Privacy Policy

Version 1.0.0 · Last updated: April 2026 · GDPR / DSGVO compliant

This Privacy Policy explains how Clarinet, a product of Obanek Labs, collects, uses, and protects personal data when you use the Clarinet service at clarinet.obaneklabs.com or the Clarinet API. We comply with the EU General Data Protection Regulation (GDPR / DSGVO).

Contents
  1. Data Controller
  2. What data we collect
  3. Why we collect it
  4. Legal basis
  5. Third party processors
  6. How long we keep it
  7. Your rights
  8. Cookies and local storage
  9. Changes to this policy

1. Data Controller

Juan Manuel Ortiz, Obanek Labs, Berlin, Germany. Contact: [email protected]

2. What data we collect

2.1 Account data (when you register for Clarinet)

2.2 Task data (when you use the service)

2.3 Server logs

2.4 Data we do NOT collect

3. Why we collect it

PurposeData used
Create and manage your Clarinet accountAccount data
Analyze cognitive load of your tasksTask data, neurodivergence profile
Track your cognitive load over timeCognitive snapshots
Send service and security emailsEmail
Prevent abuse, secure the APIServer logs, IP address
Bill paying customersSubscription status, payment metadata from Stripe

5. Third party processors

Clarinet relies on the following sub-processors. All EU-based or bound by GDPR Standard Contractual Clauses.

ProcessorPurposeLocation
Supabase, Inc.Database, authenticationEU (Ireland)
Amazon Web ServicesAPI hosting (Lambda, EU region)EU (Ireland)
Cloudflare, Inc.CDN, DNS, DDoS protectionGlobal (EU edge)
Resend, Inc.Transactional email deliveryUS (GDPR SCC)
Anthropic PBC (optional)LLM evaluation when dual engine mode enabledUS (GDPR SCC)
OpenAI, L.L.C. (optional)LLM evaluation when dual engine mode enabledUS (GDPR SCC)

When you enable the optional LLM dual engine, your task text is sent to the configured provider. Before transmission, Clarinet redacts common PII patterns (email addresses, phone numbers, national IDs). You remain responsible for not submitting sensitive data if you choose to enable this mode.

6. How long we keep it

7. Your rights

Under GDPR you have the right to:

To exercise any right, email [email protected]. We respond within 30 days.

8. Cookies and local storage

Clarinet uses browser local storage (not cookies) to keep you logged in. Stored: your Supabase access token, refresh token, and user id. Strictly necessary for the service; no consent banner required under the ePrivacy Directive.

Cloudflare may set a security cookie (__cf_bm) for 30 minutes for bot detection. Legitimate interest in security.

We do not use tracking, advertising, or analytics cookies.

9. Changes to this policy

We version this policy. On material changes we notify registered users by email and require re-acceptance before the next login. Version and date are always at the top of this page.