Clark AI Agent Privacy Review for Solo Freelancers — AI tool privacy review for freelancers

Clark AI Agent Privacy Review for Solo Freelancers

Transparency Notice: This article contains affiliate links. If you purchase through these links, we may earn a small commission at no extra cost to you. We only recommend products we genuinely believe in. Read our full disclosure.

Short answer: Clark trains on your prompts, actions, executed code, and generated files by default unless you switch off training in account settings — our verdict is USE WITH CAUTION for client work. Clark by Clark Labs is an autonomous “AI coworker” with its own cloud computer (browser, terminal, files, code), so it doesn’t just read your text; it acts on your behalf and records the websites it visits, the actions it takes, and the files it creates or changes. As of July 2026 (policy reviewed July 2026, last updated July 13, 2026), the posture is workable for solo freelancers — but only after you opt out of model training and keep sensitive client material out of open sessions. This review explains what Clark collects, where the risk sits, and how to lock it down before you hand it a paid task. See how we vet privacy claims for our sourcing standard.

What Clark does with your data

Privacy dimensionClark’s answer (sourced)
Trains on your data?Yes, by default (prompts, actions, code, files)
Training opt-outYes, in account settings
Data retentionDeleted chats purged within 30 days
Third-party sharingSub-processors, LLM and sandbox providers; no sale
Storage regionUnited States and other jurisdictions
Google Workspace dataZero-retention, no-training controls; not sold
Enterprise-team tierYes (Enterprise plan advertised)

Clark collects the account basics you would expect — name, email, and payment details — plus everything you feed the agent: prompts, instructions, uploaded files, and any credentials you choose to share (per Clark’s privacy policy, retrieved 2026-07-22). The unusual part is what a computer-use agent logs while it works. Clark records the websites it visits, the actions it takes, the code it runs, and the files it creates or modifies on your behalf. That is a far wider capture surface than a chat-only assistant, because the agent is operating inside live sessions, not just answering questions.

By default, Clark processes this input and output both to run the service and to train and improve its models (per Clark’s privacy policy, retrieved 2026-07-22). You can opt out of training in account settings, but opting out does not stop processing needed for service delivery, safety reviews, legal compliance, or terms enforcement. On sharing, Clark states it does not sell personal information and does not send your prompts, chat contents, or uploaded files to advertising or affiliate networks. It does route your content to sub-processors: cloud compute providers that run the sandbox, and large language model providers that perform the inference you request.

Google Workspace connections get stronger treatment. When you connect Google, Clark accesses only the scopes you select — which can include email content you ask it to send, calendar details, and Drive, Docs, or Sheets files you pick. That Google-derived data is handled with zero-data-retention and no-training controls, is excluded from generalized model training, and is not sold or used for advertising. OAuth tokens are encrypted at rest and deleted when you disconnect. On retention overall, deleted conversations leave your visible history immediately and are purged from backend systems within 30 days; a closed account is deleted or de-identified within 90 days.

Two details deserve a closer look because they shape the real-world risk. First, the sandbox model: Clark runs your tasks on third-party cloud compute providers and routes inference to external large language model providers, so your content is transmitted to infrastructure Clark does not own (per Clark’s privacy policy, retrieved 2026-07-22). Clark says it contracts these sub-processors to protect your data consistently, but the current list is available only on request, not published — so you cannot audit the chain before you sign up. Second, the advertising layer: Clark can associate campaign and affiliate click identifiers with your account for up to 30 days when you consent to marketing measurement, and it honors Global Privacy Control by disabling nonessential tracking. Prompts, chat contents, and uploaded files are explicitly kept out of that advertising flow, which is the reassuring part. The takeaway is that Clark separates your work content from its ad measurement, but your work content still travels across a sub-processor chain you cannot fully inspect in advance.

What this means for solo freelancers

The core tension for a solo worker is that Clark is powerful precisely because it touches real accounts and real files — which is also where the exposure lives. Based on the policy as written, here are three concrete scenarios worth thinking through before you point Clark at paid work.

  • If you paste a client contract into an open (non-opted-out) session, that document becomes input Clark may use to train its models. Based on the policy as written, this carries the risk that confidential client language contributes to a shared model corpus you cannot later claw back.
  • If you let Clark act inside a client’s logged-in web app or code repository, the agent records the actions it takes and the files it modifies. Based on the policy as written, that log of client-system activity is retained on Clark’s infrastructure, which raises a controller-processor ambiguity if your client is an EU business expecting a signed data processing agreement.
  • If you connect a shared or client Google Workspace, Clark can reach the email, calendar, and Drive scopes you approve. The zero-retention and no-training controls reduce the training exposure, but you are still granting an autonomous agent standing access to a client’s mailbox until you disconnect.

None of this makes Clark unusable. It means the default settings are tuned for growth, not for the confidentiality a freelancer owes a client. The safe path is to treat every new session as untrusted until you have changed the training default and scoped access down to exactly what the task needs.

How to use it safely

Clark can be run responsibly for client work if you configure it deliberately. Do these steps before your first paid task:

  1. Opt out of AI model training in your account settings first. This is the single highest-impact toggle, and it applies going forward, so set it before you paste anything sensitive.
  2. Redact client identifiers before you paste. Strip names, account numbers, and contract party details out of prompts; give Clark the task shape, not the client’s identity.
  3. Scope Google connections to one mailbox or folder, never a blanket account grant. Approve only the specific Drive files or calendar scope the task needs, and disconnect Google when the job is done to revoke the tokens.
  4. Use a separate, disposable workspace for client-sensitive runs rather than your personal signed-in browser, so the agent’s cloud computer is not touching credentials it does not need.
  5. Delete conversations when the task closes. Deleted chats are purged within 30 days, so clearing sensitive sessions shortens the window your client’s data sits on Clark’s backend.

For any project under a signed NDA or an EU client’s data processing agreement, ask Clark Labs for its sub-processor list (the policy says it is available on request) and its DPA terms before you run the agent against that client’s systems at all.

Privacy-friendlier alternatives

If Clark’s default training posture or its broad agent access is more than your client work can absorb, a few tools cover the same jobs with a tighter data footprint. Match the swap to the specific risk you are trying to remove.

  • Proton — what it gives you that Clark doesn’t: end-to-end encrypted mail, calendar, and Drive where the vendor cannot read your content, so a client’s documents never sit in a training-eligible pool. Pricing band roughly $10-15/month for the business bundle. Best for freelancers who mainly need a private place to store and send client files, not an autonomous agent.
  • 1Password — what it gives you that Clark doesn’t: a dedicated secrets vault so you never paste credentials into an agent session at all. Pricing band around $8/month for the business tier. Best for isolating the API keys and client logins Clark would otherwise ask you to share.
  • Tailscale — what it gives you that Clark doesn’t: a private network so you can reach a client’s internal system yourself, without granting a third-party cloud agent standing access. Pricing band free for solo use, roughly $6/user/month for teams. Best for consultants who need secure remote access more than autonomous task execution.

On the hardware side, if your objection to any cloud agent is account takeover, a physical security key such as a YubiKey 5 series hardens the Google and platform logins Clark connects to, so a leaked token cannot be replayed without the key in hand.

[INTERNAL_LINK_TO_CLUSTER_ai-privacy-reviews]

[INTERNAL_LINK_TO_CLUSTER_ai-privacy-reviews]

The verdict

ATP Privacy-Vetted: USE WITH CAUTION

Our verdict for Clark is USE WITH CAUTION for client work. Clark trains on your prompts, actions, code, and files by default, and its autonomous agent touches live accounts and repositories — but a clear opt-out, a 30-day deletion window, and genuine zero-retention controls on connected Google Workspace data make it defensible for freelancers who configure it before the first paid task rather than after. Turn off training, scope access tightly, and keep NDA-covered client material out of open sessions, and Clark moves from risky to workable.

Frequently asked questions

Does Clark train on my prompts?

Yes, by default. Clark’s policy states it processes your input and output to train and improve its models unless you opt out (per Clark’s privacy policy, retrieved 2026-07-22). The opt-out lives in your account settings and applies going forward, so set it before you paste sensitive client material. Note that opting out does not stop routine processing needed to deliver the service, run safety reviews, or meet legal obligations.

Is Clark GDPR-friendly for EU clients?

Based on the policy as written, Clark names GDPR legal bases and relies on Standard Contractual Clauses for EU, UK, and Swiss transfers to the US. That is a reasonable foundation, but for a paid EU engagement you still need a signed data processing agreement and the sub-processor list, which Clark provides on request. Treat those documents as prerequisites before running the agent against an EU client’s systems, not optional extras.

Can I use Clark for HIPAA-covered data?

Based on the policy as written, Clark does not advertise a Business Associate Agreement or HIPAA-specific controls, and its default training and broad sub-processor routing are a poor match for protected health information. If your freelance work touches patient data, do not paste it into Clark. Handle HIPAA-covered material in a dedicated environment with a signed BAA instead, and keep the agent scoped to non-regulated tasks.

How long does Clark keep my data?

Deleted conversations disappear from your visible history immediately and are purged from backend systems within 30 days (per Clark’s privacy policy, retrieved 2026-07-22). When you close your account, Clark deletes or de-identifies your personal information within 90 days, except where law requires retention. Aggregated or de-identified data that cannot reasonably identify you may be kept indefinitely for research, so deletion reduces but does not fully erase your footprint.

What happens to my Google data when I connect Workspace?

Google Workspace data gets stronger handling than general prompts. Clark accesses only the scopes you approve, applies zero-data-retention and no-training controls, excludes that data from generalized model training, and does not sell it or use it for advertising. OAuth tokens are encrypted at rest and deleted when you disconnect. Still, until you disconnect, an autonomous agent holds standing access to whatever mailbox, calendar, or Drive scope you granted, so scope narrowly.

Is Clark safe for confidential client code?

Only with training turned off and access scoped tightly. Clark records the code it executes and the files it creates or modifies, and by default that activity feeds model improvement. For NDA-covered repositories, opt out of training first, use a disposable workspace rather than your personal credentials, delete the session afterward, and confirm the sub-processor list is acceptable to your client before you let the agent run against their codebase.

Sources

  • Clark Labs privacy policy — https://www.clarkchat.com/privacy (retrieved 2026-07-22; policy last updated 2026-07-13)
  • Clark Labs homepage / product description — https://www.clarkchat.com/ (retrieved 2026-07-22)
  • Clark Agent launch listing — https://www.producthunt.com/products/clark-agent (retrieved 2026-07-22)

Reviewed by Jérémy, founder of AidTaskPro and GreenBudgetHub. Based in central France. Privacy posture sourced from public policies and vendor documentation as of 2026-07-22.

Get Your Free Cybersecurity Checklist

Protect your digital life in 5 minutes. Free checklist + weekly productivity & security tips.

Similar Posts