Privacy Policy
Last updated: July 17, 2026
Cariktr is a service of Copperhead Holdings LLC. This Privacy Policy explains how Copperhead Holdings LLC ("Cariktr," "we," "us," "our") collects, uses, shares, and protects information when you use the Cariktr mobile applications, website (cariktr.com), hardware (window decals and Bluetooth beacons), and all related products, features, and services (collectively, the "Service"). It applies to vehicle owners, members of the public who interact with Cariktr personas, business users, and visitors to our website.
By using the Service, you acknowledge the practices described here. Please also review our Terms of Use and Content Policy.
1. Information We Collect
We collect information you provide, information generated through your use of the Service, and information from third parties. We collect this broadly to operate, secure, personalize, analyze, improve, and monetize the Service, including through analytics and advertising.
A. Information you provide directly
- Account information: name, display name, email address, password/authentication identifiers, and (if you use Apple, Google, or Facebook sign-in) the identifiers and basic profile information those providers return.
- Profile and owner information: vehicle details (year, make, model, color, trim, history), persona configuration and personality settings, public descriptions, and photos or media you upload.
- Business information: for business users, business name, address, hours, contact details, logos, event details, and related content.
- Payment and transaction information: processed by our payment processors and the app stores. We receive transaction confirmations, amounts, and limited billing details, but we do not store full payment card numbers.
- Communications: messages, support requests, appeals, survey responses, and feedback you send us.
B. Conversation and content data
- Voice and audio: recordings of your spoken conversations with Cariktr personas.
- Transcripts and derived data: text transcripts of conversations and AI-derived summaries, "memories," ratings, sentiment, topics, and other inferences generated from them.
- Uploaded media and metadata: photos and any associated metadata, screened for policy compliance before becoming public.
C. Information collected automatically
- Device and technical information: device type and model, operating system and version, app version, language, time zone, network/carrier information, screen attributes, crash logs, and diagnostic data.
- Identifiers: IP address, user and device identifiers, installation IDs, session IDs, and mobile advertising identifiers (Apple IDFA, Google Advertising ID) where permitted.
- Location information: precise (GPS) and/or approximate (IP, network) location. Precise location is used for event check-in (to confirm you are at a listed event) and may be used, where permitted, for nearby features, analytics, and location-relevant advertising. You control location permissions in your device settings.
- Proximity / Bluetooth: Bluetooth is used to detect a vehicle's beacon to confirm physical proximity. The beacon is a one-way transmitter and does not itself collect information about you; we log proximity/scan events.
- Usage and analytics data: see Section 4 for the categories of activity and metrics we measure.
- Cookies and similar technologies: on our website and within the app, including SDKs and pixels used for functionality, analytics, and advertising (Section 8).
D. Information from third parties
- Sign-in providers: Apple, Google, and Facebook provide identifiers and basic profile data when you use social sign-in.
- Advertising and analytics partners: ad networks (e.g., Google AdMob) and analytics providers may share measurement, attribution, and audience signals with us.
- Service providers: vendors that help us run the Service may provide related data.
2. How We Use Information
We use information to:
- Operate the Service: authenticate accounts; run voice conversations; build and serve the social feed (posts, likes, comments, follows); award and manage points and rewards; run leaderboards, awards, featured listings, and similar features; process orders; and ship and support hardware.
- Personalize experiences: create persona and user "memories" so returning visitors can be recognized and conversations feel continuous. Non-sensitive personal details (e.g., a first name, what someone drives) may be remembered; we instruct our systems not to retain sensitive data such as government identifiers, financial account numbers, or health information.
- Analyze, measure, and improve: understand engagement and performance, conduct product analytics and business intelligence, run experiments and A/B tests, measure feature adoption and retention, and inform pricing, product, and roadmap decisions (Section 4).
- Advertising and monetization: serve and measure advertising on the free tier, including personalized/targeted advertising and audience building where permitted (Section 5). Paid subscribers receive an ad-free experience.
- Safety and integrity: screen uploaded photos and conversations for policy compliance, detect and prevent fraud and abuse, and enforce our Terms and Content Policy.
- Communicate: send service, transactional, and (where permitted) marketing messages.
- Comply with law: meet legal, regulatory, tax, and accounting obligations and respond to lawful requests.
3. AI Processing
Conversations, transcripts, and uploaded photos are processed by Cariktr and by third-party AI providers (for speech-to-text, conversational AI, language generation, content moderation, and related functions). AI may produce inaccurate or unexpected output. Public feed posts are generated to exclude personally identifying information about any specific individual. We may use de-identified or aggregated conversation and usage data to improve our models, prompts, moderation, and Service.
4. Analytics and Metrics We Assess
To run, improve, and monetize the Service, we collect and analyze a broad range of activity and performance data, which may include: conversation counts, duration, message counts, ratings, sentiment, topics, and completion; scan, beacon-proximity, and check-in events; points earned and redeemed and reward activity; feed engagement (views, likes, comments, follows, shares); featured listings, leaderboards, and awards activity; business scans, mentions, sponsorships, and event participation; screen views, taps, navigation paths, search queries, session counts and length, feature usage, retention and churn, conversion and funnel metrics; app performance, crashes, errors, and latency; device, location, and demographic/audience signals; and advertising metrics such as impressions, clicks, attribution, and conversions. We may combine these into aggregated statistics, audience segments, and inferences to operate the Service, guide product and pricing decisions, and support advertising.
5. Advertising and Targeting
On the free tier, the Service is supported by advertising, including through third-party ad networks (e.g., Google AdMob). Depending on your settings and applicable law, ads may be personalized/targeted using identifiers (such as the IDFA/Google Advertising ID), device, usage, location, and inferred-interest data, and we and our partners may measure ad performance, attribution, and conversions and build audience segments. On Apple devices, personalized advertising that involves cross-app tracking is subject to the App Tracking Transparency prompt and your choice. You can limit ad personalization through your device's advertising settings, and a paid subscription removes ads.
6. How We Share Information
- Service providers / sub-processors: including hosting and database (e.g., Supabase), conversational voice/AI and speech processing (e.g., Cartesia, Deepgram, LiveKit, ElevenLabs), language and moderation AI (e.g., Anthropic), web/data search, advertising (e.g., Google AdMob), analytics, payments, email, shipping/fulfillment, and identity/verification providers — under contracts that limit their use of the data to providing services to us.
- Advertising and analytics partners: as described in Sections 4–5, for advertising, measurement, and analytics.
- Public content: AI-generated feed posts and content you choose to make public (e.g., vehicle photos, persona, public descriptions) are visible to other users and may appear on our website and promotional materials.
- Business users: when you interact with a participating business (e.g., scan, check in, or attend an event), related engagement data may be shared with that business in aggregated or limited form.
- Legal and safety: when required by law or legal process, or to protect the rights, property, safety, or security of Cariktr, our users, or the public.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets.
We do not sell your personal information for money. However, certain sharing for targeted advertising or analytics may be considered a "sale" or "sharing" of personal information under some US state laws — see Section 11 for how to opt out.
7. Sensitive and Voice Data
Conversations with Cariktr personas are voice conversations. In plain terms, here is what happens to your voice:
- Recording and transcription: when you talk to a persona, your audio is captured and processed in real time to transcribe what you say and generate the persona's reply. We ask for permission to use your microphone before any of this happens.
- What we keep: we store the text transcript of the conversation and data derived from it (summaries, "memories," ratings, topics). Transcripts are kept for as long as your account is active plus a reasonable period afterward, unless you delete your account (Section 10) or the law requires us to keep specific records longer.
- Voice cloning: if we offer custom persona voices created from a vehicle owner's own voice recordings, we create such a voice only with that owner's explicit consent, and only from recordings the owner deliberately provides for that purpose. We never create a cloned voice from visitors' conversation audio.
- No voice identification: we do not use your voice to identify you (no voiceprint authentication or biometric identification).
Voice recordings and certain conversation content may be considered sensitive or biometric-adjacent in some jurisdictions. We instruct our systems not to retain sensitive personal data shared in conversation. Where required, we will obtain consent and provide additional disclosures before collecting or using such data.
8. Cookies and Tracking Technologies
We and our partners use cookies, SDKs, pixels, local storage, and similar technologies for authentication, preferences, security, analytics, and advertising. You can control cookies through your browser settings and mobile ad/tracking settings. Some features may not function properly without certain technologies. We aim to honor recognized opt-out signals such as the Global Privacy Control (GPC) where required.
9. Your Choices and Controls
- Device permissions: microphone, location, Bluetooth, photos, and notifications are controlled in your device settings.
- Advertising: use your device's ad-personalization/tracking controls; respond to the App Tracking Transparency prompt on Apple devices; or subscribe to remove ads.
- Marketing: opt out of marketing emails via the unsubscribe link.
- Account data: request access, correction, export, or deletion (Sections 10–11). In-app account deletion is available and removes your account and associated data, subject to legal retention.
10. Data Retention
We retain information for as long as needed to provide the Service and for legitimate business, analytics, advertising, security, and legal purposes. Conversation memories persist to support recognition of returning visitors. Aggregated or de-identified data may be retained indefinitely. When you delete your account, or when an owner's account lapses, we delete or de-identify associated personal data after a reasonable grace period, except where retention is required by law or for fraud prevention, dispute resolution, or enforcement. Specifically, after account deletion:
- Conversation transcripts you created are deleted; anonymized conversation statistics (counts, durations) may be retained without your identity.
- Safety records: if your account was flagged, suspended, or banned for content or conduct violations, we retain a minimal record (name/email, violation history, and short transcript excerpts of the violating conversation) to prevent a banned user from re-registering, and conduct-review records are otherwise retained with your account identifiers removed.
- Purchase and transaction records are retained as needed for accounting, tax, refund, and fraud-prevention purposes, with shipping details removed where we can.
11. Your Privacy Rights (US State & International)
Depending on where you live — including California (CCPA/CPRA), other US states (such as Virginia, Colorado, Connecticut, Utah, and others), and the EU/UK/EEA (GDPR/UK GDPR) — you may have rights to access, correct, delete, or port your personal data; to opt out of targeted advertising, the "sale"/"sharing" of personal information, and certain profiling; and to limit the use of sensitive personal information. EU/UK users may also object to or restrict certain processing and lodge a complaint with a supervisory authority; our legal bases include performance of a contract, legitimate interests, consent, and legal obligation. To exercise rights, contact privacy@cariktr.com. We will verify your request and respond as required by law, and we will not discriminate against you for exercising your rights. You may use an authorized agent where permitted.
12. Canadian Users (PIPEDA)
If you are in Canada, we handle your personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws.
- Meaningful consent: we collect, use, and disclose your personal information with your consent, obtained in context — for example, we request microphone permission before any voice conversation, and conversations with personas are recorded and transcribed as described in Section 7. For sensitive information — including any voice-cloning feature that uses a vehicle owner's own voice recordings — we obtain express consent before collection. You may withdraw consent at any time (for example, by revoking device permissions or deleting your account), subject to legal or contractual restrictions; withdrawing consent may limit the features we can provide.
- Access and correction: you may request access to the personal information we hold about you, information about how it has been used and disclosed, and correction of inaccurate or incomplete information, by contacting privacy@cariktr.com. We will respond within the timelines PIPEDA requires.
- Cross-border transfers: we store and process personal information in the United States, using service providers located there (including our hosting, voice/speech, AI, payment, and advertising providers listed in Section 6). While your information is outside Canada, it is subject to the laws of those jurisdictions, including lawful access by courts and authorities there. Our service providers are bound by contracts requiring protection comparable to this Policy.
- Challenging compliance: our privacy contact (Section 17) is accountable for our PIPEDA compliance. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada (priv.gc.ca).
13. Security
We use reasonable technical and organizational safeguards (such as encryption in transit, access controls, and server-side handling of sensitive keys) to protect information. No system is perfectly secure, and we cannot guarantee absolute security.
14. Children's Privacy
The Service is intended for users 13 and older and is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Because members of the public — including minors — may scan a Cariktr code in public settings, conversations are held to family-friendly safety rules and our systems are instructed not to solicit personal information. We do not knowingly serve targeted advertising to children. If you believe a child under 13 has provided personal information, contact us at privacy@cariktr.com and we will delete it.
15. International Transfers
We may process and store data in the United States and other countries that may have different data-protection laws than your own. Where required, we use appropriate safeguards for cross-border transfers.
16. Changes to This Policy
We may update this Policy from time to time. Material changes will be notified in the app, on our website, or by email. The "Last updated" date above reflects the latest revision.
17. Contact
Copperhead Holdings LLC (operator of Cariktr) — privacy@cariktr.com Mailing address: ⟨BUSINESS ADDRESS — pending from owner⟩