Privacy Policy
Last updated: 12 June 2026
Clarify ("we", "us") is a social-media moderation platform that helps the teams behind public figures and organisations review and respond to comments on their social pages. This policy explains what personal information we collect, how we use it, and the choices available to you. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Information we collect
From our customers (account holders)
- Account details: name, email address, and a password (stored hashed). Two-factor authentication is mandatory for every account.
- Billing details: subscriptions are processed by Stripe. We store your plan, billing status, and Stripe customer reference — we never see or store full card numbers.
- Usage records: actions taken in the app (for example approving a reply or hiding a comment) are recorded in an audit log attributed to the signed-in user.
From connected social accounts
When an administrator connects a social account — a Facebook Page, Instagram professional account, Threads profile, or TikTok Business Account — we access, with their authorisation and through each platform's official APIs, content that is already visible to that account, including:
- Posts published by the account, and comments and replies left on those posts;
- The public profile of commenters as exposed by the platform to account admins (such as display name or username, a profile identifier, and where available a profile picture);
- Reaction and engagement metadata on posts and comments, where the platform provides it.
Access tokens are encrypted at rest with AES-256-GCM. We do not collect social-platform passwords and we cannot access anything the connected account cannot itself see.
Posts you compose and media you upload
Clarify lets a customer's authorised team compose and schedule posts to publish to their own connected accounts. When you do, we store the post text, your scheduling choices, and any photos or videos you upload, so the post can be published at the chosen time.
- Uploaded photos and videos are stored on our servers for up to 30 days after the post goes live, then permanently deleted. The post itself remains on the social platform, subject to that platform's own policies.
- To publish a post, the photo or video is made available at a temporary web address so the social platform can retrieve it, as those platforms require.
- Posts are only ever published on a person's explicit instruction — Clarify never composes or publishes content on its own.
How we use information
- To present comments to the customer's authorised team for human review;
- To classify comments with AI assistance (for example flagging abuse, spam, or suspected coordinated activity) and to draft suggested replies for human approval — Clarify takes no autonomous action on any social platform;
- To publish posts the customer's team composes and schedules, to that team's own connected accounts, at the time they choose;
- To build evidence files (for example for reports to the eSafety Commissioner) at the customer's direction;
- To operate, secure, and bill for the service, and to send service email such as account confirmation and notifications.
Who we share information with
We do not sell personal information. We share it only with the processors that run the service:
- Meta Platforms (Facebook, Instagram, Threads) and TikTok — we read and, on human approval, write content to a customer's own connected accounts through each platform's official API, subject to that platform's terms;
- Anthropic — comment text is sent to the Claude API for classification and reply drafting. Under Anthropic's commercial terms, API inputs and outputs are not used to train their models;
- Stripe — subscription billing;
- Resend — transactional email delivery;
- Microsoft Azure — hosting and data storage in the Australia East region (Sydney, Australia).
We may also disclose information where required by law. Some processors listed above operate outside Australia; we take reasonable steps to ensure they handle personal information consistently with the APPs.
Storage and security
- Data is hosted on Microsoft Azure in Australia, encrypted in transit (TLS) and at rest;
- Facebook Page tokens are additionally encrypted at the application layer;
- Secrets are held in a managed vault, the database is not reachable from the public internet, and access by our customers' staff requires mandatory two-factor authentication;
- Customer data is segregated per organisation (tenant) with enforced isolation.
Platform operator access
A small number of authorised Clarify personnel can access customer environments where necessary to operate, support, and secure the service — for example diagnosing a failed page sync, investigating suspected abuse of the platform, or assisting with an account issue. In-app operator accounts are subject to the same mandatory two-factor authentication as every other account, and actions taken in the application are recorded in the audit log. Direct access to the underlying infrastructure and database is limited to authorised engineers over restricted network paths and is read-only except where maintenance requires changes. Operator access is not used to read customer content for any other purpose.
Retention and deletion
We keep synced content and account information while the relevant account connection and customer account are active. When a connected account is disconnected or a customer account is closed, the associated data is deleted on request — see our data deletion instructions for the exact steps. Backup copies are removed in line with our backup retention cycle.
Photos and videos uploaded for a composed post are retained for up to 30 days after the post goes live and then permanently deleted from our servers automatically; a draft's media is removed when the draft is deleted. The published post remains on the social platform until removed there.
We may retain specific content beyond a deletion request where it forms part of an active safety case or evidence file (for example documentation of threats, abuse, or suspected coordinated harassment), has been provided to or prepared for law enforcement or a regulator, or where retention is required by law or reasonably necessary to establish, exercise, or defend a legal claim. The data deletion instructions describe how these grounds are applied and communicated.
Your rights
You may request access to, correction of, or deletion of personal information we hold about you — whether you are a Clarify customer or a person whose comment on a connected Page was processed by the service. Contact us at support@clarify.net.au and we will respond within 30 days. Deletion requests may be declined or deferred on the limited safety-and-evidence grounds described in our data deletion instructions. If you are unsatisfied with our response you may complain to the Office of the Australian Information Commissioner (oaic.gov.au).
Changes to this policy
We will post any changes to this policy on this page and update the date above. Material changes will be notified to customers by email.
Contact
Clarify — support@clarify.net.au
