← Back to site

Privacy Policy

Last updated: June 23, 2026

Clearbase Software ("Clearbase," "we," "our," or "us") builds privacy-first software, including Whispr (an AI interview and meeting copilot) and Clearbase Vault (a local password manager). This Privacy Policy explains what information we collect, how we use and protect it, and the choices and rights you have. It applies to our websites, applications, and related services (the "Services").

Our approach in plain terms. We do not sell your personal information. We do not run third-party advertising or behavioral trackers. We collect the minimum needed to run the Services, and we design our products so that your most sensitive data, such as meeting audio and vault contents, stays on your device.

1. Information we collect

Information you provide

Information created through use of the Services

Information collected automatically

We use privacy-respecting, cookieless website analytics that measure aggregate metrics like page views and do not build a profile of you across sites. We do not use advertising cookies or third-party tracking pixels.

Cookies and local storage

We use only strictly necessary storage, such as authentication tokens kept in your browser's local storage to keep you signed in. We do not use non-essential or advertising cookies.

2. How we use information

We use the information we collect to provide, operate, and maintain the Services; create and secure your account and authenticate you; process payments and manage subscriptions; provide support and respond to your requests; send essential service communications such as email verification, password resets, security notices, and billing notices; detect, prevent, and address security incidents, fraud, and abuse; comply with legal obligations; and improve the reliability and performance of the Services. Where applicable law requires a legal basis, we rely on performance of our contract with you, our legitimate interests in operating and securing the Services, your consent, and compliance with legal obligations.

3. AI processing and model providers

Whispr generates answers using third-party large language model providers. As of the date above, we use Cerebras (United States) as our primary provider, with Google's Gemini API as a fallback. Only the text needed to answer your current request is sent to the provider. We use providers' paid API tiers and configure them so that your inputs are not used to train their models, subject to each provider's terms. We never send your raw audio, and we do not attach your name or account identity to the content sent for inference.

4. How we share information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only as follows:

5. Sub-processors

We rely on a small set of vendors to operate the Services. Each processes data only as needed to provide its service to us.

ProviderPurposeLocation
CerebrasAI inference for Whispr answersUnited States
Google (Gemini API)Fallback AI inferenceUnited States
RenderApplication hostingUnited States
NeonManaged database for account dataUnited States
ResendTransactional email deliveryUnited States
CloudflareDNS, content delivery, cookieless analyticsGlobal
PolarPayment processing and merchant of record for paid plansGlobal

6. Data retention

We keep account information for as long as your account is active and as needed to provide the Services. We retain certain records longer where required for legal, tax, accounting, security, or dispute-resolution purposes. Security and sign-in logs, including IP addresses, are retained for a limited period for abuse prevention and then automatically deleted. Short-lived items, such as email-verification and password-reset tokens, expire automatically. When you delete your account, we delete or de-identify the associated personal information, including your security and sign-in logs, except where we are required or permitted to retain it.

7. Data security

We use technical and organizational measures appropriate to the risk, including encryption in transit using HTTPS and TLS, encryption of vault contents on your device, storage of passwords only as salted bcrypt hashes, signed authentication tokens, access controls, and a local-first product design that keeps your most sensitive data off our servers. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Your rights and choices

You can access and update your profile, export the data associated with your account as a file, and permanently delete your account at any time from your account settings. You can opt out of non-essential marketing messages using the unsubscribe link or by contacting us; we will still send essential service messages.

To exercise any right, use your account settings or contact us at [email protected]. We will verify your request and respond within the time required by applicable law.

9. International data transfers

We are based in the United States, and our service providers may process information in the United States and other countries. Where we transfer personal data from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses.

10. Children's privacy

The Services are not directed to children, and we do not knowingly collect personal information from anyone under 16, or the minimum age required by your local law. If you believe a child has provided us personal information, contact us and we will delete it.

11. Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will update the "Last updated" date and, where appropriate, provide additional notice. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.

12. Contact us

Questions or requests about this Policy or your personal information: [email protected]. Clearbase Software, New Jersey, USA.