Privacy Policy
Last updated: 10 August 2026
1. Who We Are
CLARA (Corporate Litigation & Accountability Research Assistant) is operated by the Climate Litigation Lab at the Oxford Sustainable Law Programme, Smith School of Enterprise and the Environment, University of Oxford ("we", "us", "our"). We are the data controller for personal data processed through the CLARA platform at clara-research.com.
For any privacy-related questions, contact us at admin@clara-research.com.
2. Data We Collect
We collect the following categories of personal data:
2.1 Account Information
- Email address — used for authentication and account identification.
- Mobile number — provided in international format for account security and verification.
- Mobile-verification data — whether your number has been verified and, if a verified number is already associated with another account, the date and time that the verification conflict was recorded.
- Password — managed and securely hashed by AWS Cognito; we never store or have access to your plaintext password.
AWS Cognito generates and verifies the one-time SMS code used to confirm control of your mobile number. CLARA does not retain the code you enter. We use mobile numbers for authentication, account security, and preventing misuse of account and free-credit allowances; we do not use them for marketing.
An email address, password, and mobile number are required to create a CLARA account. For UK numbers, we send the initial account-confirmation code by SMS. For non-UK numbers, we confirm your email first and verify your captured mobile number separately by SMS after sign-in. If an SMS is delayed or unavailable, you may continue using CLARA and spend your normal daily credits while mobile verification remains pending. Continuing never marks your mobile number as verified and cannot bypass a known duplicate-number conflict.
2.2 Profile Information (Optional)
- First and last name — optionally provided separately during registration or later through your profile, and combined in our account record for display and support.
- Organisation — your institutional or organisational affiliation.
- Occupation / Role — your professional title.
- Sector — the sector you work in (e.g. Academic, Legal, Journalism, NGO, Government).
2.3 User-Generated Content
- Conversations — questions you ask CLARA and the AI-generated responses, including tool calls, reasoning traces, and AI-generated conversation titles.
- Conversation summaries — when conversations become long, older messages are automatically summarised by the AI model and the summary is stored alongside the conversation to manage context limits.
- Files — documents you create, edit, or upload to your personal workspace (supported formats: PDF, DOCX, DOC, TXT, MD, PNG, JPG, JPEG, TIFF, WEBP; max 50 MB per file, 200 MB total storage).
- Extracted document content — when you upload documents, their text content and structural metadata (headings, page numbers, table of contents) are extracted and stored for search and citation.
- Citations and sources — references linking AI responses to archival source documents.
2.4 Usage and Technical Data
- Credit usage — records of your daily research credit balance and transactions.
- File activity logs — records of file creation, modification, and deletion, including file paths, file names, extensions, and sizes (for audit and analytics purposes).
- Server logs — HTTP request metadata (method, URL path, status code, response time). These logs do not contain message content.
- Last activity timestamp — the date and time of your most recent authenticated request to the platform, used to calculate login and activity statistics.
- Onboarding progress — which product tours you have completed, tracked both in your browser's local storage and on our servers.
- Terms acceptance — whether you have accepted the Terms of Service and Privacy Policy.
3. How We Use Your Data
| Purpose | Legal Basis (UK GDPR) |
|---|---|
| Providing the CLARA research assistant service | Performance of a contract (Art. 6(1)(b)) |
| Account creation and authentication | Performance of a contract (Art. 6(1)(b)) |
| Verifying control of a mobile number and supporting account corrections | Performance of a contract (Art. 6(1)(b)) |
| Managing research credit allowances | Performance of a contract (Art. 6(1)(b)) |
| Processing uploaded documents for search and citation | Performance of a contract (Art. 6(1)(b)) |
| Improving and maintaining the platform | Legitimate interest (Art. 6(1)(f)) |
| Aggregate analytics and usage statistics | Legitimate interest (Art. 6(1)(f)) |
| Security monitoring, duplicate-account detection, and prevention of free-credit abuse | Legitimate interest (Art. 6(1)(f)) |
4. Third-Party Services and Data Sharing
We share data with the following categories of third-party service providers, solely for the purposes described above:
| Provider | Purpose | Data Shared |
|---|---|---|
| Amazon Web Services (AWS) | Infrastructure, authentication and mobile verification (Cognito), transactional SMS delivery (AWS End User Messaging SMS), file storage (S3), document processing (Step Functions & Lambda), knowledge graph (Neptune), and AI and OCR inference through Amazon Bedrock | Account data including your name, email address, mobile number and verification status; one-time verification messages and delivery metadata; uploaded files and document page images; authentication tokens; full conversation context and tool outputs; search queries; entity relationships |
| Mobile network operators and SMS delivery providers | Delivering transactional, one-time mobile-verification codes requested during registration or account verification | Mobile number, verification message and code, and technical delivery metadata |
| Amazon Bedrock model providers | OpenAI GPT-5.6 Luna, Terra, and Sol for research and supporting inference, and Cohere Rerank 3.5 for search relevance | No direct API transfer from CLARA. Requests are processed by AWS through Bedrock; AWS states that inputs and outputs are not shared with model providers unless we opt in. |
| Pinecone | Vector-based document search | Search query embeddings and document metadata lookups |
| Google Fonts (build-time only) | Typography (DM Sans font) | None — fonts are downloaded at build time and self-hosted; no user data is sent to Google at runtime |
Important — AI Processing: Your conversation messages (including full conversation history, search results, tool outputs, and file content when accessed by the AI assistant) are sent to OpenAI GPT-5.6 Luna, Terra, or Sol through Amazon Bedrock in an enabled US region. Conversation titles and document OCR use Luna; context summaries use the model selected for that conversation with reasoning disabled. Search queries and candidate passages are reranked with Cohere Rerank 3.5 through Amazon Bedrock in AWS US West (Oregon). CLARA's ECS and Lambda task roles sign these requests with AWS SigV4 credentials; no direct OpenAI or Cohere API key is used. AWS states that inputs and outputs are not shared with model providers unless the customer opts in; classifier-flagged traffic may be retained by AWS for up to 30 days for automated abuse detection.
AI Agent File Access: When you use the research assistant, it may read, search, create, and modify files in your personal workspace as part of answering your queries. The AI agent operates solely within your own file space and cannot access other users' data.
We do not sell, rent, or trade your personal data to any third party. We do not share your data with data brokers or advertisers.
Mobile-verification messages are transactional account-security messages. Your mobile number is not used for advertising or marketing communications.
5. Data Storage, Security, and International Transfers
5.1 Where We Store Your Data
- Primary infrastructure: AWS EU (London) region (eu-west-2).
- AI and OCR inference: AWS US East (N. Virginia) region (us-east-1) through Amazon Bedrock; response storage is disabled.
- Search relevance reranking: AWS US West (Oregon) region (us-west-2) through Amazon Bedrock.
- Database: PostgreSQL hosted on AWS.
- File storage: AWS S3 (uploads) and AWS EFS (user workspace files).
- Authentication: AWS Cognito (EU region).
- Mobile verification: AWS Cognito and AWS End User Messaging SMS, with delivery through the relevant telecommunications networks.
5.2 International Transfers
Amazon Bedrock conversation and OCR inference is processed in AWS US East (N. Virginia), and Bedrock search reranking is processed in AWS US West (Oregon). Pinecone and consent-based Google Analytics may also process data outside the United Kingdom and European Economic Area. CLARA has no direct inference API transfer to OpenAI or Cohere. Where an international transfer occurs, we rely on appropriate safeguards including Standard Contractual Clauses (SCCs) and the providers' adherence to applicable data protection frameworks (e.g. EU-US Data Privacy Framework).
5.3 Security Measures
- Authentication via AWS Cognito with Secure Remote Password (SRP) protocol — passwords are never transmitted to or stored on our servers.
- One-time SMS verification of mobile numbers, with verified-number checks used to identify numbers already associated with another account.
- All API communications use HTTPS/TLS encryption in transit.
- JWT-based authentication with RS256 signature verification and automatic key rotation.
- Per-user data isolation — all database queries are scoped to the authenticated user.
- File system path traversal protection to prevent unauthorised access.
- Server-side route protection — unauthenticated requests to protected pages are blocked at the edge before any page content loads.
- Security response headers including clickjacking protection (X-Frame-Options), MIME-sniffing prevention (X-Content-Type-Options), referrer policy controls, and XSS filtering.
- Automated bot and crawler detection on protected routes.
- Rate limiting on API endpoints to prevent abuse.
- Pre-signed URLs with time-limited expiry for file uploads (1 hour) and downloads (5 minutes).
6. Internal Access to Your Data
Authorised platform administrators have limited access to user data for operational and support purposes. Specifically, administrators can view:
- Your email address, first and last name, mobile number, mobile-verification status and any recorded verification-conflict date, and profile information (organisation, role, sector).
- Aggregate usage statistics: conversation counts, message counts, credit usage, last login timestamp, and account registration date.
- Previews of your most recent messages (truncated to 120 characters) for platform monitoring.
- File activity statistics (counts of files created, updated, or deleted, grouped by file type) — but not file names, paths, or content.
- Your terms acceptance status, including when you accepted and which version of the Terms you agreed to.
Administrators cannot view your full conversation history, read your files, or access your uploaded documents. This access is used solely for platform operation, abuse prevention, and providing support.
Account details that cannot be changed through the profile interface, including corrections to a mobile number after account creation, are handled by authorised administrators when you contact support at admin@clara-research.com.
7. Cookies and Local Storage
7.1 Cookies
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
| CognitoIdentityServiceProvider.* | AWS Amplify | Authentication session tokens (ID token, access token, refresh token) required for server-side route protection | Up to 30 days (refresh token) |
7.2 Local Storage
- Onboarding tour state (
clara_onboarding_done,clara_editor_panel_tour_done,clara_editor_file_tour_done) — tracks which product walkthroughs you have completed. These contain no personal data. - AWS Amplify session tokens — managed by the AWS Amplify SDK for authentication. Tokens are stored in cookies (see Section 7.1) to enable server-side route protection, and are cleared on sign-out.
7.3 Managing Cookies
CLARA only uses essential cookies for authentication. The Cognito authentication cookies are required for the platform to function and are set automatically when you sign in. Blocking these cookies will prevent you from accessing protected areas of the platform.
8. Data Retention
- Account data: Your name, email address, mobile number, verification status and verification-conflict metadata are retained for the duration of your account. When you delete your account, CLARA immediately removes the account and related records from its database and attempts to remove your authentication account, workspace files and uploaded objects from AWS Cognito, EFS and S3 as part of the same request. If external-service cleanup cannot complete, copies may remain until administrator intervention or the relevant provider's retention process removes them; contact us if you wish to verify completion.
- SMS verification data: CLARA does not retain the one-time verification code. AWS and telecommunications providers may retain message-delivery and security logs in accordance with their own legal, security and operational retention requirements.
- Conversations and messages: Retained for the lifetime of your account. You may delete individual conversations at any time through the platform interface.
- Files and uploads: Retained until you delete them or request account deletion. You may delete individual files and uploads at any time.
- Credit transaction logs: Retained for the lifetime of your account for audit purposes.
- File activity logs: Retained for the lifetime of your account for audit and analytics purposes.
- Server logs: Retained for up to 90 days for debugging and security monitoring, then automatically purged.
- Bedrock inference: CLARA sends
store=falseon chat, title, and OCR response requests. AWS may retain classifier-flagged traffic for up to 30 days for automated abuse detection.
9. Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — request correction of inaccurate data. You can update editable profile fields directly; for account identifiers and mobile-number corrections that are not available through self-service, contact administrator support.
- Right to erasure — request deletion of your account and all associated data.
- Right to restrict processing — request that we limit how we use your data.
- Right to data portability — request your data in a structured, machine-readable format.
- Right to object — object to processing based on legitimate interests.
- Right to withdraw consent — where we process data based on consent, you may withdraw consent at any time.
To exercise any of these rights, please email us at admin@clara-research.com. You can also delete your account and all associated data immediately using the Request Data Deletion option in your profile menu. For other rights requests, we will respond within 30 days.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).
10. Children's Privacy
CLARA is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that a child under 18 has provided us with personal data, we will take steps to delete such data promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting a notice on the platform or by email. We encourage you to review this page periodically.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:
CLARA — Climate Litigation Lab
Oxford Sustainable Law Programme
Smith School of Enterprise and the Environment
University of Oxford
Email: admin@clara-research.com