Privacy Notice
Effective date: 28 July 2026
Last updated: 28 July 2026
1. Who operates Carried
Carried is currently a pre-incorporation software project operated by Yauheni Futryn ("Carried", "we", "us", or "our"). Yauheni Futryn is the individual controller for the website, evaluation-access, and correspondence data described in this notice.
Privacy questions and rights requests can be sent to hello@usecarried.com.
This notice applies to usecarried.com, app.usecarried.com, and the current
synthetic-data evaluation service. Carried does not currently accept real client
operational content. A real-data pilot will require separate pilot terms, a Data
Processing Agreement, an agreed subprocessor schedule, and written data-handling
instructions before any client content is loaded.
2. Data collected during the current evaluation
2.1 Website and product analytics
We use PostHog for content-free product analytics. Events may include:
- an event name and timestamp;
- an in-memory anonymous browser identifier or an opaque keyed server identifier;
- bounded referral and campaign categories;
- coarse role, route, action, outcome, and numerical count fields; and
- coarse browser, operating-system, device-type, and language-prefix information.
We remove URLs, referrers, raw user-agent event properties, exact screen and viewport dimensions, full software versions, and location data before browser events are sent. Analytics events contain no transcripts, audio, knowledge claims, questions, answers, emails, demo codes, organization names or identifiers, sensitive source content, or detailed error messages.
PostHog necessarily receives ordinary HTTP connection metadata while receiving a request. The PostHog project is hosted in the European Union, anonymizes IP addresses, disables location enrichment, and does not use session recording, autocapture, person profiles, or persistent browser identifiers.
2.2 Evaluation access and authentication
If evaluation access is provided, we may process:
- an authorized email address;
- a one-time login code, stored only as a SHA-256 hash and valid for one hour;
- a time-limited demo access code; and
- a signed, HTTP-only, SameSite=Lax
cb_sessioncookie that keeps the user authenticated for up to 14 days for demo access or 30 days for full-user access.
2.3 Contact and correspondence
If someone contacts us, we process their contact details and message content to reply, arrange an evaluation, maintain appropriate business records, and protect our legal rights.
2.4 Connection and security information
Hosting, email, and analytics providers receive the technical connection information necessary to deliver and secure their services. Carried may use an IP address transiently in memory for abuse prevention and rate limiting. We do not store IP addresses in the Carried application database.
3. Why the data is used
Where the GDPR applies, we use:
- contract steps or performance to provide requested evaluation access;
- legitimate interests to operate, secure, understand, and improve a useful evaluation service, respond to inquiries, and protect legal rights; and
- legal obligations where processing is required by applicable law.
Our analytics interest is limited to content-free journey and reliability measurement. It does not involve advertising, cross-site tracking, profiling, or automated decisions with legal or similarly significant effects.
4. Service providers and transfers
The current evaluation uses:
- Vercel for website and application hosting;
- PostHog EU Cloud for content-free product analytics;
- Supabase for application database, storage, and authentication support; and
- Resend for transactional email.
These providers process data only for the service functions described above and under their applicable contractual and data-protection terms. Infrastructure may process data in the European Union, the United States, or other provider locations. Where applicable law requires transfer safeguards, we use the provider's applicable contractual transfer mechanism.
The synthetic demonstration may use additional AI and transcription providers, but no real client operational content or analytics content is authorized for those providers during the current evaluation.
We may also disclose information where required by law, to protect the Service or others, to professional advisers under confidentiality obligations, or to a successor entity subject to this notice.
We do not sell personal information or share it for cross-context behavioural advertising.
5. Retention
- One-time login-code hashes expire after one hour.
- Authentication cookies expire after 14 days for demo access or 30 days for full-user access.
- Authorized email and account records are retained while access is active and for a reasonable period afterward for security and record-keeping.
- Correspondence is retained only while needed to handle the matter and maintain appropriate records.
- Product analytics is retained only while reasonably needed to understand the evaluation journey and reliability, with the current PostHog project configured for a maximum of seven years.
We delete or anonymize controller data when it is no longer needed, subject to legal, security, and dispute-related retention requirements.
6. Cookies and device storage
The only cookie used by the Service is the strictly necessary cb_session
authentication cookie described above. PostHog identity is held in memory only
and does not use analytics cookies, local storage, session replay, or advertising
identifiers.
If we introduce non-essential cookies or persistent device storage, we will update this notice and request consent where applicable before using them.
7. Security and current limitations
We use TLS, provider-managed encryption at rest, access controls, private storage, hashed one-time codes, signed HTTP-only session cookies, and application audit logging. Carried is an early-stage evaluation product and does not currently hold a SOC 2 report or comparable third-party certification. No system can guarantee absolute security.
The current evaluation is not authorized for real company confidential information, real personal data, recordings, or operational content. These restrictions materially reduce the data risk while pilot controls are completed.
8. Individual rights
Depending on applicable law, individuals may have rights to access, correct, delete, restrict, or receive certain personal data and to object to processing based on legitimate interests. Where processing relies on consent, consent can be withdrawn without affecting earlier lawful processing.
EEA individuals may complain to their local supervisory authority. US state rights are honoured where applicable. We do not sell or share personal information, so there is no sale or targeted-advertising sharing to opt out of.
Requests can be sent to hello@usecarried.com. We may take reasonable steps to verify the requester.
9. Children
Carried is a business evaluation tool intended for adults and is not directed to children. We do not knowingly collect children's personal data.
10. Changes and incorporation
We may update this notice as the evaluation evolves. Material changes will be identified by a new "Last updated" date and, where appropriate, additional notice.
Carried is not yet incorporated. If an entity is formed and becomes the controller, this notice will be updated with the entity's exact identity and effective date. Incorporation will not reduce rights relating to processing that occurred before the change.