Clarity

Clarity privacy policy

Last updated: 7 October 2026

Clarity is made by Moon Shard Ltd, a company registered in England and Wales (company number 17130964), registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. Moon Shard Ltd is the controller of your personal data for the purposes of UK GDPR. You can reach us at clarity@moonshard.co. This policy covers the Clarity app for iPhone and iPad, and the services behind it.

The short version

Everything you save in Clarity stays on your device, and in your own private iCloud if you are signed in to it. Online AI features belong to Clarity Plus and are off until you agree to them. AI summaries, connection checks, and connecting Claude or ChatGPT are described below. When AI summaries are on, each link you save is sent to our server to be summarised, and the summary is kept there. If you connect Claude or ChatGPT, they read your saved cards from that same server, on your behalf, when you ask them to. They can only read. Anonymous usage counts go to PostHog unless you turn them off in Settings. We don't show ads, we don't track you across apps, and we don't sell data.

What stays on your device

Notes, documents, files, images, voice notes and saved links are stored inside Clarity on your iPhone or iPad. Clarity also stores the text read from documents and images, voice transcripts, titles, areas and connections on your device. If you turn on AI features with Clarity Plus, eligible text may be sent for the connection checks described below. Search runs on your device, except when a connected assistant searches, which runs on our server over the cards it holds. Voice notes are transcribed on your device only.

Clarity only puts text on your clipboard when you tap Copy. It reads the clipboard only when you choose to paste.

What leaves your device

AI summaries (Clarity Plus, only if you turn them on). Clarity asks before the first one, and you can switch them off in Settings at any time. When they are on, each link you save, in the app or from the share sheet, is sent to Clarity's server, with any text Clarity has already read from the page (such as a video caption, up to 4,000 characters). The server fetches the page, identifying itself as ClarityBot, and uses Cloudflare Workers AI to write a summary. Inside the app, links it recognises as private documents, such as a private Google Doc, are not sent. We keep the summary and the link on our server (a database hosted by Cloudflare), and we keep the text of the page there too (Cloudflare storage), so the same link isn't summarised twice. They are linked to a random ID created by the app, and never to your name or email. When you delete a card in Clarity, or use Delete everything, the app also asks our server to delete that card's summary, link, kept page text, connections and search entries. If you are offline, the request waits on your device and is sent when Clarity next has a connection. We do not send your saves to Google or to any other AI provider for summaries.

Connection checks (Clarity Plus, only with AI on). To check how your saves connect, Clarity sends one save, together with up to 8 other saves it might connect to, to Clarity's server. For each of them it sends a title, a kind (such as note or link) and up to 4,000 characters of text. The server passes them to Jev, from TypeSafe, which returns a score for each pair. This can include text from notes, voice transcripts, images and documents. Saves marked sensitive, saves with form fields, and saves that look like they contain card, bank, phone or VAT numbers are excluded on the device. Files themselves are never sent for these checks. Clarity's server does not keep the titles or text from connection checks. It keeps a yes/no verdict and a score for each pair, labelled with a fingerprint of the text and the app's random user ID, for 90 days. Deleting a card in the app does not remove these fingerprint verdicts early, and they expire after 90 days. You can turn these checks off with AI in Settings. TypeSafe's own privacy policy governs what it does with what it receives.

iCloud sync. If you are signed in to iCloud, Clarity syncs your library between your devices through your own private iCloud container, using Apple's CloudKit. It is stored in your iCloud account, and Moon Shard has no access to it. To turn it off, sign out of iCloud or turn off iCloud for Clarity in the iOS Settings app.

Purchases. Payments are handled by Apple. Clarity includes RevenueCat's software to confirm what you've bought and to restore it. RevenueCat creates a random ID the first time Clarity opens, even if you never subscribe. When Clarity registers with our server, that ID is replaced by the same random app ID our server uses for you, which is how our server checks that you have Clarity Plus. RevenueCat receives your purchase history, that ID, and standard device and app details such as app version, operating system and locale. See RevenueCat's privacy policy.

Anonymous usage counts. Unless you turn it off, Clarity sends anonymous usage counts to PostHog (US cloud), which we use to see which features get used and whether a save worked. Each event carries only an event name from a fixed list, bucketed counts such as 1-9 or 10-49, the app version, the iOS or iPadOS major version, whether the device is a phone or tablet, whether the app came from the App Store or TestFlight, the region code of your device's locale, and a random ID made on first launch. That ID is never linked to your purchases, your app ID for our server, your device or your Apple ID. Events never include what you save: no titles, text, links, site names, area names, search words, file names, codes or keys. PostHog receives your IP address as part of every connection. There is no advertising or tracking software in Clarity, no session recording and no advertising ID, and Clarity does not show the App Tracking Transparency prompt because it does not track you. To turn this off, switch off Share anonymous usage in Settings. Turning it off sends one final opt-out event, then nothing more. Turning it back on creates a new random ID.

Support email. If you email us, we receive what you send and use it only to reply.

Link previews and reading pages. When you save a link, your device fetches that page directly, whether or not AI is on, to fill in the title, picture and text. For some sites it also uses their public preview services: YouTube (title, captions and thumbnail), Vimeo, X, Reddit, TikTok, Instagram, GitHub, Apple (App Store, Books and Podcasts listings) and Open Library (book covers). For TikTok and Instagram videos, Clarity may download the audio and transcribe it on your device. The link, and the usual connection details such as your IP address, go from your device straight to that site, and nothing is kept by Moon Shard. If you tap play on a YouTube video inside Clarity, YouTube's player loads and YouTube's own privacy policy applies to that video. Nothing else leaves your device, apart from what a connected assistant reads, described below. If a future version adds other online features, this page will say exactly what is sent and where, and the app will ask you first.

Connection details. Whenever your device contacts our server, Cloudflare, PostHog, RevenueCat, Apple or a site you saved, that service sees your IP address, as happens with any online service. We do not store IP addresses with your saves or use them to identify you. Cloudflare keeps short-lived operational logs of requests to our server, which we use to keep the service running and to limit abuse.

Connected assistants (Claude and ChatGPT)

Connecting (Clarity Plus). You connect an assistant yourself, in the app, with a one-time code that works for 10 minutes. The assistant is tied to the same random app ID, and never to your name or email.

What the assistant can read. Once connected, it can search and open the cards Clarity's server holds for your random app ID, and only your own cards. A card holds the title, a short summary, the main claim, suggested steps, topics, the author and the link of a save, along with Clarity's verdict on it and its links to other cards. When the assistant asks for the full text of a save, it can also read the page text we kept for that save. It cannot read anything that never reached our server, such as notes, files, images and voice notes kept only on your device. It reads only while you are connected.

Read only. The app has no setting that lets an assistant add, edit or delete anything in Clarity, so a connected assistant can only read.

What the assistant provider receives. What an assistant reads in Clarity goes to its provider, Anthropic for Claude or OpenAI for ChatGPT. Their own privacy policies govern what they do with it, and we do not control how they handle it.

How long a connection lasts. A connect code expires after 10 minutes. An assistant's access token lasts 1 hour, and its sign-in can be renewed for up to 30 days. Cards stay on our server until you delete them in the app or ask us to delete them, as described under Keeping and deleting your data. A card you delete in Clarity is deleted from our server too, so a connected assistant can no longer read it.

Disconnecting. In Clarity, open Settings, tap Connect your AI, then Advanced, then Disconnect all assistants, and confirm with Disconnect all. This ends every Claude and ChatGPT connection to your library at once, and they stop working until you connect again. If you also use the private key with Claude Code or another tool, choose Get a new key in the same place to stop that key.

Clarity on the web

The iPhone and iPad app has no account. A web version of Clarity at clarity.moonshard.co also lets you sign in with Apple to open the same library. If you use it, Apple gives us a stable identifier for you and, depending on what you choose to share, your email address or a private relay address. We store these with your random app ID, only to sign you in, and delete them with your account.

Who receives data

These companies process data for us, or receive it when you use the feature named. Each is limited to that purpose.

We do not sell data, and we do not share it with advertisers or data brokers.

International transfers

PostHog, RevenueCat and Cloudflare are based in the United States, and some of these providers process data outside the UK. Where personal data goes to a country without a UK adequacy decision, we rely on the safeguards UK law accepts, such as the UK International Data Transfer Addendum to standard contractual clauses, or the UK-US data bridge for certified companies.

Why we use your data

What we don't do

No ads, no tracking across apps or websites, no data brokers, no selling or renting data. The only analytics are the anonymous usage counts described above, which you can turn off.

How long we keep data

Keeping and deleting your data

Your saves stay on your device until you delete them. Deleting a card removes it from your device, and also deletes its copy on our server, which a connected assistant could otherwise read. Settings, Delete everything does the same for every card, and when iCloud sync is on it also removes them from iCloud and your other devices. Deleting the app removes everything stored on the device. If iCloud sync is on, a copy stays in your private iCloud after you delete the app, until you delete it there, in the iOS Settings app under iCloud storage. You can export everything at any time from Settings. To delete the server record of your random app ID, purchase records held by RevenueCat, or anything else that remains, email clarity@moonshard.co and we'll delete it within 30 days.

Your rights

Under UK GDPR you can ask to access, correct, delete or export personal data we hold, restrict or object to its use, and withdraw consent at any time. Email clarity@moonshard.co and we'll reply within one month. You can also complain to the Information Commissioner's Office (ico.org.uk).

Children

Clarity is not aimed at children under 13, and we don't knowingly collect data from them. If you think a child under 13 has used Clarity's online features, email us and we'll delete the data.

Changes

If this policy changes, we'll update this page and the date at the top. If a change affects what leaves your device, we'll tell you in the app first.

Contact

clarity@moonshard.co