Legal

Privacy

Last updated 29 September 2026

GenClara is a paid service that keeps only the personal data listed below, holds server logs for 30 days, and never sells any of it or shares it for advertising. Every U.S. resident has the same rights here, whatever state they live in. This notice names every company that handles your data. Downloading your file or deleting your account is self-serve, at any time, from the billing page.

Who we are

GenClara is operated by Digent LLC, the controller of the personal data described here, which means it decides how that data is used. Write to us at support@genclara.com. GenClara is offered to businesses in the United States.

What we collect

  • For your account we keep your email address, the name on the account, and your sign-in sessions. Your password is stored only as a one-way scrypt hash. Nobody can read it back.
  • For your organization we keep who its members are and each one's role. The other members of your organization see your email address, name and role. When an admin invites someone, we use the address the admin enters to send the invitation and keep a record of it with the organization, erased when the organization is. The file records which member changed it and which member approved it. We keep whether each member wants reminder email, and a list of which reminder went to which member, so nobody gets one twice. That list deletes its own entries after a few months.
  • We keep your organization's audit log: each member's sign-ins, changes, approvals, downloads and API calls, with their email address and the time. Admins and read-only members download it. It stays with the organization until the organization is erased, including what it says about members who have left.
  • Your file holds what you type into the app or send to the API, such as reserve figures, reporting schedules, controls, and evidence titles, locators and digests. For evidence we record a fingerprint of a document, never the document itself.
  • For billing, Stripe collects your card details directly, and they never reach our servers. We keep your Stripe customer number, your subscription status and your renewal date.
  • Technical data means your IP address and browser details, kept in server logs and used to slow down repeated sign-in attempts.
  • Emails you send us at the support address: your address and whatever you write.

We do not request government identification numbers, health or biometric information, or precise location data. Do not enter those details in your file or in support messages.

What we use it for

To run the service, keep it secure, bill you, and send the account emails the service needs, which confirm your address and reset your password. Members who prepare or approve a file also get plain-text reminders before its filing due dates and when changes wait for their approval. Each member can turn these off on the filing calendar page. That is all. We do not sell personal data, share it for anyone else's marketing, show advertising, or run analytics or tracking scripts on the site. We do not use your data to train AI models.

Who handles it for us

  • Amazon Web Services hosts the app, the database and the account emails, in the United States (Northern Virginia).
  • Stripe takes payments, keeps the payment records, and emails you receipts, refund notices and failed-payment notices.
  • Cloudflare sits in front of the site to protect it and encrypt connections, so it carries your traffic in transit.
  • Proton hosts the support mailbox, so it holds the emails you send us.

Each of them handles the data only to provide its own service to us, under its contract with us, and this list is updated here before anyone new is given access to any of it.

We give it to no one else, except where the law requires us to disclose it, where disclosure is needed to protect someone's rights or safety, or to a successor in a merger or sale of the business, which stays bound by this notice.

Who can access your file

Other customers cannot reach your file. Each file belongs to one account, and every request is checked against that account before anything is read or written.

Digent LLC runs the service and holds the administrative access to the hosting account, so it can technically reach the database. It opens a customer's file only to fix a problem the customer reports, to restore data from a backup, or where the law requires it. The processors listed above handle data only to provide their own service. We make no claim of an independent security audit or certification of GenClara itself.

How long we keep it

  • Your account and file stay until you delete the account, even after a subscription ends, when the file remains readable and downloadable for as long as the account exists.
  • When you delete your account, your file, API keys, billing record and sign-in are erased at once. Database backups hold a copy for up to 14 days. Then it is gone.
  • If you are a member and delete your account, you leave the organization. Its audit log keeps the entries about you, because they are the organization's record.
  • Server logs: 30 days.
  • Emails you send us stay in the support mailbox as the record of the conversation; ask and we delete them.
  • Stripe keeps its own payment records, such as invoices and receipts, for as long as tax and payment law requires it to, even after your GenClara account has been deleted.

Your choices

On the billing page you can download everything in your file and delete your account. Neither needs anyone's approval. Wherever you live in the United States, you may also ask to know what we hold, get a copy in a portable format, correct it or delete it, and opt out of any sale, sharing, targeted advertising or profiling (we do none of these). Write to support@genclara.com and we will answer within 30 days. We verify each request, accept one from an authorized agent with your written authorization, never treat you differently for using a right, and if we decline you may appeal by replying to our answer.

Security

Every connection to GenClara is encrypted, and so is the database on disk. Each file belongs to one account, and every request is checked against that account before anything is read or written. No system is perfectly secure. Should a breach affect your data, you will hear from us as the law requires.

Cookies and privacy signals

GenClara sets only the cookies that keep you signed in and protect the sign-in from forgery. There are no advertising, analytics or tracking cookies, so there is nothing to opt out of. Because we never sell or share personal data for advertising, a browser's Global Privacy Control or Do Not Track signal changes nothing: we already treat every visitor as having opted out.

Adults only

The Services are offered only to adults. You must be at least 18 years old to use them. Minors are not permitted to use the Services. We do not market to minors and do not knowingly collect personal information from anyone under 18. An account found to belong to someone under 18 is closed and its data deleted.

Outside the United States

GenClara is not directed to residents of the European Economic Area, the United Kingdom or anywhere outside the United States. If you use it from elsewhere, your data is processed in the United States.

Changes

When this notice changes, so does the date at the top, and account holders hear about it by email first whenever the change affects how we use data they have already given us.