Clarnix privacy policy

Effective: April 19, 2026. Last updated: October 4, 2026

This Privacy Policy explains how NEXTGENWEBS, S.L. ("Clarnix", "we", "our", or "us") collects, uses, shares, and protects your personal data when you use the Clarnix service available at clarnix.app. It is provided pursuant to Articles 13 and 14 of the EU General Data Protection Regulation (GDPR) and applicable Spanish data protection law (LOPDGDD). Please read it carefully before using the service.

1. Data Controller

The data controller responsible for your personal data is:

NEXTGENWEBS, S.L.
CIF: B97380067
Pol. Ind. Fuente del Jarro
Plaza Gerardo Salvador, No. 1, Offices 17–19
46988 Paterna – Valencia, Spain
Privacy contact: legal@clarnix.app

The supervisory authority for data protection in Spain is the Agencia Española de Protección de Datos (AEPD), accessible at www.aepd.es.

2. Data We Collect

We collect the minimum data necessary to provide the Clarnix service.

2.1 Account Data

When you create an account we collect your name, email address, and (if applicable) a hashed password. If you sign in via OAuth (Google or Microsoft), we receive your name, email address, and provider-issued user ID.

2.2 Email Data Accessed via OAuth: Privacy by Design

Clarnix is built on a privacy-by-design principle: email body content is never stored in our systems. We process email bodies transiently in-memory to classify messages and generate briefing summaries, and then discard them immediately. The Google OAuth scopes we request are https://www.googleapis.com/auth/gmail.readonly (read mail), https://www.googleapis.com/auth/gmail.modify (apply labels and archive), https://www.googleapis.com/auth/gmail.labels (create and manage the labels we apply) and https://www.googleapis.com/auth/calendar.readonly (read upcoming events, described below). For Microsoft accounts we request the equivalent Microsoft Graph Mail.Read and Mail.ReadWrite permissions. The metadata we do persist is limited to:

  • Sender name and email address
  • Recipient email addresses (To and Cc)
  • Subject line
  • Received timestamp (received_at)
  • Message ID and thread ID (provider-issued identifiers)
  • AI-generated classification labels and priority scores
  • AI-generated briefing summaries (never verbatim body content)

Calendar data: where you grant the calendar scope, we read your upcoming events for the sole purpose of adding a short agenda to your briefing. The agenda is stored only as part of that briefing: each event's title, start and end time, and location (or "online" for a video call). It is deleted together with the briefing at the end of your plan's data retention period: 7 days on Starter, 30 days on Pro, 90 days on Team and Team Pro. Event descriptions are read only to detect a meeting link, and neither descriptions nor attendee lists are stored. Calendar data is never used to train any model, and never shared with third parties. You can switch the calendar section off for any connected account at any time.

2.3 Connected Email Account Credentials

To connect your email provider we store OAuth access tokens and refresh tokens (or, for IMAP, encrypted credentials). These are stored encrypted at rest using an ENCRYPTION_MASTER_KEY and used solely to access your mailbox on your behalf.

2.4 Billing Data

Payment card data is collected and processed exclusively by Stripe. We store only your Stripe customer ID, subscription status, last-4 card digits, billing name, billing address, and VAT ID where provided. We never see or store full card numbers.

2.5 Usage Data

We collect aggregated, anonymised usage data such as features accessed, number of rules created, briefing count, and delivery events. We also collect technical data such as IP address (for security rate-limiting), browser type, and error logs.

3. How We Use Your Data

We use the data we collect for the following purposes:

  • Providing, operating, and maintaining the Clarnix service
  • Classifying your incoming email using AI and applying the rules you configure
  • Generating AI-synthesised briefing summaries and delivering them to your chosen channel (email, WhatsApp, Telegram, Slack, Teams)
  • Processing payments and managing your subscription via Stripe
  • Sending transactional emails (account confirmation, receipts, briefing delivery)
  • Aggregated and anonymised product analytics to understand feature usage and improve the service
  • Security monitoring, fraud prevention, and abuse detection
  • Complying with legal obligations

We do not use your data for behavioural advertising, sell it to third parties, or use email content for any purpose other than in-memory triage processing.

4. Google API Services: Limited Use Disclosure

Clarnix's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • We do not use your Google user data to train generalised AI or machine learning models.
  • Human access to your Google user data is limited to: (a) with your explicit consent; (b) for security purposes such as investigating abuse; (c) to comply with applicable law; or (d) for internal operations where the data has been aggregated and anonymised.
  • We do not sell or transfer your Google user data to data brokers, advertisers, or any other third parties for purposes unrelated to providing the Clarnix service.

5. Legal Basis for Processing (GDPR Art. 6)

We rely on the following legal bases:

  • Contract Performance (Art. 6(1)(b)): Processing your email metadata and account data is necessary to deliver the triage, classification, and briefing features you have subscribed to.
  • Legitimate Interests (Art. 6(1)(f)): We process technical and usage data to maintain service security, prevent abuse, detect errors, and improve platform reliability. Our interests are balanced against your rights and do not override them.
  • Consent (Art. 6(1)(a)): For non-essential cookies and marketing communications, we rely on your consent. You may withdraw consent at any time without affecting the lawfulness of prior processing.
  • Legal Obligation (Art. 6(1)(c)): Where required, we process data to comply with applicable law (e.g., retaining invoicing records under Spanish tax law).

6. Subprocessors

We engage the following sub-processors to operate the service. Each processes only the data strictly necessary for their role.

ProcessorPurpose & Data SharedLocation
SupabaseDatabase hosting, authentication, and file storage: account data, email metadata, rules, briefingsEU (Frankfurt, Germany)
VercelWeb application hosting and edge delivery: request logsEU/USA (SCCs)
RailwayBackground worker infrastructure (email polling, triage queue): transient email content in-memoryEU/USA (SCCs)
ResendTransactional email delivery: recipient address, briefing summariesUSA (SCCs)
OpenRouter: AI model providersAI/LLM routing and inference for email classification and briefing generation. OpenRouter forwards each request to a curated set of AI model providers and inference hosts, currently including Anthropic, Google (Vertex AI), and OpenAI, alongside vetted US-based inference hosts for open-weight models. To determine the priority of an incoming email, OpenRouter also forwards its sender, subject and an excerpt of its content to a decision model: the Perplexity Decider model of Perplexity AI, Inc. (United States) and, only when that model is unavailable, the Jev model of TypeSafe. Neither of these two providers publishes where it processes data. The active set may change as we optimise quality and reliability, but every endpoint must meet the same requirements, enforced technically on every request: zero data retention and no use of your data to train models. Transfers outside the EEA are covered by Standard Contractual Clauses. Email content is processed transiently in memory only and is never stored or logged.USA/EU (SCCs); Perplexity and TypeSafe: not published
StripeBilling and subscription management: billing name, address, card dataUSA/EU (SCCs)
Google / MicrosoftOAuth authentication and email data source: OAuth tokens, email metadata accessed per your authorisationUSA (SCCs)
Meta (WhatsApp) / Telegram / SlackBriefing delivery to your configured messaging channels: briefing summary contentUSA (SCCs)
PostHogProduct analytics and error tracking: anonymous usage events (page views, feature interactions), aggregated web performance metrics, and application error reports. Configured without person profiles and without session recordings; email content, subject lines, and email addresses are never sent to PostHog. Analytics cookies are set only with your consent. Without it, measurement runs cookieless.EU (Frankfurt, Germany)
AidbaseIn-app support chat and ticketing: account identifier, first name and email address of the signed-in user, together with the messages sent in a support conversation and the subject, description and any file attached to a support ticket. Their widgets run in the browser, so the request that loads them also discloses IP address and browser user agent to Aidbase. Mailboxes are not connected to this service: email content, subject lines and email metadata are never sent to Aidbase. Aidbase is operated by Highware Solutions (Highware GmbH), Baar, Switzerland, and stores data on Amazon Web Services in the United States, Ireland and the United Kingdom. Transfers outside the EEA are covered by the EU Standard Contractual Clauses incorporated into Aidbase's data processing agreement.Switzerland/EU/USA/UK (SCCs)

"SCCs" refers to the EU Standard Contractual Clauses adopted pursuant to Commission Decision (EU) 2021/914, which provide an adequate level of protection for transfers of personal data to third countries.

7. International Data Transfers

Some of our sub-processors operate outside the European Economic Area (EEA). Where this occurs, we ensure an appropriate safeguard is in place (in all current cases, EU Standard Contractual Clauses) so that your data receives a level of protection equivalent to that guaranteed within the EEA.

8. Data Retention

  • Email body content: Never stored. Processed in-memory and immediately discarded.
  • Account metadata: Retained until account deletion, then removed from active systems within 30 days.
  • Email metadata and briefing summaries: Kept for your plan's data retention period, set out under "Data retention" below. Deleted within 30 days of account closure if that comes first.
  • Billing records: Retained for 6 years as required by Spanish tax law (Ley General Tributaria).
  • Data retention: Your Email activity record and your briefings are kept for your plan's data retention period: 7 days on Starter, 30 days on Pro, 90 days on Team and Team Pro. Server-side logs are kept up to 90 days for security purposes. They record account identifiers and system events only, never your email content, and those identifiers stop referring to anyone once your account is deleted.

During your 14-day free trial, all data is treated identically to that of a paying subscriber. If you do not convert to a paid plan, your data is deleted within 30 days of trial expiry.

9. Account Deletion

  • You can delete your account at any time from Settings → Delete Account (self-service). Account closure is permanent and cannot be reversed.
  • What gets deleted within 30 days: your profile, all connected email accounts and OAuth tokens (Google access is revoked at the provider immediately upon deletion; Microsoft offers Clarnix no way to revoke its access, so remove Clarnix yourself from your Microsoft account's app permissions; for IMAP mailboxes the stored password is deleted, but an app-specific password stays valid at your provider until you revoke it there), all classification data, briefings, rules, and team memberships. If you are the sole owner of a team, the team is deleted or ownership is transferred.
  • What is retained: billing records, for 6 years as required by Spanish tax law; and a record that your deletion happened (your email address, the date, and your payment reference), kept for 3 years as proof that we honoured your request, then deleted automatically. Your Email activity record is deleted together with your account rather than kept.
  • Removal from active systems is completed within 30 days, in line with Section 8. This timeframe accounts for backups, replicated storage, and batch deletion processes, and is consistent with the "reasonable timeframe for effective erasure" recognised under Article 17 GDPR.

10. Your Rights Under GDPR

As a data subject under GDPR, you have the following rights:

  • Right of access (Art. 15): You can see a good part of it yourself in the app: the Email activity screen in Clarnix lists every action we took on your email, together with the sender, subject, mailbox, date and the rule behind it. How far back that screen reaches depends on your plan, in line with Section 8. For a copy of anything it does not show, write to legal@clarnix.app and we will put it together and send it to you.
  • Right to rectification (Art. 16): You may ask us to correct inaccurate or incomplete data.
  • Right to erasure (Art. 17): You may request deletion of your personal data, subject to legal retention obligations (e.g., billing records).
  • Right to data portability (Art. 20): You can ask us for the personal data you gave us in a structured, commonly used, machine-readable format. Clarnix has no self-service export or download button, so we put that copy together by hand once you ask, within the response time set out below.
  • Right to restriction of processing (Art. 18): You may ask us to restrict processing of your data in certain circumstances.
  • Right to object (Art. 21): You may object to processing based on legitimate interests. We will comply unless we demonstrate compelling legitimate grounds that override your interests.
  • Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, contact us at legal@clarnix.app. In accordance with Article 12(3) GDPR, we will respond to your request within one month of receipt. Where a request is particularly complex or where we receive a high number of requests, that period may be extended by up to two further months; we will inform you within one month of receiving the request of any such extension and the reasons for it. If you are not satisfied with our response, you have the right to lodge a complaint with the Spanish data protection authority (AEPD (Agencia Española de Protección de Datos)) or the supervisory authority in your EU member state of habitual residence.

11. Security

We implement appropriate technical and organisational measures to protect your personal data, including: TLS 1.3 encryption in transit, encryption at rest managed by Supabase, OAuth tokens encrypted with an ENCRYPTION_MASTER_KEY, Row Level Security enforced at the database layer, and access controls limiting who can access production systems. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the AEPD within 72 hours.

12. Cookies

Clarnix uses strictly necessary cookies to manage authentication sessions. We also offer optional analytics cookies subject to your consent. For full details see our Cookie Policy. Cookie Policy.

13. Children

The Clarnix service is not directed at users under 16 years of age. We do not knowingly collect personal data from children. If we learn that we have collected data from a child under 16, we will delete the account promptly.

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via an in-app banner and by email at least 30 days before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.

15. Contact

For any questions, requests, or concerns regarding this Privacy Policy or the processing of your personal data, please use the addresses below. Two specialised inboxes are operated by NEXTGENWEBS, S.L.: legal@clarnix.app, monitored by the Legal & Privacy team, which handles GDPR data-subject requests, contractual queries, and other legal matters; and hello@clarnix.app, monitored by the Customer Support team, which handles day-to-day product, account, and billing questions. We aim to acknowledge incoming requests within two business days. Substantive responses to data-subject requests are issued within the statutory deadlines set out in Section 10 above. Personal data you share with us through these inboxes (your name, email address, and the content of your request) is processed on the legal basis of Article 6(1)(c) GDPR (compliance with a legal obligation, where we are responding to a data-subject request) or Article 6(1)(f) GDPR (our legitimate interest in answering correspondence). Records of these communications are retained for as long as necessary to evidence our response, and in any event no longer than 6 years where required by Spanish law.

NEXTGENWEBS, S.L.
Legal & privacy: legal@clarnix.app
Product & support: hello@clarnix.app
Pol. Ind. Fuente del Jarro, Plaza Gerardo Salvador, No. 1, Offices 17–19
46988 Paterna – Valencia, Spain
Spanish Data Protection Agency: www.aepd.es