What we collect, who touches it, what we never do with it, and how to get it deleted
This policy covers Bankshot Software, LLC, doing business as Carom ("Carom," "we," "us," "our"), and everything we offer—our websites, apps, APIs, and platforms (the "Services"). It applies to Customers and Users as those terms are defined in the Customer Terms of Service and User Terms of Service, to visitors to our website, and to people whose information reaches us because someone who uses Carom corresponded with them.
Last updated: July 26, 2026
The sections below give the same information in full.
Different rules apply to each. We use these four terms throughout.
| What it means | |
|---|---|
| Customer Content | Your mail, attachments, calendar, contacts, the comments and tasks you create, and the summaries, tags, and inferences we generate from them. |
| Account Data | Names, sign-in details, billing information, and support correspondence. |
| Service Data | Logs, usage events, performance measurements, and error reports about how the Services are running. |
| Feedback Data | A specific item, and the thread behind it, that you deliberately send us for review. |
For Customer Content, we act on our Customer’s instructions and use it only to run the Services for them. For Account Data and Service Data, we decide the purposes ourselves — billing you, keeping the Services secure, and understanding what to fix and build. Feedback Data we use only for the purpose you submitted it.
Carom is offered for business, professional, nonprofit, and organizational use to customers in the United States. It is not offered for personal, family, or household purposes, and you must be at least 18 to use it. We do not currently offer the Services in the European Union, the United Kingdom, or other regions with data-transfer requirements we have not built for.
Your Customer Content is stored and processed in the United States. Two of our vendors are European and hold Service Data there: AppSignal, which monitors performance, stores in the Netherlands, and Better Stack, which manages our application logs, stores in the European Union. Those logs can include IP addresses and request details. Everything else — your mail, attachments, calendar, contacts, and account records — stays in the United States.
Payment information (Account Data). A billing name, ZIP code, email address, and card details. Card numbers go directly to Stripe. We never see or store them.
Sales and support correspondence (Account Data). Email you send us and forms you complete.
What you create in Carom (Customer Content). Comments, tasks, notes, tags, flags, and shares.
Feedback you submit (Feedback Data). If you tell us an AI summary is wrong and choose to send it to us, you are handing us that summary and the thread behind it. This happens only when you click the button, applies only to the item you submitted, and is logged. We do not go looking on our own.
How we connect. For Google (Gmail and Workspace) and Microsoft (Outlook and Microsoft 365), you authorize us through your provider. We never see your password. Your provider issues a token, and revoking it in your provider’s security settings cuts our access off immediately and completely. Data already imported stays in the account until you delete the mailbox or the account.
What we ask for.
| Access | Purpose |
|---|---|
| Read your mail | Sync, display, search, and summarize your conversations |
| Update read and starred state | Mirror changes you make in Carom back to your mailbox |
| Send mail | Reply from within Carom |
| Read your calendar | Show events and connect them to related people and threads |
| Read your contacts | Fill in names and details for people you correspond with |
Google Workspace and Gmail data. Carom’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Writing to your mailbox. We never delete your mail, and never move, archive, or re-label it. The only things we write back are read/unread and starred/flagged status when you change them in Carom.
Sending. Carom sends email only when you write a message and click send. It never sends on its own, never sends in bulk, and no AI agent can send on your behalf.
What we store. For most messages, metadata: sender and recipient names and addresses, subjects, short snippets, dates, folders and labels, read and flag status, thread sizes, and file names, sizes, and types. We store full message text and full attachments where the product needs them — to display a thread, to preview or download a file, or for an agent to summarize a conversation. From your calendar: events, times, locations, and attendees. From your contacts: names and addresses.
Data about other people. Mailboxes contain information about the people you correspond with, who never signed up for anything. We treat that information as Customer Content held in the account that imported it. We claim no ownership of it, and the account’s Customer controls what happens to it. See If you are not our customer below.
Regulated and sensitive information. General-purpose mailboxes can contain health, financial, and other sensitive records. Carom is not designed for regulated data and we do not sign Business Associate Agreements. The Customer Terms prohibit using the Services to handle protected health information on behalf of a covered entity or business associate.
Log data. Our servers record requests: IP address, browser and device information, pages visited, and request details. We filter passwords and tokens out of our logs.
Error data. When something breaks, we record what happened.
Usage events. Which features get used and how often, tied to an account and user.
Cookies. See Cookies and local storage.
Automated processing is broad. Our software — including AI models running inside our infrastructure — reads your messages, attachments, calendar, and contacts to sync them, index them for search, summarize threads, extract tasks, apply tags, build your briefing, and diagnose problems. This runs continuously.
People are a different matter. No one at Carom reads Customer Content in the ordinary course of business, and we maintain no standing access to it. A person at Carom reads your content only:
The last two do not require your consent. Both are rare, limited to what the circumstance requires, and logged.
Where we can diagnose a problem by having our automated tools examine the content and report back a description of the technical fault, without a person seeing your message, that is what we do.
These promises are about Customer Content. We do use Account Data and Service Data for our own operational purposes, as described above.
We use a small number of vendors to run the Services. Each receives only what it needs.
| Vendor | Purpose | What it receives | Where |
|---|---|---|---|
| Amazon Web Services | File storage, database backups, and AWS Bedrock, which runs the models behind our summaries, tagging, and briefings | Customer Content — attachments, message text and metadata, calendar and contact data — plus backups and profile images | United States |
| Ubicloud | Application and database hosting | All stored data | United States |
| Stripe | Payment processing | Account Data: billing name, ZIP, email, card details | United States |
| Sentry | Error tracking | Service Data: error reports including IP address, OS, and browser version | United States |
| AppSignal | Performance monitoring | Service Data: request performance data | Netherlands |
| Better Stack | Log management | Service Data: application logs | European Union |
| PostHog | Product analytics | Service Data: usage events tied to an account and user ID. No Customer Content, no cookies. | United States |
| Postmark | Transactional email | Account Data: your email address and the contents of messages we send you | United States |
| Apple | Push notifications to the iOS app | Device tokens and notification content, which can include Customer Content | United States |
| Google Ads | Measuring whether our advertising works | The click identifier from one of our ads plus the fact that a signup occurred. No name, email, or Customer Content. | United States |
The current list lives on this page. Before a new vendor that handles Customer Content begins processing, we will update it and email every affected Customer, except where a vendor must be replaced urgently for security or continuity, in which case we notify promptly afterward. Anyone else who wants to be told of changes can email privacy@carom.io.
Beyond the vendors above, we disclose data only when legally required — a valid subpoena, warrant, or court order — where we reasonably believe it necessary to prevent serious harm, or in connection with a merger, acquisition, or sale of assets as described below. If we receive legal process for your data, we will tell you unless we are prohibited from doing so.
If Carom is involved in a merger, acquisition, or sale of assets, your data may transfer as part of it. Data obtained through Google Workspace APIs will not transfer without your explicit prior consent, as Google’s policies require.
We do not use Customer Content for anything beyond the first, third, fifth, and seventh of these. If we want to, we will ask first and explain what we want and why — and sending you a notice is not the same as asking, so a use that needs your consent will not begin until you give it.
We encrypt data in transit with TLS and at rest. Mailbox credentials and tokens are encrypted separately with AES-256-GCM under keys we rotate. Production access is restricted and requires multi-factor authentication. Our hosting providers — Ubicloud and Amazon Web Services — operate the physically secured data centers our servers and storage run in. Backups are encrypted and written to storage our application cannot read, list, or delete.
We never store your card number. Stripe does, as a PCI Level 1 certified processor.
No system is perfectly secure. A security incident means unauthorized access to, or the acquisition, loss, disclosure, destruction, or alteration of, data we hold about you. Routine unsuccessful events — blocked attacks, failed logins, port scans, pings — are not security incidents and we do not notify on them.
If we discover a security incident, we will give notice without undue delay after becoming aware of it, and no later than 72 hours after discovery, or sooner where the law requires, with what we know at the time. We will follow up as we learn more rather than waiting for a complete picture.
Who we notify depends on whose data is involved. For Customer Content, we notify the affected account’s Customer, who decides what to tell the people in their account. For Account Data and Service Data — which we hold as controller — and for website visitors, we notify affected individuals directly. We notify regulators wherever the law requires it.
Reporting vulnerabilities. Send findings to security@carom.io. We will not pursue legal action for good-faith research that gives us reasonable time to respond and does not access data belonging to others.
While your account is open, we keep the data you have given us and imported.
When you cancel, your account closes at the end of your current billing period. Seven days later we delete the Customer Content we imported from your mailboxes — messages, attachments, contacts, calendar events, files — along with the content created in your account.
Backups persist longer. Encrypted backups expire permanently within 45 days. Because a backup cannot be selectively edited, we record every deletion outside the database and re-apply those deletions to any restore. Data you deleted does not return through a restore.
By category:
| How long | |
|---|---|
| Customer Content | Until deleted, or 7 days after account closure |
| Account Data | Duration of the account. Invoice, transaction, and tax records are kept 7 years; sign-in records are deleted with the account |
| Support correspondence | 3 years from the last message |
| Service Data (logs, errors, usage) | Up to 24 months, then deleted or aggregated so it no longer identifies you |
| Security and audit logs | Up to 24 months, except records of human access to Customer Content, which are kept for the life of the account |
| Feedback Data | Up to 24 months from submission |
| Ad click identifiers | 90 days |
| Encrypted backups | Up to 45 days |
We keep material longer where a legal hold or an active dispute requires it, and we do not attempt to re-identify data we have aggregated.
You can delete individual mailboxes, and their content, at any time without closing your account.
We extend the following to everyone who uses Carom, wherever you live, rather than only where a statute requires it:
We do not sell your personal information and do not share it for cross-context behavioral advertising.
Some state privacy laws add rights beyond this baseline once a business meets their thresholds. Where such a law applies to us, we will honor its additional requirements; the baseline above applies regardless.
Who answers depends on the data. For Account Data and Service Data, we decide the purposes, so we respond to you directly. For Customer Content, we hold it on our Customer’s behalf and they decide — so we route your request to them and assist them in answering it. We are not entitled to make decisions about a Customer’s data on our own.
To exercise any of these, email privacy@carom.io. We will verify the request is yours before acting on it and will respond within 45 days. You may use an authorized agent; we will ask for proof of their authority. We may decline or narrow a request where the law requires it, where we cannot verify you, or where fulfilling it would compromise security, waive a privilege, or expose someone else’s information.
If we hold your data because you corresponded with someone who uses Carom, email privacy@carom.io. That data sits in a customer’s account under their control, so in most cases we will route your request to them and help them act on it.
We do not use cookies or identifiers to personalize advertising or to track you across unrelated services. We use no advertising pixels, no third-party trackers, and no session recording. Our product analytics run without cookies.
What we do use:
You must be at least 18 to use Carom, and we do not knowingly collect personal information from anyone under 18 as a user of the Services. If we learn that we have, we delete it.
Separately: mailboxes we import can contain information about children. We do not seek it out or use it for anything beyond running the Services, and it is deleted along with everything else when an account closes.
We will update this policy as the product and the law change. The current version, with its date, is always at carom.io/policies/privacy, and we keep prior versions on request. If a change materially affects your privacy, we will email you or tell you in the product before it takes effect. Changes are not retroactive: they do not alter how we handled data before the change, and a use that requires your consent does not begin until you give it.
Email: privacy@carom.io
Mail: Bankshot Software, LLC d/b/a Carom c/o Legalinc Corporate Services Inc. 131 Continental Drive, Suite 305 Newark, DE 19713