Our complete policies, written in plain language. No legalese. No dark patterns.
ClearCiviQ is built on a single principle: your private data is yours. We designed the app so that we technically cannot read your roadmaps, documents, or personal information, not by choice, but by architecture.
This policy explains what data we collect, why we collect it, how it is protected, and what rights you have. If you have questions not answered here, contact us at privacy@clearciviq.app.
Effective date: April 30, 2026. We will notify you of material changes via in-app notice before they take effect.
WHAT YOU GIVE US
You sign in with Apple. ClearCiviQ never sees your email address or password. Apple Sign In handles those on your device. We receive only an opaque account identifier we use to recognize you on return visits.
When you set up a profile: your first name, last name, city, and state, all optional, all encrypted on your device before transmission.
WHAT THE APP GENERATES
Roadmaps, step statuses, document references, and monitoring configurations are encrypted on your device with a key derived from your passphrase. We store only the ciphertext, opaque data we cannot read.
WHAT WE COLLECT AUTOMATICALLY
Aggregate, anonymous telemetry: how long government agencies take to process steps, fee changes, office closures. This data is reported through a separate anonymous pipeline with no user ID, no device ID, and no IP address logged. It is never linked to your account.
WHAT WE DO NOT COLLECT
We do not collect: the contents of your roadmaps or documents, your government application details, your Social Security number, or location data beyond the city and state you optionally provide.
Your vault is encrypted with XChaCha20-Poly1305 using a key derived from your passphrase with Argon2id. This means, whether you unlock with your passphrase or Face ID / Touch ID:
The two-pipeline architecture ensures that your private roadmap data and anonymous community telemetry are handled by completely separate systems that never share a database, request ID, or timestamp.
Different parts of ClearCiviQ have different privacy expectations. Knowing which is which helps you use the app the way you want to be using it.
YOUR PRIVATE VAULT
Roadmaps, documents, intake answers, step progress, and monitoring nicknames are private. They are encrypted on your device with a key derived from your passphrase. We store only the ciphertext. We cannot read your private data.
YOUR COMMUNITY POSTS
Tips you submit to the community feed are public by design, that’s the whole point of the feed. Other ClearCiviQ users will see what you post. Tips are unlinked from your account: we never attach your Apple account identifier to your public submissions. Your identity is detached from the tip. Please note that all submissions remain subject to our Legal & Subpoena Carve-Out policies, see the Legal Process section for the specific, narrow circumstances under which any submission may be reviewed or disclosed.
WE MODERATE COMMUNITY POSTS
We check community posts on your device before they are submitted. If a post looks like harassment, a slur, a threat, profanity, or purely dismissive negativity, you’ll see an error and the post will not be sent. We moderate the community feed because the people who use ClearCiviQ include domestic violence survivors, immigrants, elderly users, and people in crisis, keeping the feed respectful matters.
WHAT WE DON’T LOG
We do not log your real name, your email address, or any payment information. Apple handles sign-in. The App Store handles billing. We never receive your card details or your password.
We do store the IP address and device type your sign-in came from, saved with that session and updated each time the session renews. This is standard account security. It is what makes it possible to notice a login from a device or a place you do not recognize. It is never linked to your roadmaps, your documents, or anything else in your vault. We do not sell it and we do not give it to advertisers. You can see your active sessions, and sign any of them out, in Settings under Active sessions. All of it is deleted when you delete your account.
When you enter a goal, we send your goal text, your city, and your state to Anthropic, our AI research provider. If you answer intake questions for that goal, your answers are sent with it so the roadmap fits your situation.
YOUR GOAL TEXT IS SCRUBBED BEFORE IT IS SENT
Before your goal text leaves your device, and again on our server, a PII scrubber redacts personal identifiers: names from any cultural background, email addresses, phone numbers, physical addresses, Social Security numbers, and similar, so the AI receives the process you are describing, not your identity. No automated redaction is perfect. We minimize what is sent for that reason, and we recommend leaving unnecessary personal details out of your goal text.
We never send your name, your email address, your documents, your roadmap history, your step statuses, or your biometric data.
RECORD MONITORING IS THE ONE EXCEPTION
If you ask us to watch a personal record, checking it means looking it up at the agency, and looking it up means knowing the number. So the number you enter is sent to our AI research provider, which searches the issuing agency’s official site for that record. This applies to green cards, work permits, USCIS cases, driver’s licenses, passports, and Social Security cards.
We ask for your explicit agreement before the first check, and we tell you exactly what is sent at the moment you turn it on. The number is used for that one search. It is never written to our servers, and your name is never sent with it. You can turn agency checking off at any time and the number stops being sent. Expiration reminders keep working without it, because those run entirely on your device.
WE DO NOT TRAIN AI MODELS ON YOUR DATA
Your data is never used to train, fine-tune, or teach foundational AI models. ClearCiviQ is built to use a technique called Retrieval-Augmented Generation (RAG), which means a community tip you submit may be stored and retrieved as context to help generate accurate roadmaps for other users in your area. Retrieval is a lookup, not training: a tip read this way is used at the time of the request and never becomes part of any model. Your goal text is likewise never used as training data, and we do not retain AI conversation logs linked to your account.
COMMUNITY TIPS ARE A CLOSED LOOP
Community tips are processed on infrastructure ClearCiviQ controls. They are never sold, never shared with advertisers or data brokers, and never handed to any AI provider as training data. When community-tip text is included as retrieval context in a request to our AI research provider, that transmission is governed by commercial-API terms that prohibit training on customer content. Community tips can inform roadmaps without ever becoming part of any model’s training data and without ever being sold to anyone for any purpose.
The AI engine operates under a constrained source hierarchy: federal and state .gov websites are prioritized. Law firm blogs, forums, and unverified sources are explicitly excluded.
We do not sell your data. We do not run advertising. We share data only with the service providers required to operate the app. The current named list, and what each one receives, is published in our Trust Center:
Account data is retained until you delete your account. When you delete your account, all data is permanently erased within 30 days.
If you lose both your passphrase and recovery key and request account deletion, your encrypted data is permanently erased within 30 days of your request.
Anonymous community telemetry has no retention limit, it contains no personal information and cannot be traced to you.
You can delete your account at any time from Settings → Account Actions → Delete Account. Cancellation of your subscription does not delete your account or data.
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) give you specific rights:
RIGHT TO KNOW: You have the right to know what personal information we collect, use, share, or sell about you. See "What We Collect" above for the complete list.
RIGHT TO DELETE: You have the right to request deletion of your personal information. Use Settings → Delete Account, or contact privacy@clearciviq.app.
RIGHT TO OPT OUT OF SALE: We do not sell personal information. There is nothing to opt out of.
RIGHT TO NON-DISCRIMINATION: We will not discriminate against you for exercising your CCPA rights, no denial of service, different pricing, or reduced quality.
RIGHT TO CORRECT: You may correct inaccurate personal information through Settings → Profile.
RIGHT TO LIMIT USE OF SENSITIVE INFORMATION: We do not use sensitive personal information (immigration status, health data, financial information) for purposes other than providing the service you requested.
To submit a verifiable consumer request: email privacy@clearciviq.app or use the in-app report function. We will respond within 45 days.
ILLINOIS BIOMETRIC INFORMATION PRIVACY ACT (BIPA): ClearCiviQ does not collect, store, or process biometric identifiers or biometric information as defined under 740 ILCS 14, including fingerprints, retina scans, face geometry, or voiceprints. Document images you store in your vault are encrypted on your device and we cannot access them.
BIOMETRIC AUTHENTICATION (FACE ID / TOUCH ID): When you enable biometric unlock, your biometric data is handled entirely by your device's operating system (Apple Secure Enclave on iOS, Android StrongBox on Android). Your fingerprint scan, face geometry, or iris data is stored in hardware-level secure chips that no app, including ClearCiviQ, can access. ClearCiviQ receives only a binary success or failure result from the operating system. We never see, store, transmit, or have access to any biometric identifier. This is consistent with BIPA's requirements and Apple's and Google's own privacy frameworks.
BIOMETRIC REAUTH POLICY: Biometric unlock is valid for 30 days from your last passphrase entry. After 30 days, your passphrase is required to re-anchor the cryptographic chain to something only you know. This ensures zero-knowledge guarantees remain intact, the vault key derivation still depends on your passphrase, not only your biometrics.
ILLINOIS PERSONAL INFORMATION PROTECTION ACT (PIIPA): We maintain reasonable security measures to protect personal information from unauthorized access, destruction, use, modification, or disclosure, consistent with Illinois law.
ILLINOIS CONSUMER FRAUD AND DECEPTIVE BUSINESS PRACTICES ACT: ClearCiviQ does not engage in unfair or deceptive practices. All material terms of our service are disclosed in this policy and in the app.
Under the Virginia Consumer Data Protection Act (CDPA), Virginia residents have the right to: access personal data we hold about you, correct inaccuracies, delete personal data you provided, obtain a portable copy of your data, and opt out of targeted advertising (we do not conduct targeted advertising).
To exercise these rights, contact privacy@clearciviq.app. We will respond within 45 days and may extend by an additional 45 days with notice.
Under the Colorado Privacy Act (CPA), Colorado residents have the right to opt out of the processing of personal data for targeted advertising, the sale of personal data, or profiling. ClearCiviQ does not conduct targeted advertising, sell personal data, or use profiling for automated decision-making that produces legal effects.
To exercise your rights under the CPA, contact privacy@clearciviq.app.
Under the Texas Data Privacy and Security Act (TDPSA), Texas residents have the right to: confirm whether we process personal data about you and access that data, correct inaccuracies, delete personal data you provided or that we collected about you, obtain a portable copy, and opt out of the sale of personal data, targeted advertising, or profiling that produces legally significant effects. ClearCiviQ does not sell personal data, conduct targeted advertising, or use automated profiling for decisions with legal effects.
TDPSA also requires us to provide a clear and conspicuous notice if we sell sensitive personal data or biometric data. We do not sell either.
To exercise your rights under TDPSA, contact privacy@clearciviq.app. We will respond within 45 days.
Under the Montana Consumer Data Privacy Act (MCDPA), Montana residents have the right to access, correct, delete, and obtain a portable copy of personal data we hold about you, and to opt out of targeted advertising, the sale of personal data, and profiling. The MCDPA also requires data-protection assessments for high-risk processing, which ClearCiviQ conducts before adding any new AI feature that processes user data.
To exercise your rights under MCDPA, contact privacy@clearciviq.app.
Under the Oregon Consumer Privacy Act (OCPA), Oregon residents have the right to confirm whether we process your personal data and obtain a list of specific third parties to which we have disclosed it; access, correct, delete, and obtain a portable copy of your personal data; and opt out of the sale of personal data, targeted advertising, and profiling for legally significant decisions.
OCPA gives Oregonians a unique right to a list of specific third parties (not just categories) to which we have disclosed personal data. ClearCiviQ does not disclose personal data to third parties for their own use; our sub-processors are listed in our Privacy Notice.
To exercise your rights under OCPA, contact privacy@clearciviq.app.
Under the Delaware Personal Data Privacy Act (DPDPA), Delaware residents have the right to access, correct, delete, and obtain a portable copy of personal data, and to opt out of the sale of personal data, targeted advertising, and profiling.
DPDPA requires us to obtain opt-in consent before processing sensitive data (which includes data revealing racial or ethnic origin, religion, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, or biometric data). ClearCiviQ does not process any of these data categories. If a roadmap touches on immigration, we work from the information you provide for that roadmap only; we do not retain or aggregate immigration-status data across users.
To exercise your rights under DPDPA, contact privacy@clearciviq.app.
Under the Iowa Consumer Data Protection Act (ICDPA), Iowa residents have the right to confirm whether we process your personal data, access that data, delete personal data you provided to us, obtain a portable copy, and opt out of the sale of personal data and targeted advertising.
ICDPA does not provide a right to correct inaccuracies. If you find inaccurate data, please contact us, we will correct it as a matter of policy even though Iowa law does not require us to.
To exercise your rights under ICDPA, contact privacy@clearciviq.app.
Under the Nebraska Data Privacy Act (NDPA), Nebraska residents have the right to access, correct, delete, and obtain a portable copy of personal data, and to opt out of the sale of personal data, targeted advertising, and profiling.
NDPA requires opt-in consent before processing sensitive personal data. ClearCiviQ does not process sensitive data categories as defined under NDPA.
To exercise your rights under NDPA, contact privacy@clearciviq.app.
Under the New Hampshire Privacy Act, New Hampshire residents have the right to confirm processing, access, correct, delete, and obtain a portable copy of personal data, and to opt out of the sale of personal data, targeted advertising, and profiling for legally significant decisions.
To exercise your rights under the NH Privacy Act, contact privacy@clearciviq.app.
Under the New Jersey Data Privacy Act (NJDPA), New Jersey residents have the right to confirm processing, access, correct, delete, and obtain a portable copy of personal data, and to opt out of the sale of personal data, targeted advertising, and profiling that produces legally significant decisions.
NJDPA requires explicit opt-in consent before processing sensitive personal data, which includes precise geolocation, racial or ethnic origin, religious beliefs, mental or physical health condition, sexual orientation, citizenship or immigration status, or biometric data. ClearCiviQ does not collect precise geolocation or process the other listed categories.
To exercise your rights under NJDPA, contact privacy@clearciviq.app.
Under the Minnesota Consumer Data Privacy Act (MCDPA), Minnesota residents have the right to access, correct, delete, and obtain a portable copy of personal data, and to opt out of the sale of personal data, targeted advertising, and profiling.
MINNESOTA, UNIQUE PROVISION ON AUTOMATED DECISIONS: MCDPA gives Minnesota residents the right to question the result of profiling that produces legally or similarly significant effects, to be informed of the reasons the profiling led to that result, and (where the data was incorrect) to be informed of what actions you can take to secure a different result. ClearCiviQ uses AI to generate civic-process roadmaps. If you believe a roadmap we generated for you reflects incorrect reasoning or inaccurate data and you are a Minnesota resident, you may request a review by contacting privacy@clearciviq.app. We will respond within 45 days with an explanation of the reasoning and, where applicable, the option to regenerate.
To exercise your rights under MCDPA, contact privacy@clearciviq.app.
Under the Maryland Online Data Privacy Act (MODPA), Maryland residents have the right to access, correct, delete, and obtain a portable copy of personal data, and to opt out of the sale of personal data, targeted advertising, and profiling for decisions that produce legally significant effects.
MARYLAND, UNIQUE DATA MINIMIZATION REQUIREMENT: MODPA prohibits collecting, processing, or sharing personal data beyond what is reasonably necessary for the purpose for which it was collected. ClearCiviQ's zero-knowledge architecture is designed around this principle: we collect only what is required to generate a roadmap for the specific civic process you have asked us to help with. We do not collect personal data "in case it becomes useful later." If a feature requires new data collection, we will ask for it at the time of feature use, not at signup.
MODPA also prohibits the sale of sensitive personal data, including precise geolocation, biometric data, and information about consumers known to be under 18. ClearCiviQ does not sell any personal data and does not knowingly process data of users under 18.
To exercise your rights under MODPA, contact privacy@clearciviq.app.
Several additional states have enacted comprehensive consumer privacy laws. Your rights and our compliance posture under each are detailed below.
New Hampshire (SB 255, effective January 1, 2025). New Hampshire residents have the right to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, data sales, and significant profiling. New Hampshire also requires us to honor global opt-out preference signals. We do not engage in targeted advertising or data sales. Response: 45 days (extendable 45 more). Appeal: NH AG at doj.nh.gov. Contact: privacy@clearciviq.app, subject "New Hampshire Privacy Request."
New Jersey (P.L.2023, c.266, effective January 15, 2025). New Jersey residents have the right to access, correct, delete, and obtain portable copies of personal data, and to opt out of targeted advertising, data sales, and profiling with significant effects. New Jersey's law applies when processing data of 100,000+ NJ consumers or 25,000+ when deriving revenue from data sales. We do not sell data. Response: 45 days (extendable 45 more). Appeal: NJ AG at njoag.gov. Contact: privacy@clearciviq.app, subject "New Jersey Privacy Request."
Minnesota (MNDPA, Minn. Stat. § 325O, effective July 31, 2025). Minnesota residents have the right to access, correct, delete, and obtain portable copies of personal data, and to opt out of targeted advertising, data sales, and significant profiling. Minnesota's law includes a specific right to obtain human review of automated decisions that produce legal or similarly significant effects. If ClearCiviQ's AI-generated roadmap guidance affects a decision with legal significance, you may request that a human review that output. Submit your request with details of the specific decision to privacy@clearciviq.app; we will acknowledge within 10 days and complete review within 45 days. Note: ClearCiviQ provides process information and does not make legal decisions on your behalf, but we take this right seriously. Contact: privacy@clearciviq.app, subject "Minnesota Privacy Request" or "Minnesota Human Review Request."
Maryland (MODPA, Md. Code Ann., Com. Law § 14-4601 et seq., effective October 1, 2025). Maryland's Online Data Privacy Act contains the strongest data minimization requirements of any U.S. state privacy law: we may only collect personal data that is "reasonably necessary and proportionate" to the purposes for which it is processed. Our zero-knowledge architecture and minimal data collection posture are directly aligned with this requirement. Maryland residents have rights to access, correct, delete, and port personal data, and to opt out of targeted advertising, data sales, and significant profiling. Maryland also provides a private right of action for certain violations. We do not process personal data beyond what is strictly necessary to provide the service. Response: 60 days. Contact: privacy@clearciviq.app, subject "Maryland Privacy Request."
Other emerging state laws. Additional state privacy laws have been enacted or are expected to take effect including laws in Indiana (effective January 1, 2026), Kentucky (effective January 1, 2026), and others. Our privacy practices, including zero-knowledge encryption, strict data minimization, no advertising or data sales, and a straightforward deletion mechanism, are designed to comply with the full scope of U.S. state privacy laws. If your state is not listed here, your rights under any applicable state law are honored on the same terms. Contact privacy@clearciviq.app for any privacy rights request. For general help, contact support@clearciviq.app. To report a security issue, contact security@clearciviq.app.
ClearCiviQ is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided personal information to ClearCiviQ, contact us at privacy@clearciviq.app and we will delete it promptly.
Users must be 18 or older to create an account, consistent with the nature of the government processes the app navigates.
ClearCiviQ includes a dedicated safety mode for domestic violence survivors. This mode is accessible directly from the app's first screen without creating an account, tap 'Need immediate safety help?' on the welcome screen. No email address, no passphrase, and no account data is collected when using safety mode.
The DV survivor roadmap flow is permanently free and cannot be paywalled. No data from a safety mode session is linked to any account.
The QuickExit feature allows any user to instantly clear all local app data and navigate away in one tap. Local storage is wiped before the navigation redirect, ensuring the app's presence disappears even if the redirect is slow.
If you are in immediate danger, call 911. The National DV Hotline is available 24/7 at 1-800-799-7233 (TTY: 1-800-787-3224).
We implement administrative, technical, and physical security measures appropriate to the sensitivity of your data. Key measures include client-side XChaCha20-Poly1305 encryption, separated data pipelines, k-anonymity enforcement on community data, and zero plaintext storage of personal vault contents on our servers.
No system is perfectly secure. If you discover a security vulnerability, please report it responsibly to security@clearciviq.app before public disclosure.
In the event of a data breach affecting your personal information, we will notify you as required by applicable state breach notification laws.
IMPORTANT: This section describes a deliberate, narrow exception to ClearCiviQ’s zero-knowledge architecture. It applies ONLY to community tips you publicly submit. It does NOT apply to your vault, your roadmap data, your documents, your personal notes, or anything else stored on your behalf.
WHAT ZERO-KNOWLEDGE STILL COVERS: Everything in your private vault remains end-to-end encrypted with a key only you hold. That covers documents, journal entries, roadmap progress, sub-step checkmarks, monitoring records, and the goal text of any roadmap you generate. ClearCiviQ cannot read this data. A subpoena cannot compel us to produce it because we mathematically cannot decrypt it. This guarantee is unchanged.
WHAT THE CARVE-OUT COVERS: A community tip is a piece of advice shared with other ClearCiviQ users to help them navigate a government process. When you publicly submit one, the content of that tip is, by design, NOT end-to-end encrypted. Tips are public content, intended to be seen by other users. Before your tip is published, it is automatically scrubbed of personal identifiers (names, phone numbers, addresses, license numbers, etc.) by both your device and our server, but the remaining text is stored on our servers in readable form so that other users can read and benefit from it.
WHY THIS CARVE-OUT EXISTS (LEGAL COMPLIANCE): U.S. federal law (18 U.S.C. § 2258A) requires electronic service providers to report apparent child sexual abuse material (CSAM) to the National Center for Missing & Exploited Children (NCMEC) when we have knowledge of it. The federal Stop Enabling Sex Traffickers Act (SESTA-FOSTA, 18 U.S.C. § 2421A) creates parallel obligations regarding content that facilitates sex trafficking. We cannot fulfill these legally required reporting obligations on encrypted content we cannot read. Because community tips are public content where another user could submit material implicating these statutes, we maintain the ability to moderate community tip content for these specific categories.
WHAT MODERATION MEANS TODAY: Every community tip is automatically classified before publication. A tip that is flagged as potentially involving (a) child sexual abuse material, (b) sex trafficking, or (c) a credible imminent threat of serious harm is blocked. It is not published, and it is not stored. If we obtain actual knowledge of apparent child sexual abuse material, we report it as federal law requires.
WHAT IS NOT YET RUNNING: We have built, but not yet turned on, a second stage for these three categories. In that stage a flagged tip would be held in a secured quarantine rather than discarded, reviewed by a designated human operator, and where review confirms the statutory threshold is met, filed directly with NCMEC along with the edge-log metadata captured at submission (typically an IP address and a timestamp, never your Apple identity, your name, or your email). That stage requires our registration as an Electronic Service Provider with NCMEC to complete first. Until it does, flagged content is blocked and discarded as described above, and the edge log for a submission is deleted within one hour like any other. We will update this section when the second stage is enabled, and everything below describing quarantine applies from that point forward, not today.
WHAT THIS NEVER COVERS: Tips with PII (names, phone numbers, addresses), tips that are off-topic, tips that are spam, and tips that are simply inaccurate are NOT part of this carve-out, today or after the second stage is enabled. They are scrubbed and either rejected at submission time or filtered by community reporting. The carve-out is limited to the three narrow categories listed above and is designed to be triggered rarely.
WHAT WE DISCLOSE TO YOU AS A SUBMITTER: If you submit a tip that is rejected for ordinary reasons (PII, off-topic, spam, low quality), you will see a generic rejection message. You are never told that a tip was flagged under the three legal-compliance categories, or which one. This is by design, to avoid creating a feedback loop a malicious user could exploit to refine attempts to bypass moderation. Once the second stage described above is enabled, such a tip will show to you as "pending review" rather than as rejected, for the same reason.
WHAT TO DO IF YOU BELIEVE YOUR TIP WAS WRONGLY BLOCKED: Contact privacy@clearciviq.app with the approximate date and time of submission. We will review the classification within 30 days of your request. Note that a tip blocked under these categories is not retained today, so a review can tell you how the classifier treats that text but cannot recover your original submission.
YOUR PRIVATE DATA IS UNAFFECTED: To restate the most important point: this carve-out applies ONLY to community tips, which are public-by-intent. Nothing in your private vault, your roadmap, your documents, or your personal account data is subject to this moderation. Those remain encrypted and unreadable to ClearCiviQ.
ClearCiviQ is built so that we cannot disclose what we do not have. The following describes, in plain English, what a court order or subpoena can compel ClearCiviQ to produce, and what it cannot.
WHAT WE CANNOT DISCLOSE under any subpoena, search warrant, or court order, because we do not possess it:
• The contents of your vault. Documents, attachments, journal entries, and roadmap content are encrypted on your device with a key derived from your passphrase. We never see your passphrase, we never store the key, and we cannot decrypt this data. We can hand over the encrypted blob; it is unreadable without your passphrase.
• Your passphrase or any key derived from it. We do not know it. We cannot reset it.
• Raw step-accuracy feedback. This is the telemetry generated when you mark a roadmap step as correct or incorrect, or submit a fee correction. It is internal accuracy data, not a community post and not displayed to anyone. Raw step-feedback rows are rolled up into anonymized aggregates and the raw rows are deleted within 36 hours of submission. After that window, the underlying rows no longer exist for us to disclose.
• The text of community tips rejected at moderation for ordinary reasons (PII, off-topic, spam, low quality). Rejected text for these categories is never persisted on our servers; only an anonymous category counter is incremented.
• A server-side mapping between users and the public community tips they have contributed. We never record which account submitted which tip. The "tips submitted" count surfaced in your Settings is a counter stored only on your device. Even for a community tip that is fully public and that we can produce the text of, we cannot tell anyone, including law enforcement, who wrote it, because that link was never created.
NOTE ON COMMUNITY TIPS (these are NOT deleted): Community tips you submit to the public feed are public by design and persist in the feed. They are not aggregated-and-deleted like step-feedback telemetry, and they are not part of the zero-knowledge vault. The only thing we cannot disclose about a community tip is the identity of its submitter (see the last bullet above). The tip text itself is public and is listed below under "What We Can Disclose." Do not submit anything to the community feed that you would not want to be public and permanent.
WHAT WE CAN DISCLOSE under a valid legal request, because we do possess it:
• That an account exists for a given Apple identifier ("OAuth subject"). Note that Apple does not disclose your subject identifier to law enforcement absent their own separate legal process; a request that arrives at ClearCiviQ naming an email address or your real name cannot be matched to a ClearCiviQ account by us.
• The subscription tier and billing history associated with that account, via our payment processor.
• The IP address a session was created from, stored on the session record itself (see the account data section above). Our operational logs are separate and contain no IP address: they record the request method and route only, with IP addresses, user agents, and request bodies stripped before anything is written. We retain operational logs for 14 days.
• Account creation date and last-seen timestamp.
• Community tip content in our public corpus. Public tips are publicly visible in the app; they are also retrievable by us in response to lawful process. The corpus does not include a server-side mapping to the submitter.
• Once the quarantine stage is enabled, quarantined community tip content held for legal-compliance review (CSAM, trafficking, imminent-threat categories only), and the edge-log metadata associated with that submission (IP address and timestamp). That stage is not running yet, so at present we hold no quarantined content and no edge log older than one hour, and cannot produce either. See the "Community Tips, Privacy Carve-Out" section above.
WHAT SCA PRESERVATION ORDERS CAN COMPEL: Under the Stored Communications Act, 18 U.S.C. § 2703(f), law enforcement may serve a preservation request directing us to retain specified records that we would otherwise routinely delete. A preservation order does not by itself compel disclosure. Disclosure still requires the appropriate level of legal process (subpoena, court order, or warrant depending on data type). However, a preservation order can prevent records that would normally age out of our 30-day retention window from being deleted. We comply with valid preservation orders.
WHAT WE WILL CHALLENGE: We will, where we have a reasonable basis, challenge legal process we believe is overbroad, lacks proper authority, or violates user rights under the First or Fourth Amendments. We cannot promise to challenge every request, but we will not comply with a request we believe is plainly unlawful.
WHAT NON-DISCLOSURE ORDERS PROHIBIT US FROM TELLING YOU: If legal process arrives with a non-disclosure order (sometimes called a "gag order"), federal law may prohibit us from informing you that we received it, for the duration of the order. We may, where lawful, challenge non-disclosure orders we believe are overbroad. We will not lie to you: if you ask us "have you received a subpoena about my account," and we have received one under a non-disclosure order, we will decline to answer rather than answer falsely.
This posture is intentional. The user-facing zero-knowledge promise applies to the CONTENT of your private data, not to the EXISTENCE of an account, and not to public content you have chosen to share through community features. We can confirm an account exists; we cannot read what the account has stored in their private vault.
If you lose your device AND your recovery key, your vault data is permanently unrecoverable. This is not a bug. It is the only model in which "no one at ClearCiviQ can read your vault data" is honestly true. Save your recovery key.
Transparency: ClearCiviQ publishes an annual transparency report describing the number of legal requests we received and how we responded, in accordance with applicable laws and any non-disclosure orders. We do not publish the contents of any individual request. The first transparency report will be published on the one-year anniversary of public launch, or sooner if material volume of legal requests warrants.
Privacy requests: privacy@clearciviq.app
Security reports: security@clearciviq.app
General: support@clearciviq.app
ClearCiviQ
Chicago, Illinois
For any data rights request, please include your email address and a description of your request. We will respond within 45 days as required by applicable law.