Privacy Policy
Last updated: July 10, 2026
Claremo (“Claremo,” “we,” “us,” or “our”) provides an AI-native financial dashboard for SaaS and ecommerce founders. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have. By creating an account or using Claremo (the “Service”), you agree to the practices described in this policy.
1. Information We Collect
Account information
When you sign up, we collect your name (if provided), email address, company name, and a securely hashed password. If you sign up with Google, we receive your name and email from Google.
Financial data, via the connections you authorize
When you connect a data source, we receive and store the financial data that source makes available, for example:
- Stripe — charges, subscriptions, customers, products, and revenue data
- Plaid (bank accounts) — account balances and transaction history
- QuickBooks — profit & loss statements, chart of accounts, invoices, bills, and COGS
- Shopify — orders, products, refunds, and store revenue
- Ad platforms (Meta Ads, Google Ads), if connected — campaign spend and performance
You choose which sources to connect, and can disconnect any of them at any time from Dashboard → Connections.
Uploaded documents
If you upload receipts, invoices, or other financial documents for AI-assisted extraction, we store the document and the data extracted from it.
Usage and device data
We automatically collect log data such as login timestamps, IP address, browser type, and session activity, to operate and secure the Service. See Section 8 (Cookies) below for details on session cookies.
2. How We Use Your Information
We use the information described above solely to operate and improve Claremo, specifically to:
- Build your financial dashboards, reports, and reconciliation views
- Generate AI briefings, chat responses, scenario explanations, and document extractions
- Detect anomalies and generate alerts
- Process billing and subscription payments
- Send transactional emails (e.g. briefings you request, security notices, billing receipts)
- Maintain the security and integrity of the Service
We do not sell your data. We do not use your financial data for advertising, and we do not share it with data brokers or ad networks — ever.
3. AI Processing Disclosure
When you use AI Briefings, AI Chat, Scenario Explanations, or Document Extraction, the relevant financial data is sent to Anthropic (maker of the Claude models) to generate the output. Anthropic acts as our data processor for this purpose.
Per Anthropic’s commercial API terms, Anthropic does not use data submitted through its API to train its models. Your financial data is used only to generate the specific response you requested, and is not retained by Anthropic beyond what is required to provide that response and meet its own legal and safety obligations.
AI features run only when you explicitly trigger them (for example, clicking “Generate briefing” or sending a chat message) — with one exception: an optional nightly automation job, which is disabled by default and must be explicitly enabled by you. Additionally, Claude never writes directly to your data. Every AI-suggested action (such as a bookkeeping categorization) follows an extract → validate → your explicit approval → execute flow — nothing is applied to your records without your review.
4. Sub-processors
We use the following third-party sub-processors to provide the Service:
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication, and encrypted data storage |
| Vercel | Application hosting and deployment |
| Anthropic | AI processing for briefings, chat, and document extraction (see Section 3) |
| Resend | Transactional email delivery |
| Stripe | Billing, payment processing, and (if you connect it) revenue data |
| PostHog | Product analytics — feature usage and page views (see Section 8) |
We may add or change sub-processors as we add functionality. Material changes will be reflected here with an updated “Last updated” date.
5. Security Measures
- Access tokens for connected accounts (Stripe, Plaid, QuickBooks, Shopify) are encrypted at rest using AES-256 before being stored
- All data in transit is encrypted via TLS/HTTPS
- Row-level security is enforced at the database level — every query is scoped to your organization; there is no cross-tenant data access
- Role-based access control (owner / admin / member / viewer) is enforced on every server-side request
- Optional multi-factor authentication is available (authenticator app or passkey), plus one-time backup recovery codes
- Security-sensitive actions are recorded in an audit log
No system is 100% secure, and we cannot guarantee absolute security. We design and operate Claremo according to security practices appropriate for a company at our stage, and we continue to invest in this as we grow.
6. Data Retention
- We retain your account and financial data for as long as your account and connections remain active.
- When you disconnect a data source, the data previously synced from it is deleted from our systems within 30 days.
- When you delete your account, we delete your organization’s data — connections, transactions, documents, and briefings — within 30 days, except where we are required to retain certain records (for example, billing records) to comply with legal or tax obligations.
7. Your Rights
You have the right to:
- Access — request a copy of the data we hold about you or your organization
- Export — export your financial data from the Service at any time
- Correction — request correction of inaccurate account information
- Deletion — request deletion of your account and associated data
To exercise any of these rights, email support@claremo.com. We will respond within 30 days. If you are located in the EEA, UK, or California, you may have additional rights under GDPR, UK GDPR, or the CCPA — contact us and we will accommodate applicable requests.
8. Cookies and Tracking
We use only strictly necessary cookies to keep you signed in and maintain your session, via our authentication provider (Supabase Auth). We do not use third-party advertising cookies, tracking pixels, or cross-site trackers, and we do not participate in any form of ad-based tracking or retargeting.
We use PostHog, a product analytics tool, to understand how the Service is used — for example, which pages are viewed and which features (like generating a briefing, sending a chat message, or exporting a report) are used, and how often. This is first-party product analytics, not advertising: we do not send PostHog your financial data, account balances, or transaction amounts — only which feature was used and when. This data helps us prioritize what to build and fix next.
9. Children’s Privacy
Claremo is a business tool intended for users 18 years of age or older. We do not knowingly collect information from children.
10. International Data Transfers
Our infrastructure providers (including Supabase and Vercel) may process data in the United States and other regions. By using Claremo, you consent to this transfer and processing.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will update the “Last updated” date above, and for material changes, we will notify you by email or an in-app notice.
12. Contact
Questions about this policy or your data? Email us at support@claremo.com.