Privacy policy
Privacy Policy
Last updated: 27 August 2026
This policy covers testcaroufy.com and the Caroufy for Agencies application. It describes what we collect, why, how long we keep it, and who else sees it. There is no analytics, no tracking pixel, and no third-party advertising script on this site or in the product.
What we collect
Account information. When an Owner creates an account, we collect a name, work email, and password (stored as a salted hash, never in plain text). Admins, Designers, and Client Reviewers added to a workspace provide a name and email when they're invited.
Uploaded and generated content. Source material you paste or upload to generate a carousel (text, PDFs, images used in a brand kit), and the carousel drafts, comments, and export files produced from it, are stored so the workflow described on the overview page — draft, review, approval, export — actually works. This content belongs to you or your client, not to us; see the Terms of Service for the license we need to operate on it.
Client reviewer access. When a Client Reviewer link is generated, we log the recipient email, the workspace it's scoped to, and its expiration (14 days from issue). We do not require a Client Reviewer to create a password-based account.
Billing information. Payment is handled by a third-party payment processor. We store the plan, seat count, workspace count, and billing history; we do not store full card numbers on our own servers.
Operational logs. Server logs capture IP address, timestamp, and request path for security and abuse prevention, retained for 90 days and then deleted on a rolling basis.
What we don't collect
No advertising cookies. No cross-site tracking. No sale of personal information to data brokers. No behavioral profiling for marketing purposes. This site sets no cookies for analytics; the only cookie the application uses is a session cookie required to keep you signed in, which is not shared with any third party.
How data is used
Account and content data is used to operate the product: to render your workspaces, enforce the role permissions described on the overview page, route drafts through approval, generate exports, and produce the per-workspace delivery log. Email addresses are used for account notifications (review requests, approval status, billing receipts) and, if you've separately opted in, occasional product updates. Operational logs are used only for security monitoring and debugging.
Who it's shared with
We share data with the infrastructure providers that host the application and store files, and with the payment processor that handles billing — each bound by their own data protection obligations and used only to provide the service. Content inside a client workspace is visible to the people you've explicitly assigned to that workspace (via roles and permissions) and to nobody else. We do not sell or rent personal information.
Data retention and deletion
Workspace content is retained for as long as the account is active. If an account is canceled, exported files and drafts are retained for 30 days to allow recovery, then permanently deleted. You can request deletion of a specific client workspace at any time by contacting us; deletion is irreversible and typically completed within 7 days.
Your choices
You can access, correct, or delete your account information from account settings, or by emailing us. You can unsubscribe from any mailing list at the link in that email or via our unsubscribe page; unsubscribing does not affect transactional emails required to operate an account you keep active (approval requests, billing receipts).
Changes to this policy
If this policy changes materially, we'll update the date at the top of this page and, for account holders, note it in the product. Continued use of the service after a change constitutes acceptance of the updated policy.
Contact
Questions about this policy or a specific data request can be sent to hello@testcaroufy.com.