stored, and the choices you have.
We have written this policy to reflect how ClaroFlux actually works. We do not collect data we do not use, and we do not run third-party advertising or tracking networks.
02Information We Collect
Almost all of the data ClaroFlux holds is information you choose to create. We group it as follows:
- Account information
- Your email address and a securely hashed password (managed by our authentication provider), or — if you sign in with Google — your name, email address, and profile picture from your Google account.
- Profile
- An optional display name and an optional profile picture you upload.
- Study sessions
- Subject, duration, optional notes, the date studied, and (for live-timer sessions) the session start time.
- Tasks
- Task title, optional description, priority, due date, and completion status.
- Preferences
- Your daily study goal, preferred session length, and whether notifications are enabled.
- AI content
- Study plans and coaching feedback generated for you, along with the inputs used to produce them, so they can be shown again later.
- Feedback submissions
- The category, optional title, message, and any optional screenshot you attach, plus basic technical metadata (described below).
- Feedback metadata
- When you submit feedback we attach your app version, platform (“web”), browser, operating system, and screen resolution so we can reproduce issues. This is collected only at the moment you submit feedback — not continuously.
We do not use third-party analytics, advertising pixels, fingerprinting, or behavioural tracking tools. ClaroFlux does not collect your location, contacts, or device sensors.
03How We Use Your Information
- To operate core features — logging sessions, managing tasks, and showing your dashboard and analytics.
- To generate AI insights, study plans, and post-session coaching (see AI Features below).
- To send you a weekly study report by email, when that feature is enabled and you have studied that week.
- To respond to and act on the feedback you submit, and to fix bugs you report.
- To secure your account, prevent abuse, and maintain the reliability of the service.
We do not sell your personal information, and we do not use your study notes or feedback to send you marketing.
05AI Features
ClaroFlux uses third-party AI providers to generate insights and coaching. To do this, a limited set of your study data is sent to these providers to produce a response:
- Daily insights & weekly report narratives are generated by Google’s Gemini models using derived statistics — such as hours studied, streaks, subject names, task counts, and consistency signals.
- AI Lab study plans and post-session coaching are generated by an NVIDIA Nemotron model accessed through OpenRouter, using the subject, duration, and any topic or notes you provide for that session or plan.
AI-generated content is produced automatically and may be inaccurate. It is intended as study guidance only and is not professional, medical, or academic advice.
06Uploaded Files & Screenshots
ClaroFlux stores two kinds of uploaded images, in separate buckets:
- Profile pictures
- Stored in a public storage bucket. This means the image URL can be accessed by anyone who has the link. Please do not use a profile picture you consider private.
- Feedback screenshots
- Stored in a privatestorage bucket, limited to image files up to 5 MB. They are organised per user and served through expiring signed links. Other users cannot browse them.
Screenshots may capture whatever is on the screen at the time you take them. Please review a screenshot before attaching it so you do not share information you would rather keep private.
07Data Storage & Security
Your data is stored in a managed PostgreSQL database and object storage operated by Supabase. We protect it with several layers:
- Row-Level Security is enabled on every table, so the database itself enforces that you can only read and write your own rows.
- Passwords are hashed and managed by our authentication provider — we never see or store them in plain text.
- Encryption in transit protects data moving between your browser and our servers.
- Feedback screenshots are kept in a private bucket and reached only through short-lived signed URLs.
No system is perfectly secure, but we work to follow sensible, industry-standard practices and to limit access to your data to what is required to run the service.
08Third-Party Services
We rely on a small number of trusted providers (“sub-processors”) to run ClaroFlux. Each receives only the data it needs:
- Supabase
- Authentication, database, and file storage. Holds your account and all study data.
- Google (Gemini API)
- Generates dashboard insights and weekly report narratives from derived study statistics.
- OpenRouter / NVIDIA Nemotron
- Generates AI Lab study plans and post-session coaching from the inputs you provide.
- Google (OAuth)
- Optional “Sign in with Google”. Shares your Google name, email, and avatar with us only if you choose it.
- Resend
- Delivers weekly study report emails to your registered address, when that feature is enabled.
- Vercel
- Hosts and serves the application and runs the scheduled weekly-report job.
- GitHub
- Used only to fetch the latest desktop-app download. No personal data is sent to GitHub.
We do not sell your personal information or share it with third parties for their own marketing. We may disclose data if required by law or to protect the rights, safety, and security of ClaroFlux and its users.
09Data Retention
We keep your data for as long as your account is active. Study sessions, tasks, AI content, and feedback remain available to you until you delete them or delete your account.
When you delete your account, your account record and the data linked to it are removed; database relationships are configured to cascade so your sessions, tasks, profile, settings, AI content, and feedback are deleted along with it. Backups and provider logs may persist for a limited period before being overwritten.
10Your Rights & Choices
- Access & edit — view and update your sessions, tasks, profile, and preferences at any time from within the app.
- Delete your account — permanently remove your account and associated data from Settings → Delete account.
- Email preferences — weekly report emails are sent only when the feature is enabled; you can stop them by adjusting your notification preference or contacting us.
- Request help — contact us about any data question, including a copy or correction of your information.
11Children’s Privacy
ClaroFlux is intended for students aged 13 and older. We do not knowingly collect personal information from children under 13. If you are under the age of majority in your region, please use ClaroFlux only with the involvement of a parent or guardian. If you believe a child has provided us personal information, contact us and we will remove it.
12Changes to This Policy
We may update this Privacy Policy as ClaroFlux evolves. When we make material changes we will update the “Last updated” date at the top of this page. Your continued use of ClaroFlux after an update means you accept the revised policy.
13Contact Us
Questions about this policy or your data? Email us at studyflowapp.official@gmail.com.