We’re asking you to trust us with your most valuable company data, and you deserve to know—in plain English—how we’ll handle it.
You authorize Carom through Google or Microsoft directly. They hand us a token you can revoke at any time, from their site, without asking us.
We ask for the smallest amount of access we can to fulfill our promises to you, and we never import data we don’t need.
Carom reveals what’s in your inbox—we don’t try to replace it. We never delete your mail, so you keep the canonical records.
You decide what your team sees, contact by contact or thread by thread. Threads you keep private are visible to you and no one else on your team.
Every connection uses bank-level cryptography to transmit information, and stored content is encrypted.
Cancel anytime. We delete everything we imported, and your inbox (as always) remains your own.
Carom sends email only when you write a message and click send. Never on its own, never in bulk, and no agent can send on your behalf.
When you connect a mailbox, you authorize Carom through your email provider (Google or Microsoft). Your provider gives us a token rather than your password, and you can revoke it from your provider’s security settings at any time. Here is exactly what we ask for and why:
Read and starred status are the only things we ever write back. We never delete your mail, and never move, archive, or re-label it.
We never store data that isn’t directly shown in Carom (email subjects, contacts, etc.) or used to power the screens we display (internal IDs that allow us to identify emails sent to multiple mailboxes, for example). In practical terms, that data includes:
We fetch and store full message text and attachments when we need them—to display a thread, preview or download a file, or let an agent summarize a conversation. We never sell your data, and we never share your content with anyone beyond the vendors listed in our Privacy Policy—or where we’re legally compelled to, in which case we’ll tell you unless we’re prohibited from doing so.
We’re always balancing privacy and transparency: our goal is to enable collaboration, after all. But we follow the principle that anything you share with colleagues is done explicitly. You (or your account administrator) can create shared mailboxes, like sales@yourorganization.example, which you can choose to show to people in your organization. Carom never shares your own emails, files, and events within your account unless you explicitly choose to share them, and you can limit that sharing to certain individuals or groups and revoke access at any time.
One thing worth being direct about: that promise governs what Carom does, not who controls your mailbox. If your employer administers your Google Workspace or Microsoft 365 account, they can reach it at the provider, and no setting here changes that. What we can promise is that we won’t hand your data to anyone else on request—including an employer asking for a departed colleague’s. We say no.
Carom’s agents—the ones that summarize threads, tag conversations, and turn emails into tasks—need access to your information to work. They run inside our own infrastructure, and every AI vendor we use is contractually barred from training on your data. If you don’t want the agents to see this data, you can turn them off. Your data is not used to train any AI models.
Machines reading your mail is how the product works. People are a different matter: nobody at Carom reads your email unless you ask us to look at something. We hold no standing access to your content. If you report a problem we can’t solve without looking, we’ll ask first and you can say no—and when you say yes, access is scoped, time-boxed, and logged.
Carom runs on infrastructure hosted with Ubicloud and Amazon Web Services, with stored content encrypted and access to our servers tightly restricted. The complete, current list of vendors we partner with to deliver our services is always in our Privacy Policy.
Cancel whenever you like. We’ll terminate billing as soon as you cancel, and you can choose to end your access then or at the end of your current billing period. After a short recovery window, we delete the data you provided and everything we imported from your mailboxes.
Encrypted backups take a little longer to age out—up to 45 days. A backup can’t be selectively edited, so we record every deletion outside the database and re-apply it to any restore. Data you deleted doesn’t come back to life.
This page is the deal in plain English; the Privacy Policy is the same deal in full detail. If anything here is unclear—or you have a question we didn’t answer—email us at partner@carom.io and we’ll walk you through it.
Want to see Carom without connecting anything?
The live demo runs on sample data—no signup, no email access, nothing to revoke.