ClearTerms · Almareem Technologies
Your privacy, explained.
What we collect, why we use it, and the choices that stay yours.
Effective 1 October 2026 · Version 2026-10-02 · Supervised pilot
Who is responsible
Almareem Technologies operates ClearTerms at Noble Center. Contact Johnson Mmbaga at [email protected] for privacy questions, access requests, corrections, deletion or complaints. This notice describes the account, website, browser extension and supervised document-review service.
Information we collect
When you choose Google or GitHub sign-in, we save its profile-photo URL and display that photo in your account and administrative account listings. Loading the photo contacts the provider’s image service. Account information includes your name, email, verification state, sign-in provider identifiers, hashed password where used, public passkey credentials, encrypted two-factor recovery information, sessions and policy-consent history. Review information includes submitted originals, reading copies, extracted text, supplied context, exact passages, findings, questions, corrections and review decisions. Operational records include delivery status, security events and limited technical information such as IP addresses or device information needed for authentication.
Passkeys and biometrics
Your device or password manager checks your fingerprint, face or device PIN. ClearTerms receives a public-key credential and verification result. We do not receive or store your fingerprint, facial image or biometric template. You can remove a registered passkey from Security.
Why we use information
We use information to create and secure your account, provide the review you request, verify access, communicate about your account, investigate errors, maintain an audit history and honour privacy choices. We rely on the grounds available under applicable law, which may include providing a requested service, security and legal obligations. Where processing requires consent, we ask separately. Agreeing to the Terms is not blanket consent to unrelated uses.
Who can access it
Case access is available to the owner, the assigned authorised reviewer, and superadmins who have completed second-factor verification. Superadmins can inspect submitted documents and draft reports for platform operation, support and incident handling, manage assignments, withdraw reports, and delete documents or accounts. Administrative document reads and changes are recorded. The role does not itself qualify a person to approve legal findings; qualified reviewer and independent evidence-approval requirements still apply. Operational oversight concerns activity within ClearTerms, not unrelated browsing or device activity. Necessary infrastructure, email and authentication providers process information to supply their configured services. We do not sell your documents or personal information.
Email and your choices
Verification, password recovery, sign-in codes and essential security messages support your account. Welcome messages explain the service. Campaign emails are sent only to verified accounts that opted in. You can withdraw that choice in Settings or use the unsubscribe link without signing in. We do not add tracking pixels to campaign messages. Unsubscribing from campaigns does not prevent essential account messages.
Providers and international processing
The configured services may include Neon PostgreSQL, Nodemailer delivery through the configured SMTP provider, Google or GitHub when you choose social sign-in, and OpenAI for enabled live analysis. A production deployment may also use private AWS storage and processing. These services may process data outside your country. Specific regions, contracts and any required transfer safeguards must be reviewed before real confidential documents are admitted to the pilot. A development label is not permission to upload live customer documents.
AI processing
Fixture mode does not make AI requests. When live mode is approved and enabled, the server sends extracted document text, context and approved evidence to the configured OpenAI API. The adapter requests store:false, which alone does not guarantee zero provider retention. Provider security monitoring and contractual retention can still apply. ClearTerms does not use your documents to train models.
Document retention and deletion
With the current default configuration, unsaved case content expires after 24 hours; release resets that period to 24 hours. Saved cases expire after 30 days. A running worker removes expired content. A deletion request immediately revokes case access and schedules removal of originals and derived content, including extracts, reports, embeddings, questions and issue text. Active-job fencing prevents deleted content from being recreated. Storage failures remain queued for retry. Minimal content-free tombstones and audit records may remain for security and integrity.
Account, email and backup records
Account information remains while you use the service or while a closure request is being resolved. Contact us to request account closure and related erasure; we will explain any necessary retention. Email message payloads are encrypted while queued and removed after successful delivery or expiry; delivery metadata is removed after 30 days. Copies held by your email provider, downloaded files and provider backups have separate retention arrangements. We do not promise immediate removal from every backup; backup expiry and restoration controls require verification in the deployment environment.
Browser extension and cookies
The extension acts only when you choose to capture a page or selection and submit the preview. It records the submitted content, source URL, time and version information needed to anchor findings. It does not silently upload browsing history. Pairing codes expire after five minutes; extension access tokens expire after one hour and can be revoked. The web app uses essential session, security, OAuth and short-lived registration-consent cookies. Marketing consent is stored separately and is not assumed from browsing.
Your rights and contact
Depending on applicable law, you may request access, correction, erasure, restriction, a copy of your information, or object to a use. You may withdraw optional marketing consent at any time. Email [email protected]; we may need proportionate verification of your identity. You can also complain to a competent data-protection authority, including Tanzania’s Personal Data Protection Commission where applicable. We will not treat a privacy request as permission to send marketing.
Security, children and changes
We use access controls, hashed passwords, encrypted authentication secrets and queued email payloads, and secure transport where configured. No system is perfectly secure; contact us promptly about suspected unauthorised access. ClearTerms accounts are intended for adults aged 18 and above. Material changes to this notice will be published with a new version, with renewed acknowledgement requested where appropriate.