Carouza · Purple Labs Inc.
Privacy Policy
What we collect, why we are allowed to, where it lives, how long we keep it, and how to take it with you or delete it.
Effective [TO BE COMPLETED: effective date] · Last updated [TO BE COMPLETED: last updated date]
The short version
What we learn about your business stays with your business, and when you leave, it leaves with you. Your carousels, your brand, your results and everything we work out from them are used to make your carousels better. They are never used to make another customer’s. That is enforced by the database itself, not by our good intentions. Every table is walled per business by Postgres row-level security, and the jobs that do the learning run inside those same walls.
The one exception, stated plainly rather than buried. The statistical model behind our predictions has a handful of global constants, such as how much to trust a small sample. Those can only be tuned from the pooled, anonymised residuals of many businesses at once: numbers with no content, no names and no identifiers in them. Nothing you wrote, nothing you published, and nothing that could be traced back to you is in that pool. Everything else about you is yours alone.
You can download everything we hold about you as a ZIP at any time, including your original photographs and not just links to them. You can delete your account yourself too, immediately, without asking us.
Who we are
Carouza is a product of Purple Labs Inc., a corporation incorporated in British Columbia, Canada (incorporation number [TO BE COMPLETED: BC incorporation number]), with its registered office at [TO BE COMPLETED: registered office address, British Columbia]. We are the data controller for the personal information described here.
Privacy enquiries: [TO BE COMPLETED: privacy email address]. General support: [TO BE COMPLETED: support email address].
Our representative in the European Union
We have no establishment in the European Union, so under Article 27 of the GDPR we have appointed a representative there. EU and EEA residents may contact them instead of us on any matter relating to this policy: [TO BE COMPLETED: Art 27 EU representative, name of the appointed firm], [TO BE COMPLETED: Art 27 EU representative, address in an EU member state], [TO BE COMPLETED: Art 27 EU representative, contact email].
Our privacy officer in Quebec
Under Quebec’s Law 25 the person responsible for the protection of personal information is [TO BE COMPLETED: Quebec Law 25 privacy officer, full name, to be published], reachable at [TO BE COMPLETED: Quebec Law 25 privacy officer, contact email].
What we collect, and what allows us to
The table below states our lawful basis for each purpose, as Article 6 of the GDPR requires. Where the basis is consent you can withdraw it at any time; where it is our legitimate interests you can object.
| Why we process it | What that involves | Lawful basis |
|---|---|---|
| Giving you an account and signing you in | Your email address, plus your Google account identifier if you use Continue with Google. There is no password: we never create one, so we never hold one. | Performance of our contract with you |
| Building your business profile and brand kit | What you tell us about your business, the text of a website address you give us, your logo, your colours, and the notes and evidence we derive from them. | Performance of our contract with you |
| Writing and editing carousels | Your briefs and instructions, the copy on each slide, captions, hashtags, ideas, and the photographs you upload. | Performance of our contract with you |
| Publishing to Instagram or TikTok | The images, caption and hashtags of a post you tell us to publish, and the handle of the account you connected. We never hold your Instagram or TikTok password. | Performance of our contract with you |
| Measuring how a post did, and learning from it | The engagement figures the platform returns for posts you published, your follower count at the time you published, and the statistics we compute from them. | Performance of our contract with you |
| Taking payment | Your email address and subscription details. Card details go to Stripe directly and never reach us. | Performance of our contract with you, and legal obligations relating to tax and accounting |
| Service messages we must send | Notices that a post failed to publish, that a payment failed, that a published price is changing, and your sign-in codes. You cannot switch these off, because switching them off would mean not telling you your posts stopped going out. | Performance of our contract with you |
| Marketing email | The weekly digest, the onboarding sequence and product news, each only if you asked for it. | Your consent |
| Keeping the service working and secure | Server logs, error reports, rate limits and abuse controls. | Our legitimate interests in operating a service that stays up and is not abused |
| Tuning our statistical model | Anonymised, aggregate residuals across many businesses, containing no content and no identifiers. | Our legitimate interests in the accuracy of what we tell every customer |
We do not collect special-category data, we do not buy personal information from anyone, and we do not sell yours.
Where your data lives
Your account, your content and your uploaded files are stored in the European Union, in Frankfurt, Germany, on Supabase’s eu-central-1 region. That was set when the project was created and cannot be moved afterwards.
The web servers that run the application are on Vercel’s global network and are not pinned to a single region, so a request you make may be handled outside the EU even though the data it reads is stored inside it.
Canada, and why that matters to you
We are a Canadian company, so when we look at your data we are looking at it from Canada. Canada holds a current adequacy decision from the European Commission for commercial organisations subject to PIPEDA, which means transfers of personal data from the EU to us need no standard contractual clauses and no additional safeguards. A US company in our position cannot say that. Adequacy decisions are reviewed and can change, so we say current and we mean it.
Where a sub-processor is outside the EEA, the transfer relies on the transfer mechanism in that vendor’s own data processing terms. For US vendors that is normally the European Commission’s standard contractual clauses. If you need the position for a specific vendor before you sign up, ask us and we will tell you.
The full list of vendors, what each one receives and where it sits is on our sub-processor page.
What we send to AI providers, and what they do with it
To write and edit your carousels we send text to Anthropic: your business profile, the brief or website text you gave us, and the copy being edited. We use paid API access, never a free tier, including on our own development machines. A free tier typically trains on what is sent to it, and one careless call would make this page untrue.
On a paid API tier, what we send is not used to train the models, and content may be retained briefly for abuse monitoring. That is the accurate position and it is the one we will state. We do not claim that our AI providers retain nothing, because we have no written arrangement that would make that true. If that changes we will say so here and date the change.
If you give us a website address, we fetch that page ourselves in order to read it. We identify ourselves as CarouzaBot when we do, and we refuse addresses that point inside private networks.
How long we keep things
The honest shape of this is simple: most of your data is kept for as long as your account exists, and goes when your account goes. The specific periods that do exist are below, and each one is a number the software actually enforces rather than an intention.
| What | How long | Then what |
|---|---|---|
| Your account, content, carousels, published posts and metrics | For as long as your account exists | Deleted when you delete your account |
| A data export ZIP you asked us to build | 7 days | The file is deleted and the download link stops working |
| The download link for an export | 1 hour from the moment you click download | Expires; ask for another and we mint a fresh one |
| An uploaded file that never became part of anything | At least 24 hours, then swept | Deleted |
| An idea you never acted on | 60 days | Marked expired. It stays in your export until you delete your account |
| An idea you snoozed | 30 days | Comes back to you |
| The cached reading of a website address | 30 days | Discarded and re-read if you ask again |
| A credit hold placed while an AI action runs | 5 minutes | Released back to your balance |
Two things are honestly outside that table. Server logs and error reports are not stored per business and cannot be filtered down to one customer, so they are not in your export and are not deleted with your account; they are held on our hosting and error reporting providers under those providers’ own retention settings. Our AI providers’ own records of the requests we sent them are theirs, not ours. We do not control their retention and, as above, we do not claim they keep nothing.
Your rights, and how to use them
Under whichever of the GDPR, PIPEDA, BC PIPA and Quebec’s Law 25 applies to you, you can ask for access to your personal information, correction of it, deletion of it, a portable copy of it, restriction of how we use it, and you can object to processing based on our legitimate interests. Where processing rests on consent, you can withdraw it.
Two of those you do not have to ask us for
- A copy of everything. Settings builds you a ZIP containing every row we hold for your business, your account record, your notification settings, your consent history and the image files themselves, including the photographs you uploaded rather than links to them. It says in the manifest what was left out and why.
- Deletion. Settings deletes your account. It is immediate and it is not reversible; there is no grace period and no soft-deleted copy waiting somewhere.
Anything else: one calendar month
For anything you have to ask us for, write to [TO BE COMPLETED: privacy email address]. We will respond within one calendar month of receiving your request, as Article 12 of the GDPR requires. If a request is unusually complex we may need longer and will tell you why inside that same month. We do not charge for this.
What deletion actually reaches
Deleting your account removes, in this order:
- Your files first: every bucket, enumerated live so a bucket added later cannot be silently missed, and then read back to confirm the bytes are gone rather than trusting the reply.
- Then your database records: your business and every table that hangs off it, including your carousels, publications, metrics, credit ledger and notifications.
- Then your sign-in account, unless you still own another business with us, in which case we keep the sign-in and tell you we did.
- Your connection to Instagram or TikTok is revoked with our publishing partner before the record naming it is removed, because afterwards there would be nothing left to revoke it with.
If any part of that fails, nothing is deleted and you can try again. We would rather tell you it did not work than tell you it did.
One caveat we would rather state than have you discover. Images are served through a content delivery network, and a copy already sitting in that network keeps being served from there for a short time after the original is gone. Measured against our own system, a deleted image’s URL stopped working after about a minute. The bytes are removed immediately; the cached copy is not the original.
Posts you already published to Instagram or TikTok stay on those platforms. They are yours, on your account, and only you can take them down.
Email, and Canada's anti-spam law
We are a Canadian sender, so Canada’s anti-spam legislation (CASL) applies to us and it is stricter than the rules most services you use are written against.
What we send without asking
Service messages about your own account: a post failed to publish, a payment failed, a published price is changing, and the six-digit code you asked for to sign in. These are not marketing and there is no switch for them. A switch that stopped us telling you your posts had stopped going out would be a feature that harms you.
What we only send if you ask
The weekly digest, the onboarding sequence and product news. We will not send you any of these unless you have given us express consent, asked for separately and never bundled into your acceptance of our terms, on a checkbox that is not ticked for you. We keep the wording you were shown, the version of it, the time, and the IP address it came from, so that the record can be produced. Under CASL the burden of proving consent is ours, not yours. That record is in your data export.
Stopping it
Every marketing email carries an unsubscribe link, and it is one click. We apply it immediately: a single write, with no queue and no batch behind it, and in any event well within the 10 days CASL allows. The link does not expire, because your copy of an email may sit in your inbox for years. You can also turn any stream off in Settings.
Unsubscribing stops the marketing. It does not stop the service messages above, and it does not close your account.
How we protect it
- Separation between customers is enforced by the database, using Postgres row-level security on every table, rather than by application code remembering to filter. The background jobs that generate, publish and learn run inside those same policies.
- We never hold a password. Signing in is a six-digit code by email or Continue with Google. There is no password to steal from us because we never create one.
- We never hold your Instagram or TikTok credentials. Our publishing partner holds the platform authorisation; we hold a reference to it, which you can revoke from Settings.
- Error reports are scrubbed before they leave our servers. Slide copy, captions, hashtags, briefs, prompts, email addresses, phone numbers and addresses are removed by a deny-list that fails closed, IP addresses and cookies are never attached, and performance traces are switched off entirely, because they would carry prompts.
- The key that can bypass those database policies lives in exactly one file, is refused in the browser, and a lint rule fails the build if another file imports it.
- Images are stored in public buckets, deliberately, because Instagram has to fetch them and a browser canvas has to read them. Their paths contain random identifiers and are not guessable, and nothing confidential is stored there. Your data export ZIP is the exception: it is private and reachable only through a link that expires in an hour.
Encryption in transit and encryption at rest are provided by our hosting and database providers as part of their platforms. We hold no security certifications and this page will not imply otherwise.
Children
Carouza is a tool for businesses and is not directed at children. You must be at least 16 to use it, or the age of digital consent where you live if that is higher. We do not knowingly collect information from anyone below that age; if you believe we have, write to [TO BE COMPLETED: privacy email address] and we will delete it.
If you think we have got this wrong
Tell us first, at [TO BE COMPLETED: privacy email address], and we will look at it. You do not have to, and your right to complain to a regulator does not depend on it.
- In the EU or EEA: your national data protection authority, or our Article 27 representative above.
- In Canada: the Office of the Privacy Commissioner of Canada; in British Columbia, the Office of the Information and Privacy Commissioner for BC.
- In Quebec: the Commission d’accès à l’information.
- In the United Kingdom: the Information Commissioner’s Office.
Changes to this policy
When we change this page we change the date at the top. If a change materially affects what we do with your personal information we will tell you by email before it takes effect, because that is a service message about your own account rather than marketing.