Legal
Privacy Policy
Effective June 1, 2026. This is a first-draft document and will be superseded by a lawyer-reviewed version before general availability. Questions: contact@skdaddle.com.
Who we are
ClearReport is a software product operated by Skdaddle, Inc.(“Skdaddle,” “we,” “us”), a Utah corporation. ClearReport helps licensed California assisted living facilities — Residential Care Facilities for the Elderly (RCFEs) — file incident, death, and suspected-abuse reports required by state law.
This policy explains what data we collect, why, with whom we share it, and the rights you have. It applies to www.useclearreport.com and the ClearReport web application.
Who this policy applies to
- Customers: organizations and facilities that subscribe to ClearReport.
- Users: individual staff members (administrators, facility admins, caregivers, nurses) who file or review reports.
- Subjects of reports: residents, family members, staff, and suspected perpetrators referenced in the regulatory reports our customers file using ClearReport. Skdaddle is a data-processor for our customers' report content — the customer facility is the data controller and is responsible for obtaining any consents required under applicable law.
Data we collect
Account & organization data
- Name, email address, and authentication state (provided to us by Clerk, our identity provider)
- Organization name and Clerk organization ID
- Facility details: name, license file number, phone, address, bed count
- Role assignments (org admin / facility admin / worker) and facility scope
Report content
- Resident name, date of birth, sex, room number, admission date
- Incident narrative: description, immediate actions, witnesses, injuries, location, time
- For LIC 624A (death reports): cause of death, place of death, conditions prior to death
- For SOC 341 (suspected abuse reports): abuse categories, reporter observations, suspected abuser details, last 4 digits of victim SSN, reporter information
- Compliance deadlines, agency notifications, audit log entries
- AI-generated suggestions and risk flags attached to each report
Billing data
- Subscription status, plan, trial end date, facility quantity, invoice history
- Stripe customer ID (we do not store full payment card numbers; those live with Stripe)
Usage data
- Server logs (timestamps, request paths, status codes, IP address, user-agent)
- Audit trail of user actions inside the application (who created/edited/deleted each report, who ran AI review)
- Aggregated usage metrics (number of reports, login frequency, feature use) for product improvement
Things we do NOT collect
- Full social security numbers (SOC 341 stores only the last 4 digits, as required by the form)
- Payment card numbers (handled entirely by Stripe)
- Biometric data
- Location data beyond the facility address you provide
- Tracking cookies for advertising
How we use data
- Provide the service: store and retrieve incident reports, generate PDF forms, deliver them to the regulators you designate
- AI features: send report text to Anthropic (Claude) for the liability-language review and the Ace advisor. Anthropic does not train on this data per their commercial agreement.
- Authentication and access control: verify your identity (via Clerk) and enforce role-based permissions
- Billing: process subscriptions and invoices via Stripe
- Support: respond to your requests, troubleshoot issues, and (with explicit per-incident authorization) view your data to help
- Compliance and security: maintain the audit log, detect abuse, comply with subpoenas and regulator requests
- Product improvement: aggregated, de-identified usage statistics
Subprocessors
ClearReport depends on third-party services that process customer data on our behalf. We have data-processing terms in place with each.
| Subprocessor | Purpose | Location |
|---|---|---|
| Clerk | Authentication, organization management | United States |
| Supabase | Primary database (Postgres) and storage | United States |
| Anthropic (Claude API) | AI report review and Ace advisor | United States |
| Voyage AI | Vector embeddings of administrator-entered reporting standards and of your organization's own approved reports (de-identified — resident names, rooms and dates of birth stripped — before transmission; embeddings stored by ClearReport, not retained by Voyage; never retrieved across organizations) | United States |
| Resend | Transactional email (compliance-deadline digest to administrators — deadline metadata only, no report narratives) | United States |
| Stripe | Billing, subscriptions, payment processing | United States |
| AWS Amplify | Application hosting and CDN | United States |
| Infisical | Secrets management for our infrastructure | United States |
| Sentry | Application error monitoring | United States |
We'll notify customers in writing at least 30 days before adding a new subprocessor with access to report content.
How long we keep data
- Report content: for the life of your subscription plus 90 days after cancellation, then deleted unless you have requested an export. Deletion after cancellation is currently performed as an operational process rather than an automated job — if you want your data removed sooner, email us and we will action it.
- Account data: until you delete your account or your organization is removed.
- Audit logs: 7 years (California statute of limitations for elder-abuse civil claims is generous; we retain logs long enough to support customer defense).
- Billing records: 7 years (IRS requirement).
- AI prompts/responses: not retained by Anthropic per their commercial agreement; retained by us inside the report record for the same period as the report itself.
How we protect data
- Encryption in transit: TLS 1.2+ on all connections
- Encryption at rest: AES-256 (Supabase managed)
- Authentication: handled by Clerk; MFA available for all users
- Access control: role-based, scoped to facility for non-org-admins
- Audit trail: every mutation logged with actor identity
- Backups: daily Supabase point-in-time recovery, 7-day window
- Incident response: we notify affected customers within 72 hours of confirmed unauthorized access
For a more detailed posture, see our Security overview.
Your rights
California residents (CCPA / CPRA)
You have the right to:
- Know what personal information we collect about you and how we use it (see above)
- Access a copy of your personal information
- Delete your personal information, subject to lawful retention obligations
- Correct inaccurate information
- Opt out of any “sale” or “sharing” of personal information — we do not sell or share personal information for advertising purposes
- Non-discrimination for exercising these rights
To exercise these rights, email contact@skdaddle.com. We verify identity before fulfilling requests and respond within 45 days (extendable to 90 with notice).
Subjects of regulatory reports
If a report filed using ClearReport references you (as a resident, family member, witness, or suspected perpetrator), the data controller is the licensed facility that filed the report, not Skdaddle. Direct access, correction, or deletion requests to that facility. We will forward inquiries we receive directly to the facility you specify.
Do Not Sell or Share My Personal Information
ClearReport does not sell your personal information, and does not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We have not done so in the preceding 12 months.
Because we do not sell or share, there is nothing to opt out of for advertising purposes. If our practices ever change, we will update this section and provide a working opt-out mechanism before any such sale or sharing begins. To submit a privacy request of any kind, or to confirm our no-sale status in writing, email contact@skdaddle.com.
Cookies and tracking
We use first-party cookies to keep you signed in (Clerk session cookies) and to remember UI preferences. We do not use cookies for advertising or cross-site tracking. We do not deploy third-party analytics tags that share data with advertisers. Server-side logs include IP address and user-agent for security and debugging only.
Children
ClearReport is a B2B product used by licensed-facility staff. We do not knowingly collect personal information from anyone under 18 as a userof the service. If you believe a minor has created an account or otherwise provided us information directly, contact us and we'll delete it.
Separately, a regulatory report filed through ClearReport may, in rare cases, reference a subjectwho is under 18 — for example, a dependent adult who meets the SOC 341 definition. In those cases the data controller is the licensed facility that filed the report, not Skdaddle, and we process that information solely as the facility's processor under the terms above.
International transfers
Our infrastructure is located in the United States. By using ClearReport, you understand that your data is stored and processed in the U.S. We do not currently offer EU/UK data residency; if your organization requires it, contact us before subscribing.
Changes to this policy
We may update this policy as our service evolves. We'll notify customers in writing at least 30 days before material changes take effect (for example, adding a subprocessor with access to report content). The effective date at the top of this page reflects the most recent version.
Contact
Privacy questions, data-access requests, or breach reports: contact@skdaddle.com
Skdaddle, Inc. — California assisted living incident reporting.