Privacy
Last updated: 2026-05-29.
Karte is a personal profile + chat product. Here is exactly what we store, what we send to third parties, and how to remove your data. We aim to be specific, not legalistic.
What we store
- Your Google OAuth identity (email, name, profile image URL) for sign-in.
- Profile content you enter: bio, links, projects, info blocks (chat memory), timeline events, page sections, theme + accent.
- Avatar and project images you upload — stored in Cloudflare R2 under the karte.cc account.
- AI-generated content for your profile (encyclopedia, newspaper, roast) — cached so repeat visitors don’t re-trigger generation.
- Anonymous visitor identifiers: a first-party cookie (
lc_vid, 2-year expiry) and a localStorage mirror, used to attribute page views and chat sessions. - Visitor chat conversations (transcript, visitor email, timestamps) saved against the page they were started on — so the page owner can read what people are asking.
- Email addresses entered into the visitor chat gate or the agent waitlist on the landing page.
- Anonymous analytics events (clicks, scrolls, mode triggers) tagged by visitor cookie.
Third parties we send data to
- Cloudflare — hosts the application (Workers), the database (D1), and uploaded images (R2). Cloudflare receives traffic logs by default.
- Google — handles sign-in via OAuth; receives the standard auth metadata.
- PostHog (us.i.posthog.com) — receives anonymous product analytics events (page views, button clicks, AI-component renders, errors). We identify by visitor cookie, not by name or email.
- AI inference providers — chat queries, page content sources, and generation prompts are sent to the AI gateway (default: a free-ai-gateway service routing to Cloudflare Workers AI; optionally to a key the profile owner configures). Providers may log requests for abuse prevention; we do not share your data with them for training.
What we don’t do
- We don’t sell your data.
- We don’t serve third-party ads.
- We don’t fingerprint visitors with cross-site trackers.
- We don’t share visitor chat transcripts with anyone other than the page owner.
Public vs private
Profiles are public by default — your slug, bio, links, projects, and timeline are visible to anyone with the URL. You can set a profile private from the dashboard; private profiles return 404 to anyone but the owner.
Deletion
Delete your profile from the dashboard to remove all stored content — page row, links, projects, info blocks, timeline events, generated pages, conversations, and R2 avatar/image uploads. Visitor analytics events keyed to your slug are retained anonymously for fleet metrics but are no longer queryable in any user-facing surface.
Email sarthak@vaultwealth.com if you need help removing data or if anything on this page is inaccurate.