Security and trust

Coaching context deserves a higher standard of care.

Clarity is designed around explicit consent, client-level access boundaries, server-side authorization, reviewable context, and controlled use of private coaching material.

Identity

Signed-in user and assigned client

Authorization

Server role and client-boundary checks

Data

RLS, scoped sources, consent, and review

Retrieval

Only permitted context reaches the coaching turn

Current service providers used to operate Clarity

Vercel · hostingSupabase · auth & databaseStripe · subscription billingOpenAI · AI & transcriptionFathom · approved call importResend · email

Defense in depth

Privacy is enforced beyond what the interface shows.

The current architecture uses multiple controls so hiding a button is never treated as authorization.

Authenticated access

Private workspace routes verify the signed-in user before returning client data.

Client-level authorization

Server routes check the user’s role and assigned client before privileged reads or writes.

Row-level security

Exposed Supabase tables use RLS and scoped policies; server-only public intake tables are revoked from browser roles.

Source governance

Calls and knowledge sources carry scope, consent, review, and approved-use status.

Audit records

Sensitive administrative, source, consent, and privacy operations create reviewable events.

Human control

Source approval, client assignment, privacy resolution, and canonical method changes remain human decisions.

How private context moves

A narrow path from source to coaching response.

Providers process only the data needed for their part of the service. Clarity keeps method knowledge and private client context in separate retrieval lanes.

1. Source enters a controlled boundary

A voice response, upload, coaching call, goal, or message is associated with the correct client and source type.

2. Consent and review decide approved use

Private calls and imported histories do not become active context merely because they exist.

3. The server retrieves scoped context

The coaching route selects reviewed method content and the signed-in client’s permitted private context.

4. The member receives a response

The system returns the response without exposing another client’s source material.

Your controls

Ask what is remembered. Correct what is wrong.

Trust requires understandable choices, not only technical controls.

Review

Inspect onboarding summaries, calls, goals, and other visible coaching context.

Correct

Use product controls or support to correct inaccurate client information.

Export

Submit a privacy request for an export of your information.

Delete

Request deletion, subject to information that must be retained for security or legal obligations.

Questions

Know how the experience works.

Clear expectations are part of a trustworthy coaching relationship.

Does Clarity mix one client’s calls into another client’s coaching?

No. Private sources are assigned to a client and retrieved inside that client boundary. The Robert-method library is governed separately.

Are call imports automatic?

Eligible matching can happen automatically, but active use still depends on client identity, consent, source status, and approval rules.

Does Clarity replace crisis or professional care?

No. It is not therapy, emergency support, or legal, medical, financial, or HR advice.

Where can I report a concern?

Use the Security or Privacy category on the support page. Safety-response concerns have a dedicated support category.

Have a privacy or security question?

Send it directly to the Clarity support queue so the team can review the specific issue.