Built for trust
Recovery data is deeply personal. PathClear is designed from the ground up to protect it with encryption, anonymization, and strict consent controls.
Your data is encrypted and anonymized before any AI processing
Personal identifiers are stripped. Data is encrypted with AES-256-GCM. The AI never sees who you are. Your privacy is not a feature — it is the foundation.
How We Protect You
Six pillars of your privacy
Military-Grade Encryption
EncryptionEvery piece of sensitive data — journal entries, check-ins, conversations, craving logs — is encrypted before it is stored. This is the same encryption standard used by banks and governments. Even if someone gained access to the database, your data would be unreadable without the encryption key.
Anonymized Before AI Processing
PII StrippedWhen PathClear uses AI to generate insights, reflections, or risk predictions, your personal identifiers are stripped first. Names, locations, and other identifying information are removed before any data reaches the AI model. The AI never knows who you are.
Consent-First Architecture
You DecideYou are in control. During onboarding and at any time in Settings, you can toggle data processing and AI analysis on or off. If you turn them off, we stop processing immediately — no exceptions. Every AI-powered route checks your consent before doing anything.
Full Data Deletion
Right to DeleteWant to leave? Delete your account and every piece of data is permanently removed from our servers — check-ins, journals, conversations, activities, everything. No hidden archives, no retention tricks. Your data is yours, and you can take it all with you or erase it completely.
Data Export & Portability
Data PortabilityRequest a complete export of all your data at any time. You will receive a structured file containing everything PathClear knows about you. This is your data — you should always be able to access it, regardless of whether you continue using the app.
Automatic Data Retention
Auto-CleanupData does not live forever on our servers. Configurable retention policies automatically clean up old records — check-ins after 1 year, conversations after 6 months, dismissed alerts after 90 days. This minimizes the data footprint and reduces risk.
Compliance & standards
Our practices are aligned with major data protection frameworks.
HIPAA-Informed Design
While PathClear is not a covered entity under HIPAA, our architecture follows HIPAA security principles: encryption at rest, audit logging, access controls, and minimum necessary data collection.
GDPR-Aligned Practices
Users can access, export, correct, and delete their data. Consent is explicit and revocable. Data processing is transparent with clear purposes. These practices align with GDPR requirements.
No Ads, No Selling, No Third-Party Sharing
We do not display advertisements. We do not sell your data to anyone. We do not share your personal information with third parties for marketing purposes. Period.
Audit Logging
Every significant action — logins, data access, consent changes, AI processing — is logged in an audit trail. You can view your own audit log in the Privacy & Data settings.
Questions about security?
Read our full privacy policy or check the FAQ for answers to common questions about how your data is handled.