Security

Security

Security notes for Clair Flow: device auth, transcript handling, and hosted processing.

Clair Flow is a hosted product. Security depends on being clear about the trust boundary.

Account and device access

  • browser sign-in uses magic links with an explicit confirmation step
  • each native device receives its own device-specific credential
  • device credentials are stored hashed on the server
  • devices can be revoked from the account dashboard

Dictation data handling

  • raw audio is processed during dictation and is not stored afterward
  • transcript text and session metadata are stored in the cloud and kept until you delete them
  • glossary entries are stored in the hosted account so transcript cleanup can respect your terms
  • you can delete your dictation history from the account dashboard at any time

Subprocessors

Clair Flow relies on named third-party providers for speech-to-text, transcript cleanup, billing, authentication, hosting, and database storage. The full list of subprocessors and the role each one plays is published in the privacy summary.

Operational support

If you discover a security problem or sensitive account issue, email support@clairflow.ai.