Privacy Policy

Last updated: 23 June 2026

The short version

Your blood test PDF is read entirely inside your browser and is never sent to our servers. We store only anonymous, aggregated scores. We do not sell your data. Ever.

1. Who we are

Clariti ("we," "us," or "our") operates the website clariti.living and the Clariti health score service (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. By using the Service you consent to the practices described in this Policy.

If you do not agree with the terms of this Privacy Policy, please discontinue use of the Service immediately.

2. Information we do NOT collect

Clariti is designed with a privacy-first architecture. The following data is never collected, transmitted, or stored by Clariti:

The contents of your blood test PDF — parsed entirely in your browser using PDF.js and never uploaded to any server

Your name, email address, or any personally identifiable information

Your IP address linked to health data

Any login credentials (we have no accounts)

3. Information we do collect

When you use the Service, the following anonymous, non-identifiable data is transmitted to our servers and stored solely for benchmarking and service improvement:

Age band (e.g. "30s") — never your exact age

Biological sex — male or female, as entered by you

Country code — two-letter ISO country code (e.g. "US", "GB")

Domain scores — numerical health scores per domain (e.g. cardiovascular: 72)

Overall health score — your aggregate A–F score as a number

Detected biomarker values — the numerical values of biomarkers identified in your report (e.g. glucose: 5.2, HDL: 1.4). These are stored anonymously alongside the data points above and cannot be linked to your identity.

None of this data can be linked back to you. It is used only to generate population benchmarks that improve the accuracy and relevance of scores for all users.

3a. Anonymous usage analytics

When you visit any page on clariti.living, our server automatically records the following anonymous data for the purpose of understanding how the Service is used and improving it:

Page path visited — e.g. "/", "/blog/vitamin-d-deficiency-blood-test"

Referrer — the URL of the page that linked you here (or blank if you arrived directly)

Time on page — approximate seconds spent on the page

Device type — mobile, tablet, or desktop (derived from your browser's User-Agent string)

Browser and operating system — e.g. Chrome on Windows (derived from User-Agent; the raw string is not stored)

Country — two-letter code and full name, derived from your IP address via ip-api.com. Your IP address is not stored — only the resulting country.

This data is collected without cookies and requires no consent-banner interaction. It contains no personally identifiable information and cannot be linked back to you. It is used solely for internal analytics (which pages are popular, where visitors come from, what devices are used). No third party receives this data.

Separately, when you click "Analyze" after selecting a PDF, we record the same anonymous attributes (country, device, browser, operating system, and timestamp) as an "upload attempt" event — this tells us that someone tried to use the tool, regardless of whether the analysis succeeds. No part of your file, its filename, or its contents is ever recorded — this event fires before your PDF is even read.

The legal basis for this processing under GDPR is Legitimate Interests (Art. 6(1)(f)): measuring aggregate, anonymous page traffic and tool usage is a proportionate interest of any website operator, and this processing does not override your rights or freedoms given the absence of personal data.

4. Shared results (optional feature)

If you choose to use the "Share Results" feature, we store your score result(s) (domain scores, overall score, grade, and — when two tests are compared — the results for both tests) against a randomly generated 10-character ID in our database. This data:

Is stored for a maximum of 30 days, then automatically deleted

Contains no raw biomarker values extracted from your PDF — only computed scores

Is accessible only to anyone who has the unique link — you control who you share it with

Is not indexed by search engines (shared result pages carry a noindex,nofollow directive)

Displays a health-data disclaimer to anyone who opens the link, reminding them that the content is sensitive personal health information

Use of the Share Results feature is entirely optional and requires your deliberate action. When you copy a share link, we display a reminder that you are about to share sensitive health information — you bear sole responsibility for deciding who receives that link.

4a. Deleting a shared link

You can permanently revoke a shared link at any time using the Delete a shared link feature available on the results page and the upload page. Paste the share URL (e.g. https://clariti.living/?r=abc123) or the bare link ID and confirm deletion. The record is removed immediately and the link becomes permanently inaccessible. Note:

Deletion is irreversible — the link cannot be restored

Deletion of a share link does not affect the anonymous benchmarking data described in Section 3, which is stored separately and cannot be linked back to you

If the link has already expired (30-day TTL) it is already gone — you do not need to delete it manually

5. Cookies and tracking

Clariti uses minimal cookies and tracking technologies. Specifically:

No advertising cookies — we do not display ads or use ad-tracking pixels

No third-party trackers — we do not embed Facebook Pixel, Google Ads, or similar tracking scripts

Analytics (Google Analytics 4) — with your explicit consent, we load Google Analytics 4 to collect anonymised page-view and usage data (e.g. pages visited, session duration, general geography). GA4 is only activated after you click "Accept cookies" in the cookie banner — it is never loaded if you decline or ignore the banner. Your IP address is anonymised before processing. You can withdraw consent at any time by clearing your browser's local storage or using the Google Analytics opt-out browser add-on. For full details see our Cookie Policy.

6. Third-party services

Clariti uses the following third-party services that may process data as part of delivering the Service:

PDF.js (Mozilla Foundation) — an open-source library loaded from a CDN to parse your PDF inside your browser. No data is sent to Mozilla.

Tailwind CSS CDN — a CSS framework loaded from a CDN for styling. No personal data is transmitted.

Hosting provider (DigitalOcean) — our servers are hosted on DigitalOcean. Standard server logs (IP addresses, request timestamps) may be collected by DigitalOcean in accordance with their own privacy policy.

Telegram (operational monitoring) — we use a private Telegram bot to receive internal operational alerts when a new analysis is completed or when a server error occurs. These alerts contain only the anonymised data already described in Section 3 (health score, biomarker count, biological sex, country) and never contain raw PDF content or personally identifiable information. Telegram processes messages in accordance with Telegram's Privacy Policy.

We do not sell, rent, trade, or otherwise share your data with any third party for marketing or commercial purposes.

7. Affiliate links

Clariti may display affiliate links to third-party products (such as Amazon Associates, Function Health, or Hone Health). Clicking these links may result in us receiving a small commission if you make a purchase. These links do not affect our scoring methodology and are disclosed transparently. Third-party sites have their own privacy policies which we do not control.

8. Children's privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect any information from children under 18. If you are a parent or guardian and believe your child has used the Service, please contact us and we will take appropriate steps to remove any associated data.

9. International users and GDPR/CCPA compliance

Clariti is available to users worldwide. If you are located in the European Economic Area (EEA) or California, the following applies:

GDPR (EU users): The anonymous aggregate data we collect does not constitute personal data under the GDPR as it cannot be used to identify you. We process this data on the lawful basis of legitimate interest (improving our benchmarking service). You can delete any shared result link yourself at any time using the "Delete a shared link" feature described in Section 4a, or by contacting us with your link ID.

CCPA (California users): We do not sell personal information. As we do not collect personal information in the first instance, most CCPA rights (access, deletion, opt-out of sale) are satisfied by design. For any inquiries, contact us at the address below.

10. Data security

We implement commercially reasonable technical and organisational security measures to protect the limited data we store. Our servers use HTTPS/TLS encryption in transit. Our database is not publicly accessible. However, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security and disclaim liability for any breach outside our reasonable control.

11. Data retention

Anonymous aggregate health scores are retained indefinitely for benchmarking purposes. Shared result records are automatically deleted after 30 days. We do not retain any other data.

12. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page will reflect the revision date. Your continued use of the Service after any changes constitutes your acceptance of the revised Policy. We encourage you to review this Policy periodically.

13. Contact

For any privacy-related questions, requests, or concerns, please contact us at:

Clariti

Email: hello@clariti.living

Website: clariti.living