Clearhour
Draft, pending legal review. This statement is not yet in force. Drafted against the NZ Privacy Act 2020 (IPP 3 and IPP 3A, in force 1 May 2026).

Clearhour Privacy Statement

DRAFT v2, 2026-08-28 (updates the 2026-08-13 draft). Prepared for legal review; not in force.

The most important thing

We cannot read your clients' questionnaire answers. The questionnaire runs in the client's own browser and their answers stay on their device while they fill it in. When the client finishes, their browser locks the answers to your firm's own key before anything is sent. Clearhour briefly holds an encrypted file it cannot open, and deletes it on delivery to your firm. Your firm opens it in its own browser. We designed the platform this way on purpose.

A few things are handled differently and we say so plainly. If a client chooses the questionnaire assistant, what they type or say to the assistant is sent through Clearhour's server to our AI provider to generate the explanation; Clearhour does not store it. If a client chooses the spoken interview, the words read aloud are sent to our voice provider to turn into speech, and so that the client hears one natural voice throughout this includes reading their own answers back to check them; the voice provider synthesises the words in the moment, does not store them, and no one can access them there. When a client speaks an answer, their spoken words are sent through Clearhour's server to our speech provider (OpenAI) to turn into text; the provider turns them into text in the moment, does not store them, and does not use them to train its software; a client who types their answers instead uses none of this. When anyone types or speaks an address in a form, the part they have entered is sent to our address provider to find matching addresses to pick from; that provider uses it only to find matches, does not store it, and no one can access it there. And your firm's own questionnaire records, described below, are held by us so that every device in your firm shows the same list.

What we do collect, and why (IPP 3)

When your firm creates an account we collect: the account holder's name, firm name, email address, and password (stored only as a salted hash); firm profile information you choose to add (logo, branding, the countries you work in); billing information, which is handled by our payment processor Stripe (we do not store card numbers); records of purchases and metadata about what was generated, such as the client label the firm typed, dates and verification results; and technical logs needed for security and support. If the account holder signs in with a Google or Apple account instead of setting a password, we receive a confirmation of their identity from Google or Apple for that sign-in, and we do not receive the password to that account. We collect this to operate your account, take payment, provide support, meet our legal obligations, and protect the platform against misuse. Providing it is voluntary, but the account features that depend on it will not work without it.

Your firm's questionnaire records

So that every device your firm signs in from shows the same list, we hold one record per questionnaire: the client name and email address your firm typed, the status, which documents were chosen, and the dates. These records are protected at rest in the same way any professional service protects its account data. They never include a client's answers or a generated document. Answers come back to your firm encrypted and are deleted from our storage on delivery; generated documents are produced in your browser and downloaded to you, and we do not keep a copy.

The questionnaire assistant

If a client chooses the assistant, what they type or say to it is sent through Clearhour's server to our AI provider (Anthropic) to generate the explanation. Clearhour does not store it. The provider handles it only to reply and does not keep it afterwards or use it to train their software. We keep a metadata-only record of these requests: timestamps, token counts, the firm identifier and the identifier of the question being asked about, never the words themselves. A client can decline the assistant and fill the questionnaire in themselves.

If a client chooses the spoken interview, the words the assistant reads out loud are sent through Clearhour's server to our voice provider (OpenAI) to turn into speech. So that the client hears one natural voice throughout, this includes reading the client's own answers back to them to check them. Clearhour does not store these words and keeps only a metadata-only record (timestamps, character counts, the kind of line spoken), never the words themselves; the voice provider synthesises them in the moment and does not keep them or use them to train their software. A client can decline the spoken interview and read and type the questionnaire themselves.

During the spoken interview the assistant also needs to understand what the client meant when a turn is not a plain match, for example an answer given with extra context rather than a simple yes or no. When that happens, what the client said is sent through Clearhour's server to our AI provider (Anthropic) to work out the intended meaning in the moment. This can include the client's own answers. Clearhour does not store it and keeps only a metadata-only record (timestamps, token counts, the firm identifier, the identifier of the question, and the kind of intent recognised), never the words themselves; the provider handles it only to return the meaning and does not keep it afterwards or use it to train their software. The straightforward cases (a clear yes or no, a clearly named option) are handled on the client's own device and are not sent anywhere.

Speech to text

The spoken interview lets a client answer by voice. To do that, the client's spoken answer is sent through Clearhour's server to our speech provider (OpenAI) to turn into text. The provider converts the audio to text in the moment; it does not store the audio or the text, and does not use them to train its software. Clearhour keeps only a metadata-only record of the turn (timestamps, a byte and second count, the firm identifier), never the audio and never the transcript. A client who reads and types the questionnaire instead of speaking does not use this at all, and the typed lane is always one tap away.

Address search

Wherever an address is typed or spoken into a form, whether by a client filling in the questionnaire or by your firm filling in its own details, the part entered so far is sent through Clearhour's server to our address providers (Addressfinder for New Zealand and Australia, Google for other countries) to find matching addresses to pick from. Only the address partial is sent, and only to find matches for that one field; none of the other answers go with it. Clearhour does not store it and keeps only a metadata-only record (timestamps, a count of matches, the firm identifier), never the address text or the matches; the provider returns matches in the moment and does not keep the partial. Typing is never blocked, so anyone can ignore the matches and type the address in full. The provider keys are held on our server and are never in the browser.

Reminders by text

When your firm sends a questionnaire it may also type the client's mobile number, beside the email address. If it does, and a client has started their questionnaire but not sent it back, we may send a short reminder by text as well as by email: the firm's name and the client's own link, and nothing else. The mobile number is a contact detail your firm holds for its client, kept with your firm's questionnaire records. It is never a number the client typed into the questionnaire as an answer, which we cannot read. The reminders stop the moment the client sends their answers back, and stop on their own after the last one. Text reminders are sent through our messaging provider (Twilio); we keep only a metadata-only record that a reminder went, never the number or the message body. Your firm can switch these reminders off for any one client or for the whole firm in Settings.

Forms your firm uploads

If your firm uploads one of its own forms so we can build a questionnaire from it, that file is sent to our server and read by our AI provider to map its fields. Uploads must be blank template forms. We ask firms never to upload completed documents containing client information.

Pre-launch registration

If you register interest before launch, we collect your name, firm name, email address and country, directly from you, for two purposes only: to email you once when we launch, and to provide the free first set of documents offered on the registration page. This list is never used for marketing and is never shared. Entries are held in our hosting provider's storage (Cloudflare) until launch. Reply to any email we send you, or contact us, and we delete your entry.

Information we collect indirectly (IPP 3A)

If your firm's owner invites you as a team member, we receive your name and email address from the owner rather than from you. We use it to send the invitation and create your login, and this statement explains the rest of your rights. If a firm uploads forms for configuration, uploads must be blank template forms; we ask firms never to upload completed documents containing client information.

Who holds and processes it

We use service providers to run the platform: Stripe (payments), Anthropic (the questionnaire assistant and form mapping), OpenAI (the spoken interview voice and speech to text), Addressfinder and Google (address search), Google and Apple (sign-in, only if the account holder chooses to sign in with them), Resend (the emails the platform sends), Twilio (text reminders), and our hosting and database providers (Cloudflare). They process information on our behalf under their own safeguards. Some of this handling happens on computers outside New Zealand. We do not sell personal information and we do not use it for advertising. New Zealand holds data protection adequacy status with the EU and the UK, which means information can flow to us from those regions without additional transfer mechanisms.

Access, correction, retention and deletion

An encrypted return sitting in our relay is deleted the moment your firm collects it. If nobody collects it, we email your firm a reminder after 7 days and delete it after 30 days whether it has been collected or not. You may ask for a copy of your personal information, and ask us to correct it, at any time. When an account is closed, account data is available for export for 30 days and then deleted, except records we must keep by law (for example transaction records) and the append-only audit ledger, where a departed user's row is deactivated rather than deleted so past actions remain attributed.

For the other information we hold, our retention is as follows. The record your firm keeps for each questionnaire, which includes the client name and email your firm typed, is held until your firm deletes that questionnaire or closes the account. The details we use to send and track a questionnaire invitation, including the client email address it was sent to, are held for up to six months to handle delivery, bounces and resends, then removed. Sign-in codes and the counters that protect against misuse are short lived, from minutes to about a day. If someone sends us feedback and chooses to leave an email address, we hold it for up to about a year so that we can reply. Our own request logs are metadata only and never contain answer content.

Privacy Officer and complaints

Our Privacy Officer under section 201 of the Privacy Act 2020 is Daniel Ibbotson, [email protected]. If you have a concern, contact the Privacy Officer first; if you are not satisfied, you may complain to the Office of the Privacy Commissioner (privacy.org.nz).

Clearhour Limited · New Zealand · Version DRAFT v2, 2026-08-28