Who we are
Lucas Barnes offers the Clara service at clarainsure.com, pending formation of a dedicated legal entity. Contact hello@clarainsure.com.
What we collect
Google identity as provided by Google sign-in: Firebase UID, email, and display name. Organization membership. Structured interview answers. Generated RISK.md and Insurance.md files. Consents. Audit events. Product emails. Coarse security logs: UID, route, status, timestamp.
We do not collect payment cards, unrestricted document uploads, or precise geolocation.
Processors
We use these processors to run the service:
- Google Firebase Authentication — identity.
- Google Firebase / GA4 — funnel event names only. Never answers, legal names, or file text.
- Neon — Postgres workspace, region aws-us-west-2.
- Vercel — application hosting.
- Resend — transactional email.
- Human reviewer — submitted snapshots, today Lucas Barnes.
Why we process
To provide the account; to generate and review files; for security; and for optional research or communications if you consented. Required processing is to perform the service contract. Optional research and marketing rest on consent, which you can withdraw without deleting the account.
Sharing
We do not sell personal data. The reviewer can read submitted files. We do not hand files to a broker or insurer without a separate authorization, and that handoff is not built yet.
Retention
An active workspace is kept until you delete it. After 24 months without a sign-in, Clara may email the membership address and then delete the workspace. Neon point-in-time backups exist for the configured recovery window, then expire. An audit record of deletion is retained for 24 months without packet bodies.
Your rights
You may export the workspace as JSON, correct a draft while it is editable, delete the account in the product, and withdraw optional consents. Use the in-product controls or email hello@clarainsure.com.
International transfers
Processors operate in the United States: Firebase, Vercel, Resend, and Neon in aws-us-west-2. If you use Clara from Canada or elsewhere, your data is processed in those locations.
Security
Traffic is served over TLS. APIs require a Firebase ID token. Postgres uses row-level security and a least-privilege runtime role. Reviewer access is an allowlist of Firebase UIDs. This is a small production system. It is not a SOC 2 report.
Children
Clara is not directed at anyone under 18.
Incidents
When legally required, we will notify affected accounts at the email on the membership row. Contact hello@clarainsure.com.