Skip to content
ClaireAI

Privacy Policy

ClaireAI processes law-firm intake information on the firm’s instructions and handles account, billing, support, and website information for its own business purposes. This notice explains those distinct roles, the information involved, and available privacy choices. The Data Processing Addendum governs personal data we process for a firm.

Version 2 · Last updated: September 4, 2026 · Issued by Claire AI, LLC

This Privacy Policy is a notice about information practices, not a request for blanket consent. The Terms of Service govern the commercial relationship. We seek separate consent when it is legally required. A law firm’s own privacy notice and professional obligations apply to its use of intake information.

1. Our roles and the information we handle

Service Data: processed for the law firm

The firm determines why intake information is collected and how it is used. ClaireAI acts as its processor or service provider, or as a subprocessor if the firm acts for another controller. “Customer Content” includes information supplied by or for a firm and customer-specific outputs. “Caller Data” includes information about people who call or otherwise communicate through a firm’s configured service.

Service Data may include names, phone numbers, email addresses, legal inquiries, incident dates, matter and conflict-check information, call audio, transcripts, summaries, messages, attachments, scheduling details, communication-consent records, and delivery metadata. Callers may disclose sensitive information about health, family circumstances, finances, criminal allegations, or other legal issues. We receive this information from the firm, callers, authorized users, communications providers, and systems the firm connects. Integration credentials and firm configuration used to deliver these functions are also protected service information.

ClaireAI Business Data: account and company operations

We act as controller for business contact details, account identity, authentication and security logs, support requests, subscription records, invoices, transaction status, and communications with ClaireAI. Sources include you, your organization, payment and authentication providers, and interactions with our services. Trial and checkout records include the selected plan, billing cadence, usage allowance, conversion timing, and provider checkout identifiers.

Stripe collects payment details through its hosted checkout or payment-processing systems. ClaireAI receives billing and payment-method status needed for account provisioning, support, subscription administration, trial conversion, and reconciliation; we do not receive full card numbers or card security codes through hosted checkout. Stripe’s privacy notice describes its processing.

Website and Marketing Data: public-site interactions

We receive contact-form submissions, demo-scheduling details, business inquiries, IP addresses, browser and device information, referral sources, and website activity. Public-site analytics are distinct from confidential intake. Avoid including confidential legal-matter information in marketing forms or ordinary support email.

2. Purposes and legal bases

We process Service Data to answer and route calls, transcribe and summarize interactions, support the firm’s intake criteria, schedule appointments, transmit requested messages, synchronize authorized integrations, and maintain and protect those services. Processing follows the firm’s documented instructions and the DPA. The firm is responsible for its lawful basis and any conditions required for sensitive information.

We use Business Data to perform our customer agreements, authenticate users, administer billing and trials, provide support, prevent fraud, investigate security issues, maintain business records, comply with law, and communicate about the service. Where European or UK law applies, our bases are performance of a contract with the individual where applicable; legitimate interests in operating, securing, and developing our business, subject to individuals’ interests and rights; legal obligations; and consent where required. For organization representatives who are not personally parties to the contract, account administration generally relies on legitimate interests.

We use Website and Marketing Data to respond to inquiries, arrange demonstrations, understand consented website activity, and communicate about ClaireAI. We rely on legitimate interests where permitted and consent where required for cookies or marketing. You may unsubscribe from promotional email using its unsubscribe link; essential account and security notices may continue. We do not use caller intake to make independent decisions about representation or legal rights.

3. AI processing and limits on use

Configured AI providers receive the audio, text, instructions, and context necessary to provide voice interactions, transcription, and customer-specific outputs. Models can make mistakes, and firms must supervise and verify their use. Our Subprocessor List identifies the service providers involved.

ClaireAI does not sell Customer Content or Caller Data, share it for cross-context behavioral advertising, or use it to train a general-purpose or public foundational model. Our DPA restricts how subprocessors may use Customer Personal Data. Service-specific troubleshooting and improvement follow customer instructions; statistics used more broadly must be aggregated or de-identified so a firm or individual cannot reasonably be identified. We maintain safeguards against re-identification and require recipients to respect applicable restrictions.

4. Voice, recordings, and sensitive information

Voice audio and transcripts are personal information and may receive additional protection depending on the law and how they are processed. ClaireAI does not use caller recordings for biometric identification or verification and does not intentionally create voiceprints or biometric identity templates unless separately disclosed and lawfully authorized. This statement does not mean that voice audio can never constitute regulated biometric data.

The firm must provide accurate AI, recording, and transcription disclosures and obtain required consent. The firm also determines whether it may lawfully collect sensitive information. Do not submit HIPAA-regulated protected health information unless ClaireAI has expressly agreed to support that processing and the parties have executed an appropriate BAA. The public DPA is not a BAA.

5. Messages sent on a firm’s behalf

The law firm controls its intake communications program and is the responsible sender. ClaireAI sends configured SMS and other messages on the firm’s behalf and instructions, including intake follow-ups, appointment reminders, and document links. The firm is responsible for required notices, consent, consent evidence, and honoring revocation. ClaireAI separately controls its own account and support communications with customers.

Message frequency varies. Message and data rates may apply. Marketing consent is not a condition of purchase. Follow the opt-out instructions in a message, including STOP where supported, or contact the responsible firm. For assistance, use HELP where supported or contact ClaireAI. We route requests to the responsible program and assist with required suppression. Carriers may delay or fail to deliver messages.

We do not sell or rent mobile numbers, SMS content, or messaging consent for promotional purposes. Mobile information and consent evidence may be disclosed to the firm and providers only as needed for the authorized communication program, compliance, and protected service operations; they are not shared with third parties for their own marketing.

6. Cookies, analytics, and Global Privacy Control

The public website uses necessary technologies for delivery, security, and remembering privacy choices. Google Analytics and Microsoft Clarity load only after an affirmative analytics choice. They may receive page views, device and referral details, and interaction events. Clarity captures session interactions such as scrolling and clicks; masking reduces exposure but does not make every session anonymous. Marketing analytics are not intended to receive caller recordings, transcripts, or authenticated portal content.

Select Privacy settings in the footer to accept or reject optional analytics or withdraw a previous choice. A recognized Global Privacy Control (GPC) signal is treated as an opt-out for that browser and disables optional analytics even if a previous local choice allowed them. Choices apply to this browser; use the controls on each device or browser. Blocking storage may prevent a preference from persisting, in which case optional analytics remain off until a valid choice.

The current public website does not load RB2B or another business-visitor identification service by default. We will provide required notice and choices before introducing such processing. We do not intentionally use website information for sale, cross-context behavioral advertising, or targeted advertising; to the extent a consented analytics disclosure is treated as a sale, sharing, or targeted advertising under applicable law, the same rejection and GPC controls opt you out. Browser “Do Not Track” signals do not have a uniform standard; use our controls or GPC.

7. Recipients and disclosures

We disclose information to providers performing the relevant hosting, database, AI, voice, telephony, messaging, monitoring, security, payment, support, scheduling, or analytics functions. The provider page distinguishes service subprocessors from public-website and business vendors. Firm-connected CRMs, calendars, and other systems receive data at the firm’s direction under its own relationship with those providers.

Personnel and professional advisers receive information only as needed for their work and subject to appropriate confidentiality obligations. We may disclose information to comply with a binding legal request, protect rights or safety, or investigate unlawful activity, subject to the DPA where applicable. We notify the affected customer of requests for its data where legally permitted. In a merger, financing, acquisition, or asset transfer, relevant information may be disclosed under protections appropriate to the transaction, with notice of material changes where required.

8. Retention, return, and deletion

We determine retention by the type of information, the purpose of processing, the customer agreement and instructions, account status, and applicable legal requirements. We do not promise a universal 90-day recording or transcript retention period. Any service-specific setting or schedule must be documented for that service.

Return and deletion of Customer Personal Data follow the DPA, including protected legal-retention exceptions and isolated backups until their ordinary deletion cycle. Account, billing, security, and dispute records may be retained as necessary for lawful business and legal purposes. Retention exceptions do not authorize unrelated use of caller intake.

ClaireAI is not a records-management, legal-hold, evidentiary-preservation, or archival system. The firm must export and preserve records it is obligated to retain. Deleting data in ClaireAI does not automatically delete copies already sent to firm-controlled systems.

9. Security and confidentiality

We maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature and risk of the information. The Security page and DPA describe their scope. No system is completely secure. We do not make a blanket certification, penetration-testing, or universal encryption specification claim in this notice.

Confidentiality protections do not determine whether an attorney-client relationship or privilege exists. Those questions depend on the firm’s circumstances and applicable law; ClaireAI does not provide legal advice about them.

10. Privacy rights and requests

Depending on your jurisdiction and our role, you may have rights to know or access personal information and its sources and recipients; obtain a portable copy; correct inaccuracies; request deletion; restrict or object to processing; withdraw consent; opt out of sale, sharing, targeted advertising, or certain profiling; and limit or require consent for specified uses of sensitive information. We do not independently profile callers to make decisions producing legal or similarly significant effects. Available rights and exceptions vary by law.

For ClaireAI Business Data and Website Data, send requests to info@theclaireai.com or call +1 (954) 997-0065. Identify your request and relationship to ClaireAI without sending confidential case details. We will verify identity and authority using information reasonably necessary for the request, and respond within applicable legal deadlines. An authorized agent may submit a request with evidence of authorization; we may also seek your confirmation where permitted. Browser opt-outs do not require identity verification.

If we deny a request, you may appeal by contacting the same address with “Privacy appeal” in the subject. We will review and explain the outcome within the applicable deadline and provide any required regulator-contact information. We do not unlawfully discriminate against people for exercising privacy rights. You may also complain to your state attorney general or applicable data-protection authority; EEA and UK individuals may contact their local supervisory authority.

For Caller Data, contact the law firm first because it controls the information. If you contact ClaireAI, we will route the request to that firm and assist it as required, without independently disclosing or deleting its records contrary to lawful instructions.

11. California and other U.S. state disclosures

The categories described in section 1 include identifiers; commercial and billing information; internet or electronic-network activity; audio and other electronic communications; professional information; and customer-directed intake inferences or classifications. Sensitive categories may include account credentials and information a caller discloses about health or other protected matters. We use these categories for the purposes in sections 2–6 and disclose them to the recipient categories in section 7. These disclosures describe our current practices and, to the extent those practices were in operation, the preceding 12 months. Retention criteria appear in section 8.

We do not use Customer Content or Caller Data for sale or sharing for advertising, and do not knowingly sell or share personal information of anyone under 16 for advertising. Sensitive information is used to deliver requested services, protect accounts, follow lawful customer instructions, and meet legal obligations, rather than to infer characteristics for independent marketing. Where additional consent or a right to limit is required, it must be supported before that use occurs. The rights, agent, appeal, and opt-out methods above apply where required by the relevant state law.

12. International processing

ClaireAI is based in the United States. Information may be processed there and in other countries where relevant providers operate. For transfers requiring safeguards, our DPA sets out the EU Standard Contractual Clauses, UK Addendum, and applicable Swiss adaptations, together with required transfer assessments and supplementary measures. A U.S. hosting location alone does not establish compliance with transfer requirements. We do not claim that Claire AI, LLC is certified under the Data Privacy Framework. Contact us for information about applicable safeguards.

13. Children and changes to this notice

ClaireAI’s business website and account service are intended for adults, not directed to children under 13. A firm’s intake may involve information about minors; the firm must establish a lawful basis and required guardian permissions. If you believe a child provided information directly to ClaireAI contrary to this notice, contact us.

We update this notice as practices or legal requirements change and revise the version and date. We provide additional notice or obtain consent when required. Changes do not themselves authorize a new use of Service Data contrary to the DPA or a firm’s lawful instructions.

14. Contact

Claire AI, LLC · Attn: Privacy Officer
4410 NW 5th Ave
Boca Raton, FL 33431, United States
info@theclaireai.com
+1 (954) 997-0065