Privacy policy
Last updated 15 September 2026
This policy explains what Claimref-x (“CRx”, “we”) collects when you use claimrefx.com and the CRx application, why, and what we do with it. It applies to people who sign in to CRx as members of a brand workspace and to visitors of our website. Where a brand workspace is operated by your employer or agency, that organisation decides what content is uploaded and who has access; we process that content on its behalf.
01What we collect
Account data. Your name, email address and profile image from the sign-in provider you choose (Google, Microsoft, or email), and your role in each brand workspace. Authentication is handled by Clerk; we never see your password, and passkeys never leave your device.
Workspace content. The documents a brand uploads to its library (for example clinical publications, prescribing information and guidelines), the copy written in the editor, claims, references, comments, approved-claim lists, and exports. This content belongs to the brand that uploaded or wrote it.
Activity and audit records. Who did what and when inside a workspace: uploads, checks, reference selections, comments, approvals, exports and settings changes. Brand admins can see these records for their workspace.
Technical data. Server logs (IP address, browser, pages requested, errors) kept for security and debugging. We do not use advertising trackers or sell data.
02How we use it
To run the service: sign you in, show you the workspaces you belong to, store and search a brand’s library, find and grade evidence for claims, and produce exports.
To send transactional email: invitations, mentions in comments, and account notices. We do not send marketing email to workspace members.
To keep the service secure and reliable, and to meet our legal obligations.
We do not train AI models on your content. Library documents are parsed and indexed so they can be searched; copy and claims are sent to AI models only to answer the request in front of you (extract claims, grade a passage, describe a figure). See section 04 for the providers involved.
03Who can see workspace content
Only members of that brand workspace, according to their role (admin, writer, reviewer, viewer). Nobody outside a workspace can see that it exists. Our staff access workspace content only to provide support you have asked for or to investigate a security incident, and that access is logged.
04Service providers
We use these providers to run CRx. Each processes data only to provide its service to us:
- Vercel (hosting) · Neon (database) · Cloudflare R2 (file storage) · Inngest (background jobs)
- Clerk (sign-in and workspaces) · Google and Microsoft (sign-in, if you choose them) · Resend (email)
- LlamaCloud (PDF parsing) · Anthropic (Claude models for claim extraction, grading, figure descriptions) · Voyage AI (embeddings) · Pinecone (vector index) · Cohere (reranking)
Content sent to AI providers is processed under their API terms, which do not permit training on customer data. Data may be processed in the United States.
05Retention
Workspace content is kept while the workspace exists. A brand admin can delete documents, projects and claims at any time, which removes the files, the parsed text and the search index entries for them. When a workspace is deleted, its content is removed from our systems within 30 days, except where a copy must be kept to meet a legal obligation. Audit records are kept for as long as the workspace exists. Server logs are kept for 90 days.
06Your rights
You can view and change your account details through your sign-in provider and inside CRx. You can ask us to export or delete your personal data, or object to how we process it, by emailing privacy@claimrefx.com. If your workspace is operated by your employer, some requests may need to go through them. Where GDPR, UK GDPR or CCPA apply, you have the rights those laws give you, and we will honour them.
07Security
Data is encrypted in transit and at rest. Access to production systems is limited to named staff with multi-factor authentication. Sign-in supports passkeys and single sign-on. If we become aware of a breach affecting your data, we will tell affected workspace admins without undue delay.
08Cookies
We use only the cookies needed to keep you signed in and to remember interface preferences (such as whether the sidebar is collapsed). No analytics or advertising cookies are set.
09Changes and contact
We will post changes to this policy here and update the date above. Material changes will be announced to workspace admins by email. Questions: privacy@claimrefx.com.
Operated by [Company legal name], [address]. [Governing jurisdiction].