Version 2026-09-08. In force from 8 September 2026.

Legal

Privacy policy

This policy explains what personal data Carthagent holds about you, why we hold it, how long we keep it and what you can ask us to do with it. It covers the Carth website and the Carth product.

  1. 1. Who we are
  2. 2. Scope, and the two very different things this covers
  3. 3. What we collect
  4. 4. Why we use it, and our lawful basis
  5. 5. What we never do
  6. 6. Cookies
  7. 7. Who processes data for us
  8. 8. Where your data lives, and transfers
  9. 9. How long we keep things
  10. 10. How we protect data
  11. 11. Your rights under the GDPR
  12. 12. Other jurisdictions
  13. 13. Children
  14. 14. Changes to this policy
  15. 15. How to reach us

1. Who we are

Carth is a development cockpit for supervised AI work. It is built and operated by Carthagent, a company registered in Tunisia, based in Tunis, Tunisia, with a presence in San Francisco, California. Company registration details are available on request at apply@carthagent.com.

For anything to do with privacy, write to apply@carthagent.com. That is the single address for access requests, deletion requests, questions and complaints, and it reaches a person rather than a queue. We have not appointed a statutory data protection officer, because we are a small company below the threshold that requires one. We have not appointed a representative in the European Union yet. People in the EU can write to apply@carthagent.com and we answer in the same way.

2. Scope, and the two very different things this covers

Before anything else, one distinction, because everything below depends on it. Personal data around Carth falls into two categories, and Carthagent has a different role in each.

  1. Account and website data, where we are the controller. This is data about the people who visit carthagent.com, apply for access, and sign in to Carth: names, work emails, company, role, billing details, sign in records. We decide why and how this is used, so we are the controller and this policy governs it.
  2. Customer content inside a cockpit, where the customer is the controller. When a company uses Carth, they bring their own code, files, records and data into their cockpit. Some of that may contain personal data about their employees, their clients or other people. That data is theirs. They decide what goes in and what is done with it, so they are the controller and Carthagent is a processor acting on their documented instructions. Our handling of it is governed by the data processing agreement, not by this policy.

If you believe a company holds personal data about you inside their Carth cockpit and you want to exercise rights over it, your request belongs with that company. If you contact us instead, we will not be able to identify you in their content, but we will pass the request on to them where we can, and tell you that we have done so.

3. What we collect

Account data

Your name, work email address, the company you work for, your job title where you give it, the role assigned to you in the cockpit, your preferred language, and the password hash or authentication token that lets you sign in. We never store your password in a readable form.

Application data

Access to Carth is by waiting list. What you send reaches us by email and is also kept on the list itself, so that we can come back to you in turn rather than lose you in an inbox. That means we hold whatever you chose to send us: your name and contact details, your company, the size of your team, what you want your AI crew to work on first, and any correspondence that follows. We also record that you accepted these documents, when, and which version you were shown, because an agreement nobody can evidence protects neither of us. Ask us to remove you and we delete your entry the same day. Please do not send us sensitive personal data or confidential third party material in an application.

Billing data

Company name and billing address, tax identifier where applicable, plan, invoice history and payment status. Card details are entered directly with our payment provider and are handled by them. We do not store full card numbers. What we see is the limited information the provider returns to us, such as the card brand, the last four digits and whether a payment succeeded.

Usage and operational data

Records of how the product is used: sign ins and sign outs, missions created and run, which agents ran, approvals and rejections with the person, the moment and what they were shown, budget and spend counters, configuration changes, and application logs and error reports produced by the service.

Technical data

Your IP address, browser type and version, operating system, device type, approximate location derived from the IP address at country level, and timestamps of requests. This comes with any connection to a web service and we use it to keep the service running and secure.

Support data

Emails you send us, the content of a support conversation, and any screenshots or files you attach to it.

4. Why we use it, and our lawful basis

Under the GDPR we need a lawful basis for each purpose. Here they are, one row per purpose, so you can check them rather than take our word for it.

What we do Data used Lawful basis
Create and run your account, give you the cockpit, run missions you brief Account, usage Performance of a contract
Review an application and decide whether to onboard the company Application Steps at your request before entering a contract
Take payment, issue invoices, chase unpaid fees Billing, account Performance of a contract, and legal obligation for tax records
Keep the audit trail of who approved what Usage Performance of a contract, and legitimate interest in a reliable record of authority
Enforce budget caps and count spend Usage Performance of a contract
Keep the service secure, detect abuse, investigate incidents Technical, usage Legitimate interest in protecting the service and our customers
Diagnose faults and improve reliability Technical, usage Legitimate interest in a service that works
Answer support requests Support, account Performance of a contract
Send service messages, such as a renewal notice or a security alert Account Performance of a contract, and legal obligation for breach notices
Send occasional product news to an existing customer contact Account Legitimate interest, with a one click unsubscribe in every message
Send marketing to someone who is not yet a customer Application, contact Consent, which you can withdraw at any time
Meet legal, accounting and sanctions obligations, defend legal claims Account, billing, usage Legal obligation, and legitimate interest in establishing or defending claims

Where we rely on legitimate interest, we have weighed our interest against your rights and concluded that the processing is limited to what is necessary and would not surprise a reasonable person. You can object to it, and section 11 explains how.

5. What we never do

This list is short on purpose, so that it is easy to hold us to.

  • We do not sell personal data. Not to anyone, for any price.
  • We do not share personal data with advertisers, ad networks, data brokers or social platforms, and we run no advertising and no behavioural or cross-site tracking on this website.
  • We do not use customer content to train models. Not ours, and not anyone else's. We contract with our AI model providers so that content we send them is not used for their training either.
  • We do not read customer content inside a cockpit. The exception is narrow and deliberate: when a customer asks for support and grants access so that we can investigate their problem. That access is time limited, recorded, and used only for the issue at hand.

6. Cookies

The marketing website you are reading uses no advertising cookies and shows you no advertising. It does use Google Analytics to count visits and see which pages people read, and Google Analytics sets cookies. Because it is not necessary for the site to work, it does not run until you accept it. Nothing is requested from Google before that: if you refuse, or simply never answer, no analytics script is ever loaded and no analytics cookie is ever set. Refusing costs you nothing, and every part of this site works the same either way.

Your answer is remembered in your own browser so that we do not ask again. To change it, clear this site's data in your browser and the question will be put to you afresh. We use the data only in aggregate, to understand what people look at; we do not use it to build a profile of you, we do not link it to a customer account, and it is never used for advertising.

The product is different, and only slightly. When you sign in to a cockpit, Carth sets a session cookie or stores a session token so that the service knows who you are between one page and the next, and so that gates can be enforced against your role. Without it, signing in would not be possible. It is strictly necessary for a service you asked for, it carries no advertising identifier, and it is cleared when you sign out. We may also store a small preference, such as your chosen language or layout, in your browser's local storage.

7. Who processes data for us

We keep the list of vendors deliberately short, and every one of them is under a written contract that limits them to processing on our instructions. By category:

  • Hosting and infrastructure. Runs your private container and its encrypted volume, and stores backups.
  • Payments. Takes card payments and issues receipts. They hold the card details, we do not.
  • Transactional email. Delivers service messages such as invitations, renewal notices and security alerts.
  • AI model providers. Run the models that agents use to do the work, on the hosted plans. On the Enterprise plan this is your own provider account under your own agreement.
  • Error monitoring and operational tooling. Collects crash reports and logs so that faults can be found.

The current named list, with each vendor's role and location, is available on request from apply@carthagent.com and sent to every customer before it changes. The definitive version is maintained in the subprocessor table of the data processing agreement, and we provide it in full on request before signature.

Outside those vendors we disclose personal data only in three situations: where you or your company instruct us to, where the law or a valid legal request compels us, and to a buyer or successor if the business is sold, in which case we would tell you first and the data would stay under a policy at least as protective as this one.

8. Where your data lives, and transfers

Customer cockpits are hosted in the European Union or in Canada, and the customer chooses which at onboarding. Backups are kept in the same region as the cockpit they belong to.

Carthagent is established in Tunisia, and our own team works from there and from other locations, so our staff access support and administration systems from outside the hosting region. Some of our vendors, notably AI model providers, operate in other countries. That makes some transfers of personal data outside the European Economic Area unavoidable.

Where a transfer leaves the EEA to a country without an adequacy decision, we rely on appropriate safeguards, currently the European Commission's standard contractual clauses, module two or module three as the case requires, together with the technical and organisational measures described in section 10. You can ask us for a copy of the safeguards that apply to a specific transfer.

9. How long we keep things

We keep personal data only as long as we need it, then delete it. Some of these windows are still being fixed and are marked as such rather than invented.

Data Kept for
Account data While the account is active, then deleted within thirty (30) days of termination
Customer content in a cockpit On the customer's instructions, and per the retention window in the terms and the data processing agreement
Applications that do not become customers Up to 12 months, then deleted, unless you ask us to delete them sooner
Invoices and accounting records As long as tax and company law requires, typically several years, the period required by applicable law
Audit trail of approvals For the life of the account, because its value is that it does not disappear
Application and security logs Between 30 and 90 days for routine logs, longer where an incident is under investigation
Support conversations Up to 24 months after the conversation closes
Backups Until the backup expires on its normal cycle: at most 7 days on Enterprise, shorter on every plan below it

When something is deleted from the live service it may persist in backups until those backups expire. During that period the data is not restored to the live service except to recover from a failure, and it is deleted with the backup.

10. How we protect data

In plain terms, and without dressing it up:

  • Each customer company gets its own private container. It is not a shared database with your name in a column.
  • Storage volumes are encrypted, and traffic to the service is encrypted in transit.
  • Access is per user and revocable. Your Admin can remove a person's access immediately, and rights are enforced by the server rather than hidden in the browser.
  • Sensitive values such as provider keys are held in a secret store rather than in plain configuration.
  • Actions that matter leave an audit trail: who approved what, when, and what they were shown.
  • Our own staff access is limited to the people who need it, and support access to customer content happens only when a customer grants it.

An honest word about certifications. Carthagent is an early stage company. We hold no security certification or third party audit report, and we will not imply otherwise on this page or in a sales conversation. What we can give you is a clear description of how the system is built, answers to your security questionnaire, and the option of the Enterprise plan, where Carth runs entirely inside your own infrastructure under your own controls.

No system is perfectly secure. If a personal data breach occurs and it is likely to result in a risk to people's rights, we notify the competent supervisory authority within 72 hours of becoming aware of it where the law requires, and we tell affected people and affected customers without undue delay. The processor side of that duty is set out in the data processing agreement.

11. Your rights under the GDPR

If the GDPR applies to you, you have the following rights over the personal data for which we are the controller.

  • Access. Get confirmation of whether we hold data about you, and a copy of it.
  • Rectification. Have inaccurate data corrected and incomplete data completed.
  • Erasure. Have data deleted where we no longer have a good reason to hold it.
  • Restriction. Have processing paused while a dispute about accuracy or lawfulness is resolved.
  • Portability. Receive the data you gave us in a structured, commonly used, machine readable format, and have it sent to another provider where technically feasible.
  • Objection. Object to processing based on legitimate interest, including profiling. If you object to direct marketing we stop, with no balancing test and no argument.
  • Withdraw consent. Where we rely on consent, withdraw it at any time. That does not affect processing already carried out.
  • Complain. Lodge a complaint with the supervisory authority in your country of residence, place of work, or where you think the problem occurred. We would rather you came to us first, but that is your choice and not a condition.

We do not make decisions producing legal or similarly significant effects about you by automated means alone. Agents produce output, and people approve it.

To exercise any of these rights, email apply@carthagent.com. We reply within one month, and we will tell you if a complex request needs up to two further months. It is free, unless a request is manifestly unfounded or excessive, in which case we will explain the reason before charging anything. We may ask you for information to confirm your identity, and no more than we need for that.

12. Other jurisdictions

We sell internationally, and other privacy laws may apply to you. Where they do, we honour equivalent rights of access, correction and deletion through the same address and the same process, and we will not discriminate against you for exercising them. Residents of certain jurisdictions have specific rights, for example to know what categories of personal data are collected and disclosed, and to opt out of a sale or a share of personal data. As stated in section 5, we do not sell or share personal data in that sense, so there is nothing for you to opt out of. Tunisian data protection law also applies to Carthagent as a company established in Tunisia. If your local law gives you a right this policy does not mention, write to us and we will deal with it.

13. Children

Carth is a business product and is not for children. We do not knowingly collect personal data from anyone under 18, and every seat holder must be at least 18. If we learn that we hold data about a child, we delete it. If you believe a child's data has reached us, tell us at apply@carthagent.com and we will act on it quickly.

14. Changes to this policy

We will update this policy as the product changes and as the placeholders in it get filled in. The version in force is always the one published here, with its effective date at the top of the page. For a material change, for example a new purpose or a new category of recipient, we notify account Admins by email at least thirty days before it takes effect. We keep previous versions and will send you one on request.

15. How to reach us

Email apply@carthagent.com for privacy questions, rights requests, security reports, or to ask for the current subprocessor list. A person reads that address and we aim to reply within two business days, and within one month for a formal rights request.

Carthagent, registered in Tunisia. Tunis, Tunisia, and San Francisco, California. Registration details on request.