Clear Scholr
Privacy PolicyTerms of ServiceSecurity
 

Security

Last updated: August 2026

Clear Scholr is designed with security and privacy in mind. We use established infrastructure and security practices to protect account information and help prevent unauthorized access.

Authentication

Clear Scholr uses Supabase Auth for account authentication and management.

Users sign in with an email address and password. Clear Scholr does not store or have access to users' passwords. Password authentication is handled by Supabase Auth, which securely stores password hashes rather than plaintext passwords.

Email verification may be required for new accounts depending on project settings, and password recovery is available through the authentication system.

Supabase Auth also provides protections and rate limits designed to help defend authentication endpoints against abuse and automated attacks.

Session Security

Authenticated access to Clear Scholr is managed through Supabase Auth sessions.

Supabase Auth uses short-lived access tokens together with refresh tokens to maintain authenticated sessions. Sessions can be terminated when a user signs out or performs certain security-sensitive actions, depending on the applicable configuration.

Clear Scholr does not directly store users' passwords or use passwords as application-level authentication credentials.

Account Data

Clear Scholr stores limited account information required to provide the service, such as:

  • Name
  • Email address
  • Selected grade level
  • Authentication and account information
  • Account preferences

Access to administrative tools is restricted to authorized Clear Scholr administrators, who may access account and academic information when reasonably necessary to operate the service, respond to support requests, manage accounts, investigate abuse, or enforce platform rules.

Academic Data

Classes, assignments, grades, GPA information, trends, and projections are stored in Clear Scholr's Supabase database.

Row-level security limits routine application access to each user's own records. You can export or delete your data from Settings.

Database Security

Clear Scholr uses Supabase's managed PostgreSQL database for account and academic data.

Supabase provides authentication, database security controls, access management, and other infrastructure designed to protect application data.

Clear Scholr limits application and administrative access to the information necessary to operate the service.

Transport Security

Clear Scholr is served over HTTPS in production, helping protect information transmitted between users and the service from interception while in transit.

Vercel provides HTTPS-enabled production deployments and supports additional security controls through response and custom headers.

Infrastructure

Clear Scholr's production infrastructure uses established third-party providers, including:

  • Vercel for hosting and deployment
  • Supabase for authentication, database storage, and application data
  • Resend for transactional email delivery

These providers maintain their own security measures and infrastructure controls.

Application data is stored in Supabase and protected by access controls, encryption in transit, and provider security practices.

Application Security

Clear Scholr uses multiple measures intended to reduce common security risks, including:

  • Authentication and authorization controls
  • Rate limiting
  • Input validation
  • Security-focused application configuration
  • Protected production credentials
  • Environment-based secrets management
  • Dependency and code security practices
  • Restricted administrative access
  • Regular monitoring and maintenance

No security system can eliminate all risks. We continuously work to identify and address vulnerabilities as the service develops.

Administrative Access

Access to Clear Scholr's administrative tools is restricted.

Authorized administrators may access limited account information and perform necessary account-management actions, such as responding to support requests, managing accounts, and enforcing platform policies.

Authorized administrators may access account and academic information when necessary for support, abuse investigation, and platform operations.

Backups and Recovery

Clear Scholr and its infrastructure providers maintain backups to help protect against accidental data loss. You can also download a personal export from Settings at any time.

Security Reporting

If you believe you have discovered a security vulnerability in Clear Scholr, please report it through Support on the Clear Scholr website.

When reporting a potential vulnerability, please provide enough information for us to reproduce and investigate the issue, including the affected page or feature and the steps required to reproduce the behavior where possible.

We will review legitimate security reports and take appropriate steps to investigate and address confirmed vulnerabilities.

No Guarantee of Absolute Security

While we take reasonable measures to protect Clear Scholr and the information we process, no online service, system, or method of transmission can be guaranteed to be completely secure.

Users should also take reasonable steps to protect their accounts, including using a strong, unique password and avoiding sharing account credentials with others.

Clear Scholr
© 2026 Clear Scholr