Privacy Policy

What Clear AI Spend collects, why, who processes it and how long it is kept.

Last updated: Oct 1, 2026

Principle

Clear AI Spend collects only what it needs to show you what your AI usage costs. It does not need your prompts, model responses or your customers' content, and the product is built so that it never stores them.

What we process

Account: your email address, an optional name and company, and your language. Passwords are handled by our authentication provider; we never see or store them in readable form.

Usage metadata you choose to provide: provider, model, token counts, cost, latency, retries, success or failure, quality score, a task label or reference and configuration settings such as temperature. This comes from a connected provider, a CSV you save, or calls you send to the ingest API.

Provider credentials: if you connect OpenAI or Anthropic, the admin key you enter is encrypted on our server (AES-256-GCM) and used only to read your usage and cost from that provider. It is never sent back to your browser, and we only keep its last four characters in readable form.

Subscription: your Stripe customer and subscription identifiers, plan and status. Card details are entered at Stripe and never reach our servers or database.

Messages you send us through the contact form: your name, work email, company and what you write.

What we do not collect

Prompts, model responses, payment card data, advertising identifiers or analytics profiles. The free scan reads your CSV or JSON in your browser; its rows are sent to us only if you choose to save them to your account.

How we use it

To run your account, calculate and display your costs and savings findings, bill your subscription, answer your messages and keep the service secure. We do not sell your data and we do not use it to train AI models.

Who processes it for us

Supabase (database and authentication), Netlify (hosting), Stripe (payments), and an email delivery provider for notifications about contact messages. When you connect OpenAI or Anthropic, we send your key to that provider to read your own usage and cost, and nothing else. The booking calendar on the contact page is provided by Calendly and loads from its servers when you open that page.

Cookies and browser storage

We use only what is needed to run the site: your signed-in session is kept in your browser's storage, and your language choice in a small first-party cookie and browser storage. We do not use advertising or analytics cookies. Calendly may set its own cookies on the contact page.

How long we keep it

Usage records and provider cost reports are kept for 13 months and then deleted automatically. Contact messages are kept for 12 months. You can delete any saved scan, and its records, at any time. When you delete your account, your profile, scans, usage records, provider connections and keys, and API keys are deleted immediately and your subscription is cancelled; copies may remain in provider backups until they expire. Stripe keeps its own payment records as required for accounting.

Security

Each account's data is isolated at the database level with row level security, so one customer cannot read another's records. Provider keys are encrypted at rest, privileged operations run only on the server, and connections use HTTPS. No system is perfectly secure; tell us at once if you suspect a problem.

Your choices

You can view, change and delete your data in the app, including deleting your account under Settings. To ask for a copy of your data or for anything else about your privacy, email support@clear-ai-spend.com.

Changes

If this policy changes materially we will update the date above and, where appropriate, tell you.