Privacy Policy

Last updated: September 2026

CarryForward handles sensitive financial data. We treat your privacy as a first-class requirement, not an afterthought. This policy explains what we collect, where it lives, who else touches it, and what rights you have. Where we fall short of what you might expect, we say so rather than leaving it out.

1. What Data We Collect

We collect the following:

  • Account information: Your email address and name when you create an account, plus your state of residence and, if you enter them during onboarding, your marital status and details about your spouse's role and start year.
  • Carry parameters: Fund details, vesting schedules, ownership percentages, and other inputs you provide to our calculators.
  • Uploaded documents: Any documents you upload for analysis, such as K-1s or partnership agreements.
  • Payment information: Processed securely by Stripe. We never see or store your credit card number.
  • Your conversations with Carrie: If you use Carrie, our assistant, we send your message and a summary of your workbook — fund name, vintages, carry percentages, and your estimate figures — to Anthropic, which runs the model that writes the reply. We keep a per-day count of your conversations so we can enforce plan limits.
  • Fund research requests: If you ask us to look into a fund we haven't covered, we keep the fund name, the email you give us, your role, your notes, and your browser's user-agent string.
  • Share links: If you create a link to share an estimate, we store the figures in that link on our servers so the recipient can open it.

2. Where Your Data Lives

Your workbook, estimates, scenarios, and document records are stored in your own browser's local storage, on the device you are using. They do not sit in a CarryForward database, and we do not encrypt them ourselves — they are protected by your device and your browser. That has a real consequence you should know about: if someone else can open your browser, they can read them. Use "Delete all my data" in Settings when you're finished on a shared device.

A small amount of data does reach our servers: share links you create, messages you send through our contact page, and fund research requests you submit. The first two are encrypted at rest with AES-256-GCM — for a share link that covers the fund name, the figures, and any label you attached; for a message, your email address, your name, and the message itself. Fund research requests are not encrypted. One caveat we would rather state than gloss over: that encryption depends on a key being configured on the server, and where it is not, the data is stored exactly as it would have been without it.

The key is a server environment variable — never written into the database, never sent to your browser, never written to a log. We do not use a dedicated key management service, and there is one key for the whole platform rather than one per person. That second point has a consequence worth being direct about: it means we cannot destroy one person's data by destroying a key. Deletion is deletion, not cryptographic erasure, and we will not describe it as the latter.

3. What We Log, and What We Don't

We do not record your clicks, your scrolling, your session, or which fund, company, or figure you looked at. We use no session recording, no heatmaps, no advertising pixels, and no analytics service that builds a profile following you across the internet.

We removed the page-view counter our host used to run on these pages. It set no cookies and did not identify you, but it reported the page address — and our own addresses name things: a company page carries the company's name, and a share link carries its access token. Counting visits was not worth handing either to anyone else, so it is gone.

One thing does still reach our server logs. When you ask us to research a fund we haven't covered, or send us a message, we record that a request came in — an identifier, the kind of request, the broad role you selected if you gave one, and nothing else. We deliberately do not write your email address, the fund name, or your message into those logs, because a log line pairing a person with the fund they were researching is exactly the record we do not want to exist. The request itself is held so we can act on it; the log is not where it lives. Our host keeps logs under the retention period of our plan, and we do not run our own purge schedule, so we won't promise you a deletion window we don't control.

4. Who Else Touches Your Data

We do not sell, rent, or license your data, and we never use it for advertising. That will not change.

We do rely on a handful of companies to run the platform, and they handle data on our behalf: Vercel (hosting), Clerk (sign-in and two-factor authentication), Stripe (payments), Supabase (our database), and Anthropic (the model behind Carrie). Google serves the fonts on our pages, which means Google sees your IP address when a page loads.

Carrie deserves a specific warning. When you chat with her, your message and a summary of your workbook — the fund, the vintages, your carry percentages, your estimate figures — go to Anthropic to produce the reply. If you would rather no outside company ever see those details, don't use Carrie; everything else on the platform works without her.

Beyond those providers, we hand over your data only when the law requires it, such as a valid court order.

5. No Aggregation Across Users

Your carry parameters, K-1 figures, and documents are never used to build benchmarks, train models, or generate insights for anyone but you. Your data informs your estimate and nobody else's.

The one thing we count across people is how many have asked us to research a given fund, so we know what to work on next. That counter holds the fund name and nothing about you.

6. User Deletion Rights

In Settings, under Data management, "Delete all my data" erases your workbook, estimates, scenarios, document records, and settings from the browser you're using — immediately, permanently, no recovery. Because that data lives in your browser rather than on our servers, deleting on one device does not delete on another. If you've used CarryForward on your phone and your laptop, run it on both.

For the small amount of data that does reach our servers — share links you created, any message you sent us through the contact page, and any fund research request you submitted — get in touch through our contact page and we will delete it by hand. We don't yet hold a separate encryption key per person, so we can't offer you cryptographic deletion, and we won't quote you a turnaround time we can't guarantee.

7. Cookie Policy

The only cookies we set are the session cookies our sign-in provider, Clerk, uses to keep you signed in and to enforce two-factor authentication. No advertising cookies. No tracking cookies.

One thing beyond cookies is worth your attention. We keep your workbook and estimates in your browser's local storage, where they stay until you clear your browser or use "Delete all my data." That control now sweeps every key we write, in both local and session storage, rather than a list someone has to remember to update.

8. California Consumer Privacy Act (CCPA) Compliance

If you are a California resident, you have the right to: know what personal information we collect about you; request deletion of your personal information, which we handle as described in section 6; opt out of the sale of your personal information (we never sell it); and not be discriminated against for exercising your privacy rights. To exercise any of these rights, reach us through our contact page.

9. Changes to This Policy

When we change this policy materially, we post the change here and update the "Last updated" date at the top. We don't currently have email notifications set up, so please check that date rather than waiting to hear from us.

Questions about your data? Reach us through our contact page.