Privacy Policy
1. Who we are
"MeetClara" (the "App", "we", "us") is operated by Alex Koby (sole proprietor). The App is a service that places scheduled, AI-driven phone calls to a "loved one" (typically a parent or grandparent) on behalf of a "buyer" (typically an adult family member). The buyer reviews recorded calls, transcripts, and AI-extracted summaries from a mobile dashboard.
2. Who can use MeetClara
MeetClara is intended for use by adults age 18 and over. We do not knowingly collect data from anyone under 18. If you believe a minor has provided data to us, contact us and we will delete it.
3. The people involved
MeetClara is unusual: the person paying for the service ("buyer") is not always the person being called ("loved one"). Both are covered by this policy — as are care-team members the buyer invites (§6).
- Buyer: the family member who installs the App, creates an account, schedules calls, and reviews recordings.
- Loved one: the person Clara (our AI) calls. The loved one is not required to install anything. Their phone rings; Clara introduces herself as calling on behalf of their family member (see §5 on recording).
4. Data we collect
From the buyer (when you sign up + use the App)
| Category | Examples | Why we collect it |
|---|---|---|
| Email address | you@example.com | Account login (one-time codes), care-team invites, support |
| Google / Apple identity (optional) | Name + email from your Google or Apple account if you use Sign in with Google or Sign in with Apple | Account creation and login |
| Phone number (optional) | +1 555 123 4567 | Account contact, account recovery |
| Name + relationship | "Alex", "Daughter" | Personalize emails + dashboard |
| Profile photo (optional) | Avatar uploaded to Supabase Storage | Personalize dashboard |
| Loved-one details you enter | Name, phone, relationship, life context, photos | Required to call them and personalize the conversation |
| Coarse location (optional) | City of the loved one (resolved via Google Places) | "Margaret in Louisville, KY" personalization in the dashboard and call prompts |
| Authentication tokens | Issued by Supabase Auth on sign-in | Keep you signed in; protected on-device by the operating system |
| Nothing from your microphone | The App may request microphone permission (required by the audio session used for Listen In playback) — we never capture audio from your device | — |
| Server-side error reports | Error details from our servers when something breaks (configured to exclude message content and to minimize personal identifiers) | Diagnose failures and regressions |
From the loved one (during a phone call)
| Category | Examples | Why we collect it |
|---|---|---|
| Voice recording | Lossless FLAC of the full conversation | Buyer's review on the dashboard. AI summary + memory extraction |
| Transcript | Text of what was said by the loved one and by Clara | Buyer review, AI processing |
| Conversation content | Whatever the loved one chooses to share — childhood memories, wellness signals, family stories, opinions | Memory extraction, buyer review |
| Sentiment / wellness signals | Computed mood score, "red flags" (e.g. mentions of falls or distress) | Surfaced to the buyer as a "wellness pulse" |
| Phone number | Already provided by the buyer; not separately collected from the loved one | Required to dial the call |
We do not collect:
- The loved one's email
- The loved one's location beyond the city the buyer entered
- Any data outside of the scheduled phone call (we do not access the loved one's contacts, calendar, microphone, or any device data — they are not running the app)
5. Call recording (important)
Every Clara call is recorded — audio and transcript. That is the heart of the service: the recording is what lets your family listen to the conversation and keep the stories. On a first call, Clara introduces herself as calling on behalf of the buyer. The loved one can hang up at any time; the recording stops the moment the call ends.
Buyers are responsible for recording consent. Call recording laws vary by state and country, and some places require the consent of everyone on the call. By scheduling calls, you confirm that you have told your loved one that these calls are recorded and that they have agreed, to the extent your local law requires their consent. If a loved one does not want to be called or recorded, remove their profile in the App (which stops all future calls) — and email privacy@meetclara.org to have existing recordings deleted.
6. How we use your data
Buyer data
- Authenticate you and protect your account.
- Show you the dashboard, transcripts, summaries, recordings.
- Send service emails (sign-in codes, care-team invites). We do not send marketing email.
Loved-one data
- Generate the AI conversation in real time (we send live audio to a speech-to-text vendor and recent transcript to a large language model — see §7).
- Produce a written summary, sentiment score, and "memories" after the call ends (an LLM processes the transcript).
- Display all of the above to the buyer in the App.
Sharing within your family (care team)
- The buyer can invite other family members or trusted people to their care team. Active care-team members can see the loved one's data in the App — including recordings, transcripts, summaries, notes, and schedules — until the buyer removes them.
- Invitations must be accepted from a signed-in account matching the invited email address. Only invite people you trust with this access.
Aggregated, non-personal use
- We compute non-identifying performance metrics across all calls (e.g. average call duration, transcription latency) to debug and improve the service. None of this is shared externally.
7. Third-party services we share data with
We use the following processors. Each one receives only the data necessary to do its job. None resell your data.
| Vendor | What they receive | Purpose |
|---|---|---|
| Supabase (Inc., USA) | Account data, profiles of loved ones, transcripts, summaries, audio file references, vector embeddings | Database, authentication, file storage |
| Twilio (Inc., USA) | Loved-one phone number; live audio stream during the call | Place + receive the phone call |
| Deepgram (Inc., USA) | Live audio stream; recorded audio for post-call transcription | Real-time + batch speech-to-text (AssemblyAI Inc. or OpenAI LLC serve as automatic fallbacks if Deepgram is unavailable) |
| ElevenLabs (Inc., USA) | Text of Clara's responses | Synthesize Clara's voice (Cartesia Inc., USA is a supported alternate provider) |
| OpenAI (LLC, USA) / Google (LLC, USA) / Anthropic (PBC, USA) | Recent transcript + system prompt; memory and transcript passages, and your search queries, for embedding generation (Google) | Generate Clara's conversational responses; post-call summary; memory extraction and search |
| OpenRouter (Inc., USA) | Transcripts, conversation history, and profile context sent to certain of the language models above | API gateway that routes some of our LLM requests (e.g. to Anthropic models) |
| Railway (Corp., USA) | All data our backend processes, including live call audio in transit and transcripts in memory | Hosts our servers |
| Resend (Inc., USA) | Your email address; the content of sign-in-code and care-team-invite emails (invites can include short excerpts from the loved one's calls) | Transactional email delivery |
| LiveKit (Inc., USA) | A copy of the live call audio during calls, when our "Listen In" service is enabled | Lets a buyer listen to a call in real time from their app (listening itself is buyer-initiated) |
| Google Places API (Google LLC) | City name typed by the buyer during onboarding | City autocomplete |
| Google / Apple (as identity providers) | The fact that you signed in to MeetClara with their account system | Sign in with Google / Sign in with Apple |
| Sentry (Inc., USA) | Error reports from our servers — configured conservatively: no conversation content, no request bodies, personal identifiers excluded where possible. Not enabled inside the app on your device. | Crash + error reporting |
| Vercel (Inc., USA) | Standard web-server logs (IP address, browser info) when you visit meetclara.org pages, including invite links | Hosts this website |
| EAS / Expo (Inc., USA) | App build artifacts; no end-user data | App build + distribution |
We have signed standard data-processing agreements with each vendor where available. We do not sell or rent personal data to advertisers, brokers, or any other party.
8. Where data is stored
- Audio recordings: Supabase Storage (S3-backed), private bucket, signed URLs only. Servers are in U.S. regions.
- Database rows (transcripts, summaries, profiles, memories): Supabase Postgres, U.S. region, encrypted at rest.
- Photos (profile photos and photos of your loved one): Supabase Storage; currently served via addressable URLs rather than signed links.
- On-device data (your auth session): protected by the operating system's security features.
- In-flight audio during a call: passes through our telephony and speech vendors (§7) and our servers. The lasting copies are the recording files in Supabase Storage (a lossless original and a playback copy); transient working copies on our servers are cleaned up after processing — and if archiving fails, a copy is retained on our servers until it can be recovered.
9. How long we keep your data
| Data | Retention |
|---|---|
| Active account data + recordings | Until your account is deleted on request (below) |
| Recording access audit log (who played which recording, when, from where) | While the account is active — it exists to protect the recordings; retained in pseudonymized form afterward |
| Authentication logs | Retained by our authentication provider for a limited period for fraud/abuse investigation |
| Aggregated, non-identifying metrics | Indefinitely (no personal data) |
To permanently delete your entire account — including all profiles, recordings, and transcripts — email privacy@meetclara.org from your account email address. Deletion completes within 30 days. (An in-app deletion flow is on our roadmap; until it ships, email is the way.)
10. Your rights
Depending on where you live, you have the right to:
- Access the personal data we hold about you.
- Correct inaccuracies.
- Delete your data.
- Export a machine-readable copy of your data.
- Opt out of any non-essential data sharing (we already don't do any).
To exercise these rights, email privacy@meetclara.org. We respond within 30 days. If you live in California (CCPA/CPRA) or the European Economic Area / UK (GDPR), the same rights apply with the deadlines those laws impose.
11. Security
We use industry-standard practices to protect your data:
- All transport over TLS 1.2+ (HTTPS, WSS).
- Authentication sessions protected on-device by the operating system's security features.
- Database access enforced by row-level security: data is visible only to the account that created it and to care-team members that account has invited (§6).
- Vendor and database credentials (API keys, service keys) are server-side only; the app on your device never holds them — only your own sign-in session.
- Recording access is logged — each time a playback link is created: who, for which recording, when, and from where (§9).
We are a small team and do not yet have SOC 2 or HIPAA attestations. We make security decisions conservatively but cannot promise an attack will never succeed. If we discover a breach affecting your data, we will notify you within 72 hours.
12. Children's privacy
MeetClara is not intended for, marketed to, or knowingly used by anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us immediately and we will delete it.
13. Changes to this policy
If we materially change how we collect or use data, we will email you at least 30 days before the change takes effect, and update the "Last updated" date above. Continued use of the App after the change constitutes acceptance.
14. Contact
| Reason | Contact |
|---|---|
| Privacy questions, data requests | privacy@meetclara.org |
| Security disclosure | security@meetclara.org |
| General support | support@meetclara.org |