ClearMeta
← Back to ClearMeta

Security

How we protect your files and infrastructure.

File handling

  • Uploads stored in isolated server directories with random UUIDs
  • Automatic deletion after 1 hour (uploads, cleaned files, batch ZIPs)
  • No permanent image storage or CDN caching of user content
  • Shareable reports expire after 7 days

Transport & headers

  • HTTPS enforced in production
  • Security headers: X-Frame-Options, X-Content-Type-Options, Referrer-Policy
  • Download endpoints use Cache-Control: no-store

Rate limiting

API routes are rate-limited per IP to prevent abuse. Deep Clean and Pro Verify have stricter limits due to compute cost.

Authentication

Pro Verify and Deep Clean require Clerk authentication when enabled. Session tokens are managed by Clerk — we do not store passwords.

Pro Verify & third parties

When you use Pro Verify, images are sent to OpenAI's Content Provenance API over TLS. Review OpenAI's data handling before processing sensitive content.

Reporting vulnerabilities

Found a security issue? Email security@clearmeta.app. We aim to respond within 72 hours.

Last updated: September 13, 2026