Clara Join waitlist

Security

How Clara protects app, bank connection and account data.

Last updated: 24 July 2026

How Clara protects data

Clara uses TLS encryption for data in transit and provider encryption for data at rest. Supabase row-level security and access controls restrict records so authenticated users can access only data permitted for their account. Production access is limited to the people and services that need it.

JEMA Software Ltd uses separate service credentials, dependency updates, logging, stripped-down error monitoring and incident-response procedures. No online service can promise absolute security.

Bank and payment information

Bank connections are provided through Finexer Ltd, authorised by the FCA (FRN 925695).

Clara never receives bank login credentials and its account access is read-only. Apple processes App Store payments; JEMA Software Ltd does not store full payment-card details.

Security incidents

JEMA Software Ltd assesses suspected personal-data breaches promptly, records the assessment and takes proportionate containment and recovery steps. Where UK data-protection law requires notification, JEMA Software Ltd will notify the ICO without undue delay and, where feasible, within 72 hours after becoming aware of the breach.

Where a breach is likely to create a high risk to affected people, JEMA Software Ltd will tell those people without undue delay and explain the practical steps they can take.

Your part and security reports

Use a unique password, protect access to your email and device, keep Clara updated and disconnect devices or accounts you no longer use.

Send suspected vulnerabilities or account-security issues to support@getclara.co.uk. Do not access another user’s data, disrupt the service or publicly disclose an unresolved issue.