Clarity privacy policy
Last updated: 7 October 2026
Clarity is made by Moon Shard Ltd, a company registered in England and Wales (company number 17130964), registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. Moon Shard Ltd is the controller of your personal data for the purposes of UK GDPR. You can reach us at clarity@moonshard.co. This policy covers the Clarity app for iPhone and iPad, and the services behind it.
The short version
Everything you save in Clarity stays on your device, and in your own private iCloud if you are signed in to it. Online AI features belong to Clarity Plus and are off until you agree to them. AI summaries, connection checks, and connecting Claude or ChatGPT are described below. When AI summaries are on, each link you save is sent to our server to be summarised, and the summary is kept there. If you connect Claude or ChatGPT, they read your saved cards from that same server, on your behalf, when you ask them to. They can only read. Anonymous usage counts go to PostHog unless you turn them off in Settings. We don't show ads, we don't track you across apps, and we don't sell data.
What stays on your device
Notes, documents, files, images, voice notes and saved links are stored inside Clarity on your iPhone or iPad. Clarity also stores the text read from documents and images, voice transcripts, titles, areas and connections on your device. If you turn on AI features with Clarity Plus, eligible text may be sent for the connection checks described below. Search runs on your device, except when a connected assistant searches, which runs on our server over the cards it holds. Voice notes are transcribed on your device only.
Clarity only puts text on your clipboard when you tap Copy. It reads the clipboard only when you choose to paste.
What leaves your device
AI summaries (Clarity Plus, only if you turn them on). Clarity asks before the first one, and you can switch them off in Settings at any time. When they are on, each link you save, in the app or from the share sheet, is sent to Clarity's server, with any text Clarity has already read from the page (such as a video caption, up to 4,000 characters). The server fetches the page, identifying itself as ClarityBot, and uses Cloudflare Workers AI to write a summary. Inside the app, links it recognises as private documents, such as a private Google Doc, are not sent. We keep the summary and the link on our server (a database hosted by Cloudflare), and we keep the text of the page there too (Cloudflare storage), so the same link isn't summarised twice. They are linked to a random ID created by the app, and never to your name or email. When you delete a card in Clarity, or use Delete everything, the app also asks our server to delete that card's summary, link, kept page text, connections and search entries. If you are offline, the request waits on your device and is sent when Clarity next has a connection. We do not send your saves to Google or to any other AI provider for summaries.
Connection checks (Clarity Plus, only with AI on). To check how your saves connect, Clarity sends one save, together with up to 8 other saves it might connect to, to Clarity's server. For each of them it sends a title, a kind (such as note or link) and up to 4,000 characters of text. The server passes them to Jev, from TypeSafe, which returns a score for each pair. This can include text from notes, voice transcripts, images and documents. Saves marked sensitive, saves with form fields, and saves that look like they contain card, bank, phone or VAT numbers are excluded on the device. Files themselves are never sent for these checks. Clarity's server does not keep the titles or text from connection checks. It keeps a yes/no verdict and a score for each pair, labelled with a fingerprint of the text and the app's random user ID, for 90 days. Deleting a card in the app does not remove these fingerprint verdicts early, and they expire after 90 days. You can turn these checks off with AI in Settings. TypeSafe's own privacy policy governs what it does with what it receives.
iCloud sync. If you are signed in to iCloud, Clarity syncs your library between your devices through your own private iCloud container, using Apple's CloudKit. It is stored in your iCloud account, and Moon Shard has no access to it. To turn it off, sign out of iCloud or turn off iCloud for Clarity in the iOS Settings app.
Purchases. Payments are handled by Apple. Clarity includes RevenueCat's software to confirm what you've bought and to restore it. RevenueCat creates a random ID the first time Clarity opens, even if you never subscribe. When Clarity registers with our server, that ID is replaced by the same random app ID our server uses for you, which is how our server checks that you have Clarity Plus. RevenueCat receives your purchase history, that ID, and standard device and app details such as app version, operating system and locale. See RevenueCat's privacy policy.
Anonymous usage counts. Unless you turn it off, Clarity sends anonymous usage counts to PostHog (US cloud), which we use to see which features get used and whether a save worked. Each event carries only an event name from a fixed list, bucketed counts such as 1-9 or 10-49, the app version, the iOS or iPadOS major version, whether the device is a phone or tablet, whether the app came from the App Store or TestFlight, the region code of your device's locale, and a random ID made on first launch. That ID is never linked to your purchases, your app ID for our server, your device or your Apple ID. Events never include what you save: no titles, text, links, site names, area names, search words, file names, codes or keys. PostHog receives your IP address as part of every connection. There is no advertising or tracking software in Clarity, no session recording and no advertising ID, and Clarity does not show the App Tracking Transparency prompt because it does not track you. To turn this off, switch off Share anonymous usage in Settings. Turning it off sends one final opt-out event, then nothing more. Turning it back on creates a new random ID.
Support email. If you email us, we receive what you send and use it only to reply.
Link previews and reading pages. When you save a link, your device fetches that page directly, whether or not AI is on, to fill in the title, picture and text. For some sites it also uses their public preview services: YouTube (title, captions and thumbnail), Vimeo, X, Reddit, TikTok, Instagram, GitHub, Apple (App Store, Books and Podcasts listings) and Open Library (book covers). For TikTok and Instagram videos, Clarity may download the audio and transcribe it on your device. The link, and the usual connection details such as your IP address, go from your device straight to that site, and nothing is kept by Moon Shard. If you tap play on a YouTube video inside Clarity, YouTube's player loads and YouTube's own privacy policy applies to that video. Nothing else leaves your device, apart from what a connected assistant reads, described below. If a future version adds other online features, this page will say exactly what is sent and where, and the app will ask you first.
Connection details. Whenever your device contacts our server, Cloudflare, PostHog, RevenueCat, Apple or a site you saved, that service sees your IP address, as happens with any online service. We do not store IP addresses with your saves or use them to identify you. Cloudflare keeps short-lived operational logs of requests to our server, which we use to keep the service running and to limit abuse.
Connected assistants (Claude and ChatGPT)
Connecting (Clarity Plus). You connect an assistant yourself, in the app, with a one-time code that works for 10 minutes. The assistant is tied to the same random app ID, and never to your name or email.
What the assistant can read. Once connected, it can search and open the cards Clarity's server holds for your random app ID, and only your own cards. A card holds the title, a short summary, the main claim, suggested steps, topics, the author and the link of a save, along with Clarity's verdict on it and its links to other cards. When the assistant asks for the full text of a save, it can also read the page text we kept for that save. It cannot read anything that never reached our server, such as notes, files, images and voice notes kept only on your device. It reads only while you are connected.
Read only. The app has no setting that lets an assistant add, edit or delete anything in Clarity, so a connected assistant can only read.
What the assistant provider receives. What an assistant reads in Clarity goes to its provider, Anthropic for Claude or OpenAI for ChatGPT. Their own privacy policies govern what they do with it, and we do not control how they handle it.
How long a connection lasts. A connect code expires after 10 minutes. An assistant's access token lasts 1 hour, and its sign-in can be renewed for up to 30 days. Cards stay on our server until you delete them in the app or ask us to delete them, as described under Keeping and deleting your data. A card you delete in Clarity is deleted from our server too, so a connected assistant can no longer read it.
Disconnecting. In Clarity, open Settings, tap Connect your AI, then Advanced, then Disconnect all assistants, and confirm with Disconnect all. This ends every Claude and ChatGPT connection to your library at once, and they stop working until you connect again. If you also use the private key with Claude Code or another tool, choose Get a new key in the same place to stop that key.
Clarity on the web
The iPhone and iPad app has no account. A web version of Clarity at clarity.moonshard.co also lets you sign in with Apple to open the same library. If you use it, Apple gives us a stable identifier for you and, depending on what you choose to share, your email address or a private relay address. We store these with your random app ID, only to sign you in, and delete them with your account.
Who receives data
These companies process data for us, or receive it when you use the feature named. Each is limited to that purpose.
- Cloudflare: hosts our server, database, file storage, search index and Workers AI summaries. Receives links, page text, summaries and the random app ID.
- TypeSafe (Jev): checks connections between saves. Receives the titles, kinds and text described under Connection checks.
- RevenueCat: confirms and restores purchases. Receives purchase history and the random app ID.
- PostHog: anonymous usage counts, if you leave them on. Receives the events described above.
- Apple: payments, the App Store and your private iCloud. Moon Shard cannot read your iCloud.
- Anthropic and OpenAI: only if you connect Claude or ChatGPT, and only what the assistant reads. They are separate controllers of what they receive.
- Sites you save links from, and the preview services listed above: receive the link and your connection details when your device or our server fetches the page.
We do not sell data, and we do not share it with advertisers or data brokers.
International transfers
PostHog, RevenueCat and Cloudflare are based in the United States, and some of these providers process data outside the UK. Where personal data goes to a country without a UK adequacy decision, we rely on the safeguards UK law accepts, such as the UK International Data Transfer Addendum to standard contractual clauses, or the UK-US data bridge for certified companies.
Why we use your data
- To provide Clarity and Clarity Plus, including checking your subscription (UK GDPR Article 6(1)(b), performing our contract with you).
- To write summaries, check connections and let an assistant you connected read your cards (Article 6(1)(a), your consent). You give consent when you turn AI on or connect an assistant, and you can withdraw it by turning AI off or disconnecting, which stops new data being sent.
- To count anonymous usage and fix problems (Article 6(1)(f), our legitimate interest in improving the app). You can object at any time with the Share anonymous usage switch.
- To keep the service secure and limit abuse, such as rate limits and short-lived logs (Article 6(1)(f), our legitimate interest in protecting the service).
What we don't do
No ads, no tracking across apps or websites, no data brokers, no selling or renting data. The only analytics are the anonymous usage counts described above, which you can turn off.
How long we keep data
- Cards, links, kept page text and search entries on our server: until you delete the card, use Delete everything, or ask us to delete them.
- Connection check verdicts: 90 days.
- Connect codes: 10 minutes. Assistant access tokens: 1 hour. Assistant sign-ins: up to 30 days unless you disconnect sooner.
- Request counters used for rate limits: up to 35 days.
- Cloudflare's operational logs: short-lived, under Cloudflare's own log settings.
- The record of your random app ID, device ID and Clarity Plus status on our server: until you ask us to delete it. It holds no saves.
- Purchase records at RevenueCat, and anonymous events at PostHog: under their own retention. Because the usage ID is deleted from your device when you turn sharing off, we cannot tie old events to you.
- Support emails: as long as needed to help you, then deleted.
Keeping and deleting your data
Your saves stay on your device until you delete them. Deleting a card removes it from your device, and also deletes its copy on our server, which a connected assistant could otherwise read. Settings, Delete everything does the same for every card, and when iCloud sync is on it also removes them from iCloud and your other devices. Deleting the app removes everything stored on the device. If iCloud sync is on, a copy stays in your private iCloud after you delete the app, until you delete it there, in the iOS Settings app under iCloud storage. You can export everything at any time from Settings. To delete the server record of your random app ID, purchase records held by RevenueCat, or anything else that remains, email clarity@moonshard.co and we'll delete it within 30 days.
Your rights
Under UK GDPR you can ask to access, correct, delete or export personal data we hold, restrict or object to its use, and withdraw consent at any time. Email clarity@moonshard.co and we'll reply within one month. You can also complain to the Information Commissioner's Office (ico.org.uk).
Children
Clarity is not aimed at children under 13, and we don't knowingly collect data from them. If you think a child under 13 has used Clarity's online features, email us and we'll delete the data.
Changes
If this policy changes, we'll update this page and the date at the top. If a change affects what leaves your device, we'll tell you in the app first.