Privacy policy.
What Karsi does with data: on the website, in your account, in the apps and in the accounts you connect. No cookies on the website, no advertising, no selling of data.
- Last updated
In short
- The website uses no cookies and no analytics tools.
- Karsi does not sell data, does not use it for advertising and does not train artificial intelligence models with it.
- The data is kept mostly in the European Union (Ireland); the providers outside it are under "Where the data is kept". What Íris reads goes to Anthropic, in the United States, only to answer what she is asked.
- The accounts you connect (Gmail, YouTube, Meta, TikTok, Shopify) are read only for the features you use, and you can disconnect them at any time.
- You can see, correct, take or erase your data: write to karsihub@gmail.com.
Who is responsible
Karsi is operated by MVDS Solutions FZ-LLC, registered at CWEP2145, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates (tax registration number, VAT TRN, 105220044900003) — in this policy, "Karsi", "we" or "us".
Karsi is the controller of the website's data and of your login account (your name, email and password). What your company records in Karsi — the team, pay, expenses, messages, files — and its stores' customer data — orders, messages, comments — belong to your company, which is the controller; Karsi processes them on its behalf, as a processor (see "If you are a store's customer").
For any question about your data: karsihub@gmail.com.
The website
karsi.ai uses no cookies, analytics or advertising tools, and its fonts are served by the website itself. The account pages' session is kept in your browser's storage — the Cookies and storage page says what and for how long.
Like any website, this one is served by a hosting provider (Vercel), which logs each request — the IP address, the date and time, the page requested and the browser — to deliver the pages and keep the site secure. Karsi does not use those logs to identify you or to count visits. Legal basis: the legitimate interest in keeping the website running and secure.
Your account and your team
When you create your account, Karsi keeps your name, your company's name, your email and the password — never as text: only a one-way digest of it. To refuse passwords that have already appeared in data leaks, Karsi asks the Have I Been Pwned service about the first five characters of a digest of the password; the password itself never leaves. On the create-account page, when it is on, Cloudflare's Turnstile checks that whoever creates the account is a person, from technical browser data such as the IP address.
After that, Karsi keeps what your company records to work: the linked stores, the team's people, their role and the stores they can access, profile pictures, tasks, notes, files, expenses and receipts, the team chat's messages and the conversations with Íris. If your company uses the team pay features, it also keeps the salaries, bonuses and commissions it records — visible only to those allowed to see them.
Legal basis: for your login account, providing the service you asked for when you created it; for the password check and Turnstile, the legitimate interest in keeping accounts secure; for what your company records, its instructions, as a processor. This data is kept for as long as the account exists.
The apps
- Mac app: the session is kept in the macOS Keychain; data is read from Karsi's server each time. The app has no third-party analytics or crash-reporting tools.
- iPhone app: the session is kept in the iPhone's secure storage. If you allow notifications, Karsi keeps the device's push identifier, platform, language, time zone and app version, and delivers notices through Expo's and Apple's notification services; a notice's text never carries customer data, amounts or messages. The app uses the camera, microphone and photos only when you ask it to (a photo of a receipt, a voice note).
- Shopify app: it runs inside the Shopify admin; when you connect an ad account, it keeps a technical cookie for 10 minutes that protects that sign-in.
Data from Shopify
When a store installs the Karsi app on Shopify, Karsi receives from Shopify, and only about that store: the store's details (name, domain, currency, time zone); orders, refunds, fulfilments and returns, with the buyer's data — name, email, phone and billing and shipping addresses; customers and their marketing preferences; abandoned checkouts; products, inventory and costs; discounts; and Shopify Payments payouts and disputes.
Karsi uses this data to show the store's team its orders, customers and accounts, for customer service and for the money figures. When someone on the team asks for it, it can also create or change orders, draft orders, customers, discounts, products, inventory and fulfilments. This data belongs to the store: Karsi processes it on the store's behalf, as a processor.
When Shopify passes on a customer's request to erase their data, Karsi erases that customer's name, email, phone and addresses from the customer and order records it keeps. When a store uninstalls the app, Karsi stops receiving its data; to delete the data already received, the store asks by email at karsihub@gmail.com.
Data from Google: Gmail
When a store's manager connects the store's Gmail mailbox to Karsi, they authorise Karsi to read, manage and send email from that mailbox (Google's gmail.modify permission). With that permission, Karsi:
- on connection, reads the last 30 days of the whole mailbox (except trash and drafts) and then every new message — including spam and mail the store sends from Gmail itself — with the threads they belong to: sender, recipients, subject, date, body and the list of attachments; it keeps the text and that list in the matching support case;
- opens an attachment or an email's original version only when someone on the team asks, and shows it without keeping it;
- sends from the store's mailbox the replies someone on the team wrote or approved — never a reply nobody approved;
- asks Google to notify it when a new message arrives, so customer service stays up to date;
- if the store asks for it, reads the last year of conversations, once, to write the store's support playbook; the text of those conversations is erased after 180 days, and the sender and subject are kept.
Karsi uses the email only for the store's customer service: it does not delete or move email in the store's mailbox, does not use it for advertising, does not sell it and does not show it to anyone outside the store's team. The access token is kept on Karsi's server, in a table no app can read.
Karsi's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. This covers every Google API Karsi uses (Gmail, YouTube and Google Ads). In particular, Google data is used only for the features the store sees and uses; it is transferred only to provide those features, for security or to comply with the law; it is not used for advertising; it is not read by people at Karsi except with the store's consent, for security or where the law requires; and it is not used to develop, improve or train generalised artificial intelligence models.
When Íris suggests a reply or summarises a case, the case's text goes to Anthropic only to produce that suggestion, and only on an Anthropic account where conversations are not used to train models (see "Íris and artificial intelligence"). To disconnect: in Karsi's Settings, under Connections, the store disconnects the mailbox — Karsi asks Google to revoke the access and deletes the token. You can also remove the access on your Google Account permissions page. Cases already created stay until the store deletes them or asks for them to be deleted.
Data from YouTube
Karsi uses YouTube API Services. By connecting a YouTube channel to Karsi, you agree to the YouTube Terms of Service, and Google processes data under the Google Privacy Policy.
When a store connects its channel (with the youtube.upload, youtube.readonly and youtube.force-ssl permissions), Karsi:
- reads the channel's identity (id, name and picture) and the list of the channel's own videos, with each one's figures (views, likes, comments);
- reads the comments on the channel's own videos, with the commenter's name and picture, so the store can answer and moderate them in Karsi;
- uploads to the channel the videos the store approved, with the store's title, description and choices — as private, until Google allows Karsi to publish them otherwise;
- posts the replies and the moderation decisions someone on the team made.
Karsi does not read other channels or the private data of viewers or commenters, does not use this data for advertising and does not sell it. The access token is kept encrypted in the database's secret store. Of the videos, Karsi keeps the figures and a copy of the thumbnail, and of the comments the text and the commenter's name, in the store's customer service.
When Íris moderates comments or suggests replies, the comment text and the commenter's name go to Anthropic, in the United States, only to produce the suggestion. Nothing is posted to YouTube unless someone on the team accepts it.
The YouTube data Karsi keeps is refreshed or deleted at least every 30 days. If you ask for it to be deleted, write to karsihub@gmail.com: we delete it within 7 days. If you revoke access — in Karsi's Settings, under Connections, or on Google's security settings page — Karsi deletes the YouTube data it keeps within 30 days. When you disconnect in Karsi, it also asks Google to revoke the access and deletes the token.
Ads data: Meta Ads, Google Ads and TikTok Ads
When a store connects its ad accounts, Karsi reads the names, currency and time zone of the accounts the store grants access to, and the ads' daily figures — spend, impressions, clicks, conversions and their value — to show the store's profit beside what the platform says. On Meta Ads, Karsi also reads campaigns, ad sets, ads and creatives; with the store's permission, it manages catalogs, audiences and ad posts, and reads the contacts left in lead forms when someone at the store opens them, without storing them. It changes only what the store approves, within the rules the account owner sets.
If the store asks, Karsi sends Meta a customer list for ad audiences: the emails and phone numbers of those who bought or agreed to receive marketing are hashed (SHA-256) at the moment of sending and are never kept in that form. Íris reads ads data only if the account owner allows it, and that option comes switched off.
This data is not sold or shared with other companies. The access tokens are kept on Karsi's server, in tables no app can read — Meta Ads tokens connected on the website or the Mac, in the secret store — and when the store disconnects an account the access is revoked.
Data from Meta: Instagram, Facebook, Messenger and WhatsApp
When a store connects its Instagram professional account, Facebook Page or WhatsApp Business number to Karsi, Karsi receives from Meta, and only about that account:
- the account's identity: its id, username, name and profile picture;
- customers' direct messages and the store's replies, with their attachments, reactions, and delivery and read statuses;
- about whoever writes to the store: their id, username, name and profile picture (on WhatsApp, their phone number and profile name);
- the comments and mentions on the store's posts;
- the store's posts and, if the store allows it, each post's figures;
- the access token with which Karsi acts on the store's behalf.
Karsi uses this data only for the features the store uses, and on its behalf: answering customers in customer service, moderating comments, the automatic replies the store designs, publishing what the store approved, transcribing voice notes and suggesting replies with Íris. It does not use it for advertising, does not build profiles of people and does not sell it. The customers' data belongs to the store: Karsi processes it on the store's behalf.
The notices Meta sends lose their content after 30 days and are deleted after 90, and the same holds for what Karsi sends. The text of voice notes is erased after 90 days, and the audio right after; files received in conversations, after 180 days. Conversations, comments and posts are kept while the store uses Karsi, and the store's videos and images are kept while the store uses Karsi. Deleting a video in the Library hides it; the files leave storage only on request, by email to karsihub@gmail.com.
Access tokens are kept encrypted in the database's secret store and never reach the apps. When the store disconnects an account, its token is deleted.
To request deletion: anyone who connected an account can remove Karsi in Instagram or Facebook settings — Meta tells Karsi, which deletes the access and the link to that account, and Meta shows you a code to follow the request. Anyone who wrote to a store can ask the store to delete the conversation. And you can always write to karsihub@gmail.com. Meta processes data under its own Privacy Policy.
Data from TikTok
When a store connects its TikTok account to Karsi, through TikTok's own sign-in, Karsi receives from TikTok, and only about that account: the account's identifiers, its name and its profile picture; the permissions granted by whoever connected the account (user.info.basic, video.upload and video.publish — read the basic profile, upload videos and publish videos); and the access and refresh tokens with which Karsi acts on the account's behalf.
When someone prepares a TikTok post in Karsi's editor, and again before a direct post, Karsi asks TikTok which options that account has at that moment — who can view, whether comments, duets and stitch are allowed, and the longest video it accepts — to show those choices to whoever is posting. Only the name TikTok shows, the maximum length and the time of that reading are kept with the post.
Karsi uses this data only to show which account is connected and to send it the videos the store approved, with the caption and the choices the store made: to that account's TikTok drafts, where whoever manages it finishes and posts the video in the TikTok app, or, once TikTok allows Karsi to do so, published directly. TikTok sends back the status of each upload and, once the video is out, its link. Karsi does not read the account's videos, followers, messages or statistics, does not use this data for advertising and does not sell it.
The data is kept by Supabase, in the European Union (Ireland); the tokens are kept encrypted in the database's secret store and never reach the apps. The store's videos are kept while the store uses Karsi; deleting a video in the Library hides it, and the files leave storage only on request, by email to karsihub@gmail.com. When Íris prepares or follows posts, what she reads — the captions, the status of each upload and the video's link — goes to Anthropic, in the United States. Karsi does not show this data to other stores or other companies.
To disconnect: in Karsi's Settings, under Connections, the store disconnects the TikTok account — Karsi asks TikTok to revoke the access and deletes the token. Whoever connected the account can also remove Karsi in TikTok's security settings, in the list of apps with access to the account; from then on Karsi can no longer act on it, and the token it kept stops working. Once disconnected, the account (its name, picture and identifiers) stays in the store's history until its deletion is requested, by email to karsihub@gmail.com. TikTok processes data under its own Privacy Policy.
Íris and artificial intelligence
Íris is Karsi's assistant. She runs in the Mac app, on the company's own Claude Code — Anthropic's program, signed in to the Anthropic account the company chooses. She reads data through Karsi with the permissions of whoever uses her, and never sees more than that person would.
What Íris reads goes to Anthropic, in the United States, only to produce what she was asked for: with customer service open on the Mac, she summarises and classifies new cases on her own, inside Karsi; on request, she suggests replies, sorts the inbox, moderates comments and prepares posts; and she reads ads data only if the account owner allows it. Nothing she suggests goes out unless someone on the team accepts it.
Karsi does not use stores' data, or the data it receives from Google, Meta or TikTok, to train artificial intelligence models, and does not sell it. Because Íris runs on the company's own Anthropic account, the Terms of service require the company to use her only on an account where Anthropic does not use conversations to train its models — a commercial account, or a personal account with that option switched off in Claude's privacy settings. Data that comes from Google reaches Íris only on those terms. Anthropic processes data under its own Privacy Policy.
Voice notes are transcribed by Karsi's own service on Google Cloud, in the European Union (Belgium), without going through any other artificial intelligence company. In the creative studio, images and videos are generated with the company's own Higgsfield account, through Claude Code; Karsi keeps no access to that account and keeps only the results the company chooses.
Other services a store may connect
- Parcel tracking (17TRACK): each shipment's tracking number, carrier and destination country, to tell the store where the parcel is.
- Reviews (Judge.me): the reviewer's name and the review, so the store can read and answer them in Karsi; the reviewer's email is not brought over.
- Banking (Airwallex): the company account's transactions, for Karsi's books; the token is kept in the secret store.
What we use data for, and the legal basis
- Providing the service — the account, the apps, the integrations you connect, customer service, posts and the store's books: performing the contract with your company (the Terms of service).
- Processing a store's customer data: that store's instructions — it is the controller and chooses the legal basis.
- Keeping Karsi secure, preventing abuse and fixing errors: our legitimate interest.
- Answering you and sending notices about the service (not advertising): performing the contract and our legitimate interest.
- Complying with the law and answering lawful requests from authorities: legal obligation.
Karsi does not use data for advertising, does not build profiles of people, does not make automated decisions with legal effects on anyone and does not sell data.
Where the data is kept
Karsi's database, files and server are with Supabase, in the European Union (Ireland); the Shopify app and the transcription service are on Google Cloud, also in the European Union (Belgium). Some providers are outside the European Economic Area — Anthropic, Vercel and Expo, in the United States; Cloudflare (Turnstile) and Have I Been Pwned, on global networks; 17TRACK, in China — and the company that operates Karsi is in the United Arab Emirates. For those transfers we rely on the safeguards the law requires, such as the European Commission's standard contractual clauses in those providers' data processing terms.
How long we keep it
| Data | Period |
|---|---|
| Account, team, linked stores | While the account exists |
| Orders, customers and support cases | While the store uses Karsi, or until their deletion is requested |
| Meta notices (content / record) | 30 days / 90 days |
| Messages sent over the networks (text / record) | 30 days / 90 days |
| Voice-note transcripts | 90 days, and the audio right after |
| Files received in conversations | 180 days |
| Email history imported for the support playbook | The text, 180 days; sender and subject, while the store uses Karsi |
| Notices received from Shopify | 30 days |
| YouTube data (comments, figures, thumbnails) | Refreshed or deleted at least every 30 days; deleted 30 days after access is revoked, or 7 days after a request |
| Comments deleted on the network | The text, 30 days |
| Library videos and images | While the store uses Karsi, or until their deletion is requested |
| Record of marketing consents | 3 years after being superseded |
| Devices for notifications | Until you sign out, or 90 days unused |
| Activity and sync logs | 60 to 90 days |
| Access tokens for connected accounts | Until the account is disconnected |
| Emails sent to karsihub@gmail.com | Until you ask for them to be deleted |
When a company's account ends, its data is deleted as the Data deletion page describes, except what the law requires to be kept.
How we protect it
- Connections always encrypted (HTTPS), and data encrypted at rest by the hosting providers.
- Each company's data is kept apart from the others' by the database itself, with row-level access rules; the apps hold only the public key, never the server key.
- Social-network and Meta Ads tokens are kept encrypted in the database's secret store; the others stay on the server, in tables no app can read.
- Each person sees only what their role allows, and only managers connect accounts.
- The platforms' notices are verified (Shopify's and Meta's signatures, Google's identity) before they are read.
No system is perfectly secure. If a breach puts your data at risk, we will tell you and the authorities, as the law requires.
Your rights
You can ask to see the data Karsi holds about you, correct it, erase it, restrict or object to its use, receive it in a format you can take with you, and withdraw any consent you gave. Write to karsihub@gmail.com; we answer within one month. These rights come from the European Union's General Data Protection Regulation (GDPR), where it applies, and the United Arab Emirates' data protection law (Federal Decree-Law No. 45 of 2021).
If you think your data has been mishandled, you can complain to the data protection authority where you live — in Portugal, the Comissão Nacional de Proteção de Dados (CNPD).
If you are a store's customer
If you bought from a store that uses Karsi, or wrote to it by email or on social media, the store is the controller of your data and its privacy policy is the one that applies. To see, correct or erase your data, ask the store; Karsi helps it comply. If you cannot reach the store, write to karsihub@gmail.com and we will pass the request on.
Children
Karsi is built for businesses and is not meant for anyone under 18. We do not knowingly collect children's data; if you know of a case, write to us and we will delete it.
Changes to this policy
If Karsi starts processing other data, or processing it differently, this page changes first, with a new date at the top; if the change is significant, we tell you by email or in the app. This policy is in English and in Portuguese and says the same in both; if they ever differ, the English version prevails.