/ legal

Privacy Policy

Last updated: September 3, 2026

This Privacy Policy explains how Claorova (“Claorova,” “we,” “us,” or “our”) collects, uses, shares, and protects information in connection with our website at claorova.com and our digital services (together, the “Services”). By creating an account, starting a trial, paying through our checkout, or otherwise using the Services, you agree to this Privacy Policy and our Terms of Service. If you do not agree, please do not use the Services.

1. Who we are and how to contact us

Claorova is a digital studio operating in the United States. For any privacy question or request, email us at selsaady@claorova.com.

2. Scope

This policy applies to information we process through the Services. It does not apply to third-party websites, products, or services that we do not control, even if we link to them.

3. Information we collect

We collect user data. Depending on how you use the Services, we may collect personal information, business information, usage information, payment-related records, files you upload, communications you send us, and other information you choose to provide or that is generated through your use of the Services.

Contact and project information

When you email us, book a call, request a proposal, or become a client, we may collect your name, contact details, company information, project requirements, communications, and materials you choose to provide for the engagement.

Account, billing, and subscription information

When you sign up for Firm OS, the Bookkeeping Suite, or another paid service, we may collect account identifiers, organization details, billing email, subscription status, invoices, and limited payment records needed to operate the service. Payment details are entered directly with Stripe. Claorova does not receive or store full card numbers.

Usage and log data

Our hosting provider automatically records standard technical information when you use the Services, such as IP address, browser and device type, pages requested, and timestamps. We use this for security, diagnostics, and to keep the Services running.

Cookies

We use only necessary storage for core site functionality. We do not use advertising or third-party tracking cookies. Your language preference may be stored locally in your browser. See “Cookies” below.

Files and workspace content

When you use Firm OS, client portals, document uploads, messaging, exports, or related features, we may collect and store the files, messages, metadata, and other content you or your authorized users submit.

4. How we use information

5. Artificial intelligence processing

Some Services use artificial intelligence to read, classify, summarize, generate, route, or otherwise process information you submit. This may include statements, files, transaction descriptions, client details, custom categories, instructions, and related workspace content.

We use AI to provide the requested workflow, maintain the service, prevent misuse, and troubleshoot support requests. We do not use customer submissions to train Claorova models. AI processing may be performed by Claorova and by third-party AI providers acting on our instructions.

AI features are not crisis, medical, legal, tax, accounting, or mental health services. They are not designed to detect, prevent, or respond to self-harm, suicide, abuse, or other emergencies. If you or someone else may be in danger, contact local emergency services or a qualified professional immediately. Do not rely on the Services for crisis support.

6. Third-party applications and service providers

We may provide your data to other applications, integrations, and service providers that help us run the Services, and only as needed for them to perform their function. These third parties may collect, store, or process information on our behalf.

If you connect a third-party account or integration, information may also be shared with that provider according to your authorization and that provider's own terms and privacy practices.

Google account data and Gmail sending

When an authorized Firm OS owner connects a Google account, Claorova receives the account's email address and OAuth authorization tokens. Firm OS uses the requested Gmail send permission only to send firm-branded messages that an authorized user asks the Service to send. This outbound-only connection does not read mailbox contents, contacts, or message history.

OAuth tokens are encrypted at rest and are available only to the server-side connection for the organization that authorized them. We retain the connected account identity, authorization state, and limited submission records for as long as needed to provide, secure, and troubleshoot the sending feature. An organization owner can disconnect the account in Firm OS, revoke access from the Google Account permissions page, or request deletion by contacting selsaady@claorova.com.

We do not sell Google user data, use it for advertising, determine creditworthiness, or use it to train generalized artificial intelligence models. We do not allow people to read Google user data except when the user has affirmatively authorized support for a specific message, when necessary to investigate abuse or a security incident, or when required by law. Any transfer to an infrastructure provider is limited to operating the user-facing sending feature under our instructions.

Claorova's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

We never sell your personal information or use it for advertising.

We may also disclose information if required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets.

7. Storage and public buckets

We store information using reputable cloud infrastructure providers. Some files may be stored in private object storage accessible only through authenticated application requests. In certain cases, including when a feature requires a shareable or deliverable asset, files may be stored in a public storage bucket or otherwise made accessible through a public URL controlled by the Services or by an authorized user.

You are responsible for what you upload and for sharing links only with intended recipients. Do not upload sensitive information to a public location unless you intend for it to be accessible that way.

8. Data retention and deletion

We retain contact, communication, project, and business records only as long as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. Hosting logs are retained according to our infrastructure providers’ operational policies.

You can request deletion of associated personal information by emailing selsaady@claorova.com. We will honor verified requests to the extent required by applicable law.

Payment-method retention and deletion are handled by Stripe and may be subject to Stripe’s legal, fraud-prevention, and financial-record retention obligations. You can update or remove a saved payment method through the billing portal, subject to any active subscription or invoice that requires a valid method.

9. Security

We use reasonable technical and organizational measures to protect your information, including encryption in transit (HTTPS/TLS), reputable infrastructure providers, and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. International data transfers

We and our service providers are based in the United States and may process information in the United States and other countries. Where required, we rely on appropriate safeguards for such transfers. By using the Services, you understand your information may be processed in the United States.

11. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, email selsaady@claorova.com. We will not discriminate against you for exercising your rights.

EEA/UK (GDPR): you may have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your supervisory authority. California (CCPA/CPRA): you may have rights to know, delete, correct, and opt out of the “sale” or “sharing” of personal information. We do not sell or share personal information as those terms are commonly understood.

12. Children

The Services are not directed to individuals under 18, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us and we will delete it.

13. Cookies

We use only storage necessary for core site functionality, such as remembering language preferences. We do not use advertising, marketing, or third-party analytics cookies. You can control cookies and local storage through your browser settings.

14. AI credits and payment methods

A paid trial or subscription may require a payment method for the disclosed charge after the trial. The saved payment method may also be presented for optional AI credit packs if Claorova makes them available. We will show the applicable price and quantity and require the authorized account owner to confirm that purchase before charging the saved method. Saving a card during signup does not by itself authorize an unspecified future AI-credit charge.

15. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above. Material changes will be indicated as appropriate. Your continued use of the Services after an update means you accept the revised policy.

16. Contact

Questions about this policy or your information? Email selsaady@claorova.com.

This document is provided as general information and is not legal advice.