Privacy
Last updated 19 August 2026. Clarice is owned and operated by Vinclarice, LLC, which is responsible for the data described on this page. It is run day to day by one person, who you can reach at support@vinclarice.com.
The short version: Clarice holds what you write, shows it to nobody, and has no analytics of any kind. There is no advertising, no tracking, and nothing here is sold or shared. The rest of this page is the detail behind that, including the parts that are still imperfect.
What Clarice stores
Your account: a username, an email address, and a password. The password is stored only as a hash — it cannot be read back, by us or by anyone with the database.
What you write: tasks and their notes, checklist steps, tags, areas and projects, recurring commitments, routines and what you logged against them, each day's intentions, gratitude and happenings, weekly reviews, and everything captured into Second Mind. This is the point of the product, and it is the material everything below is about.
A record of what happened: Clarice keeps an append-only activity log so a completed week can be explained later. It records your own actions in your own account.
Access tokens, if you create any for a phone or another client. Each one is scoped to what you allowed it to do and can be revoked from your preferences.
What Clarice does not do
There is no analytics — no Google Analytics, no product analytics, no session recording, no heatmaps, no pixels. Nobody is measuring how you use it. There is no advertising and no profiling, and your material is never sold, rented or shared with anyone.
Pages load no third-party scripts, and the typefaces are served from Clarice's own server rather than a font network — so simply reading a page does not tell anyone else that you did.
Nobody reads your material as a matter of course. In practice the person who runs Clarice on behalf of Vinclarice, LLC has database access, as the operator of any self-hosted service does; it is looked at only when you ask for help with something specific, or where the law requires it.
Cookies
Three, all set by Clarice itself and none of them used for tracking:
sessionid— keeps you signed in.csrftoken— stops other sites submitting forms as you.clarice_theme— remembers whether you chose light or dark.
There is no cookie banner because there is nothing to consent to: all three are needed for the site to work or to honour a choice you made.
Who else sees anything
Three companies, each doing one job.
DigitalOcean hosts the server and the database, both in their New York region, in the United States. That is where everything Clarice stores lives, and there is one of each — no copies in other regions, and nothing replicated abroad.
The database is a managed one, so its backups are taken and held by DigitalOcean alongside it rather than shipped somewhere else. If you are outside the United States, using Clarice means your data is stored there — worth knowing before you sign up rather than after.
Resend delivers email — confirming your address, resetting a password, the daily summary if you have it on, and anything you send through the contact form. They receive the address the message goes to and the message itself.
Sentry receives error reports when something breaks in production, and this one is worth being precise about because error reporting is a common way for private material to leak by accident. Clarice deliberately does not send:
- your username, or your cookies;
- the body of any request — so a failure while saving a note does not send the note;
- the local variables in the code where the error happened, which is where that text would otherwise appear;
- the query string — searches and shared text arrive that way, so it is dropped before the report leaves;
- performance traces, which are switched off entirely.
What a report does contain is the kind of error, where in the code it happened, and the path of the page — enough to fix it, and none of what you wrote. Error reporting is off outside production.
Email you receive
Only about your own account: confirming your address, password resets, notice that an account is scheduled for deletion or that it was cancelled, and a receipt when it is erased. There is no marketing and no newsletter.
There are two recurring messages. The daily summary is a morning email listing what is overdue or due today; it is on by default and you can turn it off at any time on your preferences page.
The evening nudge asks what happened today and says what the day held. It is off by default — you will never receive it unless you turn it on. Nothing is sent once you have written the day.
Keeping it safe
Traffic is encrypted in transit and the site refuses to serve anything over plain HTTP. Passwords are hashed. Repeated failed sign-ins lock an account temporarily. Every part of Clarice that takes an identifier checks who owns the record before answering, and that isolation is tested rather than assumed. On Android, anything waiting to be uploaded is encrypted on the device.
No system is perfect and it would be dishonest to imply otherwise. If something involving your data goes wrong, you will be told what happened.
Taking it with you, and leaving
You can download everything in your account at any time, from your preferences page, as a single archive. It is built from the models the application actually has rather than a hand-kept list, so it does not quietly miss things.
You can delete your account from the same page. Deletion is scheduled 30 days ahead and can be cancelled by signing in during that window — a banner appears on every page so it is hard to forget. When the 30 days run out, everything is destroyed: every task, note, routine, review and the activity log with them. It cannot be undone, and the export is worth taking first.
One honest limitation. Deleting your account removes your data from Clarice. It does not reach anything already sent to Sentry or Resend — an error report from months ago, or a delivery record of an email. Those are account-level actions at those two companies, and they are done by hand on purpose: automating them would mean this application holding a credential able to delete at both, permanently, which is a worse trade than the manual step. If you want them cleared, write to support@vinclarice.com and it will be done by hand.
Your rights, and asking
You can see what is held, correct it, take a copy, or have it deleted. Most of that is self-service on your preferences page and needs nobody's permission. For anything the interface does not cover, write to support@vinclarice.com and expect a real answer.
Clarice is not built for children and accounts are not knowingly created for anyone under 16.
Changes
If this changes in a way that affects what is collected, where it goes, or who is responsible for it, the date at the top changes and anyone with an account is emailed before it takes effect. Small corrections — clearer wording, a fixed mistake — just change the date.
See also the terms of use.