Privacy Policy

Last updated: June 12, 2026

This policy explains what ClearPath Compliance("we," "us") collects, how we use it, and who processes it on our behalf. The short version: we collect your account details and your answers to questions about your security practices — we are built to never hold the sensitive material those practices protect.

1. What we collect

  • Account data: your email address and authentication credentials (passwords are hashed by our auth provider; we never see them).
  • Company profile metadata: organization name, optional CAGE code, employee count band, industry, and a one-sentence description of what your company does.
  • Questionnaire answers:your responses about your security posture (for example, "Do all computers require a password to log in?"), with optional free-text notes.
  • Generated documents:the draft SSP and POA&M content the Service produces from your answers, stored so you can view, edit, and export it.
  • Optional logo: a company logo image for document cover pages — the only file the Service accepts.
  • Billing data: handled by Stripe; we store subscription status, not payment card details.
  • Usage data: funnel events (such as signup, questionnaire completed, document exported) with identifiers and counts — never the content of your answers.
  • Free-tool leads: if you use the free Level 1 checker or score estimator and ask for your results by email, we store that email address and your summary result.

2. What we never collect

The Service must never receive Controlled Unclassified Information (CUI), contract documents, or technical data, and it is designed so there is nowhere to put them: no file uploads exist apart from the cosmetic logo. Do not enter such material into any field. We also never log questionnaire answer content in application logs, and we never send answer content or personal information to analytics.

3. How we use your data

We use your data to operate the Service: calculate your SPRS score, generate your draft documents, export them, manage your subscription, and send you transactional email (welcome, trial reminders, score reports). We use aggregate, content-free usage data to improve the product. We do not sell your data, and we do not use your answers or documents to market to anyone.

4. AI processing disclosure

Document generation uses Anthropic's Claude API. When you generate an SSP or POA&M, your company profile and the relevant questionnaire answers are sent to Anthropic's API, server-side, to draft the document text. Under Anthropic's commercial API terms, this data is not used to train their models. We send only the answers and metadata needed for drafting — the Service never asks you for, and you must never include, sensitive specifics such as CUI.

5. Service providers

The following providers process data on our behalf:

ProviderPurposeWhat they process
SupabaseDatabase, authentication, and hosting of application dataAccount details, company profile, questionnaire answers, generated documents
VercelApplication hostingStandard web request data (IP address, user agent)
AnthropicAI document generation (Claude API)Company profile and questionnaire answers needed to draft your documents
StripePayments and subscription billingBilling name, email, and payment details (we never see full card numbers)
ResendTransactional emailEmail address and the contents of emails we send you
PostHogProduct analyticsFunnel events and identifiers only — never questionnaire answers or document content

6. Security

Data is encrypted in transit (TLS) and at rest. Every customer table is protected by database-level Row Level Security so one organization can never read another's data, and our automated tests prove it. Authentication supports MFA, endpoints are rate-limited, and all AI and administrative calls happen server-side only. Our full security posture is described in our security overview.

7. Retention and deletion

We keep your data while your account is active so your assessments and documents remain available to you. If you schedule deletion of your account, we purge your organization's data after a 30-day grace period (so an accidental deletion can be undone), except minimal billing records we must keep for tax and accounting purposes. Free-tool lead emails are deleted on request.

8. Your choices and contact

You can access and correct your data in the app, export your documents at any time, and request deletion by email. We will notify account holders of material changes to this policy before they take effect. The Service is intended for business use by adults; it is not directed at children. Privacy questions or requests: support@clearpath171.com.