Carton AI — Acceptable Use
This is the same policy Carton shows in the app before AI features can be enabled — published here so you can read it before you ever install anything. It's short on purpose: it says exactly what happens to your data when you use the AI, and what we expect from you.
What gets sent
- Your prompt text.
- Output from tools the AI calls — for example, contact names if you ask “list contacts at Acme,” or event titles if you ask “what's on my calendar.”
- The active cross-pane anchor, when one is set.
Where it goes
- Your chosen provider — Anthropic (direct), Google Vertex AI, or OpenRouter. You pick in Settings → AI.
- Anthropic and Google Vertex do not train on API content. OpenRouter forwards to the underlying provider you select; check their policy.
- Carton logs token counts (not prompt content) to your account for usage tracking.
What you control
- Per-module toggles in Settings → AI let you enable AI access to each data type — Contacts, Notes, Email, etc. — independently. Modules you haven't enabled are invisible to the AI.
- Destructive actions — sending email, deleting records, modifying others' data — always require your explicit confirmation. AI never performs them on its own.
- You can revoke AI access at any time in Settings → AI.
Your responsibility
- Only use AI on data you have the right to share with the provider you've selected.
- Don't paste passwords, third-party personal data you don't own, or any other restricted information into prompts.
How acceptance works
The first time you use an AI feature in Carton, the app shows this policy and asks you to accept it; nothing is enabled until you do. You can re-read it anytime in Settings → AI, which also records the date you accepted. For how AI processing fits into our broader data practices, see the Privacy Policy; for the rules governing your use of Carton generally, see the Terms of Service.