Opt out of model trainingRecords stored in Canada EastIndependent review

    What we do with your data, and how we prove it

    Trust promises are easy to make. This page states ours plainly: where your data lives, what we will and will not do with it, and how every decision we make stays provable long after it was made.

    A faceted shield built from fine horizontal strata, with one unbroken lit line running from its top point to its base.

    Our data-use promise, tier by tier

    Like every AI company, we improve our service over time, and your organisation's data is eligible for that work unless you turn it off. Unlike most, we put the boundary in writing and enforce it in the software itself: the export step that prepares improvement data refuses anything that breaks these rules, by default.

    Turning it off is one control in the portal Settings, it takes effect on the next export, and it changes nothing else: same records, same retention, same service at the same cost. What is shared is never your original wording, and Enterprise data is excluded whatever the setting says.

    General

    Personal information is stripped out before anything is ever used to improve the service. Names, account numbers, contact details: removed first, always. If the check finds anything left over, the export fails rather than ships.

    Pro

    Your content is either generalized beyond recognition or excluded entirely. The wording of your request is replaced with a marker, and the step-by-step working collapses to a flag that says a step ran, not what it found.

    Enterprise

    Your data never leaves your dedicated environment and is never used to improve the shared service. Full isolation, contractually and technically. This one is not a setting you have to remember to check.

    Where your data lives

    Your audit records are stored in Canada. They are written to Azure storage in the Canada East region and stay there for the whole retention period. That is the part we can point at today, and it is the part your auditors will ask for.

    Processing is a separate question and we will not blur the two. The step that reads and interprets your message runs in a Google Cloud region in the United States. The governed tier that applies your policy, judges the result, and writes the record runs in Azure Canada East, but the models it calls are deployed on Microsoft global infrastructure, which can process a request outside Canada. So today, your message content can be handled outside Canada.

    Two pieces of work change that: moving the reading tier into a Canadian region, and moving every model that touches customer content onto regional Canadian deployments. Neither is finished. Both are conditions we have to meet before a pilot that requires Canadian processing, and we will show you the deployment records when they are met rather than ask you to take our word for it.

    Enterprise customers who need processing pinned to one jurisdiction should talk to us before signing. A dedicated, isolated setup is how we would do it, and it depends on the same regional model deployments described above.

    Plain answers to fair questions

    • Do you train shared AI models on our data? By default your data is eligible, in the generalized form described above, and one setting turns it off. Enterprise data is never eligible.
    • Can we see why a request was blocked? Yes. Every block names the rule that fired.
    • Can our auditors reconstruct a past decision? Yes, in full, including the rules as they stood that day.
    • Do blocked requests still cost us money? Only for the checks that ran. Held funds for unrun steps are released.
    • Is everything handled in one country? Records are stored in Canada East. Processing is not Canada-only yet, and the section on the left says exactly where it runs today.

    How the system keeps its promises

    These aren't policies taped on afterward. Each one is a mechanism built into how Clara runs every single request.

    Every decision is reconstructable

    Months later, we can show you exactly what was checked, which rules applied at the time, what each step found, what it cost, and why the final call was made. The record is built as the decision happens, not assembled afterward.

    The judge is never the author

    Before a decision leaves Clara, it is reviewed by an independent judge that had no part in producing it. Hard cases go to a panel of AI models from different companies, and a single dissenting vote blocks.

    Block first, bill honestly

    On a governed run, a risky request is stopped before any big AI is paid to run. We hold the worst-case cost up front, charge only for what actually ran, and release the rest. Your receipt shows both numbers.

    Your rules cannot be talked around

    The safety rules your business sets form a floor that nothing can lower. Not a cleverly worded request, not a customer instruction, not our own AI. Attempts to weaken the floor are refused and recorded.

    Put these promises in your contract

    Pilot customers get all of this in writing, reviewed by your security and legal teams before anything runs.