Who we are
Lucas Barnes offers the Clara service at clarainsure.com, pending formation of a dedicated legal entity. Contact hello@clarainsure.com.
What we collect
Google identity as provided by Google sign-in: Firebase UID, email, and display name. Organization membership. Structured interview answers. Reviewed risk records and optional RISK.md exports. Consents. Audit events. Product emails. Coarse security logs: UID, route, status, timestamp.
We do not collect payment cards, unrestricted document uploads, or precise geolocation.
Connected agents
A company member may authorize a desktop agent application to read draft and released risk-record information and, if granted, to save drafts. Clara issues that connection’s credentials after the member signs in with Firebase Authentication and consents. Firebase authenticates the person on the consent screen; it does not issue the agent’s credentials. Clara stores hashed credentials and grant metadata, not reusable plaintext tokens. Connections expire after 30 days without successful business-tool activity and can be revoked immediately in Account. Refresh and discovery do not extend that period.
Desktop support is a compatibility boundary, not a promise that data stays on the device. The agent application may send retrieved draft or released information to its own model provider. Clara does not host model inference for this connection and cannot tell whether a later tool call was started by a person or by automation. Clara does not treat an application-supplied name as verified vendor identity. Allowlisted callbacks do not prove the client is Cursor, Codex, or Claude Code.
Processors
We use these processors to run the service:
- Google Firebase Authentication — identity.
- Google Firebase / GA4 — funnel event names only. Never answers, legal names, or file text.
- Supabase — Postgres, region us-west-2. Customer account data is in a private schema.
- Google Cloud Storage — private document vault, region Toronto, when documents are stored.
- Vercel — application hosting.
- Resend — transactional email.
- Human reviewer — submitted snapshots, today Lucas Barnes.
Why we process
To provide the account; to process operating context and expert risk reviews; for security; and for optional de-identified learning or communications if you consented. Required processing is to perform the service contract. Optional learning and marketing rest on consent, which you can withdraw without deleting the account.
Sharing
We do not sell personal data. The reviewer can read submitted context. We do not hand a risk record to a broker or insurer without a separate authorization, and that handoff is not built yet.
Retention
Closing online access disables sign-in and connected agents. It does not erase the company record or change any insurance. Deletion of personal information is a separate request to hello@clarainsure.com. Clara does not keep every file forever, and it does not apply a brokerage retention period to an abandoned signup. Final retention periods depend on the licensing jurisdiction and are not yet a universal rule.
Your rights
You may export the workspace as JSON, correct a draft while it is editable, close online access in the product, and withdraw optional consents. To ask for access, correction, or deletion of personal information, use the in-product controls or email hello@clarainsure.com.
International transfers
Firebase, Vercel, Resend, and Supabase operate in the United States. Supabase is in us-west-2. Document files, when stored, are in Google Cloud in Toronto. If you use Clara from Canada or elsewhere, your data is processed in those locations.
Security
Traffic is served over TLS. Browser APIs require a Firebase ID token and App Check. Connected-agent requests use Clara-issued access tokens bound to a customer grant; they do not use App Check. Postgres uses row-level security and a least-privilege runtime role. OAuth permissions are enforced in application code in addition to tenant isolation. Clara staff sign in separately from customers. This is a small production system. It is not a SOC 2 report.
Children
Clara is not directed at anyone under 18.
Incidents
When legally required, we will notify affected accounts at the email on the membership row. Contact hello@clarainsure.com.