Third-Party Data Processing
Learn how your data is processed by third-party services that Clario uses.
Ce document n’est actuellement disponible qu’en anglais.
Last updated: October 6, 2026
Overview
Clario works with a small number of third-party services to run the app and website. This page details what data is shared with these services, how it's protected, and your rights regarding that data.
Third-Party Services
Below is a detailed list of third-party services we use and what data they process:
OpenAI
We use OpenAI's API for AI features: transaction insights, chat assistance, receipt scanning and category suggestions. These features are used only after you give explicit consent in the app, and our server enforces that consent. OpenAI receives only the data each request needs and does not use API data to train or improve its models (per its API terms). Data is encrypted in transit and retained according to OpenAI's API data retention policy.
Data Shared:
- Transaction amounts, dates, categories and merchant names needed for the answer
- Receipt images for scanning
- Your questions to the chat assistant
Plaid (US & Canada; UK & EU when available)
In the US and Canada, bank connections are made through Plaid; the UK and the EU will follow when bank sync launches there. You sign in to your bank inside Plaid, and we receive a read-only access token plus your account, balance and transaction data. We never receive your bank username or password. The Plaid access token is encrypted by us with AES-256-CBC and HMAC-SHA256 before it is stored. When you disconnect a bank or delete your account, we remove the connection at Plaid.
Plaid's own handling of your data is described in the Plaid End User Privacy Policy.
Monobank API
In Ukraine, Clario connects to Monobank's official API with read-only access to your account data, balances and transaction history. Data is transferred over TLS/HTTPS, and your Monobank token is encrypted by us with AES-256-CBC and HMAC-SHA256 before it is stored. Monobank's privacy policy governs how your data is processed on its platform.
Apple (Sign in with Apple, App Store, push notifications)
We use Sign in with Apple, App Store in-app purchases and Apple Push Notification service. Apple receives purchase receipts, subscription status and related transaction data, and we receive your Apple user ID if you sign in with Apple. Apple's privacy policy governs how this data is processed.
Google (Sign-In, Google Play, Firebase)
We use Google Sign-In, Google Play Billing, Firebase Cloud Messaging for push notifications, and Firebase Analytics and Crashlytics for pseudonymous product analytics and crash reports. On the website, Google Analytics runs only after you allow analytics cookies. Google receives your Google user ID (if you sign in with Google), purchase data, device tokens and pseudonymous usage and crash data. It never receives your balances or transactions. You can turn off app analytics in Settings → Privacy → Share usage data.
Meta (App Events SDK)
We use Meta's App Events SDK to attribute app installs and subscriptions to our ads. Meta receives app install, app open and purchase events. It never receives financial data. On iOS, your advertising identifier is shared only if you allow tracking in Apple's App Tracking Transparency prompt; on Android, you can reset or delete your advertising ID in your device settings.
Hosting (Google Cloud, Vercel)
Our servers and database run on Google Cloud in the United States (Cloud Run and Cloud SQL), and your data is stored in an encrypted, managed PostgreSQL database. The website is hosted by Vercel, which also provides cookieless web analytics.
Email (SMTP provider and Resend)
We send verification codes, password reset emails and account notifications through an SMTP email provider, and waitlist emails through Resend. Your email address and the message content are shared with these providers to deliver the messages. No other personal data is sent through email services.
Data Security
Data processed by Clario and shared with third-party services is protected as follows:
- Data is encrypted in transit with TLS (HTTPS) between the app, the website, our servers and these providers.
- Our database is encrypted at rest by our hosting provider (AES-256). Bank tokens are additionally encrypted by us with AES-256-CBC and HMAC-SHA256.
- Access to production systems and customer data is limited to Clario's founder, for operations and support only.
- Each provider receives only the data it needs for its function.
- Dependencies are checked for known vulnerabilities every month, and security fixes are applied on a defined schedule.
Data Retention
We retain your data only as long as necessary:
- Financial transaction data: stored as long as you have an active account. You can delete all data by deleting your account.
- Verification codes: expire 10 minutes after they are sent and cannot be used afterwards.
- After you delete your account: encrypted database backups age out within 14 days and server logs within 30 days.
Your Rights
You have the right to access, modify, and delete your personal data at any time. You can delete your entire account and associated data through your account settings. For additional requests or concerns about how your data is processed, please contact our support team at support@clarioapp.net.
Questions or Concerns?
If you have any questions about how your data is processed by third-party services or concerns about data privacy, please contact us.
ClarioFin
Email: support@clarioapp.net