Back to Carry

Privacy and data handling at Carry

Carry is designed to disclose only the handoff context a creator has reviewed and approved.

Updated August 20, 2026

No account for composers or recipients

Carry requires no account, signup, or waitlist for the composer or recipient links. The composer requires a creator name for the passport, but not an email address. That name is included in saved draft files, downloaded share packs, and reviewed hosted passports you publish. Carry receives the name only when you publish the hosted passport. Stripe Checkout collects the purchaser's email address and payment information for a white-label purchase.

Data stored on your device

Your composer draft is stored in your browser so it can survive a refresh. Clear the draft from the composer or clear this site's browser storage to remove it.

What happens in the composer

Composer drafts are stored in your browser. Saved draft files and share packs are created on your device. Choosing a PDF, PNG, JPEG, or WebP reads its name, size, type, signature, and fingerprint locally. Carry does not upload the finished file or reviewed passport unless you publish a hosted link after the passport and privacy review are complete.

What a hosted link stores

Publishing stores the reviewed passport record, a private copy of the finished file, a hashed private manage token, and the link expiry. Carry does not store raw conversations, reader identities, or an account. During a white-label purchase, Carry temporarily stores the raw manage token behind a one-time return code for up to one hour. This returns the purchaser to the private manage page without sending the token to Stripe. Revoking disables recipient access immediately and attempts to delete the stored file. Stripe handles card and payment details for white-label purchases. Carry does not receive or store the full card number or card security code.

Basic product events

Carry records a small set of anonymous events such as opening the demo, starting a draft, adding a file, downloading a share pack, continuing into ChatGPT or Claude, and copying a brief. New events are passport_published when a passport is published, link_revoked when a link is revoked, and whitelabel_checkout_started when checkout begins. Hosted links also keep anonymous per-link totals for page views, shown as opens, and provider-open clicks. Records may include the event, time, an optional source tag, the selected AI destination, and a hosted-link identifier. A one-hour counter keyed by a one-way hash of the network address limits event volume. Events do not include passport contents, reader identity, or contact details.

Your choices

Keep work local by downloading a share pack instead of publishing. You can clear local drafts at any time and avoid campaign links without affecting the product. If you publish, save the private manage link so you can change the expiry or revoke recipient access.

Contact

Questions about your data: hello@carrypassport.com