Privacy Policy
Carton is a Mac CRM made by Capralis, Inc. (“Capralis,” “we,” “us”). This policy explains what data Carton handles, where it lives, and — just as importantly — what we deliberately never collect. We've tried to write it the way we'd want to read it: specific, plain, and honest about the details.
The short version: your CRM records are stored on our servers so they can sync and be shared with your team. Your email, calendar, and reminders are not — they sync directly between your Mac and your providers, and we hold no copy and no key to them. AI features only process the data you explicitly enable, only when you invoke them, and nothing the AI reads is retained by us.
1. Data we store
When you use Carton, the following is stored in our database (hosted on Google Cloud / Firebase, in the United States):
- Account information: your email address, display name, and sign-in identifiers.
- CRM records you create: contacts, deals, notes, tasks metadata, quotes and invoices, activity history, and team membership.
- Workspace settings: your pane layout, preferences, and any facts you explicitly ask the AI to remember (visible and deletable in Settings → AI).
- Usage counters: how many AI commands you've run (numbers only — never the content of your prompts or the AI's responses).
This data is shared with members of your Carton team according to the roles your team admin sets, and it's protected by per-user and per-team access rules enforced on the server.
2. Data we never store
The following stays between your Mac and your providers. It does not pass through or rest on Capralis servers in the ordinary course of use:
- Your email. Messages sync directly between your Mac and Gmail, Microsoft, or your IMAP server. We keep no copy of your mailbox.
- Your calendar and reminders. Carton reads these from macOS's own calendar and reminders stores on your Mac.
- Your mail credentials. The tokens and passwords that grant mailbox access are stored in the macOS Keychain on your Mac — encrypted by the operating system, held by your device, not by us. (During the initial account connection and token renewal, tokens transit our servers momentarily to complete the exchange; they are not stored there.)
A practical consequence we think matters: our servers hold neither a copy of your mailbox nor a credential that can retrieve it. There is nothing mail-related on our infrastructure to access, leak, or produce.
3. AI features and your data
Carton includes an AI assistant. Its access to your data is governed by three rules:
- Off by default. Every category of data (email, contacts, deals, calendar, and so on) has its own switch, and all of them start disabled. The AI can only see a category after you turn it on.
- Only when you ask. Data is processed by the AI only in the moment you give it a command that requires that data. There is no background analysis, indexing, or training on your data.
- Processed, never retained. When you invoke the AI, the relevant data (which may include email content, if you've enabled the email module) is transmitted through our AI proxy to a model provider to generate the response. Our proxy streams it through without storing it; we log only token counts for usage metering.
Model providers we use: OpenRouter and Anthropic. Their processing of requests is governed by their own terms; we configure our use of them for service delivery, not for training on your data.
4. Google user data (Gmail and Google Calendar)
If you connect a Gmail account or use calendar features with a Google account, Carton accesses Google user data under the following scopes: read and modify access to Gmail messages (gmail.modify), sending email (gmail.send), and creating and updating calendar events (calendar.events).
That access is used only to:
- display your mailbox inside Carton on your Mac;
- send emails you compose or explicitly instruct the AI to prepare (every AI-prepared send requires your confirmation before it goes out);
- mark messages read/unread as you act on them;
- create, update, and RSVP to calendar events at your direction.
Limited Use disclosure: Carton's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we do not transfer Google user data to third parties except as necessary to provide the features described above (see Section 3 for AI processing, which occurs only for categories you have enabled and only at your instruction); we do not use Google user data for advertising; and no humans at Capralis read your Google user data unless you explicitly ask us to for support, it's required for security or abuse investigation, or we're required to by law.
You can revoke Carton's access to your Google data at any time at myaccount.google.com/permissions, or by removing the account in Carton's settings (which also deletes the stored credentials from your Mac's Keychain).
5. Service providers (subprocessors)
| Provider | Purpose |
|---|---|
| Google Cloud / Firebase | Database, authentication, server functions (United States) |
| OpenRouter | AI model routing (only for AI commands you invoke) |
| Anthropic | AI model provider (only for AI commands you invoke) |
| Apple | App distribution and, during beta, TestFlight crash reporting |
| Stripe (when billing launches) | Payment processing — we never see full card numbers |
We do not sell your data. We do not use advertising or tracking SDKs in the app.
6. Security
- All data in transit is encrypted (TLS).
- Server-side data is protected by per-user and per-team access rules enforced by Firebase Security Rules, with email verification required for password-based accounts.
- Mail credentials live in the macOS Keychain, encrypted by your device.
- API keys and server secrets are held in Google Secret Manager, not in code or in the app.
No system is perfectly secure. If we learn of a breach affecting your data, we will notify affected users promptly with what we know and what we're doing about it. More detail on our practices: capralis.com/security.
7. Data location, cookies, and the website
Carton's servers are located in the United States; if you use Carton from elsewhere, your stored data (Section 1) is processed in the US.
The capralis.com website uses only strictly necessary first-party cookies (for signing in, when account pages exist). We don't use tracking cookies or third-party advertising cookies.
8. Retention and deletion
Your CRM data is retained while your account is active. To delete your account and its data, email privacy@capralis.com and we will delete your account's data within 30 days. Removing a connected mail account immediately deletes its credentials from your Mac; since we store no mailbox data, there is nothing mail-related to delete on our side.
Team data (deals, shared contacts, notes) belongs to the team; when you leave a team, records you created remain with that team.
9. Your rights
Depending on where you live, you may have legal rights to access, correct, export, or delete your personal data. Whatever the jurisdiction, our practice is the same: email privacy@capralis.com and we'll honor reasonable requests to show you, correct, export, or delete your data.
Carton is not directed at children under 16, and we do not knowingly collect their data.
10. Changes to this policy
We'll update this policy as Carton evolves (for example, when billing launches). Material changes will be announced in the app or by email before they take effect, with the effective date above updated. Prior versions will remain available on request.
11. Contact
Capralis, Inc.
801 Shelby Street, Ste. 94457
Indianapolis, IN 46203
privacy@capralis.com