Data & Security

Effective: 22 April 2026 · Last updated: 22 April 2026

This page describes the technical and organisational security measures Clarity uses to protect your data. It complements our Privacy Policy.

Cloud vs Device Control (User Choice)

1. Data categories and storage locations

CategoryWhere it livesEncryption at rest
Account identity (email, auth tokens)Firebase Authentication (Google Cloud)Google-managed AES-256
Journal, Track, Mind, StepUp, Vault recordsOn-device by default; cloud storage only for features where user enables cloud sync or leaderboard participationGoogle-managed AES-256 (cloud) + AES-256 at device-level
Creator Studio, PDF Studio signatures/state, Resume Builder drafts, E-Sign VaultOn-device only; not cloud-syncedDevice-level encryption
Bank statement PDFs (StatementIQ)Ephemeral — processed in memory, deleted within 60 minutes; not cloud-synced for cross-device storageTLS in transit; never written to long-term storage
Generated images (Canvas)Cloudflare R2 object storageAES-256
Voice recordings (when cloud STT is used)Ephemeral — sent to provider, discarded after transcriptionTLS in transit; provider does not retain
On-device model packsYour device onlyDevice-level encryption (Android StrongBox / iOS Secure Enclave)

2. Encryption in transit

3. Authentication

4. Access controls

5. Secret and key management

6. Backup and disaster recovery

7. Incident response

We maintain an incident-response runbook covering detection, containment, eradication, recovery, and post-mortem. In the event of a personal-data breach, we will notify affected users and relevant regulators within 72 hours of awareness, in line with GDPR Article 33.

8. Vulnerability management

9. Deleting your data

You can delete your account at any time from Settings → Account → Delete account in the app, or by emailing privacy@jscreatorpro.app. Deletion removes your identifiable data within 30 days (some backup copies may persist for up to 90 days before rolling off). Anonymised aggregate usage statistics are retained.

10. Reporting a vulnerability

Security researchers: please email security@jscreatorpro.app. We do not run a bug bounty programme, but we acknowledge responsible disclosures and aim to triage within 5 business days.