Privacy policy
Last updated 21 September 2026
Who we are
This policy covers the SoftKarrot workspace and client portal at softkarrot.com and the SoftKarrot Android app (com.softkarrot.app). The controller of your data is SoftKarrot, a software studio. You can reach us at softkarrot@gmail.com.
SoftKarrot is invite-only. There is no public sign-up: an administrator of the organisation you work with creates your account and invites you by email. That organisation decides which projects you can see; SoftKarrot operates the service on its behalf.
What we collect and why
- Account details — your name, email address, optional phone number, profile photo, designation and role. To sign you in, show who you are to your teammates and apply the permissions your organisation gave you.
- Messages — chat messages, replies, reactions, and the photos, videos, voice notes and files you attach. To deliver conversations to the people in them.
- Workspace content — tickets, comments, documents, files, calendar events, personal notes and bookmarks. To run the projects your organisation manages in SoftKarrot.
- Credential vault entries — passwords and secrets stored for a project. To let authorised project members retrieve them. They are encrypted with AWS Key Management Service (KMS) and every access is recorded in an audit log.
- Presence — whether you are online and when you were last active (you can hide "last seen"). To show teammates whether you are available.
- Push notification token for your device. To send you notifications you have not turned off.
- Text you choose to send to an AI feature, and the instruction you type. To produce the summary, rewrite or translation you asked for (see "AI features" below).
- Contact form enquiries (the Contact page on softkarrot.com and in the app) — your name, email address, company (optional), the type of project you are interested in, and your message. To reply to your enquiry and understand what you would like us to build. The enquiry is stored on our servers, emailed to our team and shown to our administrators; it is not used for marketing and is not shared outside SoftKarrot. You do not need an account to send one.
We do not collect your location, contacts, call logs or advertising identifiers. The app does not record audio. Photos and files are read only when you pick them with the system picker or take a photo with the camera.
AI features
Some screens offer AI assistance — summarising, rephrasing, elaborating or translating text in tickets, documents, comments, notes and chat. When you use one, the text you selected (and any instruction you typed) is sent to a third-party AI provider, Google Gemini or xAI Grok, depending on the feature and your project’s settings. The provider processes it to return a response under its API terms. Nothing is sent unless you trigger the feature, and AI features can be turned off per project.
AI output can be wrong or inappropriate. You can report any AI response: from the panel that shows it, or — when AI text is inserted straight into what you are writing — from the “AI text inserted · Report” notice that appears. The report (including the response text and the text it was generated from) is stored so our administrators can review it.
Who we share it with
We do not sell your data or use it for advertising. We share it only with:
- People in your organisation, according to the projects and conversations you are part of.
- Amazon Web Services (Mumbai region, ap-south-1) — Hosting, database, file storage, sign-in (Amazon Cognito), email (Amazon SES) and vault encryption (AWS KMS).
- Google Firebase Cloud Messaging and the Expo push service — Delivering push notifications to Android devices. They receive your device token and the notification text.
- Google (Gemini API) and xAI (Grok API) — Generating AI responses, only when you use an AI feature.
- Authorities, where the law requires it.
All data is encrypted in transit (HTTPS / TLS) and at rest on AWS.
Reports and blocking
You can block a person in chat and report a message. A report stores a copy of the reported message, who sent it and who reported it, so an administrator can act on it even if the message is later edited or deleted.
How long we keep it
We keep your data for as long as your account exists. When your account is deleted — by you in the app, or by your organisation — your personal data is erased as described on our account deletion page.
Content that belongs to the organisation’s projects — tickets, comments, documents, files, chat messages you sent to other people, and security audit records — is kept but de-attributed: your name and email address are replaced with “Deleted user”, so the project history stays intact for the people who still rely on it. Text you wrote inside that content (for example your email address typed into a ticket) is not rewritten. Encrypted database backups can hold deleted data for up to 35 days before they expire.
Contact form enquiries are kept while we are discussing or delivering the work they are about. An enquiry that does not lead to a project is deleted within 24 months of our last exchange. You can ask us to delete yours sooner at any time by emailing softkarrot@gmail.com.
Your rights
You can see and correct your profile in the app, and delete your account at any time from Profile → Delete account. To ask for a copy of your data, a correction you cannot make yourself, or deletion without the app, email softkarrot@gmail.com. We answer within 30 days.
Children
SoftKarrot is a work tool for organisations and is not directed at children under 16. Accounts are created only by an organisation’s administrator.
Changes
If we change this policy we will update the date at the top of this page, and tell you in the app when the change is significant.
Questions about this page? Email softkarrot@gmail.com. See also our privacy policy, terms of use and account deletion pages.