Privacy Settings
Caretta

Privacy Policy

Caretta Inc. ("we", "us", "our") provides Caretta, a sales-enablement application. We are the data controller for personal data processed via our website and app. This policy explains what data we collect, why we collect it, how we use and share it, how long we keep it, your rights, and how to contact us.

Data we collect and sources

1) Account & authentication

  • Google Sign-In data: name, email, profile image (as provided by Google).
  • OAuth tokens: access and refresh tokens, granted scopes, and expiry data used to maintain only the connections you enable.
  • Google requirement: Our use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy (including Limited Use).

2) In-app data you or your organisation provide

  • Calls: duration, notes, optional transcript, optional recording URL, links to evaluations.
  • Events & scheduling: titles, start/end time, link to related contacts.
  • Contacts, companies & deals: names, emails, phones, CRM fields, lifecycle or lead state, and deal or pipeline stage.
  • Files: filename/type/size/URL you upload.
  • Context: organisation/user context, objection lists, candidate snippets.
  • LLM content: prompts/outputs (e.g., "brain context", generated notes/summaries) tied to your usage to deliver features.

3) Connected services (only if you opt in)

  • Google Calendar read-only event details, including event IDs, titles, descriptions, locations, start/end times, attendees and email addresses, RSVP status, meeting links, and colour IDs, to show schedules, prepare AI meeting briefs, and link meetings. If you separately enable and use follow-up invites after Google approves the scope, we will request write access limited to calendars you own so Caretta can create events and notify attendees.
  • Google Drive Caretta currently reads the supported files you select, including file contents and metadata, and imports them directly into Caretta Brain for workspace search. The Caretta Brain Google Drive connection requests Google's drive.file scope. That scope authorizes Caretta to view, edit, create, and delete files you select with Google Picker or create with Caretta; Caretta currently uses it to download the selected files and metadata for import. Caretta stores the Google Drive OAuth credential separately from Google Calendar. Active Drive credentials and selected-file data are not sent to Airweave. Airweave is contacted for Drive only to remove legacy Google Drive source connections.
  • Microsoft Graph (e.g., Calendars.Read delegated) for the same scheduling/context features.
  • HubSpot contact read access, plus the optional contact, company, and deal permissions you approve, to match call attendees, load CRM context, share meeting notes, and create or update CRM records when you enable those features.
  • Zoom When you connect Zoom, Caretta receives OAuth access and refresh tokens. When you ask Caretta to create a Zoom link, it sends the meeting title, start time, time zone, and duration. It does not send attendee email addresses to Zoom. After authorisation, Caretta reads and retains only your Zoom user ID and account ID from your Zoom profile so a deauthorisation notification can remove the correct token record. Caretta handles the new meeting ID and join URL to create the calendar invitation and, if calendar creation definitively fails, delete only that newly created meeting.

Caretta does not currently request Gmail scopes and does not access Gmail messages. We do not access connected-service data beyond the permissions you grant.

4) Analytics & telemetry

We use consented website analytics and marketing tools: Visitors for website analytics, which records page views and receives the page URL, referrer, IP address, and browser user agent; Vercel Web Analytics for pageview measurement using data such as timestamp, page URL or path, referrer, browser and device information, and coarse location; and Surface for marketing and visitor identification, which records a page journey and may attempt to associate a business visitor with a company or contact and enrich a lead profile. We also use PostHog for product analytics, such as feature usage, device or browser information, and coarse location or IP data, to improve performance and user experience. We load the website measurement and marketing tools only after you accept the relevant consent category.

How we use the data

  • Authenticate sessions, manage accounts, and secure the service.
  • Prepare call briefings; capture/transcribe calls if enabled; generate notes/summaries; support evaluations.
  • Read relevant Google/Microsoft calendar event data for scheduling and context, and create Google Calendar events only when you enable and use follow-up invites.
  • Index supported files from an optional Google Drive connection so they can be found through workspace search.
  • Process relevant Google-derived data through configured AI service providers only to generate requested user-facing briefings, notes, summaries, and related assistance. We do not use Google user data to train or improve generalized AI or ML models.
  • Read and, when enabled, create or update HubSpot contacts, companies, deals, and associated call notes.
  • Create a Zoom meeting you request, add its join URL to your calendar invitation, and delete that new meeting if the matching calendar event definitively fails.
  • Provide analytics, product improvement, and support.
  • Comply with legal obligations and enforce terms.

Sharing and processors

We use service providers under our instructions: Amazon Web Services (AWS) for cloud compute, storage, secrets, and operational logs; Vercel for website hosting and, separately, Vercel Web Analytics for consented pageview measurement; Visitors for consented website analytics; Surface for consented marketing and visitor identification; Supabase for authentication and database services; Airweave for optional Notion connection and indexing, and to remove legacy Google Drive source connections; OpenAI, Anthropic, and Google Cloud Vertex AI, depending on the feature and configuration, to process relevant Google-derived data for user-facing AI features; ClickHouse Cloud as the infrastructure processor for inference observability; and PostHog for product analytics. Caretta's self-hosted TensorZero gateway software routes configured AI inference; TensorZero is not a separate third-party AI model provider. Selected Google Drive files are imported directly into Caretta Brain rather than sent to Airweave. Inference observability may include request/response content and metadata where configured. For connected calendars we also use the Google Calendar API and Microsoft Graph; for CRM features we use HubSpot APIs. The named service providers receive only the data needed for their stated function. We do not sell personal data.

International transfers

If we transfer data outside the EEA/UK, we use appropriate safeguards (e.g., EU Standard Contractual Clauses) and assess local laws.

Security

We implement industry-standard technical and organisational measures, including encryption in transit and at rest, strict access controls, and role-based permissions. Our application enforces data-segregation appropriate to our environment.

Retention

We retain OAuth tokens while a connection remains enabled and as needed to refresh it. A successful Zoom disconnect or signed Zoom deauthorisation notification deletes the active Zoom token record and its Zoom user and account ID mapping. Imported Drive data remains in Caretta Brain after Drive disconnect until you or your organisation admin delete the imported file or request deletion. Calendar-derived records, AI inputs and outputs, and inference-observability records are retained only while needed to provide and secure the service, under applicable workspace settings and processor terms, unless law requires longer. Provider security or abuse-monitoring records may be kept for the limited periods in the applicable provider terms unless account-specific reduced-retention controls apply. The website analytics and marketing data is retained only as needed for the stated purposes, according to our provider settings and terms. Withdrawing consent prevents these scripts from loading on later page loads but does not automatically delete data already collected by a provider. Revoking access in Google stops new API access but does not automatically delete existing copies already imported, generated, or logged. You or your organisation admin may request deletion of Caretta and processor-held copies at any time by following the deletion process below.

Your rights

You may have rights to access, rectify, erase, restrict, object, and data portability under the GDPR, and to lodge a complaint with the Autoriteit Persoonsgegevens (NL). We will respond within statutory periods.

Revocation & deletion

Revoke third-party access

  • Google: revoke our access from your Google Account's third-party app settings at any time; this revokes the project's Google scopes and stops new Google API access. Google Account revocation does not by itself delete data already copied into Caretta or its processors. A successful Google Drive disconnect removes the separate Google Drive credential and any legacy Airweave source connection. It does not disconnect Google Calendar. It does not delete files already imported into Caretta Brain. Request deletion if you want existing Caretta and processor-held copies removed.
  • Microsoft: revoke Microsoft Graph permissions from your Microsoft/Entra account settings.
  • HubSpot: remove our app and its scopes in your HubSpot settings.
  • Zoom: disconnecting Zoom in Caretta revokes the Zoom grant and deletes the active Caretta token record. You can also remove Caretta from Zoom's Added Apps page. Zoom then sends Caretta a signed deauthorisation notification so Caretta can delete the matching active token record and Zoom user and account ID mapping.

Request deletion

To delete in-app data, Google-derived data, and processor-held copies associated with your account or organisation (e.g., calls, transcripts, context, contacts, or files), email founders@caretta.so

Google-specific disclosures

  • Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
  • We use Google user data only to provide or improve prominent, user-facing Caretta features. We do not use Google user data to train or improve generalized AI or ML models.
  • Relevant Google-derived data may be processed by the service providers identified in Sharing and processors. We use commercial API services for requested features and disable OpenAI Responses storage and OpenAI Agents SDK tracing in our server-side agent path; provider security or abuse-monitoring retention may still apply as described under Retention.
  • We request only the minimum scopes needed and justify any sensitive/restricted scopes during verification.

Children

Our services are not directed to children and we do not knowingly process children's data.

Changes

We may update this policy from time to time. We will post the new date and, where appropriate, notify you.

Scopes & permissions

Below are the exact scopes our app uses or has submitted for approval and how we use them. We only request the minimum set of permissions required to deliver the described functionality.

Google

openid, email, profile

enable Google Sign-In and retrieve the user's basic account details (name, email, and profile image).

https://www.googleapis.com/auth/calendar.events.readonly

read Google Calendar event details, including titles, descriptions, locations, times, attendees, RSVP status, and meeting links, to display schedules and prepare meeting briefings.

https://www.googleapis.com/auth/calendar.events.owned

used in our development verification flow and, after approval, requested incrementally in production only when you enable follow-up invites. It lets Caretta create events on calendars you own and notify attendees when you use that feature.

https://www.googleapis.com/auth/drive.file

access the Google Drive files you select with Google Picker or create with Caretta so their contents and metadata can be used for workspace knowledge and search.

To maintain a connection without repeated sign-in, Google OAuth is requested with the access_type=offline parameter after showing the consent screen. This asks Google for a refresh token. The access_type=offline value is an OAuth parameter. The calendar.events.owned scope is used only in our development verification flow. Calendar write access remains disabled in production while verification is pending. Production will request it incrementally only after Google approves the scope and you enable follow-up invites.

Microsoft

Calendars.Read

read your Microsoft calendar metadata (event titles, times, attendees) to display schedules and prepare meeting briefings.

User.Read

retrieve your basic Microsoft account details (name and email) to associate your user identity with your organisation's workspace.

offline_access

maintain connection to your Microsoft account and refresh tokens without repeated sign-in.

openid, email, profile

standard authentication scopes that verify identity and provide basic user information during Microsoft login.

HubSpot

crm.objects.contacts.read

required to find and read contact records so Caretta can match call attendees and load relevant CRM context.

crm.objects.contacts.write

optional; create or update contact records and save meeting notes associated with selected contacts when you use those features.

crm.objects.companies.read

optional; find and read companies associated with contacts and calls.

crm.objects.companies.write

optional; create or update company records when post-call CRM updates require it.

crm.objects.deals.read

optional; find and read deals and pipeline context related to a call.

crm.objects.deals.write

optional; create deals or update deal stages when you enable post-call CRM updates.

Caretta connects through HubSpot OAuth. Contact read access is required; the remaining scopes are requested as optional permissions and are used only by the CRM features you enable.

Zoom

meeting:write:meeting

create a scheduled Zoom meeting when you ask Caretta to send a calendar invitation with Zoom.

meeting:delete:meeting

delete only a Zoom meeting Caretta has just created if the matching Google Calendar event definitively fails.

user:read:user

read the current Zoom user once after authorisation and retain only the Zoom user ID and account ID needed for precise deauthorisation cleanup.

Caretta does not keep the Zoom name or email returned by the current-user endpoint and does not read existing meetings, recordings, transcripts, participants, or chats.

Analytics

PostHog event collection

gather anonymised usage data (feature usage, device/browser type, session duration) to improve product performance and user experience.

Visitors and Vercel Web Analytics

load only after measurement consent to collect the website pageview and related technical data described above.

Surface visitor identification

loads only after marketing consent to support business-visitor identification and lead-profile enrichment.

Consent controls

allow you to withhold or withdraw measurement and marketing consent independently.

© Caretta Inc. All rights reserved.