Privacy Policy
Clairis respects your privacy and protects your personal data.
This document explains how personal data is processed within the Clairis application.
Contents
Data Controller
Option Web
Chemin du Bas-du-Crêt 40
2013 Colombier
Switzerland
No data protection officer has been appointed. For any request related to personal data, please contact the email address above.
Scope
This policy applies to the Clairis website and web application, as well as related services: user account, readings, journal, emails, payments and support.
Clairis offers a symbolic introspection experience. Content entered or generated may contain personal information depending on what you write.
Collected Data
- • Account data: email, first name, language, subscription status and preferences.
- • Profile data voluntarily entered: birth date, birth time and place, gender and personal settings.
- • Content voluntarily entered: intentions, questions, notes, journal entries, feedback and Medium conversations.
- • Reading history: spreads, cards, dates, settings, interpretations and related content.
- • Technical data: IP address, browser, device, cookies, local storage, security and session logs.
- • Marketing and email data: subscription, preferences, unsubscribe, opens, clicks and campaign events.
Depending on what you write, some content may reveal sensitive information (private life, health, beliefs, relationships). We recommend not entering information that you do not wish to store.
The service is not intended for children. If you are a legal guardian and believe a minor has submitted personal data, please contact us.
Purpose of Processing
- • Provision of the Clairis service: readings, interpretations, history, journal, account and Premium access.
- • Technical security: prevention of abuse, fraud, incidents, session control and support.
- • Improvement of the experience: stability, quality, usage measurement, bug fixing and journey analysis.
- • Email communication: onboarding, insights, account messages, preferences and unsubscribe management.
- • Generation of symbolic readings and content using AI/LLM tools based on information you provide.
No personal data is sold to third parties.
Clairis does not claim to use “no advertising cookies”: Google Tag Manager and Meta Pixel may be loaded, depending on your consent choices, to measure visits, events and conversions.
Clairis does not provide medical, psychological, legal or financial advice. The service is a symbolic introspection tool.
Legal Basis
Under the GDPR, processing is mainly based on service performance, legitimate interest for security and improvement, compliance with legal obligations, and consent where required.
Under the Swiss Federal Act on Data Protection (nFADP), processing follows the principles of legality, proportionality, purpose limitation, transparency and security.
Recipients and Processors
Your data is accessible only to people and service providers necessary to operate Clairis.
- • Base44 and associated infrastructure providers: hosting, database, files, backend functions and technical logs.
- • Resend: transactional emails, onboarding, insights, unsubscribe management and technical campaign delivery.
- • Email tracking: opens, clicks, preferences, unsubscribes and campaign events used to measure and improve communications.
- • Stripe: payments, subscriptions, billing, fraud prevention and Premium-related accounting obligations.
- • AI/LLM providers via Base44: generation of readings, interpretations, symbolic messages and personalized content based on the information you provide.
- • AI/LLM: content needed for generation may be sent to models or technical providers, limited to data useful for the service.
- • Google Tag Manager, Google Analytics where applicable, Meta Pixel and Base44 Analytics: audience measurement, events, conversions, campaigns and service improvement.
Each processor acts only for the stated purposes and must apply appropriate protection measures.
The main providers currently identified are Base44, Resend, Stripe, Google Tag Manager/Google and Meta.
International Transfers
Some providers may process data outside Switzerland or the European Economic Area, including for hosting, email, payments, AI and analytics.
Where necessary, Clairis relies on appropriate safeguards, such as standard contractual clauses, technical measures and limitation of transmitted data.
Security
We implement appropriate technical and organizational measures to protect data against unauthorized access, loss, alteration or disclosure.
- • Encrypted communication (HTTPS/TLS).
- • Access control and least privilege principle.
- • Technical logging and anti-abuse measures.
- • Backups and recovery procedures depending on the infrastructure used.
In the event of a security incident posing a high risk to your rights, we comply with legal notification obligations under the GDPR and Swiss data protection law.
Data Retention
Data is kept only for as long as necessary for the purposes described, unless a longer legal obligation applies.
Retention Guidelines
- • Account and profile: kept while the account exists, then deleted or anonymized according to the request and applicable obligations.
- • Readings, journal, conversations and symbolic content: kept while you keep them in your space or until account deletion.
- • Technical and security logs: kept for a limited period according to security, diagnostic and abuse-prevention needs.
- • Premium payments and billing: kept according to applicable legal, accounting and tax obligations.
- • Email events, open/click tracking and preferences: kept to manage unsubscribes, measure campaigns and prevent unwanted sends.
Some exact retention periods depend on technical providers and applicable legal obligations.
Your Rights
In accordance with the GDPR and the Swiss Federal Act on Data Protection, you have several rights, subject to legal conditions and exceptions.
- • Right of access to your personal data.
- • Right to rectify inaccurate or incomplete data.
- • Right to erasure in cases provided by law.
- • Right to restriction of processing.
- • Right to object, especially to processing based on legitimate interest.
- • Right to data portability where the GDPR applies.
- • Right to withdraw consent when processing is based on consent.
To exercise your rights, please contact us at: info@option-web.ch
To protect your account, we may request reasonable identity verification before responding.
Supervisory Authorities
You may file a complaint with the competent supervisory authority. We encourage you to contact us first so we can try to resolve the issue quickly.
If you reside in the EEA, you may also contact your national data protection authority.
For any question regarding the protection of your data:
info@option-web.chThis privacy policy may be updated. In case of significant changes, a notice will be displayed on the website.
Last update: May 2026
This policy describes processing known to date, including GTM, Meta Pixel, email tracking, Stripe, Resend, Base44 and AI/LLM.