ClariZest澄知

Privacy and data governance

Privacy notice candidate

A plain-language candidate describing intended data practices and the boundary between the current engineering build and a future production service.

1. Scope and release status

This candidate covers the planned public portal, native iPhone, iPad and Mac apps, account center, optional encrypted sync, AI tasks, and support. Customer-controlled private deployments require separate role and privacy terms.

The current Portal is an engineering candidate. It does not establish a production domain, legal operator, cloud region, payment service, support operation, or launch in any country. The notice must be replaced or activated only after review against the real production data flow.

Current modeEngineering candidate
Engineering candidateSuitable for development and review, not production use.
Legal effectNot configured
Not in effectBrowsing this candidate does not create acceptance.
Production operatorProduction confirmation required
To be confirmedLegal name, address, and contacts are release requirements.
Launch regionsProduction confirmation required
To be confirmedAvailability, data locations, and transfer mechanisms require regional review.

2. Information the service may handle

  • Account and security data, such as account identifiers, authentication results, region, trusted devices, and security events.
  • User content and Context, including text, images, audio, files, links, and system-proposed classifications or summaries that remain candidates until confirmed.
  • Encrypted sync identifiers, cursors, versions, errors, and necessary diagnostics when sync is enabled. The design goal is to keep plaintext local by default.
  • Only the content and instructions a user selects for a specific AI task, together with routing, authorization, and result records. Providers, regions, retention, and training choices must be disclosed before activation.
  • Entitlements, store transaction identifiers, refund or support requests. Full payment credentials are generally handled by the store or payment provider, subject to production verification.
  • Information about other people contained in user content. Users must have authority to keep and use it and should select the minimum necessary scope before sharing.

3. Portal, cookies, and telemetry

The current Portal source does not configure advertising SDKs, third-party behavioral analytics, or marketing cookies. Production hosting may create access, security, CDN, or availability logs. Those services are not yet confirmed, so the current source must not be read as a final production disclosure.

Before launch, ClariZest must publish the actual cookie and SDK inventory, purpose, provider, duration, and controls. Optional analytics or marketing must not be silently enabled.

4. Purposes and legal grounds

  • Provide capture, organization, browsing, sync, export, deletion, account security, and support requested by the user.
  • Protect accounts, devices, content, and services from abuse, attacks, faults, and unauthorized access.
  • Improve product quality where the required choice or authorization has been obtained.
  • Meet applicable legal duties or respond to valid lawful requests while preserving review and objection records.
  • Consent, contractual necessity, legal obligation, or another permitted basis may apply depending on the region and data item. A production notice must map these precisely rather than rely on one blanket authorization.

5. Local, sync, AI, and international boundaries

Local libraryEngineering candidate
Design baselineThe native apps prioritize an encrypted local library. App removal, local erasure, and account deletion are separate actions.
Hosted syncEngineering candidate
Optional candidateProduction regions, key custody, backup, and recovery still require validation.
AI processingProduction confirmation required
Per-task choiceOnly selected task content should leave the device; no production provider disclosure exists yet.
International transfersNot configured
Not configuredNo launch region or transfer mechanism is claimed by this candidate.

6. Sharing, processors, and publication

ClariZest is not designed to sell private user Context or use it for third-party targeted advertising. A production notice must still apply each region's legal definitions and controls accurately.

Infrastructure, identity, AI, payment, support, and monitoring vendors are not final. This candidate does not invent a processor list. Real providers, purposes, regions, and contractual protections must be published before launch. User content should not become public without an explicit user action.

7. Retention, backup, and deletion

  • Local content is managed on each device. Deleting a cloud copy does not remotely erase offline local copies.
  • Account, sync, support, security, billing, and legally required records may have different retention periods. No production schedule is currently promised.
  • A request must show its real submitted, verified, processing, action-needed, and completed states.
  • Backups and immutable security records may expire on defined schedules that must be disclosed with exceptions before launch.
  • Deleting the app is not deleting the account, and deleting the account may not automatically cancel an App Store subscription.

8. Rights and choices

Depending on the applicable law and circumstances, people may have rights to notice, access, copy, portability, correction, deletion, withdrawal, restriction, objection, account deletion, and appeal. Core export, deletion, and exit controls are not intended to depend on a paid tier.

The engineering candidate now provides full-account deletion from the native apps and account center, authenticated-session verification, shared-space ownership blockers, resumable status, cancellation before the irreversible phase, and identity closure through a controlled provider adapter. Production validation against the real identity provider, regional timing rules, and completion notices remains required. Local-device erasure and store-subscription cancellation remain separate user-managed actions.

9. Security, children, and changes

  • Local encryption, minimum disclosure, provenance, permission isolation, and auditable states are design goals, not certifications or absolute-security promises.
  • The service should not offer independent accounts directly to children below the applicable regional age. Family Context may include minors and needs guardian, authorization, and deletion rules.
  • Material changes should identify what changed, when it applies, and what choices users have. A silent update must not retroactively expand prior data uses.
  • Production privacy contacts, complaint channels, and any required representative or data protection officer are not configured.

10. Release-review references

These official references support product and engineering review. They do not establish compliance and are not a substitute for legal advice.