Privacy Policy
Plain-English summary · last updated April 2026
This page is a friendly summary. The legally-binding version is at carae.ai/privacy/full.
What is Carae?
Carae is a personal AI assistant that operates through Telegram and WhatsApp. You sign up on the web, connect your accounts, and then interact with Carae through your messaging app. We're an EU-based product and we take your privacy seriously: it's designed in, not bolted on.
What data we collect (and why we can't read it)
We collect the data below to make Carae work, but no one at Carae can read your messages or memories. Our staff have no access to the database, and our internal admin tools only ever show counts and account status, never the content of your conversations.
- Account data: Your name, email address, timezone, and country. Provided at signup.
- Conversation history: Every message you send to Carae and every reply we send back. Retained for 90 days, then automatically deleted.
- Long-term memories: Key facts extracted from conversations (e.g. your preferred working hours, names you mention frequently). You can view and delete these at any time.
- Calendar data: If you connect Google Calendar, we read your event titles, times, and attendees to answer your questions and power your morning brief and reminders, and, when you ask, we create or update events on your calendar.
- Email data: If you connect Gmail, we read your messages for inbox triage, summaries, and reply context. Carae can draft emails for you, and sends an email only after you tap Send on a preview showing the exact recipient, subject, and body; nothing is ever sent silently or automatically.
- Payment data: Handled entirely by Stripe. We never see or store your card number.
- Telegram data: Your Telegram user ID and chat ID, used to route messages to your account.
- Community skill submissions (The Forge): If you publish a skill to The Forge, the skill's name, description, and instruction content are stored on our servers and reviewed by Carae before publication. This content is associated with your account.
What we don't collect
- We don't use advertising trackers, social-network pixels, or marketing cookies.
- We use Google Analytics 4 for anonymous site analytics, only if you consent via the cookie banner. It is off by default.
- We don't sell your data. Ever.
- We don't use your conversations to train AI models.
- We don't build advertising profiles.
Third parties we use
Here is every external service your data touches:
Google user data (Limited Use)
Carae's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not use data obtained through Google APIs to develop, improve, or train generalized AI and/or machine learning models. Google data is used only to provide the assistant features you see in the app; the full commitments are in the legal Privacy Policy.
How we store your data
All your data is stored on Hetzner Cloud in Frankfurt, Germany. Hetzner is a German company subject to EU law. Data never leaves the EU infrastructure.
OAuth tokens (your tool integration access credentials) are encrypted at rest using AES-256 encryption. The encryption keys are stored separately from the data. Tokens are never logged or included in error messages.
Your message content is also encrypted at rest. Each message is stored using per-user AES-256-GCM encryption, with the keys held separately from the data, so our staff and anyone with direct database or backup access cannot read your stored messages. This is not end-to-end encryption: to answer you, Carae decrypts your messages in memory and sends them to our AI providers for processing (see "AI and your data" below). Your long-term memories use the same per-user isolation, access controls, and encryption at rest with per-user keys.
Your database rows are protected by PostgreSQL Row Level Security: the platform is designed so that one user's data is inaccessible to another user's application queries, enforced at the database engine level. (We never sell your data, never use it for advertising, and never train AI models on it. Every operator-access event is audit-logged. The full details are in the legal Privacy Policy.)
AI and your data
We use the following AI providers to process your messages:
- Anthropic (Claude): for complex queries and drafting
- OpenAI: for embeddings (memory system) and fallback responses
- Groq: for fast, cheap routine tasks
- Google (Imagen & Lyria): for image and music generation (Image Studio / Music Studio)
All four are accessed via commercial API tiers. None of them train on API data.Your conversations are not used to train any AI model.
Retention and deletion
- Conversation messages: Deleted after 90 days automatically.
- Long-term memories: Kept until you delete them or close your account.
- Account data: Kept while your account is active. Deleted within 30 days of account closure.
- Payment records: Retained as required by law (7 years for tax purposes, stored only at Stripe, not on our servers).
To delete your account and all data, go to Settings in your dashboard, or email [email protected]. Deletion happens within 24 hours. This is a legal right under GDPR Article 17.
Your rights (GDPR)
You have the right to:
- Access: request a copy of all data we hold about you
- Rectification: correct inaccurate data
- Erasure: delete your account and all data
- Portability: export your data
- Objection: object to processing
To exercise any of these rights, email [email protected] or go to Settings in your dashboard. We'll respond within 30 days.
Contact
Questions about this policy? Email us at [email protected]. We're a small team and we actually respond.