Clearme logo

Clearme

clearme.com
High Risk
Updated August 27, 2026

CLEAR is a biometric identity verification and expedited-access service that collects highly sensitive biometric data (faceprints, fingerprints, iris scans). The Member Terms provide a clear biometric retention schedule with jurisdiction-specific timelines and a deletion-on-request mechanism, and the company repeatedly states it will never sell or rent personal information. However, the analysis is complicated because the two documents supplied cover different services: the Member Terms govern the core CLEAR membership, while the accessible Privacy Policy applies ONLY to the Canadian 'virtual queueing services' operated by Whyline, Inc. The primary membership privacy policy was inaccessible, leaving major gaps on how core biometric data is handled, shared, and protected. The Terms also impose a mandatory arbitration clause, class-action waiver, and a broad liability cap. Given the sensitivity of the data and the missing core privacy policy, users should exercise caution before relying on the documented protections.

AI Transparency Facts

Independent analysis by TermsWatchdog · © 2026 TermsWatchdog

Input Data Ownership

Moderate Risk

The Terms assert CLEAR owns all rights to the Services and Memberships and grant users no license, but do not clearly address ownership of the identity/biometric data users submit. The privacy documents describe collection and use of personal information without a clear ownership statement. Users retain privacy rights but ownership of submitted data is not spelled out.

Confidence
45%

Output Data Ownership

Moderate Risk

This is an identity verification service rather than a content-generation tool, so 'output' primarily means verification results and credentials. The Terms state CLEAR owns the Services and any derivative works and grant no license to users. There is no explicit provision assigning generated outputs to users.

Confidence
40%

Training Data Usage

Moderate Risk

The Member Terms permit CLEAR to use biometric data to 'operate, improve, and administer' its Services, which could encompass model improvement, though 'train' is not used explicitly. The Canadian privacy policy references using data to 'develop new products and services' and generate insights, but neither document explicitly addresses AI/ML model training on user biometric data. The core membership privacy policy is unavailable.

Confidence
45%

Data Retention & Deletion

Low Risk

The Member Terms provide an unusually clear biometric retention schedule with specific jurisdiction-based timelines (e.g. Illinois 3 years, Colorado/Texas/Europe/India 2 years) and a deletion-on-request mechanism via email. The Canadian privacy policy uses a more general 'as long as necessary' standard. CLEAR does reserve the right to retain personal data after termination subject to privacy rights, which is a modest caveat.

Confidence
75%

Third-Party Data Sharing

Moderate Risk

The Canadian privacy policy states CLEAR never sells or rents personal information and shares with service providers under confidentiality obligations, which is appropriate for the service. However, the same policy discloses participation in third-party advertising networks and interest-based advertising, and the Terms allow engaging contractors and partners. The core membership privacy policy governing biometric sharing was inaccessible.

Confidence
55%

Opt-Out Rights

Low Risk

The documents provide multiple opt-out mechanisms: users can unsubscribe from marketing emails, opt out of SMS with 'STOP', withdraw consent for advertising/third-party sharing, and request biometric data deletion at any time. GDPR and CCPA users are granted access, deletion, and objection rights. These are meaningful, clearly documented choices.

Confidence
70%

Compliance & Certifications

Moderate Risk

The documents reference compliance with the CCPA and GDPR/UK GDPR (including appointment of an Article 27 representative, VeraSafe, and a Data Protection Officer), and reference jurisdiction-specific biometric laws (implicitly Illinois BIPA via retention). No SOC 2, ISO 27001, ISO 42001, or NIST certifications are named, and there are no third-party audit attestations. Because this is a consumer service, COPPA is relevant and is partially addressed (does not knowingly collect from children under 13).

Confidence
55%

Model Explainability & Auditability

High Risk

Neither document addresses model explainability, algorithmic transparency, accuracy of biometric matching, or enterprise auditing rights. For a service that makes automated identity-matching determinations, this silence is a significant gap. No audit or transparency commitments are disclosed.

Confidence
60%

Security Practices & Breach History

Moderate Risk

The Canadian privacy policy describes administrative, technical and physical safeguards including encryption, firewalls, intrusion detection, access controls, and personnel security, plus a commitment to breach notification as required by law. However, no penetration testing, bug bounty, SOC 2, or trust center is referenced, and these controls appear in the Canadian-services policy rather than the core membership policy. No breach history is disclosed.

Confidence
55%

Enterprise vs. Consumer Risk Delta

Moderate Risk

The Terms distinguish free, paid, family, and corporate membership tiers, and marketing references a 'CLEAR1' business identity product, but no enterprise agreement, DPA, or MSA was accessible. The documents do not describe any material difference in data handling between free and paid tiers — the same biometric collection and retention terms appear to apply. Enterprise-specific terms could not be assessed.

Confidence
40%

Human Review of User Inputs

Moderate Risk

The documents do not explicitly state whether staff may review biometric data or inputs, though the Terms authorize engaging contractors and service providers to perform obligations, and the privacy policy grants service providers access under confidentiality duties. There is no explicit human-review disclosure for identity data. The core membership privacy policy was inaccessible.

Confidence
40%

Regulatory & Litigation Exposure

Moderate Risk

The privacy policy explicitly discloses that data may be disclosed in response to law, legal process, court orders, subpoenas, and government/law enforcement requests, and that service providers abroad may be subject to foreign courts and authorities. The Terms impose binding individual arbitration with a class-action waiver and detailed mass-filing procedures, indicating anticipated litigation volume. This transparency is appropriate but signals meaningful government-request and dispute exposure.

Confidence
65%

PII & SPI Data Inventory

High Risk

CLEAR collects highly sensitive biometric data — faceprints, fingerprints, iris scans, and digital images of fingers, eyes, and face — which is Sensitive Personal Information, alongside identifiers, email, IP address, flight/booking data, and usage data. While collection is disclosed and consented to with a deletion mechanism, the breadth and sensitivity of the biometric SPI, combined with the inaccessibility of the core membership privacy policy, warrants a high-risk rating. Notably, the Canadian queueing policy's CCPA table marks 'Biometric information' as 'No' collected — because that policy covers only the non-biometric queueing service, not core membership.

Confidence
70%

Policy–Product Currency

Moderate Risk

The Member Terms carry an effective date of August 24, 2026, which is current relative to the August 27, 2026 analysis date. However, the only accessible privacy policy governs Canadian virtual queueing services and carries no discoverable date, and it does not cover the biometric/eGate/CLEAR ID capabilities visible in the product surface. The core membership privacy policy referenced throughout the Terms was inaccessible, so coverage of the AI/biometric-matching product cannot be fully verified.

Confidence
50%

Cross-Document Consistency

Moderate Risk

Two documents were supplied but they govern different services and different legal entities (Clear Secure, Inc. for membership Terms; Whyline, Inc. for the Canadian queueing Privacy Policy), which limits direct comparison. A notable tension: the Terms describe extensive biometric collection for the core Services, while the queueing Privacy Policy's CCPA table lists 'Biometric information: No' — reconcilable because they cover different services, but a user reading only the queueing policy could be misled about CLEAR's overall biometric practices. This is a scope-driven ambiguity rather than a direct contradiction within the same service.

Confidence
50%

You've read all 15 risk ratings for Clearme. Create a free account to see the exact policy wording behind each rating.