carve / legalTrust, in plain sight
Your informationEdition 2026-09-14

Privacy Policy

Know what stays here. Know what is shared.

September 14, 2026 · Carvify, Inc.

The short version

Carve stores working history on your Mac. Hosted AI features send task context to the provider you select, sometimes through Carve Cloud. Cloud account and usage records are separate from local history.

This summary helps you navigate. The full text below governs.

1. Who this policy covers

Carvify, Inc., a Delaware corporation, operates Carve and Carve Cloud. This policy explains information we process through the app, cloud service, website, and support. It does not govern an independent app you automate or an AI provider you contract with directly. An organization’s separate agreement may govern content we process on its behalf.

2. Notice at collection: information and purposes

Identifiers and account data: email address, account and device identifiers, platform, app version, authentication records, and subscription status. Sources are you, your device, authentication activity, and our payment provider. We use these to sign you in, connect devices, provide entitlements, prevent abuse, and send service notices. A device identifier may later be linked to an account; it is not necessarily anonymous.

Task and screen content: prompts, goals, attachments, selected window images, recognized text, accessibility controls, app or window names, URLs, relevant task history, derived memory, and model responses, depending on the feature and settings. Sources are you, apps you authorize, captured observations, and AI processing. We use this information to answer questions, plan and perform work, retrieve relevant context, and show results. It can include personal or sensitive information about you or other people, such as messages, financial information, health information, or credentials visible on screen.

Commercial and usage data: plan, transaction and subscription identifiers, task identifiers and status, request timestamps, models, token counts, estimated cost, latency, and provider request identifiers. We use these for billing, allowances, reliability, fraud prevention, and cost control. Stripe collects payment and billing details directly; Carve does not receive full card numbers through its checkout integration.

Website, security, and support data: network information such as IP addresses processed by servers, request and security information, correspondence, and diagnostic material you choose to send. We use these to deliver pages, protect the Service, investigate problems, and respond to requests. Avoid sending passwords or unrelated sensitive information to Support. Retention criteria appear in section 6.

3. Local storage and device permissions

Carve maintains local working data, which can include captured observations, procedures, memory, conversations, approvals, receipts, settings, and audit records. Local storage does not mean the same information can never be sent to AI: relevant context may be included when you use a hosted feature.

Screen Recording permits capture of screen content. Accessibility permits reading supported controls and performing inputs such as clicks and typing. Task execution may use the clipboard and your signed-in apps. The scope and available controls depend on the mode. Review the selected windows and stop work before opening sensitive content. Redaction and exclusion controls are imperfect.

Manage capture and retention in Settings, use the app’s local export or delete controls, and revoke operating-system permissions in macOS System Settings. Uninstalling the application does not necessarily remove its data directory, exported files, operating-system backups, cloud account, or subscription. Local deletion and cloud-account deletion are separate.

4. Hosted AI, local models, and training

With Carve Cloud, a request passes through our relay to an AI provider. It may contain screen images, controls, instructions, prompts, and relevant task or memory context. The relay implementation processes request and response content in memory and records usage metadata rather than storing the payload as task history. This is not a promise of zero retention by every infrastructure or model provider.

With your own hosted provider, AI requests go from your Mac to the configured provider rather than through our model relay; account, billing, or entitlement requests may still reach Carve Cloud. With a local model, inference for that feature occurs locally, although other enabled features may use network services.

Carvify does not use relayed task content to train a general-purpose AI model. AI providers process data under the applicable API agreement and account settings. Abuse monitoring, caching, or stateful task features may involve provider retention. A request that asks a provider not to store a response is not a guarantee that all logs or abuse-monitoring records are removed. Review the providers listed in Service Providers and your own provider agreement. Any materially different use of previously collected content will receive the notice and consent required by law.

5. When information is disclosed

We disclose information to service providers as needed for AI inference, hosting, databases, transactional email, payments, and support. The Service Providers page identifies the integrations used by Carve Cloud and links to their information. Providers can have different legal roles; for example, a payment provider may independently process information for fraud prevention and legal obligations.

Actions you authorize can disclose information directly to the apps, recipients, or services involved in your task. Their privacy practices apply to what they receive. We may also disclose information to comply with lawful process, protect rights and security, investigate abuse, or in a merger, financing, acquisition, or similar transaction, subject to applicable safeguards.

Carve’s current app and gateway do not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising. We do not use sensitive personal information to infer personal characteristics for advertising. These statements do not describe independent websites you choose to automate.

Where enabled, Cloudflare provides browser verification and proxies website and API traffic. Browser verification processes technical browser and network signals. Proxied AI requests can include the task context described above. Our application does not log their bodies for fraud analysis.

6. Retention and deletion

Local information: retained according to the applicable feature, capture policy, and your deletion choices. A capture-retention setting does not necessarily expire all conversations, memory, receipts, exports, or audit records.

Relay payloads: not persisted as task content by the relay application; model and infrastructure providers may retain information under their applicable terms and settings.

Cloud account, device, and usage records: retained to operate your account, enforce allowances, resolve billing issues, and protect the Service. Account deletion disables access and initiates cancellation and cleanup. The cleanup process removes account links from usage records and replaces account contact information after required steps complete. Processing may be delayed by a failed external operation and retried. Deletion does not erase every security, transaction, or legally required record.

Authentication data: sign-in codes expire and sessions expire or are revoked under their configured lifetimes. Expiry is not the same as immediate deletion from every store or backup.

Billing, support, legal, and security records: retained as reasonably necessary for the purpose, applicable legal and accounting duties, dispute resolution, and fraud prevention. We consider sensitivity, operational need, contractual obligations, and legal requirements; we do not promise one universal deletion deadline. Provider-held records follow the provider’s applicable schedule. Contact us for information about a particular record or request.

Agreement records: we retain the accepted document versions, server-recorded acceptance time, account and device identifiers, and acceptance method separately from expiring sign-in sessions, as reasonably necessary to establish the agreement and address legal claims. Account deletion does not automatically erase these limited records; you may request review of their retention.

Trial eligibility: we retain a keyed email-derived marker, an account identifier, and limited trial-use records while the account exists. After account deletion, these records are scheduled to expire after 180 days to prevent repeated free-trial claims. They contain no raw email address, card number, or screen content. Expiry cleanup can be delayed; contact support to request review.

7. Choices and privacy requests

Use Settings to change provider and screen-sharing choices and manage local data. Revoking permission stops future authorized access for that permission; it does not undo disclosures or completed actions. Cloud-account deletion is available in the app. To request access, correction, deletion, or a copy of cloud information, contact Support on the Carve legal website with the subject “Privacy request.”

Depending on your location and whether the relevant law applies, you may have rights to know or access personal information, correct it, delete it, obtain a portable copy, restrict or object to processing, withdraw consent, opt out of covered advertising or sale/sharing, limit certain uses of sensitive information, or appeal a denied request. We will handle applicable requests within the legally required timeframe and explain any permitted extension or exception. We may verify identity and authority using proportionate information; do not send government ID unless specifically needed and requested securely.

California residents: where the CCPA applies, these rights include knowing the categories, sources, business purposes, recipient categories, and specific pieces of covered information. You may use an authorized agent, subject to appropriate verification, and may exercise rights without unlawful discrimination. Collection categories and purposes are in section 2; disclosure categories are in section 5; retention is in section 6. Because we do not sell or share information for covered advertising, there is currently no such activity to opt out of.

If an applicable state law gives you an appeal right, reply to the decision with “Privacy appeal.” You may also contact the competent regulator. EEA/UK residents, where their laws apply, may complain to their data-protection authority and withdraw consent without affecting earlier lawful processing. We do not require you to waive privacy rights to use the Service.

8. Cookies and tracking signals

The current public website does not include advertising trackers or third-party analytics scripts. Authentication and local preferences may use essential cookies, tokens, or local storage. Payment portals and independent sites have their own practices.

The Service does not track users across third-party websites for advertising. Do Not Track does not change its behavior. Global Privacy Control has no sale/sharing activity to disable under current practices; if a covered activity is introduced, we will provide required controls and honor applicable opt-out signals before it begins.

9. International processing

Carve Cloud and its providers may process information in the United States and other countries where they operate. Those laws may differ from yours. Where applicable, transfers must use a lawful mechanism and required safeguards; this policy itself is not a substitute for a transfer agreement.

Where EEA/UK data-protection law applies, we process information as necessary to perform our contract, meet legal obligations, pursue legitimate interests such as security and service operation subject to your rights, or obtain consent where required. Contact us for information about an applicable transfer safeguard. Organization-directed processing may be governed by a separate data-processing agreement.

10. Children

Carve is intended for adults age 18 and older. We do not knowingly collect children’s information for their use of the Service. If you believe a child provided information, contact us so we can investigate and take appropriate action.

11. Security and changes

We use technical and organizational measures intended to protect information, including authenticated service access and protections for credentials. No system is perfectly secure. Protect your device and accounts, review exports before sharing them, and report suspected vulnerabilities through Support.

We will publish revisions with a new version and date and provide additional notice and obtain consent when required for material changes. We will not silently treat a new policy as permission for an incompatible use of previously collected information.

12. Contact

For privacy questions, requests, or complaints, contact Carvify, Inc. using the Support contact on the Carve legal website. Include only the information needed to identify your request. Local-only content is ordinarily managed on your device, so cloud-account support may not have access to it.