Privacy Policy
Last updated: March 16, 2026
Introduction
ClariLien Inc. ("ClariLien," "we," "us," or "our") operates the ClariLien platform, an institutional mortgage due diligence service. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.
By accessing or using ClariLien, you agree to this Privacy Policy. If you do not agree, please do not use the platform.
Information We Collect
Account Information: Name, email address, company name, and role when you create an account or request a demo.
Uploaded Documents: Loan tapes (CSV/Excel) and collateral documents (PDFs) uploaded for analysis. These contain borrower information that we process on your behalf.
Usage Data: Page views, feature usage, session duration, and platform interactions. Collected to improve the service.
Technical Data: IP address, browser type, operating system, and device information. Collected automatically for security and performance monitoring.
How We Use Your Information
We use your information to:
- Operate and maintain the ClariLien platform
- Process and analyze uploaded documents and loan tapes
- Manage your account and provide customer support
- Send transactional communications (account, billing, security alerts)
- Improve platform functionality and user experience
- Detect and prevent fraud, abuse, and security incidents
We do not sell your data to third parties. Ever.
Document & Data Processing
Documents uploaded to ClariLien are processed using AI models provided by OpenAI, Google (Gemini), and Anthropic (Claude) for classification, text extraction, and analysis. These providers process data under enterprise agreements that prohibit use of your data for model training.
Document binary files are automatically deleted after processing per our configurable retention policy (default: 48 hours). Extracted metadata and analysis results are retained as long as your account is active.
Sensitive personal identifiers (SSNs, email addresses, phone numbers) are encrypted at rest with AES-256-GCM before storage.
Third-Party Processors
We use the following third-party service providers:
- Supabase — Database hosting and authentication (SOC2 Type II certified)
- Hostinger — Application server hosting
- OpenAI / Google / Anthropic — Document analysis AI. Data is not used for model training per enterprise agreements.
- Upstash — Rate limiting and caching infrastructure
- Cloudflare — Bot protection (Turnstile CAPTCHA)
Data Retention
Account data: Retained while your account is active. Deleted within 30 days of account closure upon request.
Document binaries: Deleted per configurable retention policy (default: 48 hours after processing). Legal holds can extend retention.
Analysis results: Retained while your account is active. Exportable before deletion.
Audit logs: Retained for 7 years per regulatory requirements. Immutable and append-only.
Data Security
We implement industry-standard security measures including AES-256-GCM field-level encryption for PII, row-level security (RLS) for tenant isolation, multi-factor authentication, rate limiting, and comprehensive audit logging. For full details, see our Security page.
Your Rights
You have the right to:
- Access: Request a copy of the personal data we hold about you
- Deletion: Request deletion of your personal data, subject to legal retention requirements
- Export: Export your data in standard formats (XLSX, CSV, PDF)
- Correction: Request correction of inaccurate personal data
- Opt-out: Opt out of non-essential analytics and communications
To exercise these rights, contact us at privacy@clarilien.com.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email notification to your registered account email and a notice on the platform. Continued use of ClariLien after changes constitutes acceptance.
Contact
For privacy-related questions or to exercise your data rights, contact us at privacy@clarilien.com.