Privacy Policy

Last updated: August 6, 2026

1. Introduction

Clare ("we," "our," or "us") provides an AI-powered health consultation platform designed for users in the United Arab Emirates. This Privacy Policy explains how we collect, use, store, and protect your personal information, including health data classified as sensitive personal data under UAE law.

This policy is governed by the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, "PDPL") and UAE Federal Law No. 2 of 2019 on the Use of ICT in Health Fields ("Health Data Law").

By using Clare, you agree to the practices described in this policy. If you do not agree, please do not use our services.

2. Information We Collect

2.1 Account Information

Email address, name (if provided), date of birth (for age verification), and authentication credentials managed through our identity provider.

2.2 Health Information

Symptoms, medical history, medications, allergies, vital signs, prescriptions (uploaded images), family history, social history, immunizations, procedures, hospitalizations, and other health-related information you share during consultations.

2.3 Consultation Data

Messages exchanged during AI consultations, clinical assessments generated by the AI, and consultation summaries.

2.4 Technical Data

IP address, browser type, and device information collected automatically for security, rate limiting, and audit logging purposes.

2.5 Connected Devices and Health Apps

If you choose to connect a wearable or a health app, Clare receives readings from it. Nothing is collected until you connect it, and you can disconnect at any time from the Connected devices screen. We never write data back to a connected device or app.

Apple Health. On iPhone, the Clare app can read data from Apple Health with your permission, granted in Apple's own permission screen. The specific data we read is:

  • Resting heart rate and heart rate variability
  • Blood oxygen (SpO₂) and respiratory rate
  • Blood pressure (systolic and diastolic)
  • Body temperature
  • Weight, height, and body mass index
  • Steps, active energy burned, and exercise minutes
  • Sleep duration and sleep stages

We request read access only, and only for these types. You can change what Clare may read at any time in the Health app under Sharing → Apps, or revoke it entirely by disconnecting Apple Health in Clare. Health data read from your device is not stored in iCloud by Clare.

Other connected services (such as Oura, Withings or WHOOP) are authorised through that provider's own sign-in and send comparable readings — heart rate, oxygen saturation, sleep, activity and body measurements.

2.6 Google Health data

What we access. If you connect Google Health, Clare requests read-only access to: health measurements (resting heart rate, heart rate variability, oxygen saturation, respiratory rate, core body temperature and weight); activity and fitness (steps, active energy burned and exercise sessions); sleep sessions and stages; nutrition logs; electrocardiogram records; and irregular heart rhythm notifications. Clare never writes to, modifies or deletes anything in your Google account.

How we use it. These readings become part of your health record in Clare, so that your history shows measured trends rather than recalled ones, and so a clinician reviewing your consultation can see objective context alongside what you describe.

Who it is shared with. Google Health data is shown to the healthcare professionals involved in your care, which is the purpose of connecting it. It is not sold, not shared with data brokers or advertisers, and not used for advertising. It is not disclosed to anyone else except where the law requires it.

How it is protected.It is transmitted over TLS, encrypted at rest with AES-256-GCM under keys held separately per environment, and stored in Microsoft Azure's UAE North region. Access is limited to you and the clinicians treating you, and every access to health data is recorded in an append-only audit log.

How long we keep it, and how to delete it. You can disconnect Google Health at any time from the Connected devices screen, which stops all further access and removes the synced readings. Data already incorporated into a clinical record is retained for the period UAE Federal Law No. 2 of 2019 requires of health records — a minimum of 25 years from the last procedure — because we are not permitted to delete a medical record on request. Everything outside that obligation is deleted when you delete your account.

Clare's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never used to develop, improve or train generalised artificial intelligence or machine learning models, and is never transferred to third parties for that purpose.

3. How We Use Your Information

  • AI-Powered Consultations: Your health information is processed by our AI system to generate clinical assessments. Only your age and biological sex are shared with the AI model, your name and contact details are never sent to the AI provider.
  • Health Record Management:To maintain your health record across consultations so you don't have to repeat information.
  • Prescription Processing: Uploaded prescription images are analyzed by AI to extract medication data and add it to your health record. Images are processed in memory and are not permanently stored.
  • Connected Device Readings: Readings from a device or health app you connect are added to your health record so that your care team sees more than the measurements taken during a visit. They are recorded as unverified until a clinician reviews them.
  • Security and Compliance: IP addresses and access patterns are logged for audit trail purposes, rate limiting, and fraud prevention.

We do not use your health data for advertising or marketing. Health, fitness and medical data — including everything read from Apple Health or any other connected device — is never used for advertising, marketing, or use-based data mining, and is never sold, rented, or disclosed to data brokers or advertising networks. We use it only to provide care to you and to maintain your health record. It is shared with a third party only in the limited circumstances described in Section 5, and never for any of the purposes above.

4. AI Processing and Transparency

Clare uses artificial intelligence to assist with clinical intake assessments. It is important to understand the following:

  • AI assessments are not medical diagnoses. They are informational summaries intended to help you and your healthcare provider.
  • The AI model has been developed using general medical knowledge. It has not been trained on your specific medical history prior to your first consultation.
  • AI outputs may be inaccurate or incomplete. You should always consult a licensed healthcare professional for medical advice, diagnosis, or treatment.
  • Data minimization: Only your age, biological sex, and clinical information (symptoms, conditions, medications) are sent to the AI provider. Your full name, email, phone number, insurance details, and database identifiers are never sent.
  • You may revoke your consent for AI processing at any time from the Settings page.

5. Third-Party Data Processors

We use the following third-party services to operate Clare:

  • AI Provider (OpenAI / Azure OpenAI): Processes de-identified health data for AI consultations and prescription extraction. Your name and contact details are never transmitted to the AI provider.
  • Microsoft Azure: Hosts our application, database and file storage in the UAE North (Dubai) region.
  • Azure Communication Services: Delivers our transactional email and carries video consultations between you and your doctor, within the UAE North (Dubai) region.

We maintain Data Processing Agreements (DPAs) with our third-party processors where required by applicable law.

6. Data Storage and Localization

In accordance with UAE Federal Law No. 2 of 2019 (Health Data Law), your health data is stored on infrastructure located within the United Arab Emirates:

  • Database: Azure Database for PostgreSQL Flexible Server in the UAE North (Dubai) region, with storage-level encryption and enforced SSL/TLS connections.
  • Files and attachments: Azure Blob Storage in the UAE North (Dubai) region, encrypted at rest.
  • Application and authentication: Self-hosted on Azure Container Apps in the UAE North (Dubai) region.
  • AI Processing: We are transitioning AI processing to Azure OpenAI in UAE North (Dubai) to ensure health data is processed within the UAE. During this transition, health data (excluding your name and contact details) may be processed outside the UAE with your explicit consent.

7. Data Security

We protect your data through:

  • Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS/HTTPS.
  • Encryption at rest: Sensitive personal identifiers (name, date of birth) are encrypted using AES-256-GCM before storage, in addition to database-level encryption.
  • Access controls: Row-Level Security policies ensure each user can only access their own data. Your health records are isolated at the database level.
  • Audit logging: All access to health data is logged with timestamps, action type, and source information.
  • Network isolation: Our database operates in a private network that is not directly accessible from the internet.

8. Consent

We process your health data based on your explicit consent, as required by Article 5 of the UAE PDPL. Before your health data is processed by our AI system, you must provide explicit consent. You can manage your consents at any time from the Settings page, including:

  • AI Processing: Required for AI consultations. Without this consent, the AI will not process your data.
  • Data Storage: Allows your health records to be stored for future consultations. Granted by default on signup; you may revoke it at any time.
  • Connected devices: Connecting a device or health app is itself the consent, and disconnecting withdraws it. No device is connected unless you connect it. For Apple Health you can also narrow or withdraw permission in the Health app at any time, without going through Clare.

Revoking AI processing consent prevents future AI consultations but does not delete existing data. To request deletion, see Section 10 (Your Rights).

9. Data Retention

UAE Federal Law No. 2 of 2019 requires health data to be retained for a minimum of 25 years from the date of the last health record entry. In accordance with this requirement:

  • Health records: Retained for a minimum of 25 years from your last health record activity. If you delete your account, your personal identifying information (name, date of birth, contact details) is removed immediately, but de-identified health data is retained for the legally required period and then automatically deleted.
  • Anonymous consultations: Sessions created without an account are automatically deleted after 24 hours.
  • Share links: Expire after 5 days and are automatically deleted. You can revoke them early from the app.
  • Connected device readings: Disconnecting a device or health app stops any further collection and deletes the raw readings we hold from it. Readings that a clinician has already relied on form part of your health record and are kept under the 25-year rule above, the same as a measurement taken in a clinic.
  • Audit logs: Retained for a minimum of 2 years for security and compliance purposes.

10. Your Rights

Under the UAE PDPL, you have the following rights:

  • Access: View all your health data through the Health Record section of the app.
  • Rectification: Edit or correct your health records at any time.
  • Deletion: Delete your account from Settings. Your personal identifying information is removed immediately. De-identified health data is retained for the legally required 25-year period, after which it is automatically deleted.
  • Consent withdrawal: Revoke AI processing or data storage consent at any time from Settings. Existing data is preserved but no new processing occurs.
  • Data portability: Export your consultation summaries as PDF documents.
  • Restriction of processing: Request that we limit how your data is processed by revoking specific consents.

11. Children's Privacy

Clare is not intended for use by individuals under 18 years of age. We enforce age verification during the signup process and do not knowingly collect health information from minors. If you believe a minor has provided us with health data, please contact us and we will delete it promptly, in accordance with UAE Federal Decree-Law No. 26 of 2025 on Child Digital Safety.

12. Cross-Border Data Transfers

Your health data is stored within the United Arab Emirates. For AI processing, de-identified health data (excluding your name, contact details, and database identifiers) may be processed outside the UAE with your explicit consent, until our transition to UAE-hosted AI processing is complete.

We ensure that any cross-border transfers comply with Article 22 of the UAE PDPL and are subject to appropriate safeguards, including data minimization and contractual protections with our processors.

13. Data Breach Notification

In the event of a data breach affecting your personal data, we will notify the UAE Data Office within 72 hours as required by the PDPL. If the breach poses a high risk to your rights, we will also notify you directly with details of the breach, its likely consequences, and the measures we are taking.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the app or via email. If we make changes that materially affect how your health data is processed, we will request your renewed consent before applying the changes.

15. Contact Us

For questions about this Privacy Policy, your health data, or to exercise your rights under the UAE PDPL, contact us at privacy@clare.health.