Skip to content
Carouly

Privacy

What we store, and who else sees it

Last updated 2 August 2026

What we collect

Your account details come from Clerk, our authentication provider: an email address, and whatever your identity provider passes along if you sign in with one. We never see or store your password.

Everything else is what you type in: your brand profile, your keyword bank, your carousels, and the schedule you set. Generated slides are stored as images in Supabase Storage.

Connected social accounts

When you connect Instagram, LinkedIn, X or a Facebook Page, we store the access token that platform issues us, encrypted at rest. It is used for one thing: publishing the carousels you scheduled. Disconnecting an account deletes the token.

Third parties

  • Clerk, for authentication.
  • Supabase, for the database and image storage.
  • OpenRouter, for the models that write the slides and generate hook images. Your brand profile and the chosen keyword are sent with each request.
  • Google Suggest and DuckDuckGo autocomplete, for keyword research. These receive search stems derived from your brand profile, and no account information.
  • Vercel, for hosting and request logs.

What we do not do

We do not sell your data, we do not use your brand profile or generated content to train models of our own, and we do not read your social inboxes. The tokens we hold carry publishing scopes only.

Deleting your account

Email us and we will delete your brand, keywords, carousels and stored images, and revoke every social token, within 30 days. Request logs held by our hosting provider expire on their own retention schedule.

Contact

Questions about any of this can go to the address in your account settings.