Privacy Policy
Effective date: 26 June 2026 · Version 2026-06-26
This Privacy Policy explains how personal data is collected and processed in connection with CLEAR, a self-serve platform that helps organizations analyze behaviour-change challenges. It is written to the EU/EEA baseline (the GDPR, the ePrivacy rules on cookies, and the EU AI Act).
1. Who we are
CLEAR is operated by Erik Bohjort, trading as EB Consulting (eb-consulting.se), a psychology-led consultancy based in Stockholm, Sweden. For personal data where we decide the purposes and means of processing, we are the data controller. You can reach us about any privacy matter at [email protected].
Controller vs. processor. We are the controller for data about our account holders and our website (account & identity, authentication, billing, and consent-based website analytics). For the content a customer puts into the platform to obtain an analysis — project briefs, stakeholder details, uploaded documents, and respondent contributions — the customer organization is the controller and we act as their processor, handling it only to provide the service on their instructions. The customer is responsible for having a lawful basis and for informing the people concerned; the terms of that relationship are set out in a Data Processing Agreement (available on request).
2. The personal data we process
- Account & identity. Your name and email address, authentication identifiers, and the timestamp and version of your acceptance of this policy.
- Project content. The behaviour-change challenge you describe, target group and use case, timeline, stakeholder names and roles, and any documents you upload (PDF, DOCX, XLSX, MD, TXT, CSV) plus the text extracted from them. Free-text and documents may contain personal data about third parties, chosen by the customer.
- Voice dictation (transcript only). If you use the optional in-browser dictation, the Web Speech API runs in your browser and only the resulting text reaches our servers — no audio file is recorded or sent.
- Respondent contributions. An invited respondent’s email, optional name, free-text answers, reactions/notes, and any optional uploads.
- AI outputs. The structured analysis generated for a project, stored on the customer’s behalf.
- Billing. Your Stripe customer and subscription identifiers, plan tier and status. Card details are handled by Stripe and never reach our servers.
- Enquiry & marketing data. When you submit a contact, consultation, assessment, book, or whitepaper form, the details you provide — typically name, email, organisation, role, and message.
- Website analytics. Where you consent, pseudonymous usage events, page views, and a transient (truncated) IP address.
We do not buy personal data about you, and we do not sell your personal data.
3. Why we process it, and our legal bases
- To provide the service — create and secure your account, run the CLEAR analysis you request, store your projects, and enable respondent collaboration. Legal basis: performance of a contract (and legitimate interests for security).
- To take payment and keep accounting records. Legal basis: contract and legal obligation (Swedish bookkeeping law).
- To respond to enquiries and send updates you ask for. Legal basis: consent or our legitimate interest in answering you.
- To secure and improve the service and prevent abuse. Legal basis: legitimate interests, balanced against your rights.
- Website analytics and advertising measurement. Legal basis: consent — no non-essential tracker loads until you opt in.
For third-party personal data inside customer content, the customer is the controller and relies on its own legal basis; we process it as a processor on the customer’s instructions. We do not make solely-automated decisions that produce legal or similarly significant effects about you.
4. Special-category data
CLEAR is a tool for organizational strategy and behaviour change and does not require special-category data (such as data about health, ethnicity, political opinions, religion, trade-union membership, or biometric data). Please do not upload or enter special-category data unless you have your own valid lawful basis under GDPR Art. 9 and instruct us accordingly; any such processing is performed by us strictly as a processor on your documented instructions.
5. How we use AI
The CLEAR analysis is produced with Anthropic’s Claude models, used for inference only. The project details, extracted document text, and respondent contributions relevant to a run are sent to Anthropic server-side to generate your report; under Anthropic’s commercial terms this content is not used to train its models. Where you enable the optional research feature, search queries derived from your project may be sent to web search and content providers. A de-identified summary of a research finding may, only after a project owner reviews and approves it, be added to a shared knowledge base that improves analyses across projects; de-identification is designed to remove personal identifiers, though we cannot guarantee removal in every case.
AI transparency. CLEAR outputs are AI-generated and may be inaccurate or incomplete. They are decision-support — not professional, legal, medical, or financial advice — and should be reviewed and validated by a competent person before being acted upon. No solely-automated decision with a legal or similarly significant effect is made about any individual.
6. Who we share data with
We do not sell your data. We share it only with vetted service providers (“subprocessors”) who process it on our behalf under appropriate data-processing terms, and where required by law:
- Supabase — database, authentication, and document storage hosting.
- Anthropic — AI inference that generates your analysis (see section 5).
- Stripe — payment processing for paid plans.
- Brevo — transactional and requested email.
- Google — website analytics and advertising measurement, where you consent.
- Microsoft (Bookings) — scheduling discovery calls when you book one.
7. International transfers
We aim to keep application data hosted and processed within the EU/EEA: our hosting, database, authentication and document storage run in an EU region, and our email provider is EU-based. The main exception is AI inference: Anthropic is established in the United States, so content sent for analysis is transferred to the US under the EU Standard Contractual Clauses (SCCs) and Anthropic’s data processing terms. Other US-based providers (such as payments and website analytics) likewise rely on SCCs or equivalent EU data-processing terms. You can request a copy of the relevant safeguards.
8. Cookies and analytics
Our website uses strictly-necessary cookies to run the site and remember your consent choice. Analytics (Google Analytics 4) and advertising (Google Ads) trackers are non-essential and load only after you consent. We use Google Consent Mode v2, which defaults all analytics and advertising signals to “denied” until you opt in; you can change or withdraw consent at any time.
9. How long we keep data
- Account & project data — kept for the life of your account and deleted within 30 days of account closure; backups are purged within 90 days.
- Uploaded documents & AI outputs — share their project’s lifecycle and are deletable per-project by the owner at any time.
- Respondent invitations — invite tokens expire after 30 days; contributions are retained with the project and deletable by the owner.
- Website analytics — retained for around 14 months.
- Billing & accounting records — kept for 7 years, as required by the Swedish Bookkeeping Act (Bokföringslagen), even after account closure.
When a retention period ends, data is deleted or irreversibly anonymized.
10. Your rights
Where we are the controller (account, authentication, billing, website analytics), you have the right to request: access to your personal data; rectification of inaccurate data; erasure; restriction of processing; data portability; and to object to processing based on legitimate interests or to direct marketing. Where we rely on consent, you can withdraw it at any time without affecting prior processing.
To exercise any of these rights, email us at [email protected]. We may need to verify your identity, and we aim to respond within one month. If your data was provided to CLEAR by one of our customers (for example as an invited respondent), we will refer your request to that customer as the controller.
You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), Box 8114, 104 20 Stockholm, Sweden — [email protected] · www.imy.se — or with your local EU/EEA supervisory authority.
11. Security
We use appropriate technical and organizational measures, including encryption in transit (TLS) and at rest, tenant isolation via database row-level security, SHA-256-hashed respondent invite tokens (never stored in clear text), JWT-based session authentication, and server-side secret management. No method of transmission or storage is completely secure, but we work to safeguard your data and to address any incident promptly.
12. Children
CLEAR is a business service intended for organizations and their staff. It is not directed to children and is intended for users aged 18 or over. We do not knowingly collect personal data from children.
13. Changes & versioning
We may update this policy from time to time. The version and effective date appear at the top, and the current version is recorded in the app (PRIVACY_POLICY_VERSION) against your acceptance, so we can detect when a newer version requires re-acceptance. When we make material changes we will take reasonable steps to inform you and, where appropriate, re-prompt acceptance.
14. Contact
For any privacy question or request, contact Erik Bohjort, EB Consulting, Stockholm, Sweden, at [email protected].