ClearAgency Writing Apply
Legal · Privacy

What we actually record

We build privacy-respecting analytics for clients, so it would be embarrassing to run something worse on ourselves. This notice is written from the code that runs this site — every field named below is a real column in a real table, and nothing is listed that we do not hold.

No cookies for readersNo IP stored for readersNo third-party trackersGDPR

Last updated 2 October 2026

01 The short version

✓Reading this site sets no cookies at all. Not ours, not anybody’s.
✓When you read this site, we never store your IP address or your browser’s user-agent string. They are used for a moment to compute a one-way hash, and then discarded.
✓There is no Google Analytics, no Meta pixel, no advertising tag and no third-party tracker anywhere on this site.
✓We do not sell, rent or share personal data with anyone for their own purposes. Ever.
✓You only give us your name or contact details if you choose to type them into the contact form.
✓A person answers every email. We may use an AI writing assistant to summarise a conversation and draft our reply, but a person reads, edits and sends every message. How that works.
✓One exception, by design: signing in to a password-protected client deck is recorded, including your IP address, because that material is confidential. What is recorded.

02 Who is responsible

ClearAgency is the data controller for personal data processed through this website.

Registered name
Clear Agency AB
Organisationsnummer
559600-8515
Office
Birger Jarlsgatan 42, Stockholm, Sweden
Contact
dj@clearagency.ai

03 When you are just reading the site

Every page view is counted, so we know which guides are read and whether AI assistants are reaching us. Here is the entire record that is written, field by field.

What is storedExampleWhy
Time2026-09-04 19:47To plot traffic over time.
Page address/learnTo know which guides earn their place.
Human or bothuman · bot (GPTBot)So “real people” is a real number, not inflated by crawlers.
Where you came fromgoogle · chatgpt.com · directTo see whether AI assistants are sending people here.
Country and citySweden · StockholmSupplied by Cloudflare’s network from the region of the connection. City level, never an address.
Device and browsermobile · SafariTo know what to test the site on.
A daily codea3f19c04b7e2d518See below.

The two codes, and why they are shaped that way

Counting people without following them is the whole difficulty, and we solved it with two deliberately different one-way hashes. Neither can be reversed, and neither is written to your device.

  • The daily code is a one-way hash of your IP address, your browser string, today’s date and a secret only we hold. Because the date is in it, it changes every midnight UTC. It lets us say “fourteen different people read this today”; it cannot tell us whether you were also here yesterday. This is the code stored next to each page view.
  • The person code is a separate hash without the date, kept in its own small table so that we can distinguish a new visitor from a returning one. That table holds only three things about you: when we first saw you, when we last saw you, and how many pages you have read. No addresses, no referrer, no location. It is deliberately impossible to assemble a browsing history from it, and it only exists for people — bots and crawlers never get a row.

Neither code identifies you to us or to anyone else. Without our secret key they cannot be recomputed, and they are not shared with anyone.

04 Speed measurements

A small script on each page measures how quickly it loaded for you, and posts those numbers once when you leave. What is stored is the time, the page address, the measurement, the number, and whether you were on a phone or a computer. No identifier of any kind is attached, so these samples cannot be linked to you or to each other.

05 Partnership applications

An application is read by a person, not scored by an automated tool, so nothing is fetched or logged simply because you visit. What you send when you apply — your details and your brand’s — and how we handle it is covered in “When you contact us” below.

06 When you contact us

If you use the contact form or email us, we keep what you sent so we can reply and follow up:

  • What you type: your name, your website, and your email address or phone number — whichever you give us. When you apply for a partnership, also when you can start, your brand’s name, your role, the brand’s revenue range and typical order value, how its customers buy, who introduced you (if anyone), and what you tell us about the brand.
  • Where it goes: it is stored in our own database, appears on our internal pipeline board so nothing is forgotten, and lands in the partners’ inboxes so a person sees it promptly.
  • When we work together: we keep your company’s details and the people we deal with (name, role, work email, phone) in our own client register, with our notes on the work, so invoices, agreements, meetings and mail all use the same, correct details. It lives in our own database and is never shared or sold.
  • Anti-spam: forms are protected by simple, privacy-preserving measures: a hidden field that only automated scripts fill in, and a limit on how often one address can submit. Nothing profiles you or tracks you across sites.

We use what you send to answer you, to judge whether there is a fit for a partnership, to prepare a proposal if you want one, and to keep in touch about that conversation. We do not add you to a marketing list, and we do not pass your details to anyone else.

07 Private client decks

Some presentations we prepare for a client sit behind a password, at an address beginning /s/. Before one opens, you confirm that you will keep it confidential and share it only within your own organisation. Because the material is confidential, every attempt to sign in is recorded, field by field:

What is storedExampleWhy
Time2026-09-24 09:14To see when the deck was opened.
IP address203.0.113.7To tell one visitor from another, and to notice someone guessing passwords.
Country and citySweden · StockholmSupplied by Cloudflare’s network from the region of the connection. City level, never an address.
BrowserSafari on iPhoneYour browser’s user-agent string, for the same reasons.
Which passwordthe deck’s own · the temporary one made for youTo see which invitation was used. The password you type is never recorded.
Your confirmationtickedA record that the confidentiality terms were accepted.
Resultopened · wrong passwordFailed attempts are recorded too, to spot guessing.

Once you are in, a cookie on that one deck’s address keeps you signed in for up to 30 days, or until the temporary password you were given expires. Only we can see this record, in our private console.

Shared files. When we share files with you, or ask you to send us files, we use our own file portal at /files. You sign in with your email address and a 6-digit code we email you (a cookie on /files keeps you signed in for up to 30 days). We keep the files you upload, their names and sizes, who shared what with whom and at what level, and a log of sign-ins, uploads, downloads and changes with the time and IP address, so we can see who did what. The files are stored in Cloudflare R2 and are only ever handed out after a check that you still have access. Sign-in codes are stored only as a one-way hash and expire after 10 minutes.

08 Calls, chat and videos

Our booking page, at /book, lets you pick a free time for a video call. It only shows times: it never shows what else is in our calendar. When you book, we keep:

  • What you type: your name, your email address and, if you add one, a note about what you would like to talk about.
  • The booking itself: the time and length you chose. It becomes a meeting in our calendar, with its own video room.

We use them to send you a calendar invitation with a personal link to the video room, to tell our team you have booked, and to hold the call. The invitation carries a private link where you can move or cancel the booking yourself. To stop the form being used to send invitations to strangers, it has the same privacy-preserving anti-spam check as our contact form, and a limit on how many bookings can be made from one connection or for one email address. That limit counts a one-way hash, not your IP address itself, and the counter is thrown away after a day.

The video call itself runs in your browser through Cloudflare’s RealtimeKit. It is not recorded. To keep calls clear, the call page reports technical measurements to us: picture size, frame rate, bitrate, lost data, delay, errors, and your browser type. They carry no name, email, audio or video, and we keep only the latest ones.

Transcription and meeting notes. Only if the host turns it on for a call, and everyone in the call then sees a red “Transcribing” sign: what each person says while their own microphone is on is turned into text by Cloudflare Workers AI, a short stretch at a time, and a note-taker (Anthropic’s Claude, or Workers AI) writes a summary, decisions and action items from that text. The audio itself is not kept, only the text. Everyone in the call can see and correct the notes. The transcript is deleted automatically 90 days after the meeting; the notes stay with the meeting until we delete it, and we delete both on request. Files and links shared in the call’s chat are stored by Cloudflare RealtimeKit for that call.

Chat with us

When we work together, we may invite you to message our team in our own chat app, at /chat. You get it from an invite link we send you: you add the app to your phone (or use it in your browser) and set it up with your mobile number, which is how we check that the link is yours. An invite link works once, for 7 days, and comes with a 6-digit code for setting up the app if you already have it. A cookie on /chat then keeps that phone or computer signed in, for up to about 13 months, or until you sign out or we disconnect the device. We can disconnect a device at any time: it is signed out at once, and the app clears what it keeps there (unsent drafts and notifications). The app doesn’t store messages, photos or files on your device. On a computer you can send us a screenshot or a short recording of your screen: you choose what to share, your browser shows that it’s being shared, and nothing is sent until you press send. To sign in on another device, a signed-in one shows you a 6-digit code that works for 10 minutes.

We keep your name and mobile number (and your email address, if we have it), which chats you are in, the messages, photos, files, screenshots, screen recordings and voice messages you and we send, reactions and poll answers, when each message reached and was read by the other side, and the devices you are signed in on: their type (such as “iPhone · App” or “Mac · Safari”), when they were added and when they were last used. For a month after a device is signed out or disconnected, we keep a note of that, so the app on it can tell you why. If you turn on notifications, we keep the address your browser gives us to send them to. The text of a notification is encrypted for your device, so the service that delivers it (Apple, Google or Mozilla, depending on your browser) cannot read it.

Chats are stored in the EU, on Cloudflare, and encrypted in transit and at rest. They are not end-to-end encrypted: the Clear Agency team can read them, and a chat is linked to your company in our client records. You can delete a message you sent, for everyone, at any time. If a chat has disappearing messages turned on, its messages are deleted automatically after the time shown in the chat.

Videos we send you. Sometimes we record a short video of our screen for you, for example how to change something on your site, and send it as a private link to a page on this site. The page isn’t listed anywhere or indexed by search engines. When the video is played we note that it was played, and when, so we know it reached you. To count each play once, we keep a one-way hash rather than your IP address, and that counter is thrown away within a day. The video is stored with Cloudflare, and we keep it until we delete it or you ask us to.

09 Legal basis

  • Page counts and speed samples — our legitimate interest (GDPR Art. 6(1)(f)) in understanding whether our site works and is being read. The measures described above — no cookies, no stored IP, rotating hashes, a deliberately minimal person record — are what keep that interest proportionate to your privacy.
  • Files you share with us through our file portal — performing our agreement with you (Art. 6(1)(b)), and our legitimate interest (Art. 6(1)(f)) in keeping a record of who opened, added or changed them.
  • Chats with our team — performing our agreement with you (Art. 6(1)(b)), and our legitimate interest (Art. 6(1)(f)) in keeping a record of what we discussed and agreed.
  • Sign-ins to private client decks — our legitimate interest (Art. 6(1)(f)) in protecting confidential material and knowing who has opened it. You are told what is recorded on the sign-in page itself, before you enter a password.
  • Your enquiry, your emails to us and a call you book — steps taken at your request before entering a contract (Art. 6(1)(b)), and our legitimate interest in replying to people who ask us to. That includes using an AI writing assistant to help draft our replies, as described under AI.
  • Records we must keep, such as invoices for paid work — legal obligation (Art. 6(1)(c)) under Swedish accounting law.

10 How long we keep things

RecordKept for
The person code and its three dates180 days after we last saw you, then deleted automatically.
Page views and speed samplesRetained as aggregate traffic history. They contain no identifier, and the daily code inside them stops matching anything within a day.
Free-check recordsKept as an operational log of the tool.
Sign-ins to private client decks12 months, then deleted automatically.
Files shared through our file portal, and their activity logWhile we work together, and deleted on request or when the work ends. Sign-in codes are deleted within a day of expiring.
Chats: the messages, files and voice messages in them, and who is in themWhile we work together, and deleted when we delete the chat or on request. With disappearing messages on, each message is deleted automatically after the time shown in the chat. Unsent uploads are deleted after a day; device codes within a day of expiring.
Calls booked on our booking pageKept in our calendar with the meeting, like any other appointment. Deleted on request.
Call transcripts (only when the host turned transcription on)90 days after the meeting, then deleted automatically. The notes made from them stay with the meeting. Both deleted on request.
Videos we record for you, and how often they were playedUntil we delete them. Deleted on request.
Enquiries and correspondenceWhile we are in contact and for a reasonable period after, so we can pick up a conversation. Deleted on request.
Accounting records for paid workSeven years, as Swedish law requires.

11 Who else sees it

Only the suppliers that make the site work, and only for that purpose. Each is bound by a data-processing agreement and none of them may use your data for their own ends.

SupplierWhat for
CloudflareHosts and delivers this site, stores its data (including files shared through our file portal and videos we send you, in Cloudflare R2), and filters attacks. Also provides the privacy-preserving anti-spam check on our forms, sends our meeting invitations, carries the audio and video of client calls held on this site (RealtimeKit; calls are not recorded unless everyone is told first), and stores our chats with clients, in the EU.
Apple, Google, MozillaDeliver the chat and console notifications you turn on, to your phone or browser. What they carry is encrypted for your device; they cannot read it.
ResendDelivers the email that tells us an enquiry has arrived, or that someone has booked a call.
Google WorkspaceHolds our email today. We are moving it to our own mailbox on Cloudflare, stored in the EU.
Cloudflare Workers AIAnswers questions about our own traffic inside our private dashboard, from already-aggregated figures only, can draft email replies for us (see AI), and turns speech into text in a call whose host turned transcription on. Nothing from this site is used to train a model.
AnthropicIts Claude models power the writing assistant in our mailbox (summarising an email conversation and drafting our reply) and write the notes of a transcribed call. Its commercial terms do not allow it to train models on what we send.

That is the complete list for this website. We do not use an advertising network, a data broker, a customer-data platform or a third-party analytics product, because we wrote our own and it holds less.

12 AI, and what it sees

We use a language model inside our own admin dashboard to answer questions about our traffic, such as “which guide is doing best this month”. It runs on Cloudflare’s network. It is given a summary of already-aggregated figures — totals, percentages and page names. It is not given page-view rows, visitor codes, enquiries or anyone’s contact details, and nothing from this site is used to train a model.

When we write back to you

Our mailbox has a writing assistant. When we open a conversation with you, it can summarise it and suggest a reply, and it can draft that reply in our own words. To do that, the messages in that conversation, together with free times from our calendar, are sent to the model — Anthropic’s Claude, or Cloudflare Workers AI — for that one request. Neither provider may use it to train its models. The assistant cannot send anything. A person reads, edits and sends every email, and any link or password in one is added by that person, not by the model.

Separately, and deliberately, this site invites AI crawlers to read its public pages, because being readable to assistants is what we do. That invitation covers published guides and case studies. It has nothing to do with your data: nothing you send us is published, and the password-protected client areas are excluded from it.

13 Your rights

Under the GDPR you may ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict how we use it, object to processing based on legitimate interest, and ask for your data in a portable form. Write to dj@clearagency.ai and we will deal with it within one month.

One honest limitation: for ordinary page views there is nothing to look up. We hold no identifier that we could match to you, which is the point of building it that way — but it does mean an access request there has no data to return. If you have contacted us, that correspondence is a different matter and we can find, export or delete it straight away.

If you are unhappy with how we have handled your data you may complain to the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten (IMY), or to the supervisory authority where you live.

14 International transfers

Cloudflare serves this site from the network location closest to you, and Cloudflare, Resend, Google and Anthropic are US-headquartered with global infrastructure, so data may be processed outside the EU/EEA. Those transfers are covered by the European Commission’s Standard Contractual Clauses and the suppliers’ own certifications.

15 Security

The site is served only over HTTPS and instructs browsers to refuse anything else. It sets a strict content-security policy and the full set of protective headers. Administrative areas are behind a strong, multi-factor sign-in, and every gated client document needs its own password. Enquiry data sits in an isolated store reachable only by this site’s own code. We keep the finer detail of how each of these is built to ourselves.

16 Contact

Any privacy question, or any of the requests above: dj@clearagency.ai. We have not appointed a data protection officer, as we are not required to; we handle these requests directly.

See also: the cookie notice and the terms of use.