Authenticated access
Private workspace routes verify the signed-in user before returning client data.
Security and trust
Clarity is designed around explicit consent, client-level access boundaries, server-side authorization, reviewable context, and controlled use of private coaching material.
Signed-in user and assigned client
Server role and client-boundary checks
RLS, scoped sources, consent, and review
Only permitted context reaches the coaching turn
Current service providers used to operate Clarity
Defense in depth
The current architecture uses multiple controls so hiding a button is never treated as authorization.
Private workspace routes verify the signed-in user before returning client data.
Server routes check the user’s role and assigned client before privileged reads or writes.
Exposed Supabase tables use RLS and scoped policies; server-only public intake tables are revoked from browser roles.
Calls and knowledge sources carry scope, consent, review, and approved-use status.
Sensitive administrative, source, consent, and privacy operations create reviewable events.
Source approval, client assignment, privacy resolution, and canonical method changes remain human decisions.
How private context moves
Providers process only the data needed for their part of the service. Clarity keeps method knowledge and private client context in separate retrieval lanes.
A voice response, upload, coaching call, goal, or message is associated with the correct client and source type.
Private calls and imported histories do not become active context merely because they exist.
The coaching route selects reviewed method content and the signed-in client’s permitted private context.
The system returns the response without exposing another client’s source material.
Your controls
Trust requires understandable choices, not only technical controls.
Inspect onboarding summaries, calls, goals, and other visible coaching context.
Use product controls or support to correct inaccurate client information.
Submit a privacy request for an export of your information.
Request deletion, subject to information that must be retained for security or legal obligations.
Questions
Clear expectations are part of a trustworthy coaching relationship.
No. Private sources are assigned to a client and retrieved inside that client boundary. The Robert-method library is governed separately.
Eligible matching can happen automatically, but active use still depends on client identity, consent, source status, and approval rules.
No. It is not therapy, emergency support, or legal, medical, financial, or HR advice.
Use the Security or Privacy category on the support page. Safety-response concerns have a dedicated support category.
Send it directly to the Clarity support queue so the team can review the specific issue.