Privacy Policy

Last updated: August 1, 2026

Cari is a product of Ember Development Studios, LLC(“we”, “us”, or “Ember”). This policy explains what we collect, how we use it, and your choices. Questions: support@emberdevstudios.com.

Who this covers

We serve two groups: business owners who create an account to run their AI receptionist, and the customers of those businesses who interact with Cari by web chat, text message, WhatsApp, Instagram or Facebook Messenger, email, or phone call. This policy applies to both.

Information we collect

  • Account & business data (owners): name, email, business profile, services, prices, hours, and the knowledge/FAQ content you provide to power the assistant.
  • Customer conversation content: messages and emails exchanged with Cari across web chat, SMS, WhatsApp, Instagram/Facebook Messenger, and email, plus call audio and AI-generated transcripts from phone calls.
  • Contact & scheduling data: any name, phone number, or email a customer provides, and the appointments, leads, waitlist entries, and messages created from those conversations.
  • Payment metadata: subscription billing details and booking deposit/payment records processed through Stripe. We never receive or store full card numbers.
  • Demo request data: if you request a demo through our marketing site, we collect the contact details and preferred date/time you submit.
  • Technical data: IP address, device/browser metadata, and request logs, used for security, rate limiting, and bot protection (including Cloudflare Turnstile).

How we use it

  • To operate the assistant — answer questions, capture leads, book and manage appointments, take messages, send reminders and follow-ups, request reviews, manage a waitlist, send consented outbound follow-ups, and escalate to a human when appropriate, on the business’s behalf.
  • To detect the customer’s language and reply in it (Cari supports 10+ languages).
  • To learn a business’s services, prices, hours, and FAQs from the website, public social pages, or documents the owner authorizes us to read, so the assistant can answer accurately.
  • To show the business owner their conversations, calls, leads, appointments, and analytics.
  • To process subscription payments and booking deposits, and to provide support.
  • To secure the service, prevent abuse, and enforce our Terms.

AI processing

To generate replies, summaries, and knowledge search results, conversation content is sent to our AI providers for processing — Anthropic and Google, listed below. This processing is necessary for the assistant to understand a conversation and respond.

Subprocessors

We share data only with vendors that help us run the service, each under their own security and privacy terms:

  • Supabase — database, authentication, file storage, and hosting.
  • Vercel — application hosting and content delivery.
  • Anthropic (Claude) — AI generation of replies and summaries from conversation text.
  • Google (Gemini) — text embeddings used to power knowledge search.
  • Stripe — subscription billing and payment processing.
  • Twilio — SMS, WhatsApp, and phone/voice connectivity, including the real-time AI voice channel (powered by ElevenLabs through Twilio).
  • ElevenLabs — AI voice synthesis for phone calls.
  • Apify — crawling the website and public social pages a business owner authorizes, to build the assistant’s knowledge base.
  • Resend — transactional email delivery.
  • Cloudflare — bot and abuse protection (Turnstile).

We do not sell personal information, and we do not share phone numbers with third parties for their own marketing.

SMS & messaging (A2P / TCPA)

Where a business enables the text channel, customers who message the business’s number are communicating with an AI assistant on that business’s behalf. We collect the phone number and message content to respond, book, and follow up, including consented outbound reminders, confirmations, and follow-ups. This messaging program operates under applicable A2P 10DLC carrier registration and TCPA requirements. Standard message & data rates may apply. Reply STOP at any time to opt out of further messages, or HELP for help. Phone numbers collected through the SMS channel are never sold or shared for third-party marketing. If a business separately collects phone numbers through a web form to send outbound or promotional texts, that collection requires express opt-in consent at the point of collection.

Voice calls & call recording

Where a business enables the phone channel, inbound calls (and any consented outbound calls) are answered by a synthetic AI voice. Call audio is transcribed and processed by AI to generate responses, and the resulting transcript and/or recording may be stored so the business owner can review the call. Call-recording and two-party consent laws vary by state and country. The business owner is solely responsible for providing any legally required notice or obtaining any consent from their callers before enabling call recording or transcription, and for complying with the recording-consent laws that apply to their business and their callers.

Payments

Booking deposits and balances are collected through Stripe Checkout. We receive payment status and transaction metadata from Stripe; we never receive or store full card numbers.

Data retention & your choices

  • Owners can edit or delete their business content, knowledge sources, and uploaded documents at any time from the dashboard.
  • We retain conversation, call, and booking data for as long as the business account is active and as reasonably needed to provide the service, then for a limited additional period as required for legal, security, or accounting purposes.
  • To access, export, or delete personal data, contact support@emberdevstudios.com.

California (CCPA/CPRA)

California residents may request disclosure of the categories of personal information we collect, request deletion, and opt out of the “sale” or “sharing” of personal information — we do not sell or share personal information as defined by the CCPA/CPRA. Contact us to exercise these rights.

EU/UK (GDPR)

EU/UK residents have rights of access, correction, deletion, restriction, and portability with respect to their personal data, and may object to certain processing. Contact us to exercise these rights. A Data Processing Addendum (DPA) is available for business owners who need one — contact us to request it.

HIPAA

Cari offers features that support use by healthcare businesses, including options intended to help handle protected health information appropriately. Cari is not“HIPAA certified” — no such certification exists for a software vendor. For eligible healthcare businesses that need to use Cari with protected health information, a Business Associate Agreement (BAA) is available and must be signed before “HIPAA mode” or any related feature is enabled for that account. Contact us to request a BAA.

International data transfer

Our service providers may process and store data in the United States and other countries. By using Cari, you consent to your information being transferred to and processed in those countries.

Children’s privacy

Cari is not directed to, and we do not knowingly collect personal information from, children under 13. If you believe a child has provided us personal information, contact us and we will delete it.

Security

Business data is isolated per tenant and enforced at the database level through row-level security. We use industry-standard encryption in transit and at rest via our service providers.

Changes

We may update this policy; material changes will be reflected in the “Last updated” date above.

Contact

Questions about this policy, or to exercise any of the rights above: support@emberdevstudios.com.

See also our Terms of Service.