The short version. CARAPACE is built so your conversations with AI, your API keys, and the data you process all stay on hardware
you control — your Mac, your VPS, or your Raspberry Pi. We (the app authors) don't run a cloud for your conversations. We don't receive them. We can't read them. There is exactly one place where we do ask you for personal information, and it is optional: the beta-program form at
carapace.info/beta. Section 2b states in full what that form collects, where it is stored, and what leaves our hands.
This Privacy Policy explains what the CARAPACE software and website at carapace.info do and do not collect, and what we do with the little information that does reach us. It applies to the Linux installer, the macOS application, the iOS application, and the carapace.info website.
1. What we don't collect
CARAPACE is a self-hosted personal AI operating layer. The whole point is your data doesn't leave your hardware.
- We do not run a server that receives your conversations, prompts, transcripts, images, or camera frames. Those go directly between your phone and the gateway you operate (Mac, Linux, or Pi). The one exception is not us either: if you switch the app's voice away from Apple's built-in on-device voices, your phone sends the text to be spoken directly to the speech provider you chose. Section 5c covers that in full.
- We do not log your API keys. They live in your phone's Keychain or in configuration files on your own machine.
- We do not require accounts, sign-in, or email to use the software. The iOS app and the macOS app do not have a login screen, nothing is gated behind registering with us, and pairing a machine never asks who you are. The one exception is the optional beta-program form on the website, which asks for an email precisely because we have to be able to send you a TestFlight invitation — it is described field by field in section 2b, and you can use every part of CARAPACE without ever touching it.
- We do not run analytics SDKs, advertising SDKs, or tracking pixels. There is no Segment, no Mixpanel, no Google Analytics, no Meta Pixel, no Amplitude — none of it.
- We do not sell or rent personal data, and we do not share it except where this Policy says so explicitly. There is exactly one such disclosure and you trigger it yourself: if you tell the beta form you own Meta AI glasses and give us your Meta account email, we hand that address to Meta so Meta can issue your wearables invite (section 2b).
2. What does flow over the internet
Running CARAPACE involves some network activity by design. Here's what goes where:
- Your phone ↔ your gateway. Chat, voice, camera, and context traffic moves directly between your iPhone and the gateway you're paired with, typically over your local network or your Tailnet. We never sit in the middle of this path. The specific fields the iPhone sends with each turn are enumerated in section 5.
- Your phone ↔ Apple Maps. When location permission is granted, the iOS app uses Apple's reverse-geocoder to resolve your coordinates into a street and locality, and Apple's
MKLocalSearch to fetch nearby points of interest (businesses, landmarks). These queries go to Apple under Apple's privacy policy — they don't pass through our servers or your gateway.
- Your gateway ↔ your AI provider. Whichever runtime you pair — Claude Code, Codex, OpenClaw or Hermes — your gateway runs on your sign-in or the API key you supply, and your prompts go to that provider directly from your machine. Each provider operates under its own privacy policy. We recommend reviewing it — we don't control what they do with prompts and we don't pick which provider you use.
- App updates and installer. Downloading the macOS DMG or running the Linux installer fetches files from carapace.info (hosted on Cloudflare). Those requests are standard web-server logs (IP address, user agent, timestamp) and are retained briefly by Cloudflare for abuse prevention. We don't correlate them to identities.
- iOS app downloads and IAP. Installing the iOS app and any in-app purchase goes through Apple, under Apple's privacy policy — not ours. See section 3.
- Your phone ↔ the voice provider you choose. If you switch the app's voice from Apple's built-in on-device voices to a third-party speech provider, your iPhone sends that provider the text to be spoken — your assistant's reply, and any text you ask it to read — over HTTPS, authenticated with the API key you supplied. This request goes directly from your phone to that provider. It does not pass through us and it does not pass through your gateway. Apple's on-device voices are the default and send nothing anywhere. Section 5c names the providers and explains the consent we ask for first.
2b. Beta program signups (carapace.info/beta)
The beta-program form at carapace.info/beta is the only part of CARAPACE that asks you for personal information, and it is entirely optional. You do not need it to download the App Store app, to install a gateway, to pair a machine, or to use any feature. If you never submit it, nothing in this section applies to you and we hold nothing about you at all.
What the form collects. Exactly these five fields, and nothing else:
- Name — optional, free text.
- Email address — required. This is what we use to send you the beta invitation and beta-related notices.
- Whether you own Meta AI glasses — a yes/no checkbox.
- Your Meta account email — shown and collected only if you tick the glasses box, and used for one purpose described below.
- A short free-text note ("what do you run?") — optional. Whatever you type here is stored verbatim, so please don't put anything sensitive in it.
The form asks for no password, no payment details, no device identifier, and no location. It sets no cookie. We do not fingerprint you, and we do not attach any of these fields to your use of the app — the app never sends us anything that could be joined to this record.
Where it is stored. Submissions are written to a Cloudflare D1 database (Cloudflare's hosted SQLite) that we operate on Cloudflare's infrastructure, in a single signups table keyed by email address. Submitting the same address again updates that one row rather than creating a second. As with any request to this website, Cloudflare's edge also records its standard access log (IP address, user agent, timestamp) for abuse prevention; the request is rate-limited by IP address for the same reason.
What we use it for. Sending you the beta invitation and occasional notices about the beta; issuing the Meta wearables invite described below; and understanding, in aggregate, which runtimes and machines testers actually use. That is the complete list. We do not sell it, rent it, profile you with it, advertise to you with it, or add you to any unrelated mailing list.
What is transferred to a third party. If — and only if — you tick the glasses box and supply a Meta account email, we transfer that email address to Meta Platforms, Inc. That transfer is the entire purpose of the field: Meta's wearables developer preview is invite-only and capped, so the only way to get you in is to hand Meta the address to invite. Once transferred, Meta processes it under Meta's own privacy policy, which we do not control. No other field goes to Meta — not your name, not your note, not the email you signed up with unless it happens to be the same address — and no field from this form goes to any other third party. If you leave the glasses box unticked, nothing from this form ever reaches Meta.
How long we keep it, and how to have it deleted. Beta signups are kept only for as long as the beta program runs. Concretely:
- Deletion on request, any time. Email [email protected] from the address you signed up with and we will delete your row — including the Meta email — within 30 days, and cancel the wearables invite if it has not already been issued. You do not have to give a reason. An invite Meta has already sent lives in Meta's systems and must be removed through Meta.
- Purged when the beta ends. When the beta program closes, the whole
signups table is deleted rather than retained, archived, or repurposed.
- No secondary copies. We do not export this table to a CRM, an email marketing platform, or an analytics tool.
Where the GDPR or a comparable law applies, our lawful basis for processing these fields is your consent, given when you submit the form (the form says so, and links here, directly above the button). You can withdraw that consent at any time by emailing the address above; withdrawing it means deletion, and it costs you nothing else. Section 9 covers your other rights.
3. In-app purchases
The iOS app sells CARAPACE Pro: an auto-renewing subscription offered monthly ($4.99 per month) or yearly ($39.99 per year), with a 7-day free trial for new subscribers that converts to a paid period at the price of the plan you chose unless you cancel. It unlocks Runtime Control. Payment is charged to your Apple ID at confirmation of purchase and renews within 24 hours before each period ends unless auto-renew is turned off at least 24 hours before — manage or cancel any time in your Apple ID Account Settings. If you bought Household, Power, or Corporate before CARAPACE Pro existed, those one-time purchases stay tied to your Apple ID, remain shareable through Apple Family Sharing, and keep Runtime Control unlocked forever at no further charge. All of it is processed entirely by Apple using your Apple ID.
- We do not receive your name, email, payment method, or billing address from Apple.
- We do not receive the exact dollar amount you paid — Apple handles pricing, taxes, and refunds.
- The iOS app asks Apple's StoreKit API which products you currently own on this Apple ID, to unlock the corresponding tier's features (there is no device or gateway cap on any tier — pairing machines is free and unlimited). That check happens on-device; the answer is cached locally in the iOS
Keychain and UserDefaults.
- Family Sharing propagation (if enabled) and refunds are handled by Apple; we honor whatever StoreKit reports.
If you want a refund, request it through Apple directly (Settings → Apple ID → Subscriptions → Report a Problem, or reportaproblem.apple.com). We don't have access to the transaction and can't issue refunds on Apple's behalf.
4. Data stored on your own hardware
The iOS app stores the following locally on your iPhone:
- The list of gateways you've paired with (nickname + URL + auth token), in the iOS Keychain and UserDefaults.
- Your speech-provider API key, if you entered one, and the bearer token for the gateway you're currently connected to — both in the iOS Keychain. The saved list of gateway profiles keeps its own copy of each pairing token next to the nickname and URL, in the app's preferences rather than the Keychain.
- Conversation history cache, to avoid re-fetching on every app open. This is local-only.
- App preferences (camera quality, wake word, voice selection, theme), and a record of which third-party voice providers you have allowed (see section 5c).
- Optional diagnostic logs if you enable the Debug Console. These are never transmitted unless you explicitly share them.
The macOS app and Linux installer store config, tokens, and cached conversations on the machine where they run. Deleting the app (or the config directory) removes the data.
5. What the iPhone app sends to your gateway
When you talk, scan, or open vision mode, the iOS app bundles the following fields with your message and sends them directly to the gateway you've paired with. None of this passes through our servers.
- Your words, as text — not as audio. Speech-to-text runs entirely on your iPhone (Apple's on-device speech recognition). The recording itself never leaves the device: only the resulting transcript is sent, alongside your typed messages. The optional "Hey Claw" wake-word setting also runs detection locally.
- Camera frames. Streamed only while a vision session or scan is active.
- Photos and videos you attach. When you pick an image or video from your library and attach it to a message, it is sent to your gateway with the message. A video is uploaded to the gateway as a file. A photo is not: it is embedded directly in the message body, base64-encoded. A photo that is already JPEG or PNG, no larger than 4096 px on the long edge and under 8 MB is embedded byte for byte, which means any metadata inside that file (GPS coordinates, capture date, camera model) travels with it. Photos outside those bounds, including the HEIC files an iPhone camera produces by default, are re-encoded to JPEG on the phone before sending, and that re-encode drops the embedded metadata. We do not deliberately strip metadata from a photo you send. Either way the destination is your gateway.
- A photo's own location and capture details — only if you switch it on. Separately from sending the file, the app can read an attached photo's embedded metadata and send it as its own structured fields: GPS latitude and longitude, altitude, the time the photo was taken, the lens, and the camera model. When a photo carries coordinates, those coordinates are used as the location for that message instead of your current location fix. This is off by default. It is turned on and off in Settings → Vision & Camera → “Use a photo's own location & capture details”, and while it is off the app reads nothing out of the file and the location field stays whatever your live fix reported (or nothing, if you have not granted location access). Note the limit of that switch: it governs the app's own reading, not the bytes of your file — a JPEG or PNG sent byte for byte still carries whatever metadata it already contained, as described in the bullet above.
- On-device scene perception. The Vision framework runs OCR (text), object classification, barcode decoding, and document detection on each frame on-device; the structured results (text, labels, bounding boxes) ride along with the frame so the gateway can answer faster.
- Location. When permission is granted: latitude, longitude, accuracy, altitude, speed, course/heading, and Apple's reverse-geocoded street + locality. Sent only while the app is in use; never in the background.
- Nearby places. Names, categories, and distances of nearby points of interest fetched via Apple's
MKLocalSearch (cached per ~50m grid cell for ~6 hours).
- Motion activity. A coarse classification from Apple's CoreMotion: stationary, walking, running, cycling, automotive, or unknown. No raw accelerometer data is uploaded.
- Device context. Time of day, ambient light bucket, and (on LiDAR devices) a coarse depth read of the scene.
Every one of these fields is downstream of a permission you control. Revoke Location or Motion & Fitness for CARAPACE in iOS Settings → Privacy & Security and the corresponding fields simply stop being attached; the app keeps working without them. Camera frames and scene perception are only produced while a vision session or scan is actually open, and Deep Scan is off unless you turn it on in Settings → Advanced.
5b. Long-term memory ("Rumination" and Deep Scan)
Your gateway can optionally remember what it has seen and heard across sessions, so future answers are grounded in past context (sub-areas you've visited, objects it has identified, recent utterances). This is on by default and is what we call Rumination.
The memory database lives entirely on the machine running your gateway. We don't operate any memory server, and we never receive or proxy this data.
Deep Scan (off by default, surfaced in Settings as experimental) is a 60-second passive ingestion sweep that uploads ~25–40 deduplicated frame summaries (scene description, top object labels, recognized text — never raw images for the deep-scan path) to your gateway's /context/ingest-frame endpoint, so future answers at this location are richer.
Deep Scan is turned off and on in the app (Settings → Advanced). Rumination retention is configured on the gateway itself, and you can wipe the memory database directly on that machine at any time.
5c. Third-party AI voice providers (opt-in, your key)
CARAPACE speaks with Apple's on-device voices out of the box. Nothing leaves your iPhone to make that happen, and that is the default for every install.
You may instead point the app at a third-party text-to-speech service using your own account and your own API key. If — and only if — you do that, here is exactly what happens:
- What is sent. The text to be spoken. That is the assistant's reply, or text you explicitly ask to be read aloud. Nothing else: no audio recording, no camera frame, no location, no motion, no device identifier, no account of any kind.
- Who it is sent to. Whichever provider you select. The app ships presets for xAI (api.x.ai), OpenAI (api.openai.com) and ElevenLabs (api.elevenlabs.io), plus a Custom option that sends to any OpenAI-compatible speech endpoint you type in yourself. When you choose Custom, the destination is the address you entered and nobody else.
- When you are asked. Before the first request is made. Selecting a third-party voice shows a disclosure screen naming the provider, the data being sent, and the destination, and the app does not contact that provider until you accept it. Decline, or take no action, and the app stays on Apple's on-device voices. You can withdraw consent at any time in Settings → Voice — how replies sound: tap the row reading “Sharing reply text with …” and choose “Stop sharing”. Switching Service back to Apple System also stops all further requests immediately.
- Your key. Stored in your iPhone's Keychain and sent only to the provider it belongs to, as that provider's authentication header. We never receive it. To delete it, clear the key field in Settings → Voice — how replies sound and tap Save TTS settings; the app removes the Keychain entry immediately. Do that before you delete the app if you want the key gone — iOS does not guarantee that Keychain items are erased when an app is removed, so a key left in place can still be there if you reinstall.
- What we get. Nothing. We do not proxy, mirror, log, or count these requests. We have no visibility into them at all.
Each provider handles the text under its own privacy policy and its own retention rules, using your account with them. Read theirs before you enable one — we link to them on the disclosure screen. Section 8b covers the protection we require of them.
5d. How long data is kept
- By us: none of it, because we never have it. There is no CARAPACE server holding your conversations, transcripts, images, location, or keys. There is no retention period to state, because there is no store. The single exception is the optional beta-signup row described in section 2b — the one thing on this list we actually hold.
- Beta signups (section 2b). Kept for the duration of the beta program in a Cloudflare D1 table, deleted within 30 days of a request to [email protected], and purged in full when the beta ends.
- On your iPhone. Two separate stores, with two different lifetimes. Cached conversation history, preferences, saved gateway profiles and your voice-sharing choices live in the app's own container and are removed when you delete the app. Speech-provider API keys, the active gateway bearer token, your acceptance of the terms and your purchase entitlement live in the iOS Keychain, which iOS does not guarantee to erase on app deletion — those can survive a delete and reappear on reinstall. Remove the ones you care about from inside the app first: clearing the key field and tapping Save TTS settings deletes the speech-provider key outright.
- On your gateway. Conversations and Rumination memory are kept for as long as you configure on the machine you own. You can delete the memory database directly on that machine at any time.
- At a voice provider you enabled. Retained per that provider's own policy, under your account with them, and deletable through them.
- Website logs. Cloudflare's standard edge access logs for carapace.info, retained briefly for abuse prevention and never correlated to an identity.
6. Cookies and local storage
The carapace.info website uses no tracking cookies. The only storage is first-party, same-origin localStorage used to remember UI preferences (e.g. which carousel card you scrolled to). No ad pixels or behavioral analytics run on the site. The site is served through Cloudflare (hosting/CDN, which may generate standard CDN access and security logs and network-error reports), and loads Tailwind CSS and Google Fonts via CDN. The support page uses Cloudflare email-address obfuscation.
7. Children
The CARAPACE iOS app is not directed at children under 13. We do not knowingly collect data from anyone, but because the app processes inputs (voice, text, camera) that may be sensitive, younger users should use CARAPACE through a parent's Apple ID under Apple Family Sharing, which applies parental controls and purchase approvals.
8. Third-party services we rely on
Running the service requires us to rely on a handful of third parties. None of them receive your prompts or conversations from us — we have nothing to give them. Two of them can receive your content at your direction, and both are marked below:
- Apple — App Store distribution, StoreKit in-app purchases, iCloud Keychain (for your own device, at your option). Apple's privacy policy governs this layer.
- Cloudflare — CDN and static hosting for carapace.info and the installer, plus the D1 database that holds beta-program signups (section 2b). Standard edge logging.
- Meta Platforms — receives one field, from one optional form, at your request: the Meta account email you supply on /beta when you ask for the glasses wave, so Meta can invite that address to its invite-only wearables preview. Nothing else about you is sent to Meta, and nothing is sent at all if you don't tick that box. See section 2b.
- No push service. CARAPACE registers no push-notification tokens and Apple's push servers never carry your content. Spoken announcements arrive over the app's own direct connection to your gateway — there is no relay in between.
- The AI provider configured on your gateway — your choice, running under your API key. Your gateway talks to it directly; we are not in that path and never see the traffic. That provider's own policy governs the prompts it receives.
- A voice provider you have explicitly enabled — xAI, OpenAI, ElevenLabs, or a custom endpoint you entered. Receives only the text to be spoken, only after you accept the in-app disclosure, only using your key. See section 5c.
8b. Equal protection by third parties
Where CARAPACE can send your data to a third party at your direction, we require that third party to protect it to a standard at least equal to this Policy. We reviewed the published privacy policy and API terms of each provider named in section 5c against that standard before shipping it as a preset, and we link each provider's current policy on the disclosure screen shown before the first request, so you can read it yourself before you consent. What those providers do with the text is governed by their policies and by your account with them, not by us — we are not in the request path and hold no agreement with them on your behalf.
If a provider's terms ever fell short of that standard, we would remove its preset from the app. You can always avoid third-party providers entirely: Apple's on-device voices are the default and require no external service.
9. Your rights
Because CARAPACE is self-hosted, most of your data is already in your hands — there's no "data export" request to make of us for your conversations. If you have questions about specific data you believe we hold (for example, installer logs tied to an IP address), contact us at the address below and we'll respond within 30 days.
If you're in a jurisdiction that grants rights to access, correct, or delete personal data (GDPR, CCPA, etc.), those rights apply to the limited data we do have. The main practical exercise of those rights is: request deletion, which will be honored to the extent any data exists to delete.
In practice the one record we may hold about you is a beta-program signup (section 2b). Email [email protected] from the address you signed up with and we will tell you exactly what that row contains, correct it, or delete it — within 30 days, at no cost, and without asking why.
10. Security
We take reasonable technical and administrative measures to protect the limited data we do hold. That said, no system is perfectly secure. Because the architecture keeps your conversations off our servers, a breach of our servers would not expose your AI interactions. Breaches of your gateway (your Mac, your VPS, your Pi) are out of our control — securing that hardware is your responsibility.
If we become aware of a security incident affecting data we hold that relates to you, we will notify affected users to the extent required by applicable law.
11. Changes
If we update this Policy, the new version will always be at carapace.info/privacy/, with a fresh Effective Date at the top. Material changes will also be announced in the iOS app's Settings → About section and on the website. Continued use of the Software after an update means you accept the updated Policy.
12. Contact
Privacy questions, concerns, or data-deletion requests: email us at [email protected]. See also the Support page.