Privacy Policy

Last updated: March 21, 2026

1. Introduction

Clera ("we", "our", "us") is an AI-powered self-improvement platform that helps you track and improve your appearance and wellness. This Privacy Policy explains how we collect, use, store, and protect your personal data in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

2. Data We Collect

We collect the following categories of data:

  • Account information: email address and authentication data when you create an account
  • Photos: selfie photos you upload for AI analysis. Under GDPR, facial analysis constitutes biometric data processing
  • Analysis results: appearance scores, category breakdowns, and personalized improvement tips generated by AI
  • Wellness data: quiz responses, daily logs, goals, and check-in streaks
  • Payment information: processed securely by Stripe; we do not store credit card numbers
  • Usage data: credit balance and transaction history

3. How We Use AI to Analyze Your Photos

When you upload a selfie, we use AI models to analyze facial features and provide appearance scores. This processing constitutes biometric data processing under GDPR Article 9 and requires your explicit consent before any analysis takes place.

We process your photos solely to provide you with personalized appearance feedback. Your photos are never used to train AI models, and analysis results are stored only in your account.

4. Data Storage and Security

  • Photos are stored in encrypted, private storage buckets
  • All data is transmitted over HTTPS
  • Authentication is managed through Supabase with industry-standard security practices
  • Access to your data is restricted to your authenticated account

5. Third-Party Services

We use the following third-party services to operate Clera:

  • OpenAI: for AI-powered photo analysis and generating improvement recommendations
  • fal.ai: for AI image generation features (glow-up previews)
  • Stripe: for secure payment processing
  • Supabase: for authentication, database, and file storage

These services process data on our behalf and are bound by their respective privacy policies and data processing agreements.

6. Your Rights

Under GDPR, you have the right to:

  • Access: request a copy of all data we hold about you via the data export feature
  • Deletion: permanently delete your account and all associated data
  • Export: download your data in a machine-readable format (JSON)
  • Withdraw consent: withdraw your consent for photo analysis at any time by deleting your account
  • Object: object to certain types of data processing
  • Rectification: request correction of inaccurate personal data

7. Data Retention

We retain your data for as long as your account is active. When you delete your account, all data including photos, analysis results, wellness data, and payment history is permanently and irreversibly removed from our systems. We do not retain backups of deleted accounts.

8. Legal Basis for Processing

  • Consent (Art. 6(1)(a)): for biometric data processing (photo analysis)
  • Contract (Art. 6(1)(b)): for providing the core service features
  • Legitimate interest (Art. 6(1)(f)): for service improvement and security

9. Contact

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:

privacy@clera.app

Clera