Karamel

Privacy Policy

Effective Date: 19 July 2026
Last Updated: 4 August 2026

Karamel ("Karamel", "we", "us") helps people turn their own thinking into content they publish themselves. This policy explains what we collect, why, and what we never do. We have tried to write it in plain language rather than legal fog.

What changed on 4 August 2026. Karamel now asks you to talk rather than type. Answering out loud means your voice is recorded and sent to a transcription provider so it can be turned into words. This is a new kind of information about you and a new company that receives it, so it is said here at the top rather than left for you to find: the full explanation is under Talking to Karamel.

What changed on 30 July 2026. You can now sign in to Karamel with a phone number. We do not store the number itself, only a one-way fingerprint of it and its last four digits, and it is used for nothing except sending you a sign-in code. This is a new kind of information about you, so it is said here rather than left for you to find further down: the full explanation is under Signing in with a phone number.

The short version. We collect the minimum we need to make Karamel work. We never publish anything without you pressing publish. We do not sell your data, we do not use it for advertising, and we do not read your LinkedIn or X feed, your connections, or your messages. If you answer out loud, we keep the words and not the recording. If you give Karamel your own writing so it can sound like you, we store it, we show you everything we hold, and you can download or permanently delete all of it yourself at any time.

Information we collect

We do not ask for, and do not want, sensitive personal information.

Talking to Karamel

Most of Karamel now opens with a microphone. When it asks you something, you can answer out loud, and typing is always one tap away on every screen that offers voice. Nothing records until you press a record button, and the browser will ask your permission the first time.

What happens to a recording. Audio is captured in your browser and uploaded to us. We pass it straight to a third-party transcription provider, which returns the words. We keep the words. We do not keep the recording: it is not written to our database and not written to our logs, and it exists on our servers only for as long as it takes to transcribe it. To be exact rather than reassuring, a recording longer than roughly two minutes is briefly written to a temporary file on the server while the upload is being handled, and that file is removed as soon as the request finishes.

The words are kept, and they are the point. A transcript is treated exactly like something you typed: it is stored, it is listed in your export, and it is deleted when you delete everything. Where a transcript is an answer about yourself rather than something you intend to publish, we mark it as such, so Karamel never mistakes the way you speak for the way you write.

The transcription provider receives your audio and returns text. It receives nothing else about you: no name, no email, no phone number, no account identifier. It is listed under Third-party services below.

If you would rather not. Every question in Karamel can be answered by typing, and skipping a question is always allowed. Declining the microphone permission does not reduce what you can do; it only changes how you answer. If your browser or device cannot record, Karamel says so and offers you the keyboard.

Signing in with a phone number

You can sign in to Karamel with your phone number. It is how we recognise you when you come back, on this device or another one, so your writing is waiting for you rather than lost.

We do not store your phone number. When you enter it, we convert it into a one-way fingerprint using a secret key, and we store only that fingerprint. A fingerprint cannot be turned back into a phone number, which means we could not tell you or anyone else what number is on an account even if we were asked to. Entering the same number again produces the same fingerprint, which is how signing back in works.

We do keep the last four digits, so that a screen can show you which number an account belongs to without displaying the whole thing.

Your number is used for exactly one thing: sending you a sign-in code. We do not use it to publish, we do not send marketing to it, we do not share or sell it, and nothing else is ever sent to it. Sending the code requires passing the number to the messaging provider that delivers the text; the number is not stored on our side either before or after.

Sign-in codes are stored as one-way fingerprints too, expire after ten minutes, can be used once, and stop working after a few wrong attempts.

Signing in with a phone number is separate from connecting LinkedIn or X. It identifies your Karamel account; it grants no access to any other service. Deleting your Karamel account removes the fingerprint and the last four digits along with everything else.

Pages we suggest, and pages we read

Karamel can search public sources for pages you may have written, using your name together with the headline and employer your LinkedIn profile already gave us. What comes back is what any search engine returns: a title, a web address, and a short snippet. We show you that list.

We do not open any of those pages until you tell us one is yours. Until you press a button, nothing has been read, nothing has been stored beyond the suggestion itself, and nothing has affected what Karamel knows about you. If you dismiss a suggestion we will not show it to you again.

When you do confirm a page, you tell us which kind it is, and the two are handled differently:

You can withdraw permission for any page at any time. When you do, everything we learned from it is removed and what Karamel knows about you is rebuilt without it.

LinkedIn data: what we access and why

Connecting LinkedIn is entirely optional. If you connect it, you authorize Karamel through LinkedIn's official OAuth process, and we request only these permissions:

We want to be exact about the limits of this access:

Your LinkedIn access token is stored encrypted on our server, is never sent to your browser, and is never written to our logs.

Disconnecting takes effect immediately. You can disconnect inside Karamel, or revoke access from LinkedIn directly under Settings, then Data privacy, then Permitted services. Either way, the active access token stops working straight away and we delete it. Karamel can no longer publish on your behalf, and nothing can go out again unless you choose to reconnect. Disconnecting does not delete the writing you have given us; deleting that is a separate action, described below, so that signing out never quietly erases your work.

X data: what we access and why

Connecting X is entirely optional and separate from connecting LinkedIn. You can use Karamel with either, both, or neither. If you connect X, you authorize Karamel through X's official OAuth 2.0 process, and we request only these permissions:

We want to be exact about the limits of this access:

Your X access token is stored encrypted on our server, is never sent to your browser, and is never written to our logs. Disconnecting deletes it immediately and Karamel can no longer publish for you, exactly as with LinkedIn.

How your own posts performed

For a post you published through Karamel, we may read the public counts on it, such as how many people saw it or reacted to it, and store those numbers against our own record of that post.

We do this for two reasons, and it is worth being plain about both. The first is that you should be able to see whether your own writing landed. The second is that it helps Karamel choose better things to suggest you write about.

The limits matter more than the capability:

Your LinkedIn data export

LinkedIn lets you download an archive of everything you have written there. You can choose to upload that archive to Karamel so it learns how you actually write instead of guessing. This is optional, and Karamel cannot obtain this archive on its own: you download it yourself and you upload it yourself.

We read only these parts of the archive: your posts and the comments you wrote, your headline, your about section, your industry, your roles and their descriptions, your education, and your skills.

We never open the rest. Your connections, your messages, your invitations, your contacts, your recommendations, your endorsements, and your registration record (which contains IP addresses) are not read. This is enforced by only opening the specific files listed above rather than by skipping the ones we would rather avoid, so any new file that LinkedIn adds to the archive in future is ignored by default rather than read by accident.

Two further limits are worth stating plainly. We do not build a profile of anyone other than you, so other people's information in your archive is never extracted, stored, or modelled. And a post you reshared without adding your own words is not treated as your writing, because it is not.

How we use your information

AI processing

To create a draft, the text you write is sent to a third-party AI model provider that generates the draft and returns it to us. We use these providers for one purpose only: producing the draft you asked for.

Separately, if you answer by talking, the recording is sent to a third-party transcription provider for the single purpose of turning it into words. That is a different job from writing a draft, and it is described in full under Talking to Karamel.

We choose providers whose API terms are appropriate for building an application on top of them. Where a provider states that content sent through its API is not used for model training by default, we rely on those terms. Providers and their policies can change, and we may change providers as Karamel evolves. If our AI providers or our data practices change materially, we will update this policy rather than leave it stale.

Storage and retention

Karamel used to keep nothing beyond your session. That is no longer true, and this section says exactly what changed, because a product that starts remembering you should say so rather than let you find out.

What Karamel does not do with your writing

Cookies

We use essential cookies only. They keep your session secure, handle authentication, and maintain your LinkedIn connection while you are using Karamel. We do not use advertising cookies, and we do not use cross-site tracking cookies.

Sharing

We do not sell your personal information, and we do not share it for advertising. We share information only with the service providers who make Karamel work, such as our hosting, database, and AI model providers, and only to the extent needed to deliver the service. Your uploaded export is not sent to an AI provider as a whole; it is stored by us and read by us. We may also disclose information if legally required to do so.

Third-party services

Connecting LinkedIn or X is optional and entirely your choice. If you do connect either, that connection is also governed by that platform's own Terms of Service and Privacy Policy, not only by ours. We would encourage you to read them before you connect.

If you sign in with a phone number, we pass that number to a messaging provider so it can deliver your sign-in code. That is the only thing the provider receives from us, and it is the only third party your number ever reaches.

If you answer a question out loud, we pass that recording to a transcription provider so it can be turned into words. The provider receives the audio and nothing else that identifies you.

Legal basis

We process your information to provide the service you asked for, with your consent where consent is required, and to meet legal obligations where they apply. That is the whole of it.

Your choices and rights

Depending on where you live, you may have additional rights over your personal information. Contact us and we will honour them.

Security

We use industry-standard measures to protect your information, including encrypted connections, encryption of stored access tokens, server-side handling of credentials, and keeping secrets out of the browser and out of our logs. No system is perfectly secure, and we will not pretend otherwise.

Children

Karamel is not intended for anyone under 16, and we do not knowingly collect information from children.

International users

Karamel is operated from the United States. If you use it from elsewhere, your information will be processed in the United States and in the regions where our service providers operate.

Changes to this policy

If we change this policy, we will update the date at the top of this page. If a change materially affects how we handle your information, we will make that clear rather than burying it.

Contact

Questions, deletion requests, or anything else about privacy: privacy@heykaramel.com.