Privacy policy
ClarionFlow is provided by Quazi Rabbi, Canada ("we"). This policy says what we collect when you use ClarionFlow, why, where it is kept, who else handles it, and how to have it deleted. We do not sell personal information, show advertising, or track you across other companies' apps or websites.
Who decides what happens to your organization's data
ClarionFlow is used by organizations. The documents, conversations and decisions in an organization belong to it, and its administrators decide who is invited and who is deactivated. We process that material to run the service for the organization. If your organization asks us to act on its data, we follow its instructions.
What we collect
Your account
- Your email address, which is how you sign in and how colleagues invite you.
- Your name, if you set one.
- Which organization you belong to and your role in it (member, reviewer or admin).
Sign-in itself is handled by Microsoft Entra External ID: your password is entered on Microsoft's page and never reaches ClarionFlow.
What you and your colleagues put into ClarionFlow
- Documents uploaded to the organization's library, and the text extracted from them for search.
- Your conversations with the assistant, including the threads you open about individual items.
- Actionable items, their review flows, the decisions made on them and any comments left with those decisions, and each item's history.
- Pages the assistant writes for you (artifacts), such as plans, checklists and charts.
Usage and technical information
- How many messages you have sent today, to apply your plan's daily limit.
- Service logs and diagnostics - requests, errors and timings - which we use to keep ClarionFlow working and to fix problems.
On your iPhone
The app keeps your sign-in in the iPhone's secure storage, and keeps a copy of a document you open so it can be shown. Signing out deletes both. The app contains no advertising or third-party analytics.
How the assistant uses your data
When you ask a question, the assistant searches your organization's documents - only your organization's - and sends the question and the relevant passages to a language model hosted in Microsoft Azure to write the answer. Calculations on spreadsheets run in an isolated Azure sandbox. Your content is not used to train models.
Who else handles it
ClarionFlow runs on Microsoft Azure, which processes data on our behalf:
- Azure hosting, database, file storage and search - where everything above is kept;
- Microsoft Entra External ID - sign-in;
- Azure AI Foundry - the language model that writes the assistant's answers;
- Azure Communication Services - invitation emails.
We may also disclose information if the law requires it. We do not otherwise share it.
Where it is kept, and for how long
In Microsoft Azure data centres in the United States (East US 2). Your organization's data is kept while it uses ClarionFlow. Specifically:
- A deleted document is removed from storage and from search immediately.
- When an administrator deactivates someone, they lose access at once. Their conversations, the documents they uploaded, the pages the assistant wrote for them and the decisions they made stay with the organization, because they are the organization's records.
- When an administrator deletes the organization, everything in it is deleted: its people's accounts in it, documents, conversations, actionable items, decisions and artifacts, from storage and from search. Copies remain only in database backups until those expire.
- Database backups are kept for 35 days, and service logs for 30 days.
Deleting your account
Email hello@clarionflow.co from the address you sign in with and ask us to delete your account. We will delete your account and personal information within 35 days and confirm when it is done. Material you contributed to your organization - documents, decisions - belongs to the organization, and its administrators decide what happens to it.
Your rights
Depending on where you live, you may have the right to see the personal information we hold about you, to correct it, to have it deleted, or to object to how it is used. Write to hello@clarionflow.co and we will respond.
Security
Every request is authenticated, and every read is limited to the caller's own organization. Data is encrypted in transit and at rest. No security measure is perfect; if you find a problem, please tell us at hello@clarionflow.co.
Children
ClarionFlow is a workplace tool and is not directed at children under 16.
Changes
If we change this policy we will update the date at the top, and tell organizations' administrators about any significant change before it takes effect.