How Clarify Handles Your Documents: Privacy & Storage (UK 2026)

You're about to upload a tenancy agreement, an HMRC letter, or an NHS appointment to an AI tool — so where does it actually go, who can see it, and what happens when you're done? Here's exactly how Clarify stores your documents, what we never keep, and how your rights under UK GDPR apply.

Share

Your data, your rules: Under UK GDPR and the Data Protection Act 2018, you have the legal right to know exactly how any company handles your documents — and to demand they delete them. This article explains how Clarify answers those questions, in plain English.At a glance

  • Your documents are encrypted both while travelling to us and while stored — nobody can read them by browsing our systems.
  • We use your document only to answer your questions about it. We do not sell it, share it for advertising, or hand it to third parties.
  • You can delete any document permanently at any time from your dashboard, and it is removed from our storage — not just hidden.
  • We keep the minimum we need to run the service, in line with the UK GDPR principle of data minimisation.
  • You have full rights under UK GDPR: to access your data, correct it, delete it, and take it with you.
  • Not legal advice: This article explains our approach and the rules in plain English. For advice on your specific data-protection situation, speak to a solicitor, the Information Commissioner's Office (ICO), or Citizens Advice.

There is a moment of hesitation almost everyone feels the first time they use an AI tool to make sense of a confusing letter. You are holding a tenancy agreement with your home address on it, an HMRC letter with your tax reference, or an NHS appointment with your medical details — and you are about to hand it to a website you have known for all of five minutes.

That hesitation is healthy. These are exactly the documents that fraudsters, data brokers, and careless companies would love to get their hands on. So before you upload anything to Clarify, you deserve a clear, honest answer to three questions: where does my document go, who can see it, and what happens to it when I am finished?

This is that answer. No marketing fog, no 40-page privacy policy you will never read — just what we do, what we do not do, and the rights the law gives you regardless of what any company promises.

Where your document actually goes

When you upload a document to Clarify, three things happen in sequence.

First, the file travels from your device to our storage over an encrypted connection. This is the same kind of encryption your bank uses — anyone intercepting the traffic in between sees scrambled nonsense, not your letter.

Second, the document is stored in a secure cloud store, encrypted at rest. "At rest" simply means "while sitting on a disk waiting to be used". Even someone with physical access to the storage cannot read the contents without the keys, which are held separately and tightly controlled.

Third, when you ask a question, the relevant text is sent to the AI model that generates your answer. The model reads your document to answer your question and nothing else. It is not browsing your file for its own purposes, and your document is not added to some public training pool for anyone else to benefit from.

What "the cloud" really means here

"The cloud" sounds vague and slightly ominous, but in practice it means specialist data centres run to security standards far higher than a laptop in your kitchen or a document sitting in your email inbox. The uncomfortable truth is that forwarding a sensitive letter to a friend over ordinary email is usually less secure than uploading it to a service built for the job. Email was never designed to protect sensitive documents; purpose-built storage is.

Who can see your documents

The short version: you, and the automated systems that answer your questions. That is the design goal, and everything else follows from it.

  • Our staff do not read your documents for fun or profit. Access to stored files is restricted and logged. The only time a human would ever look at content is a narrow, legitimate reason — for example, if you contact support with a specific problem and explicitly ask us to investigate — and even then, access is limited to what is needed to help you.
  • Other users cannot see your documents. Your account is yours. On a Family plan, documents are shared only with the people you add, and only if you choose to share them.
  • We do not sell your data. Not to advertisers, not to data brokers, not to anyone. Your tenancy agreement is not a product we monetise.

This matters because the business model behind a tool tells you a lot about how it treats your data. Clarify is a paid subscription. You are the customer, not the product — which means we have no incentive to squeeze value out of your personal information, because you are already paying us to keep it safe.

Read your own documents privately. Clarify turns confusing official letters into plain-English answers with citations back to the exact line — without your file ever becoming someone else's product. Upload a letter, ask what it means, and delete it whenever you like.

Try Clarify free → getclarify.co.uk

What we deliberately do not keep

Good privacy is as much about what you refuse to collect as what you protect. We work on the principle of data minimisation — a core requirement of UK GDPR that says you should only hold personal data you actually need, for as long as you actually need it.

In practice, that means:

  • We do not store your card details. Payments are handled by a specialist, regulated payment processor. Your card number never touches our systems, so it cannot leak from them.
  • We do not build a hidden profile of you. We are not stitching your documents together to work out your income, health, or family circumstances for resale.
  • We do not keep documents you have deleted. When you delete a document, it is removed from our storage. Delete means delete — not "hidden from your view but quietly retained".
  • We do not need your document forever. The service exists to help you understand a letter now, not to hoard your paperwork indefinitely.

Your rights under UK GDPR — and how to use them

Here is the part that too many companies bury. Regardless of any promise Clarify or any other business makes, UK law already gives you enforceable rights over your personal data. The Data Protection Act 2018 and UK GDPR entitle you to the following.

The right to be informed

You are entitled to a clear explanation of how your data is used — which is exactly what a privacy policy is for. If you cannot understand a company's privacy policy, that is a red flag in itself.

The right of access

You can ask any company what personal data it holds about you. This is called a Subject Access Request, and the company must respond, usually free of charge, within one month.

The right to erasure

Often called the "right to be forgotten", this lets you ask a company to delete your personal data. With Clarify you do not even need to send a formal request — you can delete documents yourself from your dashboard.

The right to data portability

You can ask for your data in a usable format so you can take it elsewhere. You should never feel locked in.

The right to complain

If you believe a company has mishandled your data, you can complain to the Information Commissioner's Office (ICO), the UK's independent data-protection regulator, at ico.org.uk. They have real enforcement powers.

Practical steps before you upload anything, anywhere

Whether you use Clarify or any other tool, a few habits keep you safe:

  1. Check the business model. A free tool with no obvious way of making money is often making its money from your data. Paid subscriptions usually have cleaner incentives.
  2. Look for encryption. The website address should start with "https" and show a padlock. This is the bare minimum.
  3. Redact what you do not need to share. If a document has a reference number or address that is not relevant to your question, you can black it out first. (Our separate guide on safely sharing documents walks through how to do this properly.)
  4. Read the deletion policy. Can you delete your data yourself, and does the company confirm it is actually removed? If you cannot find the answer, ask before you upload.
  5. Keep your account secure. Use a strong, unique password. The best storage in the world cannot protect you if someone else logs into your account.

See the privacy in action. Sign in, upload a document, get your answer, and delete it — all in a couple of minutes. You stay in control of what we hold and for how long.

Get started with Clarify → getclarify.co.uk

Frequently asked questions

Is my document encrypted?

Yes. Documents are encrypted while travelling to us (in transit) and while stored (at rest). That means the contents are unreadable to anyone who does not have the proper access, whether they are intercepting your connection or looking directly at the storage.

Does Clarify sell my data?

No. We do not sell, rent, or share your personal data or documents for advertising. Clarify is funded by subscriptions, so you are the customer — not the product.

Is my document used to train AI models?

Your document is used to answer your questions about that document. It is not added to a public training dataset for other people to benefit from. If you want the precise technical detail for your situation, our privacy policy and support team can confirm the current arrangements.

How do I delete a document?

You can delete any document yourself from your dashboard at any time. When you do, it is removed from our storage rather than simply hidden from your account.

Can Clarify staff read my letters?

Not as a matter of course. Access to document content is restricted and logged, and would only ever happen for a narrow, legitimate reason — such as investigating a support problem you have specifically asked us to look into.

What happens to my documents if I cancel my subscription?

You can delete your documents before you leave, and you can request erasure of your personal data under your UK GDPR right to be forgotten. If you are unsure what remains after cancellation, ask us directly and we will tell you.

Do you store my payment card details?

No. Payments are handled by a specialist, regulated payment processor. Your card number never touches Clarify's own systems, which is safer for everyone.

What if I think my data has been mishandled?

Contact us first so we can put it right. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk, the UK's independent data-protection regulator, which can investigate and enforce the law.

General information only. This article explains Clarify's approach to data and your rights under UK data-protection law in plain English; it is not legal advice and does not replace our full privacy policy. For advice on your specific situation, speak to a solicitor, contact the Information Commissioner's Office (ICO) at ico.org.uk, or visit Citizens Advice.