Early-access policy · v1
Privacy Policy
Effective 14 September 2026. Applies to clarabit.ai, app.clarabit.ai, and the Clarabit MCP server at mcp.clarabit.ai, operated by Limeade Labs.
Clarabit is a work tool. You connect it to the AI tools you already use (Claude, ChatGPT, Claude Code, and others), and it keeps tasks, context, pages, and agent sessions in one shared record. This page explains, in plain language, what we collect to do that, where it lives, who else touches it, and how to get it removed. If anything here is unclear, email support@clarabit.ai and a person will answer.
What we collect
Account details
You sign in with Google. From that we receive your name, email address, and profile picture, plus a Google account identifier so we can recognise you next time. We do not get access to your Gmail, Drive, Calendar, or anything else in your Google account. We use email only to run your account and answer support requests; we do not send marketing email to it unless you separately subscribe on clarabit.ai.
Workspace content
Everything you and your agents put into Clarabit on purpose: projects, tasks, comments, pages and their version history, context entries, labels, time entries, attachments, and session logs. This is your data. We store it so your team and your AI tools can read it back, and we do not use it to train models or for any purpose other than running the service for you.
MCP tool-call telemetry
When an AI tool calls Clarabit through the MCP server, we record a small event per call: the tool name (for example cla_get_task), timing (when it ran and how long it took), whether it succeeded or errored, and the client type (Claude, ChatGPT, Claude Code, and so on). We never record the arguments passed to the tool or the content it returned. We use this to see which tools are used, catch failures, and keep the server fast.
Product analytics
In the web app we use PostHog to record page views and which features get used, tied to your account so we can understand how teams actually work in Clarabit. Session recording (replaying your screen) is switched off. We do not run advertising trackers.
Technical logs
Like every web service, our servers record request logs containing IP addresses, browser or client identifiers, and timestamps. We keep these for security, abuse prevention, and debugging, and rotate them on a short cycle, never longer than the telemetry retention below.
Email updates (optional)
If you enter your email in the "keep me posted" form on clarabit.ai, it goes to Buttondown, which we use to send occasional product updates. Every email has an unsubscribe link, and subscribing is not connected to having a Clarabit account.
How we use it
- To run Clarabit: store your workspace, show it to the people and agents you have allowed in, and answer MCP calls from your AI tools.
- To keep the service secure and working: spot abuse, debug failures, and understand load.
- To improve the product: see which features and tools are used and where people get stuck.
- To answer you when you write to us.
We do not sell your data, show you ads, or share workspace content with anyone you have not invited.
Where it is stored and who processes it
We use a small number of infrastructure providers to run Clarabit. Each one processes data only on our instructions, to provide their service to us.
| Provider | What they do for us | What they see |
|---|---|---|
| DigitalOcean | Hosts the Clarabit web app and database, and stores attachments (DigitalOcean Spaces). | All workspace content and account details, at rest and in transit, on servers we operate. |
| Cloudflare | Runs the MCP server at mcp.clarabit.ai on Cloudflare Workers, and provides DNS and edge networking. | MCP requests in transit between your AI tool and Clarabit, and tool-call telemetry. |
| Sign-in (OAuth). | That you signed in to Clarabit. We receive your basic profile from Google; Google receives nothing about your workspace from us. | |
| PostHog | Product analytics (US-hosted). | Usage events tied to your account: pages viewed, features used, tool names called. Never page bodies, comments, or tool arguments. |
| Buttondown | Email list for optional updates. | Your email address, only if you subscribe on clarabit.ai. |
Beyond these processors, we share personal data only if the law requires it, or to protect the rights and safety of Clarabit users. We will tell you if that happens unless we are legally prevented from doing so.
Your AI tools
Clarabit does not run its own AI. When you use Clarabit inside Claude, ChatGPT, Claude Code, or another host, the conversation itself stays with that host and is governed by their privacy policy. Clarabit only sees the tool calls the host makes on your behalf and the workspace content those calls read or write. Tool calls are made under your permissions and recorded under your identity, so you can always see what an agent did in your name.
How long we keep it
- Workspace content is kept until the workspace owner deletes it, or asks us to delete the workspace. Deleted items are removed from our systems, with backups expiring on their normal cycle.
- MCP telemetry and product analytics are kept for 12 months, then deleted.
- Account details are kept while your account exists and deleted when you close it, apart from what we must retain for legal or accounting reasons.
- Technical logs are rotated on a short cycle and are never kept longer than telemetry.
Your choices and rights
- See and export your workspace content at any time from the app or through the MCP tools.
- Correct or delete anything you have created. A workspace owner can delete the whole workspace.
- Disconnect Clarabit from an AI tool by removing the connector in that tool's settings. This stops it calling Clarabit immediately.
- Revoke Google sign-in from your Google account's third-party access page.
- Close your account or ask us to delete everything we hold about you by emailing support@clarabit.ai. We aim to respond within 30 days.
Depending on where you live, you may have further rights under data protection law (access, portability, restriction, objection, and the right to complain to a supervisory authority). Write to us and we will help.
Security
Data is encrypted in transit (TLS) and at rest on our hosting provider. Access to production systems is limited to the people who run Clarabit. MCP access uses OAuth with short-lived tokens that you can revoke from your AI tool at any time. No system is perfectly secure; if we learn of a breach affecting your data we will tell you promptly.
Children
Clarabit is a tool for work and is not directed at children under 16. We do not knowingly collect data from them.
Changes to this policy
This is version 1, written for early access. When we change it we will update the version and effective date at the top of this page and note material changes in the changelog.
Contact
Limeade Labs operates Clarabit. For anything about this policy or your data, email support@clarabit.ai.