Carae Privacy Policy
Effective: 17 May 2026
Version: privacy-v1
Data Controller: Learn By Numbers Limited, Unit 26J, Building 6500, Cork Airport Business Park, Cork, T12 E6RY, Ireland
DPO contact: [email protected]
TL;DR (this section is informational; the legally binding text is below)
- We host all your data in Frankfurt, Germany (Hetzner). No US data transfers.
- Your messages and memories are isolated per-user in our database via Postgres row-level security.
- We do not sell your data, ever.
- No one at Carae can read your messages or memories. Our staff have no access to the production database; our internal admin tools only ever show counts and account status, never the content of your conversations. Your stored message and memory content are additionally encrypted at rest with per-user keys, so they cannot be read from the database or from backups.
- LLM providers (Anthropic, OpenAI, Groq, Google) see your messages as plaintext when we send them for processing. We have Data Processing Agreements with each provider.
- You can export everything we have on you at any time, and delete your account in 24h.
- We use Google Analytics to understand aggregate usage; we do not use advertising pixels or behaviour-tracking SDKs, and we never sell your data.
1. Who we are
Carae is operated by Learn By Numbers Limited, a private limited company registered in Ireland. We are the Data Controller for the personal data described in this Policy. Our DPO can be reached at [email protected].
We are EU-headquartered, EU-hosted, and EU-owned. We do not transfer your personal data outside the European Economic Area except where strictly necessary to operate the Service (see Section 6 on LLM providers).
2. What personal data we collect
2.1 Data you provide
We collect the data below to make Carae work, but no one at Carae can read your messages or memories. Our staff have no access to the database, and our internal admin tools only ever show counts and account status, never the content of your conversations.
- Account data: your name, email address, phone number (if you sign up via Telegram), country, timezone, and — only if you choose to tell Carae where you live — a home city you name (used for weather-style Skills such as Daily Weather and Pollen Alert).
- Messages: the content of every message you send to the Service, including text, voice transcripts, photos, and document attachments. Message content is encrypted at rest (see Section 4.2).
- Long-term memories: facts the Service extracts from your conversations and stores so it remembers them across sessions (e.g. "user's preferred music genre is pop", "user commutes by train").
- Skills configuration: which Skills you have installed and any per-Skill settings.
- Integration credentials: OAuth tokens for connected services (Calendar, Notion, etc.). These are encrypted at rest with AES-256-GCM envelope encryption (see Section 4).
- Connected Google data (if you connect Gmail, Google Calendar, or YouTube): calendar events (titles, times, attendees) that we read to answer you and to power briefs and reminders, and events we create or update when you ask; Gmail messages that we read for inbox triage, summaries, and reply context, drafts we create for you, and emails we send only after you confirm each message by tapping Send on a preview showing the exact recipient, subject, and body; your YouTube subscriptions and the results of searches you request. See Section 6.4 for our Google Limited Use commitments.
2.2 Data we collect automatically
- Service logs: request timestamps, error traces, IP address (truncated to /24 for IPv4, /48 for IPv6), and the version of the bot/app you used. Retained for 30 days.
- Audit logs: records of significant account events (signup, plan change, Skill install/uninstall, integration connect/disconnect, payment events, deletion requests) for fraud prevention and your own data-export requests. Retained for 3 years or as long as your account exists, whichever is shorter.
- Stripe billing data: Stripe processes your payment information and shares with us only the limited subset needed for invoicing (last 4 digits of card, billing country, subscription status). Stripe is the data controller for the full card details; we are not.
2.3 Data we do NOT collect
- Web-tracking pixels, ad-network identifiers, third-party cookies, or fingerprinting
- Your contacts or address book unless you explicitly connect Gmail/Calendar
- Precise location data (no GPS; we use your timezone and, only if you tell us one, a home city you name yourself)
- Audio recordings of voice mode beyond the transcript and a 30-day debug retention
3. Why we use your data (legal bases under GDPR Article 6)
| Purpose | Legal basis | Examples |
|---|---|---|
| Operating the Service | Contract performance (Art. 6(1)(b)) | Receiving messages, generating replies, running scheduled jobs, executing Skill actions |
| Long-term assistant memory | Contract performance + your consent during onboarding | Storing facts you've told us so the assistant remembers across sessions |
| Billing | Contract performance | Charging your subscription, handling refunds |
| Fraud prevention and abuse detection | Legitimate interest (Art. 6(1)(f)) | Audit logs, rate-limit enforcement, integrity checks |
| Customer support | Contract performance + legitimate interest | Investigating fault reports you submit |
| Legal compliance | Legal obligation (Art. 6(1)(c)) | Responding to lawful requests, tax records |
We do not use your messages or memories for marketing, ad targeting, or to train any model.
4. How we secure your data
4.1 Database isolation
Your data lives in a Postgres database in Frankfurt with row-level security enforced at the database engine level. Application code can only read or write rows belonging to the authenticated user; cross-user reads are technically blocked, not just policy.
4.2 Encryption at rest
Tokens for connected services (Notion, Microsoft, etc.) are encrypted using a per-user data-encryption key (DEK) wrapped by a key-encryption key (KEK). The KEK is held in a separate secure store. Tokens are never logged, displayed, or transmitted in plaintext after the initial OAuth flow.
The content of your messages is encrypted the same way. Each message is encrypted with a per-user DEK wrapped by the KEK, and the plaintext of your message content is not stored in our database. As a result, no one with direct access to the production database or to backups can read your stored message content. This is not end-to-end encryption: to generate a reply, our services decrypt your messages in memory and send them to our LLM providers for processing (Section 6), which receive your message content in plaintext under Data Processing Agreements. Your long-term memories are isolated per user and, like your message content, are encrypted at rest with the same per-user DEK wrapped by the KEK, so no one with direct database or backup access can read your stored memory content either.
4.3 Operator access
To deliver the Service we sometimes need to investigate problems. This means:
Production database access is restricted. Our deployed services operate on your data to run the AI, but our staff have no direct access to the production database. There is no routine path for a human at Carae to read your messages or memories.
Our internal admin tools show counts and account status only, never the content of your conversations. When we investigate a fault you've reported, we work from metadata, error traces, and aggregate counts, not from reading your messages.
Rare exceptions. The only circumstances in which we may access data beyond counts and account status are when we are responding to a lawful request from a competent authority, or responding to a security incident. Any such access is logged.
Encryption at rest, not end-to-end. Your stored message content is encrypted at rest with per-user keys (Section 4.2), so no human at Carae, and no one with database or backup access, can read it from storage. This is not end-to-end encryption: a personal AI assistant has to work on the content of your messages, so to answer you Carae decrypts them in memory and sends them to our AI providers for processing (Section 6). The providers receive your messages in plaintext at the moment of processing; encryption at rest protects your stored content, not the processing path.
4.4 Backups
We take daily automated backups of our server, retained on a rolling seven-day basis in Hetzner's Frankfurt region. Backup access is restricted. Because your message and memory content are encrypted at rest (Section 4.2), these backups contain only the encrypted form of that content, not plaintext.
5. How long we keep your data
| Category | Retention |
|---|---|
| Messages | While your account is active. Messages older than 90 days are deleted once their key details have been saved to your long-term memories, except for your most recent conversation, which is always kept so Carae can follow the thread. |
| Long-term memories | While your account is active. Deleted within 24 hours of deletion. |
| Integration tokens | Until you disconnect the integration or delete your account. |
| Service logs (technical) | 30 days |
| Audit logs (security) | 3 years |
| Billing records | 7 years (Irish tax-law minimum) |
| Backups | 7 days |
deletions_log (no PII) |
Indefinite, for fraud prevention |
After account deletion: messages, memories, integration tokens, scheduled jobs, and Skill configurations are removed within 24 hours. Audit logs and billing records are retained for the legal periods above; backups age out within 7 days.
6. Who we share your data with
We share the minimum necessary personal data with:
6.1 Large language model providers (sub-processors)
When you send the Service a message, we send the message content and recent conversation context to one of our LLM providers for processing. Providers used:
- Anthropic (Claude models) — US-headquartered, with EU data-processing options. Their API does not retain customer prompts beyond a 30-day operational retention window unless we opt in (we do not).
- OpenAI (GPT models) — US-headquartered, EU residency tier where available.
- Groq (open-weight models, currently GPT-OSS) — US-headquartered, used as a fast fallback for short prompts.
- Google (Gemini models) — US-headquartered, EU options where available.
Each provider's standard Data Processing Agreement applies to our use of their API. These DPAs are incorporated by reference in the providers' commercial terms (which we accept by being a paying customer of their API) and bind them to act as data processors under GDPR Article 28. They commit not to use API content for training of public models. We have no influence over their security beyond what those contracts grant.
Links to the applicable DPAs:
- Anthropic: https://www.anthropic.com/legal/data-processing-addendum
- OpenAI: https://openai.com/policies/data-processing-addendum
- Groq: https://console.groq.com/docs/legal/customer-data-processing-addendum
- Google Cloud: https://cloud.google.com/terms/data-processing-addendum
6.2 Infrastructure providers (sub-processors)
- Hetzner Online GmbH — Frankfurt, Germany. Hosts Postgres, Redis, application servers, backups.
- Stripe Payments Europe — Dublin, Ireland. Processes subscription payments.
- Cloudflare — DNS only. No content proxying.
- Resend — transactional email (signup confirmations, deletion confirmations).
6.3 Lawful requests
We will respond to lawful requests from Irish or EU authorities. We will challenge requests we believe are overbroad or unlawful, and will inform affected users where the law permits. We have not received any government data requests as of the date below.
We do not voluntarily share data with any third party other than the sub-processors above.
6.4 Google user data: Limited Use
If you connect a Google integration (Gmail, Google Calendar, or YouTube), our handling of Google user data is additionally governed by the Google API Services User Data Policy, including its Limited Use requirements:
Carae's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Carae stores Gmail message content solely to provide user-facing assistant features (inbox triage, summaries, draft assistance, user-confirmed email sending, and your personal assistant memory) that are prominent in the app's interface. Every email send is confirmed by you: Carae shows a preview of the exact recipient, subject, and body with Send and Cancel buttons, and the email is sent only when you tap Send; nothing is ever sent silently or automatically. Carae does not transfer this data to third parties except as necessary to provide these features, does not use it for advertising, does not allow humans to read it except with your explicit consent or for security or legal reasons, and does not retain or use Google user data to develop, improve, or train non-personalized (generalized) AI or machine-learning models.
In plain terms, per integration: Google Calendar: we read your schedule (events, times, attendees) to answer your questions and power briefs and reminders, and, when you ask, we create or update events. Gmail: we read messages for triage, summaries, and reply context; we create drafts on your behalf; we send email only after you tap Send on a preview showing the exact recipient, subject, and body, never silently or automatically. YouTube: we read your subscriptions and run the searches you request; we never modify anything on your YouTube account.
7. International transfers
Service infrastructure is hosted in the EU (Frankfurt, Dublin). However, when your messages are processed by an LLM provider headquartered in the US, the request transits to the provider's API endpoint, which may be served from US infrastructure depending on the provider's region selection.
We rely on:
- The EU-US Data Privacy Framework, where the provider is certified;
- Standard Contractual Clauses (Module 2: Controller to Processor) for any provider that is not DPF-certified;
- Article 49(1)(b) GDPR (necessary for performance of a contract) as the secondary basis where DPF/SCC do not cover an edge case.
We are tracking the EU AI Act and will move to EU-resident inference where commercially feasible (Mistral, Aleph Alpha, etc.).
8. Your rights under GDPR
You have the right to:
- Access the data we hold on you. Download your data from your dashboard settings, or email [email protected].
- Rectify incorrect data. Update your details in your dashboard settings, or email us.
- Erase ("right to be forgotten"). Delete your account from your dashboard settings. We will action within 24 hours.
- Restrict processing in certain circumstances. Email [email protected].
- Portability — receive your data in a machine-readable format (JSON). Download it from your dashboard settings.
- Object to processing based on legitimate interests. Email [email protected].
- Withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
- Lodge a complaint with the Irish Data Protection Commission (www.dataprotection.ie) or the supervisory authority of your country of habitual residence.
We aim to respond to all rights requests within 30 days.
9. Children
The Service is not directed at, and we do not knowingly accept users under, the age of 18. If we become aware of an account belonging to a minor, we will delete it.
10. Changes
We may update this Policy. Material changes will be notified to active users 30 days before they take effect. The version in force at any time is identified by privacy-vN and visible at carae.ai/privacy.
11. Contact
- Privacy and data-protection requests: [email protected]
- General contact: [email protected]
- Postal: Learn By Numbers Limited, Unit 26J, Building 6500, Cork Airport Business Park, Cork, T12 E6RY, Ireland
End of Privacy Policy.