// privacy
This policy explains, in plain language, which personal data Claru collects, why we collect it, who we share it with, and how you can exercise your rights under the GDPR, the Brazilian LGPD and equivalent laws.
Claru is the controller of personal data collected through claru.org, the collector app and related support channels. Whenever we act on behalf of a client that defines its own purposes — for example in a custom collection project — we act as a processor and the client remains the controller.
You can reach our data protection officer at any time at contato@claru.ai with the subject line “Privacy”.
We never sell personal data. Collected videos are licensed as training datasets, always after privacy processing.
We collect only what is necessary to operate the collector network, deliver datasets to clients and comply with legal and tax obligations.
Each purpose below maps to a concrete, time-limited operation. We do not reuse data for purposes incompatible with those disclosed at collection time.
We process personal data to perform our contract with you (GDPR art. 6(1)(b); LGPD art. 7, V), to comply with legal obligations, on the basis of legitimate interests in protecting the platform and improving our services, and on consent — freely given, informed and revocable — for marketing messages and non-essential cookies.
Where processing relies on legitimate interests, we run and document a balancing test, available upon reasoned request.
Withdrawing consent
You may withdraw consent at any time without affecting the lawfulness of processing carried out beforehand. Requests are handled within 15 business days.
Collectors warrant that they have permission from every identifiable person in their submissions and comply with local filming laws. Before any delivery, we apply automated pipelines and human review to blur faces, license plates, documents, screens showing sensitive data and other identifiable elements, unless explicit authorization says otherwise.
If you find your likeness in content collected by Claru, request removal at contato@claru.ai; the material is pulled from active datasets and flagged to licensees.
Content featuring minors, healthcare settings, visible banking data or intimate material is rejected and permanently deleted.
We share data only as far as necessary and always under contracts with confidentiality and data protection clauses.
Claru works with collectors and clients in several countries, which may involve international data transfers. In those cases we rely on standard contractual clauses, destination-country assessments and complementary technical measures — such as encryption in transit and at rest — to keep protection equivalent to the country of origin.
Account data is kept while the relationship is active and for up to five years afterwards, for legal defense and tax compliance. Rejected submissions are deleted within 90 days. Access logs are kept for six months, as required by Brazilian internet law.
Datasets already licensed remain with clients under the license agreement, always in processed form and without direct identifiers.
We use TLS encryption for all communications, encryption at rest for submitted content, least-privilege access control, strong authentication for internal staff, audit logging and periodic vulnerability reviews.
In case of a security incident with material risk, we notify affected individuals and the competent authority within statutory deadlines, describing the nature of the incident, the data involved and the measures taken.
You may exercise the rights below free of charge at contato@claru.ai. We may request additional information to verify your identity before proceeding.
Supervisory authority
If you are not satisfied with our response, you may lodge a complaint with the ANPD (Brazil) or the data protection authority of your country of residence.
The platform is intended exclusively for people aged 18 or over. We do not knowingly collect data from minors and delete any record identified as such as soon as we become aware of it.
We may update this policy to reflect legal, technical or operational changes. The last update date always appears at the top of the page and, for material changes, we notify you by email or a prominent site notice at least 15 days in advance.
Our privacy team answers data subject requests and contractual questions within 15 business days.