Effective date: Last updated:
DRAFT: needs review before publishing. This document was written from an audit of the Clear Path codebase, so the data categories, storage locations and third parties below reflect what the app actually does today. It is not legal advice. Have a lawyer review it, and fill in every
TODO(legal entity, contact address, governing law) before it goes live.
Clear Path ("the app", "we", "us") is a personal life-management app covering tasks, personal finance, notes, mood and focus sessions. This policy explains what we collect, why, where it is stored, who else processes it, and what control you have.
Operator: Vohra Idris Shakirbhai, a sole proprietor trading as Soft Planet Studio, Ahmedabad, Gujarat, India
Contact: idrishaider987@gmail.com
1. Age requirement
You must be aged 18 or over to hold a Clear Path account. The app includes paid subscriptions, AI-assisted features and social features, and we do not operate a parental-consent process.
Tracking a child's money
Clear Path's wallets are simply named balances. They do not have to represent a bank account. A wallet can equally track a piggy bank, pocket money or an allowance.
An adult account holder is welcome to use Clear Path this way on a child's behalf, for example a parent keeping a wallet for their child's allowance. In that arrangement the account, and responsibility for it, remain with the adult. What we ask is that the child does not hold their own account, and that you do not let a child use yours to access the AI, friends or purchase features.
If you record information about another person, such as a child's allowance or a name and phone number in the ledger, you are responsible for having a proper reason to hold it, and for keeping it accurate. Please record no more than you need, and avoid entering a child's personal details where a first name or label would do.
Children's data
We do not knowingly collect personal data from anyone under 18 as an account holder. If we learn that an account belongs to someone under 18, we will delete the account and its data. If you believe a minor holds an account, or that a child's data has been entered into the app inappropriately, contact us at the address above and we will act on it.
2. What we collect
2.1 Account and identity
Collected when you create an account or sign in.
| Data | Why | Source |
|---|---|---|
| Email address | Account identity, sign-in, password reset, account-related notices | You, or your Google account |
| Password | Sign-in. Stored and verified only by Firebase Authentication. We never see or store it ourselves | You |
| Username / display name | Your identity in the app, and so friends can find you | You |
| Avatar selection | Profile display. A choice from bundled illustrations, not a photo you upload | You |
| Account creation and update timestamps | Account management | Generated |
| Date you accepted the Terms, and which version | Recording that you agreed to the Terms & Conditions when you created your account | Generated |
If you sign in with Google, we receive your email address, name and Google account identifier from Google. We do not receive your Google password.
2.2 Content you create
All of this is data you enter yourself. It is the core of what the app is for.
- Tasks: titles, descriptions, subtasks, due dates, priorities, categories, recurrence, completion history
- Personal finance: expenses, amounts, categories, dates, notes, accounts/wallets, balances, budget categories and limits, budget-period history
- Ledger (receivables): the names, phone numbers and notes of people you record, plus amounts you owe or are owed and individual ledger entries
- Notes: titles, body text (Markdown), categories, favourite/archive/draft state
- Mood entries: the mood you select, any advice text generated, and when you logged it
- Focus and Zen sessions: session templates, durations, completion records
- Preferences: religion setting (used to select quote content), currency, intention text, notification settings, layout choices
Sensitivity note. Mood entries relate to your wellbeing, and finance and ledger records relate to your money. We treat both as sensitive. They are stored under your account only and are never shown to other users, sold, or used for advertising.
2.3 Device and technical data
| Data | Why |
|---|---|
| A randomly generated device identifier | Enforcing the concurrent-device limit on your plan. It is generated by the app. It is not an advertising ID, IMEI, or hardware serial |
| Device platform (Android / web / Windows) and last-active time | Showing and managing your active sessions |
| Connectivity state | Deciding when to sync data that was saved while offline |
2.4 Subscription data
If you purchase Clear Path Pro, purchase and entitlement records (product purchased, purchase and expiry dates, renewal status, platform) are processed by RevenueCat and mirrored into our database so the app knows your plan.
Payment itself is handled entirely by Google Play (or the relevant app store). We never receive your card, bank or UPI payment details.
2.5 What we do NOT collect
- No advertising identifiers, and no advertising or tracking SDKs
- No precise or background location
- No contact-list upload
- No photos or files from your device
- No analytics profiling for advertising purposes
- No biometric data (see §4)
3. Where your data is stored
Clear Path is offline-first. On Android and Windows, your data is written to a local database on your device first, so the app works without a connection.
- On your device: a local SQLite database plus app preferences. This is the primary copy on mobile and desktop.
- In the cloud (Google Firebase / Cloud Firestore): a synced copy, so your data survives losing your device and appears on your other devices.
Cloud sync of notes and the ledger is a Clear Path Pro feature. If you are not on Pro, those records stay on your device and are not uploaded.
Cloud data is stored in Google Cloud infrastructure in the asia-south1 (Mumbai) region.
4. Device permissions and sensors
| Permission | Used for | Notes |
|---|---|---|
| Notifications | Task reminders, alarms and app notices you have enabled | You can revoke this in system settings |
| Microphone | Optional voice entry for tasks and notes | Only while you are actively dictating |
| Camera | Optional scanning of UPI payment QR codes to prefill an expense | Images are processed on-device to read the code and are not stored or uploaded |
| Biometric / device credential | The optional app lock | Authentication is performed by your device's operating system. We never receive or store your fingerprint, face data or PIN |
| Exact alarms | Delivering task alarms at the time you set | Android only |
5. Third parties who process your data
We use the following processors. We do not sell your personal data to anyone.
| Processor | What they process | Purpose |
|---|---|---|
| Google Firebase (Authentication, Cloud Firestore, Cloud Functions) | Account identity and all synced app data | Core hosting, authentication, sync |
| Google Firebase AI (Gemini 2.5 Flash Lite) | The text you submit to an AI feature | See §5.1 |
| Google speech recognition | Audio you dictate, when you use voice entry | Converting speech to text. On Android this may be processed by Google's speech service rather than on-device |
| Google Play | Purchase transactions | Payment processing |
| RevenueCat | Purchase and entitlement records, and your account identifier | Managing subscription status |
Quotes API (fight-addictions-api.deno.dev, operated by us) | A request for quote content, including your religion preference so the content matches | Serving motivational and spiritual quote content |
5.1 AI features
Some features are optional and AI-assisted: generating a task breakdown, drafting or improving note text, and parsing a dictated task.
When you use one of these features, the text you provide is sent to Google's Gemini model via Firebase AI to produce a response. This happens only when you explicitly invoke an AI feature. If you never use them, none of your content is sent to a model.
Please do not enter information into an AI feature that you would not want processed by a third-party model.
5.2 Sharing you initiate
Some features open another app with content prefilled: sending a ledger reminder via WhatsApp or SMS, or sharing a note or task. When you do this, the content and the recipient's phone number are handed to that app and are governed by its own privacy policy, not ours. Nothing is sent until you confirm the send in that app.
6. Other users and social features
- Your username, avatar and email address are readable by other signed-in Clear Path users. Username and avatar are what make friend search work; your email address sits on the same profile record and is therefore also readable. It is not displayed anywhere in the app, and we do not publish it outside Clear Path, but you should know it is visible to signed-in users rather than private to you. If you would rather it were not, use an address you are comfortable sharing.
- Sending or accepting a friend request records the connection between your account and theirs.
- Your tasks, finances, ledger, notes and mood entries are never visible to other users, including friends.
7. How we protect your data
- Data in transit is encrypted with TLS.
- Cloud data is protected by server-side security rules so one account cannot read or write another account's records. Sensitive fields (your subscription entitlement, your account status, and your device-session status) can only be written by our server, never by an app client.
- Passwords are hashed and managed by Firebase Authentication; we never store or see them.
- Sensitive actions such as changing your password or deleting your account require you to re-authenticate first.
- You can enable an app lock (biometric or device credential) to prevent someone with your unlocked device from opening the app.
No system is perfectly secure. We cannot guarantee absolute security, but we will notify affected users and, where required, the relevant authority, of a breach that affects personal data.
8. How long we keep data
- While your account exists: we keep your data so the app works.
- When you delete your account: we delete your account and its cloud data, including your profile, username reservation, all synced records, your device sessions, your friend connections, and pending friend requests. See §9.
- Data on your device: deleting your account does not erase the local copy on that device. This is deliberate, so you do not lose your records if you delete the account but keep using the app offline. You can remove it by clearing the app's data or uninstalling the app.
- Subscription records: purchase records may be retained by Google Play and RevenueCat under their own policies and for tax/accounting obligations, even after your account is deleted.
9. Your rights and controls
You can, at any time:
- Access and correct your data. Everything the app holds is visible and editable inside the app.
- Change your username (subject to a cooldown period).
- Change your password.
- Delete your account and cloud data. In the app, go to Profile → Privacy & Security → Delete account. This is irreversible. You can also request deletion by writing to the contact address above:
- Withdraw permissions. Revoke notification, microphone or camera access in your device settings. The related features stop working; the rest of the app continues to.
- Opt out of cloud sync. Cloud sync of notes and ledger is a Pro feature; if you do not subscribe, those records remain on your device.
Depending on where you live, you may also have rights to data portability, to restrict or object to processing, and to complain to a data-protection authority. To exercise any of these, contact us at the address above.
10. Legal basis for processing
Where the GDPR or similar law applies, we process your data on these bases:
- Contract: to provide the app and your subscription.
- Legitimate interests: to secure accounts, enforce plan limits, and prevent abuse.
- Consent: for optional features you switch on, such as notifications, voice entry, camera scanning, and AI assistance. You can withdraw consent by turning the feature off.
11. Changes to this policy
We may update this policy as the app changes. When we make a material change, for example adding a new category of data, a new processor, or a new way of sharing data, we will update the "Last updated" date and notify you in the app or by email before the change takes effect. Continuing to use Clear Path after that means you accept the updated policy.
12. Contact
Questions, requests or complaints about this policy or your data:
Vohra Idris Shakirbhai, sole proprietor trading as Soft Planet Studio
Akbari Building, Opp. Nagina Masjid, Relief Road, Ahmedabad 380001, Gujarat, India