Karamel ("Karamel", "we", "us") helps people turn their own thinking into content they publish themselves. This policy explains what we collect, why, and what we never do. We have tried to write it in plain language rather than legal fog.
What changed on 4 August 2026. Karamel now asks you to talk rather than type. Answering out loud means your voice is recorded and sent to a transcription provider so it can be turned into words. This is a new kind of information about you and a new company that receives it, so it is said here at the top rather than left for you to find: the full explanation is under Talking to Karamel.
What changed on 30 July 2026. You can now sign in to Karamel with a phone number. We do not store the number itself, only a one-way fingerprint of it and its last four digits, and it is used for nothing except sending you a sign-in code. This is a new kind of information about you, so it is said here rather than left for you to find further down: the full explanation is under Signing in with a phone number.
The short version. We collect the minimum we need to make Karamel work. We never publish anything without you pressing publish. We do not sell your data, we do not use it for advertising, and we do not read your LinkedIn or X feed, your connections, or your messages. If you answer out loud, we keep the words and not the recording. If you give Karamel your own writing so it can sound like you, we store it, we show you everything we hold, and you can download or permanently delete all of it yourself at any time.
Information we collect
- Your email address, if you join the waitlist. We use it only to contact you about Karamel.
- Your phone number, if you sign in with one. We do not keep the number itself. See the section below.
- The thoughts and drafts you write in Karamel. When you share a thought, we process it to generate a draft in your voice.
- What you say out loud, if you answer by talking rather than typing. The recording is transcribed into text and the recording itself is not kept. See the section below.
- Basic account information from LinkedIn or X, if you choose to connect either of them. See the sections below.
- How your own posts performed, for posts you published through Karamel. Counts only, on your own posts. See the section below.
- Your own writing, if you give it to us. There are three ways, all optional: upload your LinkedIn data export, paste a few things you have written straight into Karamel, or confirm that a public page we suggest is yours. See the sections below.
- Standard technical information that any website receives, such as your IP address and browser type, generated by our hosting provider in the ordinary course of serving the site.
We do not ask for, and do not want, sensitive personal information.
Talking to Karamel
Most of Karamel now opens with a microphone. When it asks you something, you can answer out loud, and typing is always one tap away on every screen that offers voice. Nothing records until you press a record button, and the browser will ask your permission the first time.
What happens to a recording. Audio is captured in your browser and uploaded to us. We pass it straight to a third-party transcription provider, which returns the words. We keep the words. We do not keep the recording: it is not written to our database and not written to our logs, and it exists on our servers only for as long as it takes to transcribe it. To be exact rather than reassuring, a recording longer than roughly two minutes is briefly written to a temporary file on the server while the upload is being handled, and that file is removed as soon as the request finishes.
The words are kept, and they are the point. A transcript is treated exactly like something you typed: it is stored, it is listed in your export, and it is deleted when you delete everything. Where a transcript is an answer about yourself rather than something you intend to publish, we mark it as such, so Karamel never mistakes the way you speak for the way you write.
The transcription provider receives your audio and returns text. It receives nothing else about you: no name, no email, no phone number, no account identifier. It is listed under Third-party services below.
If you would rather not. Every question in Karamel can be answered by typing, and skipping a question is always allowed. Declining the microphone permission does not reduce what you can do; it only changes how you answer. If your browser or device cannot record, Karamel says so and offers you the keyboard.
Signing in with a phone number
You can sign in to Karamel with your phone number. It is how we recognise you when you come back, on this device or another one, so your writing is waiting for you rather than lost.
We do not store your phone number. When you enter it, we convert it into a one-way fingerprint using a secret key, and we store only that fingerprint. A fingerprint cannot be turned back into a phone number, which means we could not tell you or anyone else what number is on an account even if we were asked to. Entering the same number again produces the same fingerprint, which is how signing back in works.
We do keep the last four digits, so that a screen can show you which number an account belongs to without displaying the whole thing.
Your number is used for exactly one thing: sending you a sign-in code. We do not use it to publish, we do not send marketing to it, we do not share or sell it, and nothing else is ever sent to it. Sending the code requires passing the number to the messaging provider that delivers the text; the number is not stored on our side either before or after.
Sign-in codes are stored as one-way fingerprints too, expire after ten minutes, can be used once, and stop working after a few wrong attempts.
Signing in with a phone number is separate from connecting LinkedIn or X. It identifies your Karamel account; it grants no access to any other service. Deleting your Karamel account removes the fingerprint and the last four digits along with everything else.
Pages we suggest, and pages we read
Karamel can search public sources for pages you may have written, using your name together with the headline and employer your LinkedIn profile already gave us. What comes back is what any search engine returns: a title, a web address, and a short snippet. We show you that list.
We do not open any of those pages until you tell us one is yours. Until you press a button, nothing has been read, nothing has been stored beyond the suggestion itself, and nothing has affected what Karamel knows about you. If you dismiss a suggestion we will not show it to you again.
When you do confirm a page, you tell us which kind it is, and the two are handled differently:
- "I wrote this." We read the page and store its text as your own writing, in the same way as anything you paste or upload.
- "This is about me." Someone else wrote it. We read the page, extract only short descriptions that the page applies to you, and store those together with the web address and a short supporting quote. We do not keep a copy of the page, and we never treat someone else's writing as yours.
You can withdraw permission for any page at any time. When you do, everything we learned from it is removed and what Karamel knows about you is rebuilt without it.
LinkedIn data: what we access and why
Connecting LinkedIn is entirely optional. If you connect it, you authorize Karamel through LinkedIn's official OAuth process, and we request only these permissions:
- Your basic profile identity (
openid,profile): your LinkedIn member identifier and name. We use this solely to attribute a post to you as its author. - Permission to post on your behalf (
w_member_social): used only to publish a specific post at the moment you press publish.
We want to be exact about the limits of this access:
- We never post anything automatically. Every post requires you to review it and press publish yourself.
- We do not read your LinkedIn feed, your connections, your messages, your notifications, or anyone else's data.
- We do not use your LinkedIn information for advertising, profiling, or resale.
- We do not share your LinkedIn data with any third party.
Your LinkedIn access token is stored encrypted on our server, is never sent to your browser, and is never written to our logs.
Disconnecting takes effect immediately. You can disconnect inside Karamel, or revoke access from LinkedIn directly under Settings, then Data privacy, then Permitted services. Either way, the active access token stops working straight away and we delete it. Karamel can no longer publish on your behalf, and nothing can go out again unless you choose to reconnect. Disconnecting does not delete the writing you have given us; deleting that is a separate action, described below, so that signing out never quietly erases your work.
X data: what we access and why
Connecting X is entirely optional and separate from connecting LinkedIn. You can use Karamel with either, both, or neither. If you connect X, you authorize Karamel through X's official OAuth 2.0 process, and we request only these permissions:
- Your basic profile identity (
users.read): your X user identifier and handle. We use this to show you which account is connected, so you can never publish to an account you did not mean to. - Permission to post on your behalf (
tweet.write): used only to publish a specific post at the moment you press publish. - Reading your own posts (
tweet.read): used only to read the public counts on posts you published through Karamel. See below. - Staying connected (
offline.access): X access tokens expire after a short time. Without this you would have to reconnect every couple of hours.
We want to be exact about the limits of this access:
- We never post anything automatically. Every post requires you to review it and press publish yourself.
- We do not read your timeline, your followers, your likes, your bookmarks, or your direct messages. We do not ask for direct message permission at all.
- We do not read anyone else's account. Every request we make is scoped to yours.
- We do not search X, collect trending topics, or build any dataset from it.
- We do not use your X information for advertising, profiling, or resale.
Your X access token is stored encrypted on our server, is never sent to your browser, and is never written to our logs. Disconnecting deletes it immediately and Karamel can no longer publish for you, exactly as with LinkedIn.
How your own posts performed
For a post you published through Karamel, we may read the public counts on it, such as how many people saw it or reacted to it, and store those numbers against our own record of that post.
We do this for two reasons, and it is worth being plain about both. The first is that you should be able to see whether your own writing landed. The second is that it helps Karamel choose better things to suggest you write about.
The limits matter more than the capability:
- Only posts you published through Karamel. We do not go looking through your account history.
- Only counts. We do not store who saw, liked, or replied to your post. Those are other people, and they did not agree to anything.
- These numbers never become part of what Karamel thinks you are. Karamel keeps a picture of how you write and what you know about, and a follower count or a like total is deliberately not allowed into it. What performed is not who you are, and we would rather build a product that does not confuse the two.
- They appear in your export like everything else, and they are deleted with everything else.
Your LinkedIn data export
LinkedIn lets you download an archive of everything you have written there. You can choose to upload that archive to Karamel so it learns how you actually write instead of guessing. This is optional, and Karamel cannot obtain this archive on its own: you download it yourself and you upload it yourself.
We read only these parts of the archive: your posts and the comments you wrote, your headline, your about section, your industry, your roles and their descriptions, your education, and your skills.
We never open the rest. Your connections, your messages, your invitations, your contacts, your recommendations, your endorsements, and your registration record (which contains IP addresses) are not read. This is enforced by only opening the specific files listed above rather than by skipping the ones we would rather avoid, so any new file that LinkedIn adds to the archive in future is ignored by default rather than read by accident.
Two further limits are worth stating plainly. We do not build a profile of anyone other than you, so other people's information in your archive is never extracted, stored, or modelled. And a post you reshared without adding your own words is not treated as your writing, because it is not.
How we use your information
- To generate drafts in your voice from the thoughts you share.
- To publish a post to LinkedIn or X when, and only when, you explicitly ask us to.
- To show you how your own posts performed, and to choose better things to suggest you write about.
- To contact you about Karamel if you joined the waitlist.
- To keep the service working, secure, and debuggable.
AI processing
To create a draft, the text you write is sent to a third-party AI model provider that generates the draft and returns it to us. We use these providers for one purpose only: producing the draft you asked for.
Separately, if you answer by talking, the recording is sent to a third-party transcription provider for the single purpose of turning it into words. That is a different job from writing a draft, and it is described in full under Talking to Karamel.
We choose providers whose API terms are appropriate for building an application on top of them. Where a provider states that content sent through its API is not used for model training by default, we rely on those terms. Providers and their policies can change, and we may change providers as Karamel evolves. If our AI providers or our data practices change materially, we will update this policy rather than leave it stale.
Storage and retention
Karamel used to keep nothing beyond your session. That is no longer true, and this section says exactly what changed, because a product that starts remembering you should say so rather than let you find out.
- Waitlist emails are stored securely with our service providers until you ask us to remove yours.
- Writing you give us, whether through your uploaded export or through Karamel itself, is stored durably in our database so it can be used to write in your voice. It stays until you remove that source or delete everything.
- The counts on your own posts are stored alongside our record of the post they belong to, and stay until you delete everything.
- A record of what happened to your data, such as when a source was added or removed, is kept alongside it so we can always show you where anything came from.
- Your LinkedIn access token is stored encrypted, is never sent to your browser, is never written to our logs, and is deleted the moment you disconnect.
- Your account exists only because you connected LinkedIn. We never ask you to create one, and we do not store a password.
- Recordings are not kept; transcripts are. Audio is held only for the seconds it takes to transcribe, is never stored in our database and never written to our logs, and is then gone. The text that comes back is stored exactly like text you typed, appears in your export, and is deleted when you delete everything.
- Your thoughts and drafts are now kept. The previous version of this policy said they were not, and said that if it changed this policy would change with it. It changed on 28 July 2026, so here is exactly what we keep and why. When you are signed in, we store the thought you typed, the draft Karamel wrote from it, and, if you edit or approve that draft, the version you kept. We keep this for one reason: the difference between what we wrote and what you kept is the clearest thing you ever tell us about how you write, and it is how Karamel stops making the same mistake twice. It is listed in your export like everything else, and it is deleted with everything else.
What Karamel does not do with your writing
- We do not use it to train AI models. Your uploaded archive is stored and read by us, not handed to a model provider wholesale, and where a provider's terms state that API content is not used for training by default, we rely on those terms as described above.
- We do not share it, sell it, or use it for advertising.
- We do not use it to build a profile of anyone other than you.
- We do not draw conclusions about you that we cannot show you the evidence for.
Cookies
We use essential cookies only. They keep your session secure, handle authentication, and maintain your LinkedIn connection while you are using Karamel. We do not use advertising cookies, and we do not use cross-site tracking cookies.
Sharing
We do not sell your personal information, and we do not share it for advertising. We share information only with the service providers who make Karamel work, such as our hosting, database, and AI model providers, and only to the extent needed to deliver the service. Your uploaded export is not sent to an AI provider as a whole; it is stored by us and read by us. We may also disclose information if legally required to do so.
Third-party services
Connecting LinkedIn or X is optional and entirely your choice. If you do connect either, that connection is also governed by that platform's own Terms of Service and Privacy Policy, not only by ours. We would encourage you to read them before you connect.
If you sign in with a phone number, we pass that number to a messaging provider so it can deliver your sign-in code. That is the only thing the provider receives from us, and it is the only third party your number ever reaches.
If you answer a question out loud, we pass that recording to a transcription provider so it can be turned into words. The provider receives the audio and nothing else that identifies you.
Legal basis
We process your information to provide the service you asked for, with your consent where consent is required, and to meet legal obligations where they apply. That is the whole of it.
Your choices and rights
- Disconnect LinkedIn at any time, either inside Karamel or from LinkedIn directly, under Settings, then Data privacy, then Permitted services. Revoking access there immediately stops our ability to post on your behalf.
- See everything we hold, including your stored drafts, inside Karamel, at any time. Every piece of writing we stored is listed with where it came from and when it was read. There is no hidden profile.
- Remove a single source, which deletes that source and everything we read from it.
- Download everything as one machine-readable file, whenever you want, without asking us.
- Delete everything, permanently, with one action inside Karamel. This is a real deletion, not a flag: your writing, your stored record, your access token, and your account are removed. We cannot restore it afterwards, and we will not pretend we can.
- Ask us to delete your information, including your waitlist email, at any time by contacting us. We will respond within a reasonable period and delete what you have asked us to, unless we are legally required to keep it.
Depending on where you live, you may have additional rights over your personal information. Contact us and we will honour them.
Security
We use industry-standard measures to protect your information, including encrypted connections, encryption of stored access tokens, server-side handling of credentials, and keeping secrets out of the browser and out of our logs. No system is perfectly secure, and we will not pretend otherwise.
Children
Karamel is not intended for anyone under 16, and we do not knowingly collect information from children.
International users
Karamel is operated from the United States. If you use it from elsewhere, your information will be processed in the United States and in the regions where our service providers operate.
Changes to this policy
If we change this policy, we will update the date at the top of this page. If a change materially affects how we handle your information, we will make that clear rather than burying it.
Contact
Questions, deletion requests, or anything else about privacy: privacy@heykaramel.com.