CarveAI
Platform Trust
Legal

Privacy Policy

Last updated: July 21, 2026

This Privacy Policy ("Policy") describes how CarveAI, Inc. ("CarveAI", "we", "us", or "our") collects, uses, discloses, retains, and protects information in connection with the CarveAI platform, applications, websites, and related services (collectively, the "Services"). It also explains the rights and choices available to you with respect to your information.

CarveAI provides an enterprise artificial-intelligence agent workforce platform to business customers ("Customers"). Where CarveAI processes information on behalf of a Customer, that Customer is the "controller" (or equivalent) of the information and CarveAI acts as its "processor" (or equivalent). In such cases, the Customer's own privacy notice and its agreement with CarveAI govern the processing, and this Policy is provided for transparency. Where CarveAI determines the purposes and means of processing (for example, account administration and Service operation), CarveAI acts as a controller.

By accessing or using the Services, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, please do not access or use the Services.

Summary of key points

  • What we collect. Account and profile details; the content you provide to your agents; data from the integrations and systems you connect (including, with your authorization, files on your own computer); and technical usage and audit logs. See Sections 1–2.
  • How we use it. To operate, secure, and support the Services. Your content is processed by large language models to produce agent output, but is never used to train machine-learning models. See Section 3.
  • Where it goes. We use sub-processors — principally Amazon Web Services (whose Amazon Bedrock service hosts the large language models) — and, at your direction, the third-party services you connect. We do not sell your personal information. See Section 5.
  • Who can see it inside your organization. Managers and administrators can view certain activity metrics and reports about the people they oversee, and can share knowledge across your organization. See Sections 6 and 8.
  • Retention. We keep an append-only audit log indefinitely; most other data is kept until you delete it or your account ends. Standard deletion hides data; "private" conversations are erased. See Section 11.
  • Your rights. Depending on your location, you may access, correct, export, or delete your information. See Sections 14 and 15.

Table of contents

  1. What information do we collect?
  2. Google user data and API services
  3. How do we process your information?
  4. What legal bases do we rely on?
  5. When and with whom do we share your information?
  6. Visibility to managers and administrators
  7. Access by CarveAI personnel
  8. The Company Brain and connected organizational sources
  9. Private conversations
  10. Do we use cookies and similar technologies?
  11. How long do we keep your information?
  12. How do we keep your information safe?
  13. Do we transfer information internationally?
  14. What are your privacy rights?
  15. United States privacy rights
  16. Controls for do-not-track features
  17. Do we collect information from minors?
  18. Do we make updates to this Policy?
  19. How can you contact us?
  20. How can you review, update, or delete your data?

1. What information do we collect?

1.1 Information you provide to us

  • Account and profile information — your name, work email address, job title or role, organization, avatar preferences, time zone, and the credentials used to authenticate to the Services.
  • Content and communications — the messages, prompts, instructions, and files you submit to your CarveAI agents; the durable "memory" your agents retain on your behalf; documents you create or upload; feedback you leave; and any information you provide when you contact us for support.
  • Configuration data — settings, roles, expertise profiles, tool and integration preferences, scheduled tasks, and other choices you make in the Services.

1.2 Information collected automatically

  • Log and usage data — Internet Protocol (IP) address, browser and device type, operating system, timestamps, feature usage, token/cost accounting, and diagnostic data. (Our audit log itself does not store IP addresses; IP is used transiently, for example for rate-limiting.)
  • Audit records — an append-only record of actions taken by agents and users within a workspace, retained so your organization can review what its agents did, when, and why. See Section 11.

1.3 Information from the systems and integrations you connect

The Services are designed to act on your behalf across the tools you use. When you connect a system or integration, we access only the data covered by the permissions you grant, and only to perform the tasks you request. Depending on what you connect, this may include:

  • email content and metadata, and calendar events (Google Workspace, Microsoft 365);
  • files and their contents (Google Drive, Box, and — with your explicit authorization — files on your own computer accessed through our optional desktop "Local Files" bridge, within folders you designate);
  • spreadsheet, document, and database content you ask an agent to work with (Google Sheets, Excel, and read-only queries against databases you connect);
  • messages and channel content (Slack), pages and databases (Notion), and repository content, issues, and pull requests (GitHub);
  • voice recordings, transcripts, and notes, where you connect a supported source; and
  • content the agent reads from public web pages when performing a task or a web search.

Section 2 describes our handling of Google user data specifically. Section 8 describes the organization-wide "Company Brain."

2. Google user data and API services

If you connect your Google account, CarveAI requests the following authorization scopes and uses the associated data only as described:

PermissionHow we use it
Gmail — read, compose, send, and modify labels (gmail.modify) Your agent reads and organizes the email you ask it to work with, drafts replies, applies labels, and sends messages on your behalf. Sending and other consequential actions require your explicit in-application approval.
Google Calendar (calendar) Your agent reads your availability and creates or updates the events you request.
Google Drive — read-only (drive.readonly) Your agent reads files you ask it to work with. If your administrator connects Drive as an organizational knowledge source, files are read to build your organization's internal knowledge base. CarveAI does not modify or delete your Drive files.
Google Sheets (spreadsheets) Your agent reads and updates the spreadsheets you ask it to work with.

CarveAI's use and transfer of information received from Google APIs to any other application will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In furtherance of the commitments above:

  • We use Google user data solely to provide and improve the user-facing features described in the table above.
  • We do not use Google user data for advertising, and we do not sell it.
  • We do not use Google user data to develop, improve, or train generalized or non-personalized artificial-intelligence or machine-learning models.
  • Human access to Google user data is limited as described in Section 7.
  • You may disconnect Google at any time in the Services' settings, or revoke CarveAI's access directly through your Google Account permissions page.

3. How do we process your information?

We process your information to: provide and operate the Services (run your agents, maintain their memory, and carry out the tasks you request); generate agent output using large language models; secure the Services and prevent abuse; provide support and communicate with you; maintain audit records and comply with law; and improve the Services in aggregate. We do not use your content to train machine-learning models, whether ours or those of our providers. To generate output, your prompts and the content in context are sent to our model-hosting sub-processor (see Section 5).

4. What legal bases do we rely on?

If you are located in the European Economic Area, the United Kingdom, or a jurisdiction with comparable law, we process personal data on the following legal bases: (a) performance of a contract; (b) our legitimate interests in operating, securing, and improving the Services, where not overridden by your rights; (c) your consent, where required (which you may withdraw at any time); and (d) compliance with a legal obligation. Where CarveAI processes personal data on behalf of a Customer, the Customer is responsible for establishing the applicable legal basis.

5. When and with whom do we share your information?

We do not sell your personal information and we do not share it with third parties for their own marketing purposes. We disclose information only as follows.

5.1 Sub-processors

We share information with the service providers that operate the Services, each bound by contract to process it only on our instructions and to protect it. Our principal sub-processors are:

Sub-processorFunctionData involved
Amazon Web Services (including Amazon Bedrock)Cloud hosting, storage, and the large language models that generate agent output and process memoryPrompts, memory, files and messages in context, and stored data
AnthropicLarge language models (used directly only where a Customer supplies its own Anthropic key or selects the direct Anthropic option)Prompts and context, when that option is used
Voyage AIText embeddings and reranking for search and retrievalText of memory, documents, and queries
Brave SearchWeb search, when an agent performs a searchSearch queries (which may include context you provided)
ResendSending outbound and transactional/login emailRecipient addresses and message content
WorkOSEnterprise single sign-on, where your organization uses itAuthentication identity (name, email, identity-provider data)
jsDelivr (CDN)Delivery of front-end JavaScript libraries to your browserYour browser's IP address and request metadata (no application content)

The large language models we use are operated within Amazon Bedrock and include models provided by Anthropic (Claude) and by Amazon (for certain background processing such as summaries and text extraction). Search and retrieval use a vector database (Qdrant); depending on our deployment it is operated within our Amazon Web Services environment or is provided to us as a managed service, in which case that provider is also a sub-processor that receives the text of your memory and queries. We maintain a current list of sub-processors and will provide it on request; material changes will be reflected here.

5.2 Other disclosures

  • Within your organization. Content may be visible to other authorized members of your workspace as described in Sections 6 and 8.
  • At your direction. We share information with the third-party services you connect, to provide the features you request.
  • Legal and safety. We may disclose information where required by law or valid legal process, or where necessary to protect the rights, property, or safety of CarveAI, our Customers, or others.
  • Business transfers. Information may be transferred as part of a merger, acquisition, financing, or sale of assets, subject to this Policy.

6. Visibility to managers and administrators

CarveAI is an organizational tool. Depending on your organization's configuration and your role, the following information about you may be visible to your managers, workspace administrators, or organization owners:

  • Activity metrics. Aggregate measures of your use of the Services — such as the number of interactions, token and cost usage, activity trends, the volume of memory your agent has created, and the time you take to respond to approval requests — are available to managers who oversee you (a manager typically sees their direct reports; owners and administrators can see the whole organization). These metrics reflect how much activity occurred, not the content of your conversations.
  • Reports. A manager may request a report from you and may author reports about you. When you complete a requested report, you can review and edit it before it is sent. If a request that permits an AI-drafted summary is not completed by its deadline, the Services may automatically generate that report from your activity data and deliver it to the requesting manager without further review by you; auto-generated reports are labeled as such. Reports draw on activity data (such as session titles and interaction counts), not the full content of your conversations; note that the title of a non-private conversation may include a short preview of your first message.
  • Organization structure. Your name, role, and reporting relationships may be visible to members of your organization through the org chart.
  • Colleague discovery ("Ask the Office"). If you complete an expertise profile, it becomes discoverable by colleagues in your organization. A colleague may also request access to specific knowledge held by your agent; such requests require your approval before any content is shared, and the requester must in turn accept the delivery before it becomes usable.

Managers and administrators cannot read the content of your conversations through these features, and they cannot read your "private" conversations at all (see Section 9). Metric views are not separately notified to the individuals measured.

7. Access by CarveAI personnel

Authorized CarveAI personnel may access your data, including content and data received from connected integrations, where necessary to operate, maintain, support, and secure the Services — for example, to investigate a support request or a security or reliability issue, to comply with law, or where the data has been aggregated or de-identified. Such access is limited to what is necessary and is subject to internal controls and logging. We do not use this access to read your content for any purpose unrelated to providing and protecting the Services, and, consistent with Section 2, we do not permit personnel to use Google user data except as that section allows.

8. The Company Brain and connected organizational sources

Your organization's administrators may enable a shared organizational knowledge base (the "Company Brain") and connect organizational sources to it — which may include Google Drive, Slack, Notion, Box, GitHub, and specified websites. Content from those sources is read ("crawled"), processed into facts and passages, and made retrievable to agents across your organization to answer employees' questions. This processing is configured by your organization, and what is ingested and who can retrieve it are governed by your organization's settings and its agreement with CarveAI. Queries made against the Company Brain are recorded in the audit log (see Sections 9 and 11).

9. Private conversations

You may mark a conversation as "private" at creation. A private conversation is designed to leave no durable trace: no facts are written to memory from it, and when it is closed (or after a period of inactivity) its transcript, feedback, and associated working state are permanently deleted, leaving only a contentless record that a private session existed. Managers, administrators, and CarveAI personnel cannot read the content of a private conversation.

One exception you should know about: if, during a private conversation, you query the Company Brain (Section 8), the text of that query (up to a short length limit) is recorded in the append-only audit log and is retained there even after the private conversation is deleted. Do not enter information into a Company Brain query that you do not want retained.

10. Do we use cookies and similar technologies?

We use strictly necessary cookies and similar browser-storage technologies (such as local storage) to authenticate you, maintain your session, remember your preferences, and keep the Services secure. We do not use advertising cookies, and we do not serve third-party targeted advertising. Your browser also loads certain front-end libraries from a content-delivery network (see jsDelivr in Section 5), which necessarily receives your browser's IP address and request metadata, but no application content. Because the cookies we set are necessary to operate the Services, disabling them may prevent parts of the Services from functioning.

11. How long do we keep your information?

  • Audit log. We maintain an append-only audit log of activity in the Services. It is retained indefinitely for the life of your organization's account, cannot be altered or deleted, and generally records metadata (who did what, when) rather than content. It does not store IP addresses. Certain entries retain limited text, such as the text of a Company Brain query (see Section 9).
  • Content and memory. Conversation transcripts, memory, documents, and similar content are retained until you delete them or your organization's account ends. We do not apply an automatic time-based deletion window to this content.
  • Deletion is generally "soft." When you delete memory, a document, or a conversation, we typically mark it deleted and remove it from view while retaining it in our systems (including so that changes can be audited or reversed). Superseded or policy-blocked memory is likewise retained in a restricted state rather than erased.
  • Private conversations are the exception and are permanently erased as described in Section 9.
  • Connected-integration credentials are deleted when you disconnect the integration.
  • Time-limited items. Certain items expire automatically — for example, pending cross-user memory requests (after 7 days), pending personal-memory approvals (after 14 days), and pending approval prompts and short-lived caches (hours to days).
  • Account closure. When a user is deprovisioned, their agent is archived and its memory may be retained for your organization; when an organization's account is terminated, associated data is deleted or de-identified except where we are required to retain it.

You or your administrator may request deletion at any time (see Section 20). We will honor applicable requests except where we are required or permitted by law to retain the information, and note that append-only audit records may persist.

12. How do we keep your information safe?

  • Encryption of data in transit (TLS) and at rest.
  • Credentials for connected integrations are encrypted with authenticated encryption using per-record keys, and the master key is not stored in our application database; certain tenant secrets are held in a dedicated secrets-management service.
  • Logical isolation of each Customer's workspace from others at the database layer.
  • An append-only audit log of agent actions and data access.
  • A requirement that consequential agent actions (such as sending email, sharing memory, writing to external systems, or running a command on your computer) receive human approval within the Services by default (see our Terms of Service).

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your credentials.

13. Do we transfer information internationally?

We operate and store information in the United States. If you access the Services from outside the United States, your information will be transferred to, stored, and processed in the United States and other jurisdictions where we or our sub-processors operate. Where such transfers are subject to European or United Kingdom data-protection law, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and the UK Addendum).

14. What are your privacy rights?

Depending on your location, you may have rights to access, correct, erase, restrict or object to the processing of, or port your personal information, and — where processing is based on consent — to withdraw consent. You may also lodge a complaint with your local data-protection authority. Because CarveAI often processes personal data on behalf of a Customer, we may direct your request to the relevant Customer or ask you to submit it through your organization's administrator. To exercise your rights, contact us using the details in Section 19.

15. United States privacy rights

If you are a resident of California or another U.S. state with a comprehensive privacy law, you may have the right to confirm whether we process your personal information; to access, correct, or delete it; to obtain a portable copy; and to be free from unlawful discrimination for exercising these rights. We do not sell personal information, and we do not "share" it for cross-context behavioral advertising. To exercise these rights, contact us using the details in Section 19. You may use an authorized agent, subject to verification.

16. Controls for do-not-track features

Because no uniform standard for Do-Not-Track ("DNT") signals has been finalized, we do not currently respond to DNT browser signals. If a standard is adopted that we must follow, we will update this Policy accordingly.

17. Do we collect information from minors?

The Services are intended for use by businesses and their personnel and are not directed to individuals under the age of 18 (or under 13 in the United States). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact us and we will take appropriate steps to delete it.

18. Do we make updates to this Policy?

We may update this Policy from time to time. The "Last updated" date at the top indicates when it was most recently revised. If we make material changes, we will provide notice appropriate to the circumstances, such as by posting the updated Policy here or notifying active Customers. Your continued use of the Services after an update takes effect constitutes acceptance of the revised Policy.

19. How can you contact us?

If you have questions or comments about this Policy or our privacy practices, contact us at demo@carveaiagent.com, or by mail to CarveAI, Inc., Attn: Privacy.

20. How can you review, update, or delete your data?

You may review or update much of your information directly in the Services' settings. To request access to, correction of, or deletion of personal information we hold about you, contact us at demo@carveaiagent.com. We will honor applicable requests and respond within the time required by law, except where we are required or permitted to retain the information. If your information is controlled by your organization, we may refer your request to that organization.

© CarveAI, Inc. · Carved with intent.
PrivacyTermsDPA