Last updated May 31, 2026
Data Retention and Deletion Policy
This Data Retention and Deletion Policy explains how Clarity retains, deletes, and disposes of user data, including personal information, Plaid-connected financial data, product records, assistant data, support records, and operational data.
This page complements the full Privacy Policy and should be read together with Clarity's public security, terms, and contact information.
1. Introduction and Purpose
Clarity retains data for clear product, security, and legal needs.
Clarity is an early-stage personal AI financial co-pilot operated by Pedro Martins as a solo founder. Clarity helps users understand spending, budgets, goals, and financial context through the Clarity apps (iOS, Android, and the web companion) and Rex, the AI assistant inside the product.
Clarity's retention approach is based on data minimization, purpose limitation, user control, security, legal obligations, and practical operational needs. Clarity does not sell personal financial data.
2. Scope of This Policy
This policy covers data handled through Clarity systems and providers.
This policy applies to user data collected, received, generated, stored, or processed through the Clarity app, public website, support channels, account connection flows, and related backend systems.
It covers account and profile data, Plaid-connected financial account data, imported financial data, budgets, goals, categories, Rex conversations and memory, voice-derived text if voice features are used, support and deletion request records, logs, backups, and other product or operational records.
3. Data Retention Practices
Retention periods vary by category, purpose, and legal requirement.
Clarity retains data only as long as reasonably needed to provide the product, support users, maintain security and reliability, comply with legal or platform obligations, resolve disputes, debug issues, and preserve necessary operational records.
| Data category | Examples | Typical retention period |
|---|---|---|
| Account and profile data | Email address, account identifiers, authentication records, preferences. | Retained while the account is active; deleted or de-identified after a verified deletion request, subject to exceptions. |
| Plaid-connected financial data | Institution metadata, account labels, balances where supported, transactions, categories, connection metadata. | Retained while needed to provide account, transaction, budget, categorization, dashboard, and Rex features; deleted or de-identified after verified deletion unless an exception applies. |
| Budgets, goals, categories, and planning data | Budgets, savings goals, spending categories, plans, progress records. | Retained while the account is active or until removed by the user or deleted through a verified request. |
| Rex assistant data | Conversations, prompts, generated responses, approved memory/context, voice transcripts if used. | Retained while needed for assistant history, personalization, memory, reliability, and support; removable where product controls allow or through a verified deletion request. |
| Support, privacy, and deletion records | Contact messages, support history, privacy requests, deletion correspondence. | Retained as needed to document and respond to requests, generally up to three years unless a longer period is required. |
| Security, audit, and diagnostic logs | Error logs, security logs, abuse-prevention records, technical metadata. | Retained for security, debugging, reliability, abuse prevention, and legal needs, generally up to twelve months. |
| Backups and recovery records | Database and system backups maintained by Clarity or providers. | Deleted data may remain in backups for a limited period, generally up to ninety days, until backup rotation removes it. |
| Legal, fraud, or incident records | Records needed for disputes, fraud prevention, security incidents, legal compliance. | Retained only as long as reasonably necessary for the applicable purpose. |
Disconnecting a financial account is different from deleting stored Clarity data. Disconnecting may stop future access through Plaid or another account connection provider, but historical data already stored in Clarity may remain unless removed through product controls or a verified deletion request.
4. User Rights to Deletion
Users may request deletion of eligible account and product data.
Users may request deletion of their Clarity account or product data. Rights and obligations may vary depending on the user's location, the type of data, Clarity's legal status, and applicable exceptions.
Clarity's practices are designed to support privacy principles reflected in applicable laws and frameworks, including data minimization, purpose limitation, storage limitation, transparency, reasonable security, and user rights to access, correct, delete, or restrict certain processing where applicable.
5. How to Request Data Deletion
Deletion requests should use Clarity's published support paths.
Users may request deletion through in-app controls where available, the public Contact page, this Data Retention and Deletion Policy page, or by emailing clarity.rex@gmail.com with the subject Data deletion request.
To protect users, Clarity may take reasonable steps to verify the requester's identity and confirm the scope of the request before deleting data. Users should contact Clarity from the email address associated with their account when possible.
6. Deletion Process and Timeline
Verified requests are processed as reasonably practicable.
After a deletion request is verified, Clarity will delete or de-identify eligible account, financial, assistant, and product records from active systems as reasonably practicable, generally within thirty days unless the request is complex, additional verification is needed, or an exception applies.
Clarity may also revoke or remove related account connection records where supported by the provider and current implementation. Backup and log removal may occur through scheduled retention and rotation rather than immediate deletion.
7. Exceptions to Deletion
Some data may be retained for limited, legitimate reasons.
Clarity may retain limited information when necessary to comply with law, complete security or fraud-prevention work, investigate incidents, resolve disputes, enforce terms, maintain audit or support records, satisfy tax/accounting or platform obligations, debug reliability issues, protect users or the service, or complete backup rotation.
Service providers, including Supabase, Plaid, AI providers, support/contact tools, hosting providers, and analytics or monitoring providers if enabled, may retain information according to their own terms, legal obligations, retention schedules, backup practices, and security requirements.
8. Data Disposal Methods
Clarity uses practical disposal methods for managed cloud systems.
Disposal methods may include deleting rows or objects from Supabase, deleting or de-identifying user-owned records, revoking or removing account connection tokens where supported, removing assistant memory or conversation records where supported, restricting access to retained records, rotating backups according to provider schedules, deleting support records when no longer needed, and requesting provider-side deletion where appropriate and available.
Clarity does not promise instant deletion from backups, logs, or all third-party systems. Where hard deletion is not immediately feasible, Clarity may de-identify, restrict, or segregate data until deletion is completed.
9. Policy Review and Updates
This policy is reviewed as Clarity's product and systems mature.
Pedro Martins, Founder of Clarity, is responsible for implementing and maintaining this policy. Because Clarity is currently a solo-founder product, deletion requests, retention decisions, and provider coordination are handled directly by the founder or by approved service-provider workflows.
This policy will be reviewed at least annually and whenever material changes occur, including major changes to Plaid integration, Supabase architecture, AI processing, data categories, deletion tooling, legal requirements, or service providers.
10. Contact Information
Questions and deletion requests may be sent to Clarity.
For deletion requests, privacy questions, or retention questions, contact Clarity at clarity.rex@gmail.com or use the Contact page.
Please include enough non-sensitive information for Clarity to identify the account and understand the request. Do not include bank credentials, full account numbers, Social Security numbers, one-time codes, API keys, screenshots, CSV files, or sensitive financial documents in public forms or email.
Clarity is currently an early-stage solo-founder product. Retention tracking, access controls, vendor review, and deletion workflows will continue to mature as the product grows.