Privacy Policy

Version dated 11 August 2026 · Clam app and clam.mom website

Release blocker: the data controller’s verified legal name, registration details, address, privacy contact, and representative (if required) must be inserted and approved by counsel before publication. This notice prevents release; it is not a substitute for those details.
In short. Account, profile, lab, user-entered health, consent, AI conversation, security, and subscription data can reach our EU server when you use the related features. Baby trackers, journals, mood entries, and the album stay on your phone. External AI runs only after separate consent. We remove common direct identifiers where possible, but health data and free text can still identify you. We do not sell data or use it for targeted advertising. Account deletion starts in the app and follows the timelines below.

1. Who We Are

Clam is developed and operated by the Clam team (clam.mom). The operator’s full legal details — registered name, registration number, and registered address — are being finalised and will be published in this section. Until then, privacy questions and requests about your data go to support@clam.mom and are handled under the rights and deadlines set out in Section 9.

2. What Data We Process on the Server

DataWhat exactlyWhy
Account E-mail, password as an irreversible hash (argon2), interface language Account sign-in, access recovery, protection against hacking
Profiles Name, date of birth, sex, country, pregnancy information (optional) — for you and the family members you have added Correct interpretation of lab results and personalization of sections
Lab result documents Photos/PDFs of laboratory report forms uploaded by you, the recognized lab markers and their statuses Recognition and clear explanation of results
AI texts AI-generated explanations, summaries for your doctor, and AI chat messages (if you use the AI features) Displaying the history of explanations and conversations; included in data export and deleted together with your account
User-entered health data Medication and supplement names, dose notes, symptoms, and timeline events that you enter for a profile Health timeline, reports, exports, and optional AI context selected by you
Sign-in and recovery Google account subject when used, refresh-session records, hashed one-time recovery tokens, and security audit events Sign-in, session revocation, account recovery, and abuse prevention
Subscription Technical Clam account identifier, store/RevenueCat event, product, entitlement, status, and relevant dates Verify Clam+ access, reconcile purchases, and meet accounting obligations
Consents Text version, date, language, and the fact of acceptance Confirmation that you have reviewed the terms
Technical data Service request logs and audit records (without the content of medical data) — kept for up to 365 days Stability, security, and protection against abuse

Legal bases (GDPR)

We process data on the following legal bases: performance of a contract — maintaining your account and showing you your results; explicit consent — processing of health data, including lab documents and the AI features (Art. 9(2)(a) GDPR); legitimate interest — security, abuse prevention, and technical logs; legal obligation — responding to requests where the law requires it.

3. What Stays Only on Your Device

  • baby trackers (sleep, feedings, diapers), the baby log, growth measurements, and developmental milestones;
  • mom trackers: fetal movements, contractions, weight;
  • mood check-ins (“shells”), the wellbeing section, and assistant responses;
  • course progress, the ultrasound album, checklists, notes, and reminder settings.

This data is not transmitted to the server and is not accessible to us. It is deleted when you sign out of your account or uninstall the app.

4. Where and How Data Is Stored

  • The server is located in the European Union (Nuremberg, Germany, Hetzner data center).
  • Data transmission is protected with HTTPS (TLS).
  • Passwords are stored only as an irreversible hash (argon2); we do not know the passwords themselves.
  • Encrypted backup sets cover the database and document storage. They are kept offsite in an EU object store and are removed once they are older than 30 days. The decryption key is not held on the server. A restore drill has been carried out on a real backup set.
  • Generated PDF reports are automatically deleted within 7 days.
  • Server access is restricted and protected with keys.

5. Document Recognition (OCR)

Recognition of uploaded lab results is performed by software on our own server — documents are not transferred to third-party services. If an option for enhanced processing by an external AI service becomes available in the future, it will work only after your separate explicit consent and will be described in this policy.

Uploaded originals are stored until you delete the document, profile, or account.

6. AI Features: Explanations, Appointment Preparation, AI Chat

AI features are enabled only after your separate explicit consent. You may withdraw it; new AI requests then stop. Before sending data, the app identifies the configured external processor and shows its region, retention terms, and zero-data-retention status. Clam removes common direct identifiers on a best-effort basis, but the payload remains personal health data and may identify you through free text or context. It can include:

  • names of lab markers, values, units, the laboratory’s reference ranges, and their statuses;
  • dates of lab results, calculated age, sex, and the profile’s pregnancy status and gestational age;
  • the names of medications/supplements you entered, symptom descriptions, and the text of your question.

The application is designed to omit the profile name, e-mail, patient name from the report, date of birth, and internal identifiers from AI prompts. This is risk reduction, not anonymity. Provider training and retention depend on the verified account contract shown in the consent screen; Clam makes no blanket training promise. AI chat uses lab context only when you explicitly enable “Use health data”.

Every AI response passes through automatic safety filters: AI texts contain no diagnoses, prescriptions, or dosages and are not medical advice. “Trend insights” work without external AI — they are algorithmic hints generated on our server.

7. Who We Share Data With

  • We do not sell your data and do not share it with advertising networks or data brokers.
  • The infrastructure provider (Hetzner Online GmbH, Germany) keeps the server running and processes data strictly as a technical contractor.
  • The configured AI processor receives personal health data and free text to generate a response only when you use an AI feature after consent (see Section 6). Its verified name and terms are shown before processing.
  • App stores (Google Play, App Store) process subscription payments on their own — we do not see your payment details.
  • RevenueCat, Inc. (USA) processes subscription status; it receives only a technical account identifier (UUID) and purchase facts from the app store — never your name, e-mail, or health data.
  • Resend (USA) sends account e-mails (verification, password reset); it receives your e-mail address and the message text.
  • Google — only if you choose “Sign in with Google”: we verify your Google token and store the technical account link; Google independently knows about the sign-in.
  • Voice input is recognized by your device’s/OS speech service (for example, Google) under its own terms; Clam’s server does not receive audio.
  • Disclosure is possible where expressly required by law.

International transfers

RevenueCat and Resend may process data in the USA. The AI processor’s region depends on the configured account and is shown to you before consent. The transfer mechanism for each of these processors, its data processing agreement, and its subprocessor list are being verified; we do not assume that a framework or Standard Contractual Clauses apply without that evidence, and we will state each mechanism here once it is confirmed. Details are available via support@clam.mom.

8. How Long We Keep Data

Active account and health data is kept while your account exists or until you delete the relevant item. Deleting an account immediately blocks new changes and starts a retryable deletion process across the database, document storage, and enabled subscription services. Limited encrypted backups are removed once they are older than 30 days. Security audit records may remain for up to 365 days. Billing, fraud-prevention, dispute, or legal records may remain for the period required by applicable law; they are access-restricted and excluded from normal product use. Soft-deleted medications, supplements, symptoms, and timeline events are permanently purged after 30 days.

9. Your Rights

  • export all your data as a single file (JSON) — right in the app;
  • delete an individual lab result, an original document, or a profile;
  • delete your account completely with all its data — see the instructions;
  • withdraw your consents and ask any question about your data: support@clam.mom.

We respond to requests within 30 days. If you are located in the EU/EEA, you also have the rights provided for by the GDPR (access, rectification, erasure, restriction of processing, portability, objection, and lodging a complaint with your local supervisory authority).

10. Children

Clam is intended for adults (parents and parents-to-be). Data about children (name, date of birth, measurements) is entered and controlled by the parent within their own account. By adding a child’s profile, the parent confirms that they are the child’s parent or legal guardian and have the right to enter the child’s data; the child’s data is processed on the basis of the parent’s explicit consent.

11. Changes to This Policy

In the event of material changes, we will notify you in the app and update the version date on this page. Continued use after the changes take effect constitutes acceptance of the new version.

12. Contact

Privacy questions: support@clam.mom