Privacy Policy
Written from how Clearable actually works, not from a template — but no lawyer has read it yet. Anything on an amber chip is a blank the founder still has to fill. Not legal advice.
Last updated: 29 August 2026
This describes what Clearable actually collects and does, written against the code that runs the site rather than from a template. Where something is not settled yet, it says so.
1. Who is responsible
The controller of your personal data is [Legal entity — fill before launch], established in the European Union. Contact: info@clearable.io. We have not appointed a data protection officer; that address reaches a person.
2. What we collect from buyers
Clearing a sound needs no account. When you send a request we collect:
- Your name and email address.
- Your Instagram handle, if you give one — it is optional.
- The creator and the sound you named, and your project or song title.
- Your self-reported monthly listener count and label status. The price is calculated from these, which is why the agreement asks you to confirm them.
- On the older per-sound link flow (
/clear/{slug}): optionally a Spotify artist URL and optionally a screenshot of your streaming statistics, plus how prominent the sound is in the song, how many other samples it uses, whether the song is released, and whether you want an exclusive buyout. - The request’s history: offers, counters, notes and status.
When you accept an agreement we additionally record the accepting email address, the timestamp, your IP address, the Stripe payment reference and a SHA-256 hash of the exact terms. This is the evidence that makes the electronic signature meaningful, and it is stamped into the PDF. We keep it for exactly that reason.
3. What we collect from creators
- Your email address and password, or your Google sign-in, held by Supabase Auth. We never see a password in readable form.
- Your display name, public @handle, email-notification preference, and your private pricing weights and auto-response rules.
- The sounds you upload — audio, cover art, titles, BPM, key, tags — stored in private buckets.
- Payout and identity data lives with Stripe, not with us. Stripe Connect Express collects your identity documents, bank details and tax information directly. Clearable stores only your Stripe account identifier and whether Stripe has enabled charges for it.
4. Other things people send us
- Rights reports (/report): your name, email, the claim type, what you are reporting and the details you write.
- Creator invites: if the creator you searched for is not on Clearable, we store the name or handle you typed and your email, so we can tell you if they join.
- Emails you send us at info@clearable.io.
5. Technical data
We use your IP address to rate-limit the public forms — the ones that write to the database and send email — so they cannot be used as a spam relay. Those counters are short-lived and expire on their own. Our host and our processors keep ordinary server logs. Application errors are logged server-side and money-critical failures raise an alert email to the operator, which can include the details of the request that failed.
6. Cookies, and what we do not do
Clearable sets no analytics or advertising cookies. There is no analytics script, no tracking pixel and no advertising network on this site. The only cookies we set are the Supabase session cookies that keep a signed-in creator signed in — strictly necessary, and never set for a buyer who has not logged in, because buyers have no account. Stripe sets its own cookies on Stripe’s checkout pages, under Stripe’s policy.
We do not sell personal data, we do not share it with advertisers, and we do not profile you for marketing.
7. Why we process it (lawful bases)
- Performance of a contract — running the clearance, producing the agreement, taking the payment, paying the creator, and sending the transactional emails that carry each step.
- Legal obligation — accounting and tax records, and responding to rights claims and lawful requests.
- Legitimate interests — keeping the tamper-evident audit record that makes a signature defensible, preventing fraud and abuse, rate limiting, security, investigating reports, operating alerts, and contacting a creator someone asked us to invite. We think these are what a user of a clearance platform would expect; you can object (section 11).
On automated decisions: Clearable computes a suggested price from the numbers a buyer declares. It is a suggestion shown privately to the creator, who decides. Creators can set rules that automatically approve or decline a request at certain amounts, and those rules deliberately stay inert when the size figure is self-reported rather than verified. If a decision affects you and you want a person to look at it, email us.
8. Who processes it for us
- Supabase — the Postgres database, authentication, and the private storage buckets holding audio, cover art, screenshots and signed agreement PDFs.
- Stripe — payments, the platform fee, and Connect Express payouts. Stripe collects card details from buyers and identity data from creators directly, and acts as its own controller for its legal and anti-fraud duties.
- Resend — delivery of transactional email.
- Vercel — hosting and server logs.
- Upstash — where configured, the shared rate-limit counters keyed to a requesting IP address.
- Spotify and our statistics provider— only when a buyer supplies a Spotify artist link, which is sent to Spotify’s public oEmbed endpoint to resolve the artist name and to our statistics provider to look up listener numbers.
We may also disclose data to a professional adviser, or where the law requires it.
9. International transfers
Some of those providers are based in, or process data in, the United States. Where data leaves the EEA we rely on the transfer safeguards those providers publish in their own data processing terms, including standard contractual clauses where they apply. We do not claim any certification or adequacy finding of our own, and our processor documentation is still being completed alongside the legal review noted at the top of this page.
10. How long we keep it
- Clearance requests, agreements and payments are a legal record and are kept as such. An agreement is never edited or deleted: a cancelled one is marked void, with a reason, and kept for the audit trail.
- Accounting records are kept for as long as bookkeeping law requires of [Legal entity — fill before launch].
- Creator accounts and uploaded sounds are kept while the account exists.
- Reports and invites are kept while they are relevant to an open matter or an outreach list.
- Rate-limit counters expire within minutes or hours.
We have not yet published a full retention schedule with fixed periods for every category; it is being drafted with the review above.
11. Your rights
Under the GDPR you can ask for access to your data, correction of it, erasure, restriction of processing, or portability, and you can object to processing we base on legitimate interests. Email info@clearable.io and we will answer within a month.
Two honest limits. A signed agreement, its audit stamp and the payment behind it cannot simply be erased on request: they are the record of a transaction between two other people and are needed for legal claims and accounting. And we cannot delete from Stripe what Stripe is required to keep. Where we cannot delete, we will tell you what we are keeping and why.
12. Complaints
You can complain to your local data protection authority, or to the supervisory authority for the country where [Legal entity — fill before launch] is established. Any dispute about this policy follows the same law and venue as our terms: [Governing law — fill before launch].
13. Security
Storage buckets are private and reachable only through short-lived signed URLs. Database access is restricted by row-level security, and the public flows write through server-side code rather than letting a browser touch the tables. A buyer’s link is an unguessable token. Card data never reaches our servers. No system is perfect, and we do not claim any security certification.
14. Children
Clearable is not for under-18s. If you believe a minor has given us personal data, email us and we will remove what we can.
15. Changes
When this policy changes, the date at the top changes with it. Material changes will be flagged on the site.
16. Contact
info@clearable.io. Also see our Terms of Use.