Privacy policy

Last updated 16 September 2026. Carte is a typed, addressable mailbox for businesses, operated by Carte Ltd ("we"). This policy says what we collect, why, how long we keep it, who can see it, and how to reach us.

What we collect

  • Account identity. When you sign in with Google we store your email address, name, avatar URL, Google account id and, for Workspace accounts, your hosted domain. We use this to sign you in and to attribute every message you send.
  • Messages and files. Everything sent to or from a Carte address: the envelope (sender, recipient, type, subject, note), any JSON body, any attached files, and a SHA-256 hash of each. Messages are the product; they form a permanent ledger.
  • Sender metadata. For abuse handling we record a hashed IP address and the user agent on web sends, and DKIM/SPF results on email-in.
  • Connected apps. When you connect an assistant over MCP with OAuth we store the app's client metadata, the scopes you approved, hashed tokens, and when the connection was last used. Messages sent through a connected app note which app sent them.
  • Product analytics. An internal event log (sign-ins, sends, webhook deliveries, connections). No third-party analytics or advertising trackers.

What we do not collect

Connected assistants only receive the tool arguments you or your assistant supply. We never read your assistant's memory, chat history or files, and we do not collect payment card data, health data, government identifiers or passwords.

Why we use it

To deliver messages, produce receipts, run the dashboard, API, webhooks and MCP server you use, keep the service safe, and understand how it is used in aggregate. We do not sell personal data and do not use it for advertising.

Who can see it

  • The business you send to sees your name, email and everything in the message. That attribution is the point of Carte.
  • Public receipts show sender identity, file names, sizes and hashes, never the JSON body or file contents.
  • Processors we rely on: Railway (hosting, Postgres and object storage), Resend (transactional and inbound email). Each acts on our instructions.
  • Apps you connect receive only what their approved scopes allow, and only while the connection is active.

How long we keep it

Messages and files are a ledger and are kept indefinitely; no user-facing path deletes them. Account data is kept while the account exists. OAuth tokens expire (access tokens in one hour, refresh tokens in thirty days) and connections can be revoked at any time from Connected apps. Revoked keys and connections are retained as records. The demo inbox is purged daily. Legal and abuse takedowns are handled manually.

Your choices

You can revoke API keys and connected apps, block senders, and change your display name from the dashboard. For access, correction or deletion requests that the dashboard does not cover, email us.

Contact

Privacy and support: support@carte.sh. Abuse and takedowns: abuse@carte.sh.