Your documents and case data are NEVER used to train, fine-tune, or improve public AI models.
Every document is protected by PostgreSQL Row-Level Security (RLS) tied to your cryptographic session.
Auto-purge deletes case data after 50 days unless explicitly saved under manual retention.
1. Scope, Purpose & Epistemic Philosophy
CLARIVO (“CLARIVO,” “we,” “us,” or “our”) provides an evidence-grounded health insurance decision support platform designed to help policyholders understand policy wordings, audit room rent sub-limits, detect waiting period obligations, and simulate out-of-pocket financial scenarios.
We operate on a philosophy of epistemic honesty and data minimization. We collect only the information strictly required to extract verifiable clauses, evaluate financial exposure, and answer your policy questions.
2. Information We Collect
We process three categories of information in connection with your use of CLARIVO:
A. Authentication & Account Information
When you register, we collect your email address, encrypted authentication credentials managed via Supabase Auth, workspace identifier, and session timestamps. We never collect payment card numbers directly; billing operations (if applicable) are handled by PCI-DSS compliant third-party payment gateways.
B. User-Uploaded Health & Insurance Documents
You may upload PDF and image documents, including Policy Schedules, Policy Wordings, Hospital Pre-Authorization Forms, Discharge Summaries, Medical Diagnostic Reports, and Itemized Hospital Estimates. These documents may contain Protected Health Information (PHI) and Sensitive Personal Data (SPD).
C. Derived Structured Intelligence & Simulation Hypotheses
During document extraction, our deterministic pipeline extracts verbatim clauses, character offsets, page coordinates, and financial parameters (such as Sum Insured, Co-pay percentages, and Room Rent caps). Hypothetical simulation assumptions you test are kept completely isolated in ephemeral memory or workspace state.
3. Absolute Zero-Model-Training Guarantee
CLARIVO guarantees that under no circumstances are your uploaded policy documents, medical records, diagnostic reports, Copilot chat conversations, or simulation parameters used to train, re-train, fine-tune, or evaluate public or proprietary Artificial Intelligence foundation models (including OpenAI, Anthropic, Google, or open-source weights).
Any inference requests sent to large language model sub-processors use zero-data-retention (ZDR) enterprise APIs where data is processed ephemerally in RAM and discarded immediately upon completion of response generation.
4. Security Architecture & Multi-Tenant RLS
Our persistence layer utilizes defense-in-depth architectural guarantees verified through automated regression suites:
- PostgreSQL Row-Level Security (RLS): Every database row in all 28 tables enforces strict tenant-isolation policies matching
workspace_id = get_user_workspace_id(). No tenant can query or mutate records belonging to another workspace. - Private Object Storage: Document binaries are stored in private Supabase Storage buckets with randomized UUID file keys. Cross-tenant path traversal and unsigned direct downloads are cryptographically rejected.
- Encryption in Transit and at Rest: All web traffic is encrypted via TLS 1.3. Persistent database tables and storage volumes are encrypted at rest using AES-256 standards.
- Log Telemetry Redaction: Our server-side observability engine automatically strips diagnostic names, claim monetary values, bearer tokens, passwords, and signed URLs from all structured system logs.
5. Data Retention & Cascade Deletion Lifecycle
CLARIVO provides explicit user-controlled data lifecycles to prevent stale medical records from lingering on the cloud:
Auto-Purge (50 Days Default)
Standard insurance investigation cases are scheduled for automatic deletion 50 days after creation. Once expired, all documents, structured facts, and conversation history are permanently purged.
Manual Retention Mode
Users who wish to retain active multi-year policies can toggle Manual Retention in Case Settings, preserving their analysis until explicit deletion is requested.
Immediate Cascade Erasure: When you delete a document or delete an entire case, CLARIVO executes an immediate multi-layer cascade deletion removing the physical storage binary, database records, derived intelligence vectors, and memory snapshots in a single transactional operation.
6. User Rights & Legal Protections
In accordance with global data protection laws (including the Digital Personal Data Protection Act (DPDP), GDPR, and California Consumer Privacy Act (CCPA)):
7. Data Protection Officer & Privacy Inquiries
If you have questions regarding this Privacy Policy, your rights under data protection legislation, or wish to exercise data subject rights, please contact our Data Governance & Privacy Office: