Privacy Notice

approved public policy

What Claire Is

Claire is a Codex plugin/MCP assistant for Malta and EU legal/regulatory research, drafting support, obligation registers, and human-review handoffs. It is not a public web user portal.

Data Processed

Claire processes prompts, tool arguments, verified Google, email, or WhatsApp identity, internal account identifiers, existing entitlement status, controlled matter references, support requests, draft work-product content and metadata, audit events, and submitted source references needed to operate the requested tool. Email and WhatsApp verification codes are stored only as short-lived keyed hashes. WhatsApp identity is stored as a keyed hash with a masked contact; the raw WhatsApp destination is not retained in the OTP challenge. Public MCP responses minimize internal identifiers and do not return storage paths, raw access tokens, verification codes, or connector request identifiers.

Purposes and Legal Basis

Account identity, security, entitlement enforcement, requested legal-productivity functions, support, fraud prevention, and auditability are processed to perform the service, protect users, comply with applicable obligations, and pursue legitimate interests in secure operation. Users must have authority and a lawful basis for the minimized personal data they submit; the sensitive-data restrictions below still apply.

Sensitive Data Boundary

Supply only public, synthetic, redacted, or pseudonymous evidence necessary for the requested task. Do not send passwords, one-time codes, API keys, payment-card data, government identifiers or identity-document images, or protected health information through MCP tools. The public release does not accept special-category or criminal-offence personal data. Redact those fields before submitting legal, employment, migration, family, financial, or AML documents. Controlled-matter status is not permission to bypass these restrictions. Do not send complete chat histories.

Storage and Tenancy

Authenticated work product follows isolated per-user processing and storage. Raw MCP bearer tokens, Google client secrets, admin tokens, connector credentials, and credential JSON are not stored in the repository. Audit logs store operational metadata and evidence references rather than broad raw prompts.

Account Controls

Authenticated users can request account export at /account/export and can submit a deletion request at /account/deletion-request. Deletion is human-reviewed because legal, professional, audit, billing, and security records may be subject to retention duties.

External Services

Google provides OpenID Connect sign-in. Cloudflare hosts the Worker, D1 database, R2 work-product storage, email-code delivery when enabled, security controls, and operational logs. Meta provides WhatsApp code delivery when enabled. OpenAI provides the Codex and ChatGPT client. Credentialed advanced connectors are separate services and require an approved data-access basis, credential-custody evidence, and smoke-test evidence before activation.

Public Source Boundary

Public source tools return Claire-authored templates and concise metadata with canonical links to official Malta, EU, OpenAI, and Cloudflare sources. Claire does not scrape or redistribute third-party full text in public mode. Judgment or other third-party source text must be supplied by the user in redacted form or returned by a separately approved connector with documented access rights and provenance.

Retention and Deletion

The operator retention schedule sets the following limits: expired or used OAuth/verification challenges within 24 hours; rate-limit buckets 48 hours; expired/revoked/rotated token hashes 30 days; account identity and entitlements while active plus 30 days after approved closure; support and rights requests 24 months after closure; manual billing confirmations 6 years after the accounting period; security and admin audit events 12 months. A documented legal hold, investigation, dispute, or applicable legal duty may extend a relevant record's period. Matter documents and work products require a recorded matter-specific retention period, reviewed at closure and annually; they must not be retained indefinitely by default. Deletion is human-reviewed and data no longer required is deleted or irreversibly de-identified. These are operator policy periods, not a representation that every category has the same statutory requirement.

Rights and Contact

Authenticated users can request access or export at /account/export and submit deletion requests at /account/deletion-request. Correction, restriction, objection, portability, complaint, and privacy-contact requests can be submitted through /support/request. Identity and authority are verified before disclosure or deletion.

International Transfers and Security

Hosting, OpenAI client operation, Google authentication, and credentialed connectors may involve international data transfers. The accountable operator and user must assess applicable transfer mechanisms. Claire uses per-user isolation, OAuth scopes, server-side entitlement checks, encrypted transport, restricted administration, audit logs, and fail-closed connector controls; no system can guarantee absolute security.

Children

Claire is intended for professional research support, is not directed to children under 13, and must remain suitable for a general audience including users aged 13 to 17. Do not submit children's sensitive or identifying case records.

Professional boundary

Codex and ChatGPT app/MCP assistance only: draft Malta and EU legal/regulatory research and work-product support for users. No public web user portal, final legal advice, client acceptance, conflict clearance, filing, authority contact, STR/SAR, payment processing, or external delivery.

Policy pack

Delivery surface: Public Codex and ChatGPT plugin/MCP; no public web user portal. Public web user portal: none.