Sign in
PRIVACY POLICY · DRAFT FOR OWNER REVIEW

How Clarform handles your work.

On this page

Privacy notice draft for Ali Saied’s invitation-only, non-commercial Clarform beta. Updated 7 September 2026. It describes the current private implementation and uses the UK data-protection framework. The lawful-basis and provider checks below remain outstanding for current processing and must be completed before introducing further users or personal information.

Who is responsible

Ali Saied is the individual operator and data controller for this private prototype. Contact ali@clarform.com about your information, this notice or a privacy complaint. Use synthetic content for testing; do not submit real customer records, sensitive personal information, payment details or credentials.

Workspace and account data

Clarform stores access-code and session digests, expiry and revocation state, project-credit entitlement, project descriptions, draft answers, names and scope choices. It also stores uploaded files, imported source and provenance, build requests, source revisions, feedback, launch preferences and verification records. Model usage is recorded for server operation; it is not a user billing meter. This private setup has no payment checkout or payment-card collection.

Why information is used

Information is used to authenticate invitations, keep drafts and source, carry out requested builds and revisions, check repository permissions, protect private workspaces, diagnose failures and answer requests. Providing project content and connecting GitHub are optional; the related features cannot operate without the information they need. The prototype does not sell personal information or use it for advertising. Model generation and technical checks do not make decisions with legal or similarly significant effects about individuals.

Proposed lawful basis

For this limited private testing, the proposed basis is legitimate interests under Article 6(1)(f) of the UK GDPR: evaluating the prototype, providing the requested workspace features and keeping them secure. A purpose, necessity and balancing assessment is recorded for owner review. Validation remains outstanding for current processing, including account and GitHub information; it must be completed before introducing further users or personal information. Visiting the site or reading this notice is not treated as consent.

Processing and service providers

The frontend is delivered through Vercel. The private backend uses the operator’s VPS with self-hosted Supabase for database and artifact storage. Relevant project instructions, source and verification feedback are sent to OpenAI through the configured Codex service when you request generation or revisions. An optional GitHub connection reads authorized account/installation identifiers, repository information, branches and selected source from GitHub. Its tokens are encrypted in server storage and do not enter generated source. No repository write is authorized by importing.

International processing

Provider processing and infrastructure may involve countries outside the UK. This draft does not claim UK-only storage or a transfer safeguard that has not been checked. Verification of hosting locations, provider terms, model-data settings and any required UK transfer arrangements remains outstanding for current processing. Complete these checks before introducing further users or personal information. Ask Ali Saied for the current provider review; a private preview does not remove these requirements.

Cookies and browser draft recovery

An HTTP-only session cookie authenticates the private workspace. You can explicitly choose to stay signed in on this device for up to seven days; otherwise the cookie lasts for the browser session. Browser session restoration may retain session cookies. Server sessions expire after at most seven days. Private preview cookies have a one-hour lifetime and are checked against live authorization. GitHub connection setup uses a temporary state cookie. Draft recovery uses browser local storage; a draft may remain there until you clear it. These features support the requested workspace and connection flows. No advertising, cross-site analytics or marketing pixels are implemented, and no optional tracking consent is requested.

Generated project records

New generated products can save a versioned private data document on the server, scoped to the workspace owner and project. Generated code cannot select another owner’s records. Legacy task-tracker previews may still use browser-local storage. Downloading source does not export private runtime records or automatically provide a public account system.

Keeping and removing information

You can export your draft and brief and download stored source. Account, project and source deletion currently require the operator; signing out or an expired invitation does not delete them. The retention review considers whether information is still needed for an active test or requested project, resolving a specific fault or complaint, security, or a legal obligation. Reviews are due when testing ends and when a deletion request is received. Data no longer needed should be removed or anonymised. Routine completed server backups rotate automatically; separately retained recovery copies need manual review. A deletion request must also consider backups and any later recovery.

Disconnecting GitHub

Disconnecting removes this workspace’s saved GitHub credentials and pending connection state. It does not delete source already imported or uninstall the App on GitHub. You can separately manage or revoke the App in GitHub settings. Imported copies remain covered by the retention and deletion process above.

Your rights and your right to object

Depending on the circumstances, UK data-protection law provides rights to access, correction, erasure, restriction and portability. You may object to processing based on legitimate interests. Send a request to ali@clarform.com; only proportionate identity checks should be requested. Rights are not absolute, and the response will explain any applicable limit. Subject-access requests are generally due within one month, subject to the lawful rules on timing and extensions.

Privacy complaints

Raise a privacy complaint with Ali Saied at ali@clarform.com. The handling process requires acknowledgment within 30 days, an appropriate investigation and communication of the outcome. You can also complain to the Information Commissioner’s Office, the UK data-protection regulator. This notice is not a claim of ICO certification or legal approval.

You’re ready for the next step.Use access key