Privacy Policy
Effective date: 11 August 2026 · Version 1.1
This Privacy Policy explains how Clastra collects, uses, and protects your information across the Clastra applications, including calendars you choose to connect. We aim to keep this policy plain-language and short, and to be explicit about why each piece of information is requested.
1. Scope — the Clastra applications
Clastra is one connected service delivered through several applications. Some are available today; others are planned and are marked as such so this policy covers them as they are released.
- Clastra Web Application — the business workspace where companies, people, objectives, priorities and planning sessions are managed. Available today.
- Clastra Mobile Application — the personal AI companion for the daily ritual, coaching and diary. Available today.
- Clastra Desktop Application — an agent installed on your Windows or macOS device that recognises your work context so coaching is timely. Planned.
- Clastra Browser Extension — the same work-context recognition for tools used in the browser. Planned.
- Clastra Wearable Application — glanceable priorities and voice check-ins on a watch. Planned.
- Clastra CarPlay Application — hands-free, voice-only daily ritual while driving. Planned.
This policy applies to all of the above and to the marketing site at clastra.ai. It does not apply to third-party websites or services we link to.
2. Who we are
Clastra is operated by Sun Gravy Pty Ltd (trading as Clastra). We are the data controller for the personal information described in this policy.
Contact: privacy@clastra.ai
3. Information we collect
Information you provide
- Account details: name, email, and role.
- Company information (Clastra Web Application): organisation name, country, industry, and the org/team structure you create.
- Content you create: strategic objectives, priorities, goals, tasks, notes, messages, and other inputs.
- Voice input, where you use the voice-first daily ritual. See section 5 for why we ask for the microphone.
- Support requests and communications with us.
Information collected automatically
- Technical data: IP address, device and browser type, and coarse location derived from IP.
- Product usage: pages visited, features used, and session events, used to improve reliability and UX.
- Work context, where you have installed and enabled the Clastra Desktop Application or Clastra Browser Extension. You control which signals are enabled, and it is off until you turn it on.
Information from connected services
- Authentication providers, when you sign in via a linked account.
- Calendars you connect — described in full in section 4.
- Other integrations you explicitly authorise from the Clastra Web Application.
4. Calendar connections and sync
Connecting a calendar is optional and separate from signing in to Clastra. It never happens automatically: you start the connection yourself and authorise it with your calendar provider, and you can disconnect at any time.
Providers
- Google Calendar (Gmail and Google Workspace accounts).
- Microsoft Outlook and Microsoft 365 calendars.
- Apple iCloud Calendar.
- The device calendar on iOS and on Android, where you grant the Clastra Mobile Application calendar permission.
Connections can be made from the Clastra Mobile Application or the Clastra Web Application, and will extend to the Clastra Wearable and CarPlay Applications as those are released. A connection you make on one surface applies to your Clastra account, so your diary is consistent everywhere you sign in.
What we read from a connected calendar
- The list of your calendars and their identifiers and names.
- Event start and end times, time zone, and busy/free status, so Clastra can see when you are actually available.
- Event title, description, location and attendee status, where the provider exposes them and where needed to show your day accurately.
- The provider's identifier and current state for events Clastra created, so we can keep Clastra and your calendar in step.
What we write to a connected calendar
- Focus blocks and planning-session events that you ask Clastra to create on your behalf.
- Updates to those same Clastra-created events.
What we do not do
- We do not edit or delete events Clastra did not create. Your own and your colleagues' events are read for availability only.
- We do not use your calendar content to train AI models, and we do not sell it or use it for advertising.
- We do not expose your calendar content to other Clastra users beyond the availability and session information your workspace already shows.
How the connection is secured
Provider refresh tokens are stored encrypted in a secrets vault on our servers. They are never sent to your browser, never returned in a web address, never written to logs, and are not accessible to other users or to your company administrators.
Disconnecting
You can disconnect a calendar at any time from Settings → Integrations in the Clastra Web Application, or from calendar settings in the Clastra Mobile Application. On disconnect we stop reading the calendar and delete the stored credential. Events Clastra already created remain in your own calendar and are yours to keep or remove. Revoking access directly with the provider (for example in your Google or Microsoft account settings) has the same effect.
Google API limited use
Clastra's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google calendar data is used only to provide and improve the user-facing features described above, is not transferred to others except as necessary to provide those features or as required by law, is not used for advertising, and is not read by humans except with your explicit consent, for security purposes, or where required by law.
5. Why we ask for each permission
We ask for the minimum needed to make Clastra work, and we say why. Anything marked optional is off until you turn it on, and turning it off again does not remove your access to Clastra.
- Account identity (name, email, role)
To create your account, sign you in, and show you as a member of the right company and team.
Where: All Clastra applications
Status: Required
- Company and organisation structure
To place people into companies, departments and teams so priorities and reporting roll up correctly.
Where: Clastra Web Application
Status: Required
- Work content (objectives, priorities, goals, tasks, notes)
To store the plan you create and connect daily work back to company objectives.
Where: Clastra Web and Mobile Applications
Status: Required
- Calendar access
To read your availability so a plan fits your real day, and to write the focus blocks and session events you ask Clastra to create.
Where: Clastra Mobile and Web Applications (Wearable and CarPlay Applications when released)
Status: Optional — off by default
- Activity context (application and document in focus, window titles, tool usage)
To recognise what you are working on so coaching and suggestions are relevant in the moment.
Where: Clastra Desktop Application and Clastra Browser Extension
Status: Optional — off by default
- Microphone and voice input
To run the voice-first daily ritual — capturing your debrief and priorities by speaking instead of typing.
Where: Clastra Mobile Application (Wearable and CarPlay Applications when released)
Status: Optional — off by default
- Device and diagnostic data
To keep the service secure and reliable, and to diagnose crashes and errors.
Where: All Clastra applications
Status: Required
- Push notification tokens
To send the daily ritual reminder and the session or priority alerts you have enabled.
Where: Clastra Mobile Application, Clastra Desktop Application, Clastra Wearable Application
Status: Optional — off by default
6. How we use it
Beyond the specific purposes listed in section 5, we use information to:
- Provide, secure, and improve the Clastra applications.
- Personalise coaching, suggestions, and context in the Clastra Mobile Application.
- Operate organisation, company and advisor workflows in the Clastra Web Application.
- Respond to support and account requests.
- Send essential service notifications, and (with consent) product updates.
- Meet legal, tax, and security obligations.
7. Legal bases (GDPR)
Where GDPR applies, we rely on:
- Contract — to deliver the services you sign up for.
- Legitimate interests — security, fraud prevention, analytics, and product improvement.
- Consent — marketing emails, calendar connections, work-context capture, microphone access, notifications, and non-essential cookies.
- Legal obligation — tax, accounting, and lawful requests.
8. Sub-processors and sharing
We do not sell your personal information, and we do not share it with third parties except sub-processors that form part of the core Clastra service.
Our sub-processors are carefully selected vendors bound by contracts to protect your data and use it only to deliver Clastra. They fall into these categories:
- Cloud hosting and infrastructure.
- Authentication, database, and storage.
- Email delivery and transactional messaging.
- Product analytics and error monitoring.
- AI model providers, including both public foundation-model services and enterprise-grade AI systems, used to power coaching, suggestions, and companion features.
- Calendar and identity providers (Google, Microsoft, Apple and the iOS and Android platforms) receive only what is needed to authorise and maintain a connection you have chosen to make, and the events you ask Clastra to create.
We may also disclose information where required by law, valid legal process, or to protect the rights, safety, or property of Clastra, our users, or the public.
9. International transfers
Clastra operates globally and your information may be processed in countries other than your own, including Australia, the United States, and the EU. Where required, we use safeguards such as Standard Contractual Clauses to protect transfers out of the EEA and UK.
10. Data retention
We keep personal information only as long as needed for the purposes described above.
- Account information: for the life of your account, then deleted on request.
- Content and companion history: retained while your account is active; deleted or anonymised on request, subject to legal retention.
- Calendar-derived information: retained while the calendar connection is active. On disconnect the stored credential is deleted and we stop reading the calendar; the record of events Clastra created is removed with your account.
- Work-context signals: retained only as long as needed to provide coaching, and deleted when you disable capture or delete your account.
- Financial records: retained for the period required by law (typically 7 years in Australia).
- Backups may retain data for a limited additional period.
11. Cookies and tracking
We use cookies and similar technologies for essential functions (sign-in, security), for product analytics, and — where you consent — for feature personalisation. You can control cookies through your browser and, where available, in-app preferences. Disabling essential cookies will break parts of the service.
12. Security
We use encryption in transit and at rest, access controls, least-privilege permissions, per-company data isolation, and monitoring to protect your information. Third-party credentials such as calendar tokens are held in an encrypted vault accessible only to our servers. No system is perfectly secure — you are responsible for keeping your account credentials safe. If a breach affects you, we will notify you as required by law.
13. Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Delete your account and associated data.
- Export your data in a portable format.
- Withdraw a permission at any time — disconnect a calendar, disable work-context capture, revoke microphone access, or turn off notifications — without losing access to Clastra.
- Object to or restrict certain processing, or withdraw other consent.
- Opt out of marketing at any time via unsubscribe links or by contacting us.
To exercise any of these rights, email privacy@clastra.ai. We respond within 30 days (or as required by local law).
14. California and Nevada rights
California residents have rights under the CCPA to know, access, delete, and opt out of the sale of personal information. Nevada residents may opt out of the sale of personal information. We do not sell personal information. We will not discriminate against you for exercising these rights.
15. Children
Clastra is not intended for children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us information, contact us and we will delete it.
16. Changes and contact
We may update this policy from time to time. When we do, we will update the effective date above and, for material changes, notify users in-app or by email.
Questions or requests? Email privacy@clastra.ai.