Privacy Policy

Last Updated: July 23, 2026

1. Introduction

At Clearance ("we," "our," or "us"), we prioritize the privacy and security of the academic institutions, supervisors, coordinators, and students who use our platform. This Privacy Policy outlines how we collect, use, process, and protect your information when you use the Clearance research governance platform, including our calendar integration services.

2. Information We Collect

We collect information that is necessary to provide our institutional governance and meeting scheduling services:

  • Account Information: Names, university email addresses, and institutional roles (Student, Supervisor, Coordinator).
  • Academic Records: Thesis drafts, milestone progress, and feedback provided by supervisors.
  • Communication Data: Chat logs within the Resolution Engine, and timestamps of approvals or rejections.
  • Integrated Calendar Data (Google & Microsoft): When you explicitly authorize meeting calendar integration (Google Calendar or Microsoft Calendar/Outlook), we access your calendar events, schedules, time slots, and availability details. Specifically, we read and write calendar entries to facilitate booking, updates, and synchronization of supervisor-student meetings within the app.
  • Audit Logs: Immutable records of actions taken within the platform to ensure compliance with accreditation bodies.

3. How We Use Your Information

Your data is strictly used for providing and improving the Clearance platform:

  • To facilitate the thesis supervision workflow and milestone tracking.
  • To facilitate and schedule supervision meetings using your integrated Google Calendar and Microsoft Calendar (reading availability to avoid scheduling conflicts and creating calendar invites for scheduled meetings).
  • To generate compliance reports and audit trails for university administrators and accreditation bodies (e.g., OfS, TEQSA).
  • To provide Risk Intelligence alerts (e.g., ghosting or overdue detection) to authorized department coordinators.

We do not sell your personal data, academic materials, or calendar data to third parties. We do not use your thesis drafts, calendar data, or feedback to train external AI models.

4. Data Sharing, Transfer, and Disclosure

We do not transfer or disclose your personal information or Google/Microsoft user data to third parties for purposes other than the ones explicitly provided to run and improve the core functionality of the Clearance application.

  • No Commercial Sharing: We do not share, sell, or rent your Google user data or Microsoft user data to third-party ad networks, data brokers, or any other entities for marketing or commercial purposes.
  • Service Providers: We may share data only with trusted service providers who perform services on our behalf (e.g., database hosting) under strict data protection agreements.
  • Compliance and Legal Obligations: We may disclose information if required to do so by law or in the good-faith belief that such action is necessary to comply with legal obligations or protect our users' safety.

5. Data Storage, Security, and Protection Mechanisms

We employ enterprise-grade security measures to protect your sensitive data, including account credentials and integrated calendar tokens:

  • Encryption: All data, including sensitive OAuth access/refresh tokens for Google and Microsoft APIs, is encrypted in transit using industry-standard TLS protocols and encrypted at rest.
  • Row-Level Security (RLS): Clearance utilizes PostgreSQL Row-Level Security (RLS) to ensure strict data isolation—meaning a supervisor can only access data for their assigned students, and students cannot access data belonging to others.
  • Access Control: Strict access controls restrict internal developer and staff access to production environments containing sensitive user data.

6. Data Retention and Deletion

We retain your data only for as long as necessary to provide services to your academic institution or until you request its deletion:

  • Account & Academic Data: Retained for the duration of the university enrollment or institution contract, in compliance with academic record-keeping standards.
  • Calendar Tokens and Data: OAuth connection tokens for Google Calendar and Microsoft Calendar are immediately deleted when you disconnect the integration in your account settings or request account deletion.
  • Deletion Requests: You can disconnect calendar integrations or request complete data deletion at any time by contacting us. Data will be completely and securely erased from our active databases and backup files within 30 days.

7. Your Rights

Depending on your location and your institution's policies, you may have the right to access, correct, or request deletion of your personal data. Because Clearance operates as a data processor on behalf of your university (the data controller), requests regarding academic records should generally be directed to your institution's administration.

8. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact our Data Protection Officer at:
privacy@clearanceuni.com