Privacy Policy
Effective date: [not yet in effect] Last updated: 2026-07-24
1. Who we are and the scope of this policy
This Privacy Policy explains how Carried (pre-incorporation working name) ([corporate form and jurisdiction — to be set on incorporation], with a registered address at [registered address — to be set on incorporation]) ("Carried", "we", "us", or "our") handles personal data in connection with the Carried website at usecarried.com and product application at app.usecarried.com (collectively, the "Service").
Carried is a business-to-business software-as-a-service application. It captures the practical, experience-based knowledge of a customer organization's operators (through voice recordings and transcripts), extracts structured, source-cited "knowledge claims" from that material, and allows the customer's authorized staff to query that knowledge with citations. The Service is currently offered on a pre-General-Availability basis (pilot and beta). It is delivered as a web application and is not distributed through any mobile app store today.
1.1 Two distinct roles: controller and processor
It is important to understand that we handle two different kinds of data in two different legal capacities. We keep these strictly separate, and so does the law.
(a) We act as a controller for account, authentication, website, and operations data.
For a limited set of data that we collect and use for our own purposes, including the email addresses of account holders, authentication data, information about website visitors, and information needed to operate and secure the Service, we are the "controller" under the EU General Data Protection Regulation and the UK GDPR (together, "GDPR"), and we act as a "business" under the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"). This Privacy Policy governs that controller relationship between us and individual account holders and website visitors. Sections 2 through 12 below describe these practices.
(b) We act as a processor (service provider) for customer operational content.
Separately, when a customer organization uses the Service, the operational content that the customer or its authorized users upload to or generate within the Service is the customer's data. This includes, without limitation, uploaded voice recordings and transcripts, diarized speaker segments, extracted knowledge claims, the identities of people named or quoted within that content, the entity and mention graph derived from it, photo attachments, and the queries, answers, and citations produced when staff use the Service.
For that operational content we act only as a "processor" under GDPR, and as a "service provider" under CCPA. We process it solely on the documented instructions of the customer organization, which is the controller (or "business") for that content. Our processing of operational content is governed by a separate Data Processing Agreement ("DPA") between us and the customer organization, not by this Privacy Policy.
If you are an individual whose personal data appears within a customer's operational content (for example, because you were recorded, quoted, named, or photographed by a customer of ours), then the customer organization, not Carried, is the controller of that data and is responsible for it. To exercise your data protection rights in respect of that content, please contact the relevant customer organization directly. If you contact us, we will refer your request to the relevant customer and assist that customer as required under the DPA, but we are generally not permitted to act on operational content except on the customer's instructions.
The remainder of this Privacy Policy concerns only the personal data for which we are the controller, except where it expressly states otherwise.
2. Personal data we collect as controller
As a controller, we collect and process the following limited categories of personal data.
2.1 Account and authentication data
- Email address. We use an email allow-list to control access to the Service. We store the email addresses of authorized account holders.
- One-time login codes. We use one-time passcodes for sign-in. We never store these codes in plaintext. We store only a SHA-256 hash of each code, and each code expires one hour after issuance.
- Demo access codes. For evaluation and demonstration access, we issue time-limited demo codes.
- Session cookie. When you sign in, we set a single authentication cookie named "cb_session". It is an HTTP-only, SameSite=Lax, signed token (a signed JWT). Its lifetime is 14 days for demo sessions and 30 days for full user sessions. See Section 8 for details.
2.2 Technical and security data
- IP address (transient, not stored). We use your IP address transiently, in memory, to rate-limit authentication attempts and protect against abuse. We do not store IP addresses in our database.
2.3 Support and correspondence data
- Support correspondence. If you contact us by email or otherwise for support, sales, or other inquiries, we process the contact details and the contents of that correspondence in order to respond.
2.4 What we do not collect or use
- We use one product-analytics tool, PostHog, for aggregate product analytics such as counts of completed sign-ins, demo access, capture limits, review actions, and report downloads. Only explicit, content-free events are sent. Automatic page views, page leaves, click or input capture, exception capture, person profiles, and session recording are disabled. Browser identity is in memory only; server identifiers are opaque keyed hashes. URL and referrer query strings and fragments are removed before events are sent. PostHog is hosted in the European Union. It receives no emails, demo labels or codes, organization names or identifiers, claim or contradiction identifiers, transcripts, audio, knowledge claims, ask content, error details, or other operational content. We do not use advertising or cross-site tracking software development kits, and we have not deployed Google Analytics, Sentry, or Vercel Analytics.
- We do not set advertising or cross-site tracking cookies.
- We do not sell or share personal information for cross-context behavioral advertising or for any other purpose.
2.5 Operational content is processed as a processor, not collected as controller
For clarity: the operational content described in Section 1.1(b), including recordings, transcripts, extracted knowledge claims, the identities of people named within them, photo attachments, and ask queries and answers, is processed by us only as a processor on the customer's behalf under the DPA. We do not treat that content as data collected for our own purposes, and this Privacy Policy does not govern it. A note on data minimization in respect of that content appears in Section 7.3.
3. How we use controller data, and our legal bases
The table below sets out, for each purpose, the personal data involved and our legal basis under GDPR Article 6. Multiple bases may apply to a single purpose.
| Purpose | Data used | GDPR Article 6 legal basis |
|---|---|---|
| Provide access to the Service; authenticate users; maintain sessions | Email address; one-time login code (hashed); demo code; cb_session cookie | Article 6(1)(b) performance of a contract; and, where there is no contract with the individual, Article 6(1)(f) legitimate interests in operating an access-controlled service |
| Secure the Service; rate-limit and prevent abuse of authentication | IP address (transient); authentication metadata | Article 6(1)(f) legitimate interests in the security and integrity of the Service; Article 6(1)(c) where required to meet a legal obligation |
| Respond to support, sales, and other inquiries | Support and correspondence data | Article 6(1)(b) where you are or are becoming a customer; Article 6(1)(f) legitimate interests in responding to inquiries |
| Maintain an append-only audit log of key actions for accountability and security | Account identifier and action metadata | Article 6(1)(f) legitimate interests in accountability and security; Article 6(1)(c) where required by law |
| Comply with legal obligations and respond to lawful requests | Relevant account data | Article 6(1)(c) compliance with a legal obligation |
| Establish, exercise, or defend legal claims | Relevant account data | Article 6(1)(f) legitimate interests in protecting our rights |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to processing based on legitimate interests as described in Section 9. We do not use controller data for automated decision-making that produces legal or similarly significant effects, and we do not use it for profiling or targeted advertising.
4. Disclosure of personal data, subprocessors, and no sale or sharing
4.1 Subprocessors and service providers
We use a limited set of third-party vendors to operate the Service. These vendors process personal data on our behalf and, for operational content, on the customer's behalf as subprocessors. The categories of vendors we use include:
- database and file storage;
- application hosting;
- speech-to-text transcription;
- automated extraction of knowledge claims;
- text embeddings and answer generation;
- transactional email delivery;
- optional text-to-speech.
We maintain a current list of these vendors, identified by name, on our Subprocessors page. Please refer to that page for the up-to-date roster. We intend to engage, and are in the process of putting in place, written data-protection terms with each vendor that require it to protect personal data and to process it only as instructed; the current per-vendor status is shown on the Subprocessors page and is marked as pending verification where confirmation is still outstanding.
4.2 Other disclosures
We may also disclose personal data: to professional advisers (such as lawyers and auditors) under duties of confidentiality; to authorities or other parties where required by law or legal process, or to protect our rights, users, or the public; and to a successor entity in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
4.3 No sale or sharing of personal information
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under the CCPA. We have not done so in the preceding twelve months.
5. International data transfers
We and our vendors are located in or process data in the United States and potentially other countries. Our database and file storage are hosted in [hosting region — see Subprocessors]. As a result, personal data may be transferred to, stored in, or accessed from countries outside the EEA, the United Kingdom, and your home country, including the United States, which may not provide the same level of data protection as your jurisdiction.
Where we transfer personal data out of the EEA or the United Kingdom to a country that has not been deemed to provide an adequate level of protection, we rely on appropriate safeguards, principally the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable, and we apply supplementary measures where appropriate. You may request information about these safeguards using the contact details in Section 12.
6. Retention
We retain controller personal data only for as long as necessary for the purposes described in this policy, and then delete or anonymize it. Our principal retention periods are:
- One-time login codes: retained only until expiry, one hour after issuance, after which they are no longer valid; only a hash is ever stored.
- Demo access codes and demo sessions: the cb_session cookie for demo access is valid for 14 days; demo codes are time-limited.
- User sessions: the cb_session cookie for full users is valid for 30 days, after which re-authentication is required.
- IP address used for rate-limiting: held transiently in memory only and not stored in our database.
- Account and authentication data (such as allow-listed email addresses): retained while the account is active, and for a reasonable period afterward to meet legal, accounting, security, and dispute-resolution needs, after which it is deleted.
- Support correspondence: retained for as long as needed to handle the matter and for a reasonable period afterward for record-keeping.
- Append-only audit log: retained for as long as needed for security and accountability, subject to applicable law.
Retention of operational content processed as a processor is governed by the DPA and the customer's instructions, not by this section.
7. Security
We take reasonable and appropriate technical and organizational measures to protect personal data. This section describes our security posture honestly and as currently implemented. We do not claim controls or certifications we do not have.
7.1 Measures currently in place
- Encryption in transit. Traffic to and from the Service is protected using TLS.
- Encryption at rest. Personal data stored in our database and file storage is encrypted at rest using the encryption provided by our hosting and storage vendors.
- Access control. Access to production systems and personal data is restricted to authorized personnel who need it to operate the Service.
- Authentication design. We use email allow-listing and one-time login codes; login codes are stored only as SHA-256 hashes and expire after one hour; the session cookie is HTTP-only, SameSite=Lax, and signed.
- Private file storage. Photo attachments within operational content are held in a private storage bucket and served only through short-lived signed URLs.
- Audit logging. We maintain an application-side append-only audit log of key actions to support accountability and security.
7.2 Maturity of our security program
We are an early-stage product and our security program is evolving. We apply technical and organizational measures appropriate to our current stage and continue to strengthen them over time. We do not currently hold a SOC 2 report or comparable third-party security certification. Customers and prospective customers evaluating the Service may request further detail about our current and planned security controls.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7.3 Data minimization: raw audio is not retained
As a data-minimization measure, we do not persist raw audio. When a recording is processed, the audio is streamed to our transcription vendor for transcription, and only the resulting transcript is stored; we do not keep the underlying audio file. Our transcription vendor's own handling and retention of the audio are described on our Subprocessors page.
8. Cookies
The Service uses a single cookie: "cb_session". It is strictly necessary for authentication; it keeps you signed in and is required for the Service to function. It is an HTTP-only, SameSite=Lax, signed token, with a lifetime of 14 days for demo sessions and 30 days for full user sessions.
Because cb_session is strictly necessary for a service you have requested, no cookie consent banner is legally required for it under the EU ePrivacy rules or comparable laws. Our product analytics (PostHog) are configured cookieless and store nothing on your device, so they set no analytics cookies. We do not use advertising cookies or cross-site tracking cookies.
If in the future we introduce non-essential cookies, or expand analytics or tracking technologies beyond the cookieless product analytics described above, we will update this policy and, where required by law, obtain your consent before setting such cookies.
9. Your rights: EU/EEA and United Kingdom
If you are in the EEA or the United Kingdom, and in respect of personal data for which we are the controller, you have the following rights under GDPR, subject to conditions and exceptions in the law:
- Right of access: to obtain confirmation of whether we process your personal data and a copy of it.
- Right to rectification: to have inaccurate personal data corrected and incomplete data completed.
- Right to erasure: to have your personal data deleted in certain circumstances.
- Right to restriction: to restrict our processing in certain circumstances.
- Right to data portability: to receive certain data in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
- Right to object: to object to processing based on our legitimate interests, on grounds relating to your particular situation. We do not engage in direct marketing of the Service to individuals, but you may object to any such processing at any time.
- Right to withdraw consent: where we rely on consent, you may withdraw it at any time, without affecting the lawfulness of processing before withdrawal.
- Right to lodge a complaint: with your local data protection supervisory authority. In the United Kingdom, that authority is the Information Commissioner's Office. We would, however, appreciate the chance to address your concerns first.
To exercise these rights, contact us using the details in Section 12. Please note that self-service export and deletion tools are not available today; rights requests are handled manually on a request basis. We will respond within the time limits required by law. If your request concerns operational content for which we are a processor, please see Section 1.1; we will refer such requests to the relevant customer organization.
10. Your rights: United States and California
If you are a California resident, and in respect of personal data for which we are a "business", you have the following rights under the CCPA, subject to verification and to exceptions in the law:
- Right to know: to request the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of recipients.
- Right to delete: to request deletion of personal information we have collected from you, subject to exceptions.
- Right to correct: to request correction of inaccurate personal information.
- Right to opt out of sale or sharing: the CCPA gives you the right to opt out of the sale or sharing of personal information. As stated in Section 4.3, we do not sell or share personal information, so there is nothing to opt out of; we will honor any opt-out preference signals we are required to recognize.
- Right to non-discrimination: we will not discriminate against you for exercising any of your rights.
To exercise these rights, contact us using the details in Section 12. You may use an authorized agent where the law permits, subject to verification. We will verify your request by confirming control of the email address associated with the relevant account, or by other reasonable means. As noted above, requests are handled manually on a request basis today; we do not yet offer self-service export or deletion tools. If your request concerns operational content for which we act as a service provider, we will direct it to the relevant customer business, which is responsible for that content.
Residents of other US states with applicable privacy laws may have similar rights; we will honor rights granted to you by applicable law. Please contact us to make a request.
11. Children
The Service is a business tool intended for use by businesses and their authorized adult staff. It is not directed to children, and we do not knowingly collect personal data from children as defined by applicable law (for example, under 16 under the GDPR, subject to member-state variation, and under 13 under the US COPPA). If you believe a child has provided us with personal data as controller data, please contact us and we will take appropriate steps to delete it. Where a child's personal data may appear within a customer's operational content, the customer organization is the controller and is responsible for the lawful basis for that processing.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate or required by law, provide additional notice (for example, by email or a notice in the Service). Your continued use of the Service after an update takes effect constitutes acceptance of the revised policy, to the extent permitted by law.
13. Contact us
For privacy questions, or to exercise your rights as described above, contact:
- Privacy inquiries and rights requests: hello@usecarried.com
- Legal notices: hello@usecarried.com
- Data Protection Officer or EU/UK representative (Article 27): [data protection contact — to be appointed]
- Entity: Carried (pre-incorporation working name), [corporate form and jurisdiction — to be set on incorporation]
- Registered address: [registered address — to be set on incorporation]
This Privacy Policy is governed by [governing law — to be set], without prejudice to any mandatory data protection rights you have under the law of your country of residence.