Privacy Policy
Effective 2026-05-30 · Last updated 2026-05-30
This Privacy Policy explains how EchoPersona ("Carets," "we," "us") collects, uses, and shares information when you use the Carets mobile application (the "App") and the carets.app website (the "Site"). The App and Site together are the "Services."
We designed Carets to be private by default. The App is local-first: your notes and editor state are stored on your device. We do not operate servers that hold your notes or your files. The only data that leaves your device is what you choose to sync to your own iCloud or Google Drive, plus what is strictly necessary for purchases and store features.
1. Quick summary
Long version below. The short version:
- The App collects no analytics, no advertising IDs, and no telemetry. We have no servers that store your notes, your edits, or your files.
- Your internal notes live on your device. Free users never sync anything off-device.
- External files you edit aren't copied anywhere by us. When you open a file from Files / iCloud Drive / Google Drive, Carets reads it and writes your edits back to its original location using the OS security-scoped file API. We do not duplicate the file into our app sandbox or any server.
- Paid cloud sync writes only to your own cloud. iOS notes go to your iCloud container; Android notes go to a private folder in your Google Drive that only Carets can see (the Drive
appDataFolderscope). We do not see or hold a copy. - Purchases are processed by Apple, Google, and RevenueCat. We receive an entitlement status (
proor not) and an anonymous subscriber ID — not your card, address, or store account email. - The Site uses Google Analytics 4 only if you opt in. Analytics cookies are blocked by default until you click "Accept" on the cookie banner.
- You can wipe all your data — locally and in the cloud — from the App's Settings → Delete all data at any time. External files in your own cloud are not deleted by this (they're yours, not ours); remove them in their original location.
2. Who we are
The data controller is EchoPersona, the operator of Carets, based in New Mexico (United States). You can reach us at contact@carets.app for any privacy request, including the rights described in section 11 below.
3. Information we process
3.1 Information processed entirely on your device (the App)
The following information is created and stored only on your device and is not transmitted to us:
- Internal notes you create inside the App (plain text, code, Markdown, checklists), stored in a local SQLite database.
- Editor state — cursor position, scroll position, language/mode, undo history, and per-document preferences.
- Recent-files list — for each external file you've opened from Files / iCloud Drive / Google Drive, we keep a security-scoped URI or bookmark, a display name, the detected language/mode, the cursor position you left off at, and the last-opened timestamp. We do not copy the file contents into the App sandbox; the file lives wherever you stored it.
- Organization — folder names, tag names, and the mapping between them and your internal notes.
- Preferences — selected theme, editor typography (font family, size, line height, tab width, wrap, line numbers), accessibility choices, and which features you have toggled.
3.2 External files you open (Files / iCloud Drive / Google Drive)
When you open an external file, the OS grants Carets a security-scoped permission to read from and write back to that specific file URI. We use that permission only to render the file in the editor and to save your edits back to the same location. We do not transmit the file's contents anywhere off-device, and we do not retain a copy beyond the editor's in-memory working buffer plus a crash-recovery buffer that is cleared when you next save successfully or use Delete all data. iCloud Drive and Google Drive files are processed by Apple and Google under their privacy terms; Carets is just the editor.
3.3 Information processed by your own cloud (paid users only)
If you turn on cloud sync as a Pro user, the App copies your internal notes and a metadata manifest into your own cloud account. External files are not synced by us; they already live in your cloud.
- iOS: an iCloud container tied to your Apple ID. The container is owned by you; we have no access to it.
- Android: a private folder in your Google Drive accessed via the
drive.appdatascope. This folder is invisible to other apps and to us — we can only write and read inside it from this device.
Apple and Google process this storage subject to their own privacy terms. We do not receive a copy and we do not have credentials to your iCloud or Drive.
3.4 Information we receive from purchase providers
Purchases happen inside the App via Apple's App Store or Google Play. We use RevenueCat to verify receipts and determine whether you have an active pro entitlement. Through that flow we receive:
- An anonymous RevenueCat subscriber ID generated for your install.
- The product identifier you purchased (
carets_pro). - The entitlement status (active / refunded).
- The store of origin (App Store or Google Play).
We do not receive your name, email, payment card, billing address, Apple ID, or Google account from the purchase flow. If you contact our support email with a purchase question we may ask you for an order ID so we can look up your entitlement in RevenueCat.
3.5 Information processed by Sign in with Apple / Google Sign-In (paid users only)
The App only invokes platform sign-in for two reasons: (a) you turned on paid cloud sync (so we can access your own iCloud / Drive container for notes); or (b) you opened an external file from Google Drive (Android only — Drive access uses the same Google sign-in).
- iOS — Sign in with Apple / iCloud: CloudKit / iCloud Drive use the Apple ID the device is already signed into. No additional sign-in is shown. Apple may share a stable, opaque user identifier with the App.
- Android — Google Sign-In: for notes sync we request the narrowest possible scope,
drive.appdata, which grants the App access only to a private folder it owns inside your Drive. For opening Drive-hosted external files we request thedrive.filescope, which grants per-file access only to the files you explicitly pick. We do not request access to your Gmail, contacts, full Drive, or any other Google data. The Google account email and OAuth token are stored on your device in Android Keystore-backed secure storage.
3.6 Information processed by the Site
The website at https://carets.app processes:
- Server request logs kept by our hosting provider (Vercel) for security and abuse prevention — including IP address, user-agent, and timestamp. These logs are retained per Vercel's standard retention.
- Google Analytics 4, only if you click "Accept" on the cookie banner. GA4 sets first-party cookies and collects pseudonymized event data (pages viewed, referrer, approximate location from IP, device class). IP anonymization is enabled. If you click "Decline," GA4 is held in denied consent state and collects nothing identifiable.
The Site does not run third-party advertising, retargeting, or social trackers.
3.7 Information we do not collect
- We do not collect advertising identifiers (IDFA, AAID) and do not use the App Tracking Transparency permission.
- We do not collect contact lists, photo library contents, microphone, camera, or location.
- We do not collect crash reports or telemetry from the App by default.
- We do not collect names, email addresses, phone numbers, or government identifiers — we have no account system.
4. How we use information
We use the limited information described above only for these purposes:
- To provide the editor and notes features (everything in 3.1 is used locally for this).
- To open and save your external files in place (3.2).
- To sync your internal notes to your own cloud, when you turn that on (3.3).
- To verify your purchase and unlock paid features (3.4).
- To respond to your support requests when you email us.
- To understand aggregate Site traffic, only if you accept analytics cookies (3.6).
- To detect and prevent fraud, abuse, and security incidents.
- To comply with legal obligations.
We do not use your information for advertising, profiling, scoring, or automated decision-making that produces legal effects about you.
5. Legal bases (GDPR / UK GDPR)
If you are in the EEA, UK, or Switzerland, we rely on:
- Performance of a contract (Art. 6(1)(b)) — for providing the App, cloud sync, and purchases you have asked for.
- Consent (Art. 6(1)(a)) — for analytics cookies on the Site. You can withdraw consent at any time via the Cookie Policy page.
- Legitimate interests (Art. 6(1)(f)) — for security, abuse prevention, and product integrity. We have weighed these interests against your rights and limited the processing accordingly.
- Legal obligation (Art. 6(1)(c)) — when we must retain or disclose information to comply with law.
6. Sharing and disclosure
We share information only with the categories of recipients listed below. We do not sell or "share" your personal information for cross-context behavioural advertising as defined by the California Consumer Privacy Act.
| Recipient | Why | Where |
|---|---|---|
| Apple, Inc. | App distribution (App Store), in-app purchases, iCloud storage (controlled by you), Files / iCloud Drive file access (controlled by you) | USA, Ireland |
| Google LLC / Google Ireland | App distribution (Play Store), in-app purchases, Drive storage (controlled by you), Sign-In, Google Analytics 4 (Site, opt-in) | USA, Ireland |
| RevenueCat, Inc. | Purchase receipt validation and entitlement status | USA |
| Vercel Inc. | Hosting and CDN for the Site | USA, EU |
| Email provider (transactional support) | Replying to messages you send to support@carets.app | USA / EU |
We may also disclose information if required by law, valid legal process, or to protect the rights, property, or safety of EchoPersona, our users, or others. We will challenge requests that we consider overbroad.
7. International data transfers
Some of the processors above are located in the United States. Where we transfer personal data outside the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses, the UK International Data Transfer Addendum, or other lawful transfer mechanisms maintained by each processor. iCloud and Drive data remains in the jurisdictions Apple and Google select for your account — please review their documentation.
8. Retention
- On-device data (internal notes, recent-files list, editor state, preferences) — retained until you delete it from the App, uninstall the App, or use Delete all data in Settings.
- Cloud-sync data — retained in your iCloud / Drive container until you (or Carets's Delete all data) delete it, or until you close the underlying Apple / Google account.
- External files you edited — we retain nothing. The file lives in your own storage (Files / iCloud Drive / Google Drive) under your control.
- Purchase records (RevenueCat) — retained for the life of your Pro purchase plus the period required to satisfy refunds, chargebacks, tax, and financial-record obligations (typically up to 7 years).
- Server logs (Vercel) — retained per Vercel's standard policy, typically days to weeks.
- Support emails — retained up to 24 months after the last interaction, unless we need longer to resolve a dispute or comply with law.
- Analytics events (GA4) — retained at the GA4 default of 14 months and not extended.
9. Security
- OAuth tokens and credentials live in iOS Keychain / Android Keystore via
expo-secure-store— never in plain SQLite or AsyncStorage. - All network traffic is TLS-only; no plaintext HTTP.
- The editor WebView ships with strict
originWhitelist,default-src 'none'CSP, and no universal access to file URLs. - External-file edits use the OS security-scoped file model so Carets can only touch the specific files you explicitly opened.
- Notes-database storage paths inside the App sandbox are UUID-based to limit path-traversal exposure; we may enable SQLCipher in a future release for at-rest encryption of the notes DB.
- The Site is served only over HTTPS with HSTS, strict CSP,
X-Frame-Options: DENY, and other hardened headers. - Dependencies are pinned and audited (
npm audit, Expo Doctor) in CI. - Despite all of this, no method of storage or transmission is 100% secure. We will notify affected users and the relevant authorities of a personal data breach as required by applicable law.
10. Children
Carets is not directed at children under 13 (or under 16 in jurisdictions where that is the relevant age of digital consent). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact contact@carets.app and we will delete it. We do not request the App Tracking Transparency prompt or collect any advertising identifiers, which is the strongest privacy posture for child users per Apple and Google policy.
11. Your rights
11.1 Everyone — built into the App
Regardless of where you live, the App gives you direct control:
- Access / export. Pro users can export internal notes to Markdown, PDF, or plain text from Settings → Export. External files remain in their original format wherever you stored them.
- Erasure. Settings → Delete all data erases the local notes database, the recent-files list, editor state, and (if cloud sync is on) the contents of your iCloud / Drive container. We delete cloud first, then local, and surface failures explicitly. External files in your own cloud are not deleted by this — they're yours; remove them in iCloud Drive / Google Drive / Files.
- Uninstall. Removing the App from your device deletes all on-device data instantly; it does not by itself delete cloud-synced notes (use Delete all data first if you want both gone), and it does not affect external files in your own cloud.
11.2 EEA / UK / Switzerland (GDPR)
You have the right to:
- Access the personal data we hold about you.
- Have inaccurate data rectified.
- Have your data erased.
- Restrict or object to processing.
- Receive your data in a portable format.
- Withdraw consent at any time (with no effect on prior lawful processing).
- Lodge a complaint with a supervisory authority. The lead authority depends on your country of residence; the European Data Protection Board lists them all.
Because the App stores almost everything on your device, most of these rights are exercised directly inside the App. For anything that requires us to act (e.g., RevenueCat records, support email history), contact contact@carets.app.
11.3 California (CCPA / CPRA)
California residents have the right to:
- Know what personal information we collect, use, disclose, and (if applicable) sell or share.
- Delete personal information we hold about you.
- Correct inaccurate personal information.
- Limit the use of sensitive personal information (we do not use any).
- Opt out of "sale" or "sharing" — we do not sell or share personal information in the CCPA sense.
- Be free from retaliation for exercising these rights.
We have not sold or shared personal information in the preceding 12 months. You may exercise your rights via contact@carets.app. We will verify your request using information you have already provided us (for example, the order ID from your store receipt).
11.4 Other jurisdictions
Residents of other US states with comprehensive privacy laws (Colorado, Virginia, Connecticut, Utah, Texas, Oregon, Montana, and others), as well as residents of Brazil (LGPD), Canada (PIPEDA), Australia (Privacy Act), and similar regimes, may have analogous rights. Contact us and we will honour them to the extent your applicable law requires.
12. App Store privacy disclosures
Our App Store "Privacy Nutrition Label" and Google Play "Data Safety" disclosures are kept consistent with this policy. In summary:
- Data Not Collected for the free experience.
- Purchases — collected and linked to you to provide the service (not used for tracking).
- User Content (internal notes you write; external files you edit) — handled on-device or, for paid users, in your own iCloud / Drive container; not collected by us.
- If you opt in to analytics on the Site, the Site discloses Usage Data processed by Google Analytics for analytics purposes — this is a Site disclosure and is independent of the App.
13. Do Not Track and Global Privacy Control
We honour the Global Privacy Control (GPC) browser signal as an opt-out of analytics cookies on the Site. If your browser sends GPC, we treat it as a "Decline" choice on the cookie banner.
14. Changes to this policy
We will update this policy when the App or Site changes in ways that affect how we handle data. Material changes will be highlighted in the App or on the Site for at least 30 days before they take effect. The "Last updated" date at the top reflects the most recent revision. Continued use of the Services after a change means you accept the revised policy.
15. How to contact us
Privacy questions, requests, or complaints: contact@carets.app.
General support: support@carets.app.
Operated by EchoPersona (New Mexico (United States)).