1. Scope and who we are
This Privacy Policy applies to Clariti’s website at claritihq.com, desktop applications, APIs, beta or preview programs, support channels, and related products and services (collectively, the “Services”). “Clariti,” “we,” “us,” and “our” refer to Clariti, the operator of the Services, based in Bengaluru, Karnataka, India.
This policy does not apply to third-party products, websites, or services that have their own privacy notices. If or when Clariti offers organization-managed accounts, an organization that provides your access may separately control information associated with your account and use of the Services.
2. Information we collect
Information you provide
- Account and profile information: such as name, email address, password or authentication information and account preferences, as well as organization and role information if organization accounts are introduced.
- Customer Content: project and feature descriptions, text instructions, screenshots, images, documents, videos, application context, test cases, expected results, prompts, guidance, and other materials you submit.
- Execution information: selected application or window names, screenshots captured during a run, AI reasoning and actions, mouse and keyboard operations, coordinates, test steps, logs, outcomes, conclusions, and run history.
- Communications: support requests, survey responses, feedback, meeting details, and correspondence with us.
- Transaction information: if paid features are offered, plan, billing contact, subscription, invoice, tax, and payment-status information. Complete payment-card details may be collected directly by a payment processor rather than Clariti.
Information collected automatically
Depending on the Service and your settings, we may collect IP address, browser type, operating system, device identifiers, application version, referring pages, pages viewed, feature interactions, timestamps, crash information, performance data, diagnostic logs, approximate location derived from IP address, cookie or similar-technology identifiers, and security events.
Information from other sources
If or when Clariti offers organization accounts, single sign-on, or integrations, we may receive information from your organization’s administrator, identity provider, a service you connect, or another user who invites you. We may also receive information from service providers, publicly available sources, and referral partners and combine it with information collected through the Services.
3. Desktop access and local data
Clariti’s desktop software may request macOS Screen Recording and Accessibility permissions. These permissions can allow Clariti to view selected application windows and simulate mouse or keyboard input so it can execute tests. Depending on the window selected, captured material may contain personal, confidential, or sensitive information visible on screen.
Parts of Clariti run locally on your device. The local component may capture and resize screenshots, inspect available window names and bounds, execute actions, and communicate with Clariti’s cloud services and your selected AI provider. Test metadata, steps, results, and content needed to provide the Services may be stored in Clariti’s cloud systems.
In the packaged desktop application, an AI-provider API key may be encrypted using operating-system security facilities and stored locally on your device. The key may pass through Clariti’s local component and be transmitted to the applicable AI provider when necessary to fulfil your request. Clariti does not intend to store that key in its cloud database. Development configurations may instead use keys supplied through local environment settings.
You control operating-system permissions and can revoke them through your device settings. Revoking permissions may prevent core testing functionality from working.
4. How we use information
We may use information to:
- create and administer accounts, projects, subscriptions, and, if offered, workspaces;
- generate context, test plans, test cases, reports, and other requested output;
- run, pause, guide, replay, and record automated test executions;
- authenticate users and, if offered, provide integrations and connected features;
- maintain, troubleshoot, secure, and improve the Services;
- understand performance, reliability, adoption, and feature usage;
- provide support and communicate about service, security, and policy updates;
- process transactions and manage paid plans if introduced;
- detect fraud, abuse, unauthorized access, and violations of our Terms;
- comply with law and protect rights, safety, property, and the Services; and
- create aggregated or de-identified information that cannot reasonably identify you.
We may use aggregated or de-identified information for lawful purposes and will not attempt to re-identify it except to test our de-identification processes or as permitted by law.
5. Legal bases for processing
Where applicable law requires a legal basis, we process personal information as necessary to perform a contract with you or your organization; pursue legitimate interests such as operating, securing, supporting, and improving the Services; comply with legal obligations; protect vital interests; or act with your consent.
Our legitimate interests do not override your rights where applicable law provides otherwise. When processing relies on consent, you may withdraw consent at any time, without affecting processing that occurred before withdrawal. Some information is required to provide the Services; if it is not supplied, the relevant functionality may be unavailable.
6. AI processing
Clariti uses third-party artificial-intelligence providers to analyse Customer Content, understand application interfaces, create tests, and direct automated execution. Prompts, screenshots, documents, videos or sampled frames, instructions, feedback, and related context may be transmitted to those providers. Their processing is governed by our arrangements with them and, where you supply your own account or API key, may also be governed by their terms and privacy practices.
Clariti does not currently use Customer Content to train Clariti-owned foundation models. We may use service telemetry, feedback, and appropriately aggregated or de-identified information to evaluate and improve the Services. If we propose to use identifiable Customer Content for model training in the future, we will update our disclosures and obtain consent where required by law.
AI providers may process information in countries different from yours. Their retention and use practices may vary by product, account type, configuration, and applicable terms. You should not submit information to an AI-powered feature unless you are authorized to have it processed in this manner.
7. How we disclose information
We may disclose information to the following categories of recipients:
- Service providers: AI, hosting, cloud infrastructure, database, storage, security, monitoring, analytics, authentication, communications, customer-support, payment, and professional-service providers.
- Your organization and users: if organization accounts are offered, workspace administrators and authorized members may access account, activity, project, and content information.
- Integrations: third parties you direct us to connect with or disclose information to.
- Professional advisers: lawyers, auditors, insurers, accountants, financial institutions, and advisers subject to appropriate duties.
- Authorities and protected parties: where we reasonably believe disclosure is required by law, legal process, or to protect rights, safety, property, users, the public, or the integrity of the Services.
- Business transactions: in connection with financing, due diligence, reorganization, merger, acquisition, sale, insolvency, or transfer of all or part of our business or assets, subject to applicable law.
We do not sell personal information for money, and we do not share personal information for cross-context behavioural advertising. If that practice changes, we will first update this policy and provide any consent or opt-out mechanism required by law.
8. Analytics, cookies, and similar technologies
Our website uses Google Analytics to understand traffic and how visitors interact with the site. Google Analytics may collect device, interaction, and approximate-location information using cookies or comparable identifiers. Our website and applications may also use essential local storage, cookies, or similar technologies for authentication, security, preferences, and core functionality.
We may use additional analytics providers on other Clariti properties. Browser controls may block cookies, but doing so can affect functionality. Where legally required and technically supported, we will provide applicable consent or preference controls and honour applicable opt-out preference signals.
9. International data transfers
Clariti operates from India and may use providers or infrastructure in other countries. As a result, information may be processed where privacy laws and government-access rules differ from those in your jurisdiction.
Where required, we use recognized transfer mechanisms or other appropriate safeguards, such as contractual protections, and assess supplementary measures where appropriate. You may contact us for information about safeguards applicable to your information, subject to confidentiality and legal restrictions.
10. Retention and deletion
We retain information for as long as reasonably necessary to provide the Services, maintain business and security records, comply with law, resolve disputes, enforce agreements, and protect the Services and users. Retention varies according to the information’s nature, sensitivity, purpose, account status, contractual commitments, legal requirements, and technical context.
Following a valid account-deletion request, we aim to delete or de-identify active account data within 30 days and remove it from routine backups within 90 days. Deletion may take longer where information must be retained for legal obligations, fraud prevention, security, billing, dispute resolution, enforcement, legal claims, a valid preservation request, or where deletion is technically infeasible. Data may remain in aggregated or de-identified form.
If organization accounts are offered, workspace administrators may control deletion of organization-managed content. Ending use of the Services does not itself delete an account; contact us to request deletion if an in-product control is unavailable.
11. Security
We use administrative, technical, and organizational measures designed to protect information, taking account of the nature of the information and the Services. No method of storage or transmission is completely secure, and we cannot guarantee that information will never be accessed, altered, lost, or disclosed.
You are responsible for securing your devices, credentials, API keys, connected systems, test environments, and backups. Notify us promptly if you suspect unauthorized use. We will provide legally required security-incident notifications to affected parties or authorities.
12. Your privacy rights
Depending on where you live and subject to legal exceptions, you may have rights to request access, correction, completion, deletion, restriction, portability, or an explanation of processing; object to certain processing; withdraw consent; opt out of certain disclosures or profiling; nominate another person where applicable; appeal a decision; or complain to a data-protection authority.
Submit requests to heyclariti@gmail.com. We may verify your identity, authority, account, and jurisdiction before responding. Authorized agents may be required to provide proof of authority, and we may ask you to confirm a request directly. We will not discriminate against you for exercising applicable rights.
Rights are not absolute. We may deny or limit a request where permitted by law, including when we cannot verify it, another person’s rights would be affected, or retention is legally required. You may contact us to appeal a decision; you may also contact your local supervisory or data-protection authority.
13. Organization accounts and customer-controlled data
If or when Clariti offers organization-managed accounts, an employer or other organization that provides your access may be the controller or data fiduciary for Customer Content and account data, and Clariti may process it on the organization’s instructions. Administrators may then be able to manage membership, permissions, content, integrations, retention, export, and account access. Direct requests concerning organization-controlled data to the organization first.
Customers are responsible for providing legally required notices, establishing a lawful basis, honouring data-subject requests, and obtaining permissions before submitting information about other people. Clariti does not currently promise a standard Data Processing Addendum. Organizations may request additional terms, but Clariti is not obligated to accept them.
14. Sensitive and regulated data
The Services are not specifically designed as a compliant repository for health records, full payment-card data, government identification numbers, biometric identifiers, passwords, authentication secrets, children’s data, or other highly sensitive or specially regulated information. If you submit such information, you do so at your own risk and represent that you have all necessary authority, notices, consents, safeguards, and agreements.
This allocation of responsibility does not remove obligations that applicable law imposes directly on Clariti. Contact us before using the Services for regulated processing that requires specific contractual, localization, certification, or security commitments.
15. Age restrictions
The Services are intended only for people aged 18 or older and are not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided information, contact us so we can investigate and take appropriate action.
16. Third-party services and links
The Services may link to, interoperate with, or rely on third-party applications, identity providers, AI providers, payment processors, websites, and platforms. Your use of those services and their processing of information are governed by their own terms and notices. We are not responsible for third-party privacy, security, availability, or content.
17. Regional availability
Clariti may make the Services available internationally, but not where doing so would violate applicable law or require registrations, licences, data-localization arrangements, representatives, contracts, or compliance capabilities that Clariti does not support. We may restrict or discontinue access by territory.
Nothing in this policy limits rights that cannot lawfully be waived. If local law conflicts with this policy, the mandatory local requirement controls to the extent of the conflict.
18. Changes to this policy
We may update this policy as the Services, providers, or laws change. We will post the revised policy and update the “Last updated” date. If changes are material, we may provide additional notice by email, in the Services, or through another reasonable channel. Where required, we will request consent before the change applies. Previous versions may be made available on request where reasonably practicable.
19. Contact us
For privacy questions, rights requests, account deletion, complaints, or concerns, contact:
Clariti
Bengaluru, Karnataka, India
heyclariti@gmail.com
claritihq.com