Cartha logoCartha
Sign in

Privacy Policy

Effective date: 1 July 2026  ·  Last updated: 28 July 2026

1. Who We Are & Scope of This Policy

Cartha Inc. (“Cartha”, “we”, “us”, or “our”) operates the Cartha agent operations platform, including the web dashboard, REST API, Python SDK, TypeScript SDK, and any associated integrations (collectively, the “Services”). This Privacy Policy explains how we collect, use, store, share, and protect personal and operational data when you access or use the Services.

This Policy applies to all visitors, registered users, and organisation administrators worldwide. Where applicable laws impose stricter obligations — including the Indian Digital Personal Data Protection Act 2023 (DPDP Act), the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA) — those obligations are reflected in the relevant sections below.

2. Data We Collect

2a. Account & Identity Data

Collected when you register or manage an account:

  • Full name and email address
  • OAuth provider tokens (GitHub, Google) — we store only the provider ID and email, never your OAuth password
  • Billing name, billing address, and the last four digits of your payment method (full card data is processed by our payment provider and never stored on Cartha infrastructure)
  • Organisation name, domain, and assigned roles

2b. Agent Operational Data

This is the core category of data you choose to route through the Services by instrumenting your AI agents with the Cartha SDK or HTTP integration:

  • Trace payloads: tool call inputs/outputs, LLM prompt and completion text, step timings, and error messages
  • Memory records: key-value and embedding-backed facts your agents store and recall
  • Policy evaluation events: which policies were checked, matched, or triggered per run
  • Agent metadata: agent identifiers, team assignments, and configuration parameters you supply
  • Budget and cost records: token counts, model pricing data, and spend per run

Your responsibility: You control what data enters your agents’ prompts and tool outputs. Do not route data through Cartha that you are not authorised to process. Cartha is a data processor for this category; you remain the data controller.

2c. Technical & Usage Data

  • IP addresses and approximate geolocation (country/city level)
  • Browser type, operating system, and device type
  • API request logs: endpoint, HTTP method, response code, and latency
  • Dashboard interaction patterns used for product analytics (no keystroke or screen recording)
  • SDK version and integration type (Python, TypeScript, HTTP)

3. Legal Bases for Processing

We rely on the following legal bases, depending on the processing activity:

  • Contract performance — processing necessary to deliver the Services you have subscribed to (e.g. storing traces, evaluating policies, sending invoices).
  • Legitimate interests — operating and improving the platform, detecting abuse, and securing infrastructure, where these interests are not overridden by your fundamental rights.
  • Legal obligation — complying with applicable law, tax regulations, and court orders.
  • Consent — for optional communications such as marketing emails, which you may withdraw at any time.

4. How We Use Your Data

  • To provision, maintain, and secure your Cartha account and organisation
  • To store, index, and serve Agent Operational Data back to you via the dashboard and API
  • To evaluate policy rules and enforce budget ceilings in real time
  • To calculate and attribute token costs per agent and per run
  • To generate invoices and process subscription payments
  • To detect and prevent fraud, abuse, and security incidents
  • To monitor platform health, latency, and reliability
  • To respond to your support requests and questions
  • To send transactional emails (e.g., payment receipts, account alerts)
  • To comply with applicable law

We do not use your Agent Operational Data or trace payloads to train, fine-tune, or benchmark our own or third-party AI/ML models.

5. Sub-processors & Third-Party Sharing

We engage a limited set of trusted sub-processors to operate the Services. We do not sell, rent, or broker your data to any third party for their own commercial purposes. Current sub-processor categories include:

  • Cloud infrastructure: servers, databases, and object storage (hosted in India and the EU)
  • Payment processing: Razorpay (INR) and Stripe (USD) — they process card data under their own PCI-DSS certification
  • Transactional email: delivery of account notifications and receipts
  • Error monitoring: anonymised crash reports and stack traces to diagnose platform failures

Each sub-processor is bound by a Data Processing Agreement (DPA) requiring them to process your data only on our documented instructions and to implement appropriate technical and organisational security measures.

LLM providers: Cartha does not proxy your LLM calls to OpenAI, Anthropic, or any other model provider. Those calls go directly from your agent to the provider. Cartha only receives the trace data you explicitly send via the SDK.

6. Data Retention

Retention periods depend on your plan and data category:

Data CategoryTraceControlAssure
Trace steps & memory30 days90 daysCustom
Account & billing records7 years (legal / tax obligation)
Security / access audit logs (CloudTrail, ALB)At least 90 days (archived longer per logging policy)
Backup systemsPurged within 30 days of primary deletion

Assure customers may negotiate custom retention windows. Upon account termination, active-database records are deleted within 14 days. Backup purge follows the schedule above.

7. Right-to-Be-Forgotten & Erasure

You may request hard-deletion of any or all of your Agent Operational Data at any time via the dashboard (Settings → Data & Retention → Delete Data) or by emailing hello@cartha.in. Upon a verified erasure request we permanently delete the applicable records from our active systems. Residual copies in backups and logs are purged according to our retention schedule (typically within 30 days). Billing records subject to statutory retention obligations are excluded from erasure requests.

8. Security Measures

We implement the following controls to protect your data:

  • Encryption at rest: AES-256 encryption for our primary database (Amazon RDS) and Redis cache (Amazon ElastiCache), using AWS-managed encryption keys
  • Encryption in transit: TLS 1.2+ on the public load balancer (HTTPS) and TLS for Redis client connections (rediss://)
  • Tenant isolation: all queries are scoped by organisation ID at the database layer (including PostgreSQL row-level security); cross-tenant access is architecturally prevented
  • Access control: production infrastructure access uses AWS IAM roles and Session Manager; API access uses hashed keys with role types (admin / agent / viewer). We continue to strengthen MFA and periodic access reviews as part of our compliance program
  • API key management: keys are stored as one-way hashed values; the plaintext is shown only at creation and cannot be recovered
  • Audit logging: AWS CloudTrail (multi-region) and Application Load Balancer access logs are written to a private, encrypted S3 bucket with retention controls
  • Vulnerability management: container images are scanned on push to Amazon ECR; we accept responsible vulnerability reports at hello@cartha.in

Despite these controls, no internet-based service is completely invulnerable to attack. If you discover a security vulnerability, please report it responsibly to hello@cartha.in.

9. Your Rights

Depending on your jurisdiction, you have the following rights regarding your personal data. Submit requests to hello@cartha.in; we will respond within 30 days (or such shorter period as required by applicable law).

  • Access & portability: receive a copy of your personal data in a machine-readable format (JSON or CSV)
  • Correction: have inaccurate or incomplete data corrected
  • Erasure: request deletion of your personal data (see Section 7)
  • Restriction: object to or restrict certain processing activities
  • Withdraw consent: for processing based on consent (e.g., marketing), withdraw at any time without affecting prior lawful processing
  • Lodge a complaint: you have the right to lodge a complaint with your local data protection authority (e.g., the Data Protection Board of India, the EU supervisory authority in your member state, or the California Privacy Protection Agency)

10. International Data Transfers

Cartha’s primary infrastructure is located in India. Where we transfer personal data to sub-processors operating outside India or the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission, or equivalent mechanisms. Indian users’ data is processed in accordance with the DPDP Act 2023.

11. Children’s Privacy

The Services are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided data to us, please contact hello@cartha.in and we will delete it promptly.

12. Changes to This Policy

We may update this Policy from time to time. For material changes, we will notify registered users by email at least 14 days before the change takes effect. The effective date at the top of this page reflects when the current version was last amended. Continued use of the Services after the effective date constitutes acceptance of the updated Policy.

13. Contact & Data Protection Officer

For privacy enquiries, data subject requests, or concerns about this Policy, contact:

Cartha Inc.

Attn: Data Protection Officer

Email: hello@cartha.in