Carabase Private alpha
Privacy

What we collect. What we never hold.

The whole policy, in plain language.

Last updated 31 August 2026

This website

Almost nothing, by default. carabase.ai sets no marketing cookies, loads no advertising trackers, and runs no client-side behavioural analytics. Netlify, which serves the site, processes ordinary request information — IP address, browser details, requested URL — to deliver and secure it, and may provide us aggregate server-side traffic statistics.

The only personal data this site collects is what you give it:

No data is sold, rented, licensed, or traded to any third party, ever, under any circumstance.

The product

Your Carabase and its database live on your hardware. The sources you connect and the memory Carabase builds from them are stored on machines you control. Your local database is never time-limited or remotely disabled, and leaving the service never deletes local data or local features.

When you use a cloud AI

If you point your context at a cloud model, the context selected for that request is processed by the model provider you chose — that provider must see plaintext to answer, and we will not pretend otherwise. Managed inference is routed through an allowlist of endpoints that are eligible for zero-data-retention handling where providers offer it, and we do not store prompt or response bodies.

Carabase’s cloud services

During the private alpha, an optional account and connectivity layer makes your Carabase reachable from your devices, signs you in, and carries encrypted messages when your host is asleep. Its visibility is deliberately narrow:

The cloud may hold
  • Account identity and sign-in state
  • Device public keys and coarse device metadata
  • Service entitlements
  • Usage quantities — model class and cost, never content
  • Routing metadata and byte counts
  • Short-lived, end-to-end encrypted delivery envelopes
The cloud never holds
  • Your Carabase database or embeddings
  • Device-to-device plaintext
  • Prompt or response bodies, including in logs
  • Provider tokens in decryptable form — connector credentials are delivered as ciphertext only your devices can open
  • Your files in the relay or mailbox, other than as ciphertext

Enforced, not aspirational. Content-free logging is tested in our release pipeline: a build fails if sentinel credentials or prompt strings reach logs, traces, or error reports. Hosted data is encrypted at rest, sensitive stores under customer-managed keys, on infrastructure where production data never flows into test environments.

Provider connections (Google, and others)

If you connect Google (Gmail, Calendar, or Drive) or another provider so Carabase can use it as a source, we request the narrowest read-only scope that does that job — never send, write, or broader access than the feature needs. The token we get back is delivered to your device as ciphertext; it is never stored on our servers in a form we or anyone else could read, and it is never used for anything except relaying the connection to your Carabase.

For Google specifically, that means these scopes and nothing else:

All of them are read-only. Carabase never asks for permission to send, modify, or delete anything in your Google Account, and it asks for a scope when you turn on the feature that needs it rather than all at once. The contents of your mail, calendar and files are fetched by the software on your Mac and stored on your Mac. Our servers do not receive them.

Carabase’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Your Google data is never used to train a model. Not by us, and not by the model providers we route to — managed inference runs under zero-data-retention terms that forbid training on your content. We do not use Google user data for advertising, we do not sell it, and no one at Carabase reads it.

To remove Carabase’s access or delete what it holds, see Deleting your data.

You can revoke Carabase’s access to your Google account at any time from your Google Account’s third-party access settings, independent of anything we do. Disconnecting inside Carabase stops the connection on our side immediately; nothing we hold needs separate deletion, because nothing is retained.

Who we rely on

If this list changes in a way that affects your data, we will update this page and tell alpha users directly.

Your rights

If you are in the EU, UK, California, or any jurisdiction with data-protection law, you have the right to ask what we have on you, correct it, delete it, or object to how we use it. Email hello@carabase.ai and we will handle it within 30 days. There is no form. There is no ticket. Just a human reply.

Changes

If we meaningfully change this policy, we will update the date above and, where practical, notify alpha users directly. We will never shrink your rights without notice.

Contact

Questions, requests, or complaints: hello@carabase.ai.