Back to Home
DATA GOVERNANCE STANDARD
Last Updated: August 19, 2026

Privacy Policy & Data Protection

How CLARIVO safeguards your private health insurance policies, medical estimates, structured intelligence, and personal data.

Core Privacy Commitments at a Glance
Zero Model Training:

Your documents and case data are NEVER used to train, fine-tune, or improve public AI models.

Multi-Tenant Isolation:

Every document is protected by PostgreSQL Row-Level Security (RLS) tied to your cryptographic session.

Autonomous Purge:

Auto-purge deletes case data after 50 days unless explicitly saved under manual retention.

1. Scope, Purpose & Epistemic Philosophy

CLARIVO (“CLARIVO,” “we,” “us,” or “our”) provides an evidence-grounded health insurance decision support platform designed to help policyholders understand policy wordings, audit room rent sub-limits, detect waiting period obligations, and simulate out-of-pocket financial scenarios.

We operate on a philosophy of epistemic honesty and data minimization. We collect only the information strictly required to extract verifiable clauses, evaluate financial exposure, and answer your policy questions.

2. Information We Collect

We process three categories of information in connection with your use of CLARIVO:

A. Authentication & Account Information

When you register, we collect your email address, encrypted authentication credentials managed via Supabase Auth, workspace identifier, and session timestamps. We never collect payment card numbers directly; billing operations (if applicable) are handled by PCI-DSS compliant third-party payment gateways.

B. User-Uploaded Health & Insurance Documents

You may upload PDF and image documents, including Policy Schedules, Policy Wordings, Hospital Pre-Authorization Forms, Discharge Summaries, Medical Diagnostic Reports, and Itemized Hospital Estimates. These documents may contain Protected Health Information (PHI) and Sensitive Personal Data (SPD).

C. Derived Structured Intelligence & Simulation Hypotheses

During document extraction, our deterministic pipeline extracts verbatim clauses, character offsets, page coordinates, and financial parameters (such as Sum Insured, Co-pay percentages, and Room Rent caps). Hypothetical simulation assumptions you test are kept completely isolated in ephemeral memory or workspace state.

3. Absolute Zero-Model-Training Guarantee

Strict Commercial Privacy Binding

CLARIVO guarantees that under no circumstances are your uploaded policy documents, medical records, diagnostic reports, Copilot chat conversations, or simulation parameters used to train, re-train, fine-tune, or evaluate public or proprietary Artificial Intelligence foundation models (including OpenAI, Anthropic, Google, or open-source weights).

Any inference requests sent to large language model sub-processors use zero-data-retention (ZDR) enterprise APIs where data is processed ephemerally in RAM and discarded immediately upon completion of response generation.

4. Security Architecture & Multi-Tenant RLS

Our persistence layer utilizes defense-in-depth architectural guarantees verified through automated regression suites:

  • PostgreSQL Row-Level Security (RLS): Every database row in all 28 tables enforces strict tenant-isolation policies matching workspace_id = get_user_workspace_id(). No tenant can query or mutate records belonging to another workspace.
  • Private Object Storage: Document binaries are stored in private Supabase Storage buckets with randomized UUID file keys. Cross-tenant path traversal and unsigned direct downloads are cryptographically rejected.
  • Encryption in Transit and at Rest: All web traffic is encrypted via TLS 1.3. Persistent database tables and storage volumes are encrypted at rest using AES-256 standards.
  • Log Telemetry Redaction: Our server-side observability engine automatically strips diagnostic names, claim monetary values, bearer tokens, passwords, and signed URLs from all structured system logs.

5. Data Retention & Cascade Deletion Lifecycle

CLARIVO provides explicit user-controlled data lifecycles to prevent stale medical records from lingering on the cloud:

Auto-Purge (50 Days Default)

Standard insurance investigation cases are scheduled for automatic deletion 50 days after creation. Once expired, all documents, structured facts, and conversation history are permanently purged.

Manual Retention Mode

Users who wish to retain active multi-year policies can toggle Manual Retention in Case Settings, preserving their analysis until explicit deletion is requested.

Immediate Cascade Erasure: When you delete a document or delete an entire case, CLARIVO executes an immediate multi-layer cascade deletion removing the physical storage binary, database records, derived intelligence vectors, and memory snapshots in a single transactional operation.

6. User Rights & Legal Protections

In accordance with global data protection laws (including the Digital Personal Data Protection Act (DPDP), GDPR, and California Consumer Privacy Act (CCPA)):

Right to Access & Portability: You can export full case intelligence packages, financial diff breakdowns, and extracted clause quotes at any time.
Right to Erasure (“Right to be Forgotten”): You can permanently wipe your account and all associated cases instantly with one click.
Right to Rectification: You can override extracted policy facts or modify user-stated attributes whenever an insurer amends their terms.

7. Data Protection Officer & Privacy Inquiries

If you have questions regarding this Privacy Policy, your rights under data protection legislation, or wish to exercise data subject rights, please contact our Data Governance & Privacy Office:

CLARIVO Systems Inc. — Data Protection Office
Email: privacy@clarivo.ai / dpo@clarivo.ai
Response SLA: Within 48 business hours