Terms of service

Last updated 16 September 2026. These terms cover carte.sh, its API, webhooks, email-in, SDK and MCP server (the "service"), operated by Carte Ltd. By using the service you agree to them.

The service

Carte gives a business an address that anyone with a Google account can send JSON and files to, keeps a permanent receipted ledger of what was sent, and lets the business read it through a dashboard, an API, webhooks and connected assistants. It is in preview and free while it is; see Limits for the soft limits that apply.

Your account

You sign in with a Google account you control. You are responsible for what is sent from your account, from your API keys, and through apps you connect. Keep keys secret; revoke any you no longer need.

Acceptable use

Do not use the service to send unlawful, infringing or malicious content, to spam, to probe or overload the service, or to access data you are not authorised to see. Receivers may block senders; we may suspend accounts that abuse the service. Report abuse to abuse@carte.sh.

Your content

You keep ownership of what you send and receive. You grant us the rights needed to store, transmit, hash and display it as the service requires, including to the recipient and on public receipts (which never include JSON bodies or file contents). Messages and files are a ledger and are not deleted through the service.

Connected apps

When you connect an assistant over OAuth, it acts within the scopes you approve until you disconnect it. Its provider's terms govern the assistant itself; we are responsible only for what our server returns to it.

Availability and changes

The service is provided as is, without warranties, during preview. We may change or discontinue features; we will give reasonable notice before removing access to your data. Our liability is limited to the fullest extent permitted by law.

Privacy

How we handle personal data is described in the privacy policy.

Contact

support@carte.sh