Built for trust

Recovery data is deeply personal. PathClear is designed from the ground up to protect it with encryption, anonymization, and strict consent controls.

Your data is encrypted and anonymized before any AI processing

Personal identifiers are stripped. Data is encrypted with AES-256-GCM. The AI never sees who you are. Your privacy is not a feature — it is the foundation.

How We Protect You

Six pillars of your privacy

Military-Grade Encryption

Encryption

Every piece of sensitive data — journal entries, check-ins, conversations, craving logs — is encrypted before it is stored. This is the same encryption standard used by banks and governments. Even if someone gained access to the database, your data would be unreadable without the encryption key.

Anonymized Before AI Processing

PII Stripped

When PathClear uses AI to generate insights, reflections, or risk predictions, your personal identifiers are stripped first. Names, locations, and other identifying information are removed before any data reaches the AI model. The AI never knows who you are.

Consent-First Architecture

You Decide

You are in control. During onboarding and at any time in Settings, you can toggle data processing and AI analysis on or off. If you turn them off, we stop processing immediately — no exceptions. Every AI-powered route checks your consent before doing anything.

Full Data Deletion

Right to Delete

Want to leave? Delete your account and every piece of data is permanently removed from our servers — check-ins, journals, conversations, activities, everything. No hidden archives, no retention tricks. Your data is yours, and you can take it all with you or erase it completely.

Data Export & Portability

Data Portability

Request a complete export of all your data at any time. You will receive a structured file containing everything PathClear knows about you. This is your data — you should always be able to access it, regardless of whether you continue using the app.

Automatic Data Retention

Auto-Cleanup

Data does not live forever on our servers. Configurable retention policies automatically clean up old records — check-ins after 1 year, conversations after 6 months, dismissed alerts after 90 days. This minimizes the data footprint and reduces risk.

Compliance & standards

Our practices are aligned with major data protection frameworks.

HIPAA-Informed Design

While PathClear is not a covered entity under HIPAA, our architecture follows HIPAA security principles: encryption at rest, audit logging, access controls, and minimum necessary data collection.

GDPR-Aligned Practices

Users can access, export, correct, and delete their data. Consent is explicit and revocable. Data processing is transparent with clear purposes. These practices align with GDPR requirements.

No Ads, No Selling, No Third-Party Sharing

We do not display advertisements. We do not sell your data to anyone. We do not share your personal information with third parties for marketing purposes. Period.

Audit Logging

Every significant action — logins, data access, consent changes, AI processing — is logged in an audit trail. You can view your own audit log in the Privacy & Data settings.

Questions about security?

Read our full privacy policy or check the FAQ for answers to common questions about how your data is handled.