This website
Almost nothing, by default. carabase.ai sets no marketing cookies, loads no advertising trackers, and runs no client-side behavioural analytics. Netlify, which serves the site, processes ordinary request information — IP address, browser details, requested URL — to deliver and secure it, and may provide us aggregate server-side traffic statistics.
The only personal data this site collects is what you give it:
- Your email address, if you apply for the private alpha. It is stored in Loops, the email service we use to manage applications and send early-access messages. You can unsubscribe from anything we send.
- Your email address and message, if you write to hello@carabase.ai. It sits in our inbox. We read it and reply when we can.
No data is sold, rented, licensed, or traded to any third party, ever, under any circumstance.
The product
Your Carabase and its database live on your hardware. The sources you connect and the memory Carabase builds from them are stored on machines you control. Your local database is never time-limited or remotely disabled, and leaving the service never deletes local data or local features.
When you use a cloud AI
If you point your context at a cloud model, the context selected for that request is processed by the model provider you chose — that provider must see plaintext to answer, and we will not pretend otherwise. Managed inference is routed through an allowlist of endpoints that are eligible for zero-data-retention handling where providers offer it, and we do not store prompt or response bodies.
Carabase’s cloud services
During the private alpha, an optional account and connectivity layer makes your Carabase reachable from your devices, signs you in, and carries encrypted messages when your host is asleep. Its visibility is deliberately narrow:
- Account identity and sign-in state
- Device public keys and coarse device metadata
- Service entitlements
- Usage quantities — model class and cost, never content
- Routing metadata and byte counts
- Short-lived, end-to-end encrypted delivery envelopes
- Your Carabase database or embeddings
- Device-to-device plaintext
- Prompt or response bodies, including in logs
- Provider tokens in decryptable form — connector credentials are delivered as ciphertext only your devices can open
- Your files in the relay or mailbox, other than as ciphertext
Enforced, not aspirational. Content-free logging is tested in our release pipeline: a build fails if sentinel credentials or prompt strings reach logs, traces, or error reports. Hosted data is encrypted at rest, sensitive stores under customer-managed keys, on infrastructure where production data never flows into test environments.
Provider connections (Google, and others)
If you connect Google (Gmail, Calendar, or Drive) or another provider so Carabase can use it as a source, we request the narrowest read-only scope that does that job — never send, write, or broader access than the feature needs. The token we get back is delivered to your device as ciphertext; it is never stored on our servers in a form we or anyone else could read, and it is never used for anything except relaying the connection to your Carabase.
For Google specifically, that means these scopes and nothing else:
- Gmail (
gmail.readonly) — read your mail so it can appear in your timeline and be searched and summarised alongside everything else. - Calendar (
calendar.readonly) — read your events so they sit on the same timeline. - Drive (
drive.readonly) — read documents you point Carabase at. - Basic profile and email address (
openid,email,profile) — identify which Google Account a connection belongs to.
All of them are read-only. Carabase never asks for permission to send, modify, or delete anything in your Google Account, and it asks for a scope when you turn on the feature that needs it rather than all at once. The contents of your mail, calendar and files are fetched by the software on your Mac and stored on your Mac. Our servers do not receive them.
Carabase’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Your Google data is never used to train a model. Not by us, and not by the model providers we route to — managed inference runs under zero-data-retention terms that forbid training on your content. We do not use Google user data for advertising, we do not sell it, and no one at Carabase reads it.
To remove Carabase’s access or delete what it holds, see Deleting your data.
You can revoke Carabase’s access to your Google account at any time from your Google Account’s third-party access settings, independent of anything we do. Disconnecting inside Carabase stops the connection on our side immediately; nothing we hold needs separate deletion, because nothing is retained.
Who we rely on
- NetlifyServes this website and receives ordinary request logs.
- LoopsStores alpha-application emails and sends our messages.
- WorkOSHandles sign-in for the cloud services. Carabase remains the authority for your account, devices, and permissions.
- Google CloudHosts the cloud services (us-central1), encrypted at rest.
- OpenRouterRoutes managed inference to model providers on our allowlist.
- Model providersProcess the context selected for a request when you choose a cloud model.
If this list changes in a way that affects your data, we will update this page and tell alpha users directly.
Your rights
If you are in the EU, UK, California, or any jurisdiction with data-protection law, you have the right to ask what we have on you, correct it, delete it, or object to how we use it. Email hello@carabase.ai and we will handle it within 30 days. There is no form. There is no ticket. Just a human reply.
Changes
If we meaningfully change this policy, we will update the date above and, where practical, notify alpha users directly. We will never shrink your rights without notice.
Contact
Questions, requests, or complaints: hello@carabase.ai.