Legal
Privacy Policy
Last updated: 1 August 2026
This policy explains what Clarity Labs collects, where it goes, and what you can do about it. It describes what the software actually does.
Who is responsible
Philipp Sidler, c/o ExpertFid & Audit SA, Sinserstrasse 65, 6330 Cham (ZG), Schweiz, is the controller of your personal data.
For any privacy question or request: privacy@claritylabs.trade
What we collect
Account information
Your email address, a hashed password, and — if you sign in with a third-party provider — that provider's account identifier. Login timestamps are recorded. Authentication is handled by Supabase.
Trading data (paid plans only)
When you upload a CSV on a Navigator or Expedition plan, we store:
- Per-session figures: date, net P&L, profit factor, win rate, trade count, average winner and loser
- Six behavioural scores: revenge sizing, revenge frequency, premature exit, session fade, overtrading, consistency
- Your assigned archetype
- Individual trade records: entry and exit timestamps, quantity, buy and sell price, P&L, direction, and duration
- The original CSV file exactly as you uploaded it
- The AI-written read of each session
- Group names and broker names you enter
Journal entries (optional)
If you use the journal, we store your self-rated mental clarity, your selected emotional state before and after a session, your plan-adherence answers, and any free-text notes you write.
Billing
If you subscribe, we store a Stripe customer identifier. Card details never reach our servers — Stripe handles payment information directly.
Free plan
On the free plan, your CSV is analysed in your browser and nothing is written to our database. No trades, no sessions, no uploaded file. This is enforced server-side: the save endpoint rejects requests from free-plan accounts.
Who else sees your data
We use a small number of processors. We do not sell data, and we do not share it for advertising.
| Processor | What they receive | Where |
|---|---|---|
| Supabase | Database and authentication — all stored data above | Ireland (EU) |
| Vercel | Hosting; processes requests including session cookies | Dublin (EU) |
| OpenAI | See below | United States |
| Stripe | Your email, a customer ID, and the plan you selected | EU / US |
| Resend | Your email address, to deliver account emails | US |
What OpenAI receives — two different cases.
The automatic session read. Aggregated numbers only: trade and session counts, win rate, profit factor, net P&L, average winner and loser, average hold times, and the six behavioural scores. No individual trades, no timestamps, no prices, no email address, and no identifier of any kind. OpenAI cannot connect this to you.
The session debrief, when you use it. If you write a session note and submit it for a debrief, that note is sent as written, together with your archetype, win rate, profit factor, and two behavioural scores.
If — and only if — you tick the box to include your journal, that submission also carries your journal entry for that day: your mental clarity rating, emotional state, plan-adherence answers, and any free-text notes. The box is unchecked by default. If you leave it unchecked, your journal is not sent and is not even read.
What Resend delivers.
Archetype-change notifications. When a Navigator or Expedition subscriber's dominant archetype shifts — compared across the last five sessions against the five before them — Resend delivers one notification email the following morning, at most once a week. The email contains your address and the names of the two archetypes. It is on by default and can be turned off in account settings or via the one-click unsubscribe in every email. The preference is stored as email_archetype_change on the profiles table.
What we do not do
We run no analytics, no tracking pixels, no session recording, and no third-party scripts of any kind. There is no advertising on Clarity Labs, and no advertiser receives your data.
Cookies and browser storage
We set no advertising or analytics cookies, so there is nothing to consent to.
- sb-…-auth-token — keeps you signed in
- activeGroupId — remembers which trading group you had selected (1 year)
Stored locally in your browser, never sent to us:
- cl-theme — your light or dark preference
- journal-draft-… — an unsaved journal draft, cleared once it saves
- A dismissal flag for the re-upload reminder
- A short countdown after a password-reset request, to limit repeat sends
Note that a saved journal draft stays in that browser. On a shared computer, sign out or clear site data.
How long we keep it
While your account is open, we keep your data so that longitudinal tracking works — comparing this month against last month is the point of the product.
Uploaded CSV files live as long as the sessions derived from them. Delete those sessions and the original file is deleted with them.
When you ask us to delete your account, everything goes.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, or export it in a portable format, and you can object to how we use it. Where we rely on your consent — the journal attachment — you can withdraw it at any time by leaving the box unticked.
To exercise any of these, email privacy@claritylabs.trade.
Deleting your account. There is no self-service delete button yet. Email privacy@claritylabs.trade from your account address and we will delete your account and all associated data within 30 days, usually much sooner.
Getting your data. You can download a copy from your account page at any time.
If you think we have handled your data badly, you can complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC), or to the supervisory authority where you live if you are in the EU.
International transfers
Your data is stored in Ireland and processed in the EU. OpenAI, Stripe and Resend process some data in the United States under standard contractual clauses.
Changes
If we change this policy in a way that matters, we will tell registered users by email rather than quietly updating the date.