Privacy policy
Clearline — beta. Last updated 6 September 2026. This page is the authoritative text.
Clearline is a messaging channel for separated parents who are under family-court communication orders. It checks each message against the conditions you enter from your own orders before it is sent, holds the ones that would plainly cross a line, and keeps an append-only, hash-chained record that both parents can verify. Clearline is not legal advice and never certifies that a message is within an order.
Who we are
Clearline is operated from Australia. The operating entity and its contact address are published here before the public release. Contact for anything in this policy: the privacy address below.
We are a small business. Under section 6EA of the Privacy Act 1988 (Cth) we choose to be treated as an organisation bound by the Australian Privacy Principles (see docs/decisions.md, M8). Everything below is written to those principles whether or not the small-business exemption would otherwise apply.
What we collect, and why
| Information | Why | Where it comes from |
|---|---|---|
| Your email address and mobile number | To confirm it is you (one-time codes), to sign you in, and to tell you — without content — that a message is waiting | You |
| Your first name, the other parent's first and full name, the children's first names and (optionally) dates of birth, your pronouns | To show the thread in plain language and to check messages against conditions that name people. Names are stored as separate rows; every screen can replace them with Parent A / Parent B / Child 1 (the Anonymise switch) | You |
| The other parent's email address and mobile number | To invite them, and — when the email bridge is switched on — to deliver your messages by email and to verify that replies came from that address | You |
| The conditions you enter from your orders (kept as versions), the orders themselves (which order, the date made, sealed or not) and the sentence you confirm with them | To screen messages. Clearline never asserts what an order means: you confirm what you entered; a lawyer can verify it later | You |
| Every message you send through Clearline, its verdict, the reasons shown to you, which option you chose, and what the message looked like before and after a suggestion | The record — the point of the service. Three versions of a sent message (your original draft, any suggestion, what was sent) are kept; only the sent text is visible to the other parent | You, as you write |
| Held drafts | Nothing about a held draft is kept. It stays on this phone until you change it or clear it. The record holds only what was sent and received | You |
| Messages the other parent sends, in the app or by email | The record. Inbound email is stored as received, with its headers and authentication results | The other parent |
| Delivery, first-read, release and hand-off facts | The record shows when a message reached the other side and when it was first opened | The app, the email provider |
| Images or PDFs you attach | Kept for the record. Location and every other metadata block is removed from every image before it is shown to anyone; the original is kept privately for the record | You |
| An access log: who viewed which thread, record, document or setting, when, from a hashed IP address and browser | So you can see who looked at your material, and so a court can be told | The app |
| Safety settings: the discreet tab title, the quick-exit address, whether safety mode is on | To make the app quieter on a device someone else can reach. These are stored on your profile only, never on a case, and are never visible to or hinted at to the other parent | You |
| Subscription state (when billing is switched on): Stripe customer and subscription ids, status, renewal date, fee-waiver status | Billing. Stripe receives only your email and an opaque user id — never a name from a case, a child, a matter number or an order | You, Stripe |
| Waitlist details: name, email, role, state, an optional clause you paste | To write to you once when your jurisdiction opens. The operator is told that a join happened — role and state only, never the name, email or clause | You |
We do not collect identity documents, precise location, contacts, photos other than what you attach, or anything from the other parent's device or accounts.
The other parent, if they never join
If the other parent replies by email rather than joining, we receive their email address, the text they send and the technical headers of each email. The first email they receive from the case address tells them who is writing, that the address is operated by Clearline on that parent's behalf, that replies are recorded with their headers and shown to the sender, how to decline (reply STOP), how to ask what is held about them, and where this policy is (APP 5 notice). Replying STOP stops the email bridge for that case and is recorded. Nothing is ever sent to any address they copy in.
The reading assistant
When you switch on Claude checks or Claude drafts, an anonymised copy of the draft, the last inbound message, a few recent messages and a paraphrase of the conditions is sent to Anthropic's API. Before anything leaves our server every name, email address, phone number and matter-number pattern is replaced with a placeholder (Parent A, Child 1); a second check refuses the call if anything survives. The assistant can only add a caution, never remove one. We store the hash of what was sent, token counts and timing — never the text. Both switches are off by default for drafts and on by default for checks; you can turn either off in Settings.
Where your information is stored
Your data is stored in Australia (Supabase, Sydney, ap-southeast-2) and the application runs in Sydney (Vercel, region syd1). Backups are held by the same provider. Before the public release we obtain and publish the provider's written statement of where backups, point-in-time archives and logs physically reside.
Processors outside Australia (APP 8)
The following providers may process your information outside Australia. Each receives only what the row says; each is bound by its own privacy terms, linked from the launch checklist.
| Provider | What it processes | Where | When |
|---|---|---|---|
| Vercel (United States company) | Runs the application in Sydney; request logs and build artefacts may be held in the United States | US / Sydney | Always |
| Supabase (Singapore/US company) | The database, authentication and file storage — in Sydney | Sydney; platform logs may be in the US | Always |
| Anthropic (United States) | The anonymised reading-assistant inputs described above | US | Only when you switch the assistant on |
| Resend (United States) | (a) A content-free notice to the operator when someone joins the waitlist — role and state only, never a name, email address or clause. (b) When the email bridge is switched on: email delivery and the case inbound address — message text and addresses of email you send and receive through the bridge. (c) The record export you ask us to email: the whole record — both parents' names, the children's names, every message, sent or held for the record, and the dates — as the text and the PDF, sent to the address you give (usually your lawyer's). (d) The invitation email: the other parent's email address and your first name, with the join link; no case content | US | (a) as soon as the operator's email is configured; (b) only when the email bridge is switched on; (c) only when you ask for an export by email — and not at all until the operator switches record export by email on (it is off today; until then the export stays on your device and you send it yourself); (d) when you invite the other parent by email and email sending is switched on |
| Stripe (United States / Ireland) | Your email, an opaque user id, payment details you enter on Stripe's page, GST calculation | US / EU | Only when billing is switched on and you subscribe |
| Twilio (United States) | (a) Your mobile number and the one-time code text. (b) The join link by text: the other parent's mobile number and your first name, with the join link; no case content | US | (a) when the phone factor is switched on; (b) when you send the other parent the join link by text and text sending is switched on (until then the app shows the link and you send it yourself) |
None of the beta's current deployments have the operator's email, the email bridge, record export by email or the phone factor switched on (billing is on since 29 September 2026). When one is switched on this table is updated first.
How long we keep it
The retention schedule is docs/retention-schedule.md. In short: the record is kept for as long as the case is open plus seven years, because it is evidence; account deletion tombstones your own sent messages (the text is removed, the hash stays so the chain still verifies) after a 30-day cooling period; a litigation hold placed on a case suspends every deletion; held-draft text, reading-assistant caches and the access log have their own shorter periods.
Your rights (APP 12 and 13)
You can see everything held about you from inside the app (the thread, the record, your settings, your access log) and export the whole thread at any time. To ask for a copy of something you cannot see, to correct something, or to complain, write to the privacy address. We answer within 30 days. If you are the other parent and have never joined, the same address works: tell us the case email address you have been writing to. If you are not satisfied you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).
Corrections to the record itself are handled as the record demands: nothing is edited after it is written. A message can be removed by its author (a tombstone, reason recorded, hash retained); a wrong condition is corrected by saving a new version of your orders, and the old version stays visible.
Security
Every table is protected by row-level security; every write goes through a checked database function; every message is part of a per-case SHA-256 chain that either parent can verify at any time; sign-in is by one-time code to an email address you control (and a phone you control when that factor is on); the service role key is never in the browser; images are stripped of metadata on upload; the application logs every read of case material. The breach runbook (docs/breach-runbook.md) commits us to assess a suspected breach within 30 days and to notify the OAIC and affected people within 72 hours of concluding that an eligible data breach has occurred.
Cookies and analytics
Clearline sets the cookies needed to keep you signed in, one cookie for the Anonymise switch, and nothing else. There is no advertising, no third-party analytics and no tracking pixel. Email open tracking is off unless the case owner turns it on in case settings, and the record says when it is on.
Children
The service is for adults. Children's first names and dates of birth appear only because the orders name them; a child never has an account.
Changes
This policy changes only with a dated entry at the top and a note in the repository history. If a change affects what is sent offshore or how long something is kept, everyone with an account is emailed first.
Contact
Privacy address: the address shown in the footer of every page (it becomes privacy@ the application's domain once the domain exists). Until that address is published, no one outside internal test accounts is admitted to the beta. Postal address: published with the operating entity before the public release.