Last updated May 11, 2026
Privacy Policy
How Carbon Alliance collects, uses, protects, exports, and deletes personal data across the public platform and private Agent layer.
Data we collect
We collect account data, profile fields, authentication events, public community content, reviews, votes, reports, appeals, search interactions, Agent conversations, Agent memories, scheduled Agent tasks, and service diagnostics needed to operate the platform.
Some sensitive account data, such as email addresses and credentials, is protected through application-level security controls and encrypted storage where supported by the infrastructure layer.
How we use data
We use data to authenticate users, operate public community surfaces, rank and search AI tools, personalize Agent experiences, prevent abuse, support moderation, provide data export and deletion workflows, and improve reliability.
AI usage metadata such as capability name, model, token counts, latency, and estimated cost may be recorded for budget governance and operational safety.
Public and private surfaces
Published posts and published or verified reviews can be visible to other users. Public profiles can appear in author bylines, search, and profile pages.
Private Agent conversations, Agent memories, account settings, export jobs, deletion requests, and authentication audit logs are treated as private account data and are not exposed through public community pages.
AI providers and processors
Certain Agent and AI capabilities may send prompts, tool context, or generated outputs to configured AI model providers through the platform AI routing layer.
We may also use providers for email delivery, object storage, observability, payments, and infrastructure operations. These integrations should be limited to the data required for the relevant service.
Your rights and controls
You can update profile fields and privacy preferences, request a synchronous JSON export, request an asynchronous export with a 7-day download link, and request permanent account deletion with a 30-day cooling-off period.
Account deletion anonymizes the user identity and disables public profile and Agent preferences while preserving records needed for integrity, audit, legal, or abuse-prevention purposes where allowed by law.
Retention and security
We retain data for as long as needed to provide the service, satisfy legal obligations, protect users, resolve disputes, and maintain audit trails.
Security controls include password hashing, OAuth state protection, rate limiting, session management, audit logs, role-based admin access, and event-driven operational records.
Regions and legal framework
The v1 service is designed around Hong Kong-hosted primary infrastructure, Cloudflare-backed media delivery, and backups or standby systems as defined by the project infrastructure plan.
The privacy program is oriented around GDPR, CCPA, Hong Kong PDPO, and future regional compliance work before expansion into additional regulated markets.