← Back to ClearMeta
Security
How we protect your files and infrastructure.
File handling
- Uploads stored in isolated server directories with random UUIDs
- Automatic deletion after 1 hour (uploads, cleaned files, batch ZIPs)
- No permanent image storage or CDN caching of user content
- Shareable reports expire after 7 days
Transport & headers
- HTTPS enforced in production
- Security headers: X-Frame-Options, X-Content-Type-Options, Referrer-Policy
- Download endpoints use Cache-Control: no-store
Rate limiting
API routes are rate-limited per IP to prevent abuse. Deep Clean and Pro Verify have stricter limits due to compute cost.
Authentication
Pro Verify and Deep Clean require Clerk authentication when enabled. Session tokens are managed by Clerk — we do not store passwords.
Pro Verify & third parties
When you use Pro Verify, images are sent to OpenAI's Content Provenance API over TLS. Review OpenAI's data handling before processing sensitive content.
Reporting vulnerabilities
Found a security issue? Email security@clearmeta.app. We aim to respond within 72 hours.
Last updated: September 13, 2026