← Back to 40 Carrot
PRIVACY POLICY
Last updated: July 30, 2026
This Privacy Policy describes how Charlie Calotta Vocal LLC ("we," "us," or "our") collects, uses, and protects information when you use 40 Carrot (the "App"), available at 40-carrot.app. We've tried to write this in plain language. If anything is unclear, email privacy@40-carrot.app and we'll explain it.
Who we are
40 Carrot is operated by Charlie Calotta Vocal LLC, a limited liability company organized in the State of New York, United States. You can reach us at:
Charlie Calotta Vocal LLC
165 E 66th St
New York, NY 10065
United States
privacy@40-carrot.app
What we collect
We collect only what's needed to run the App, keep your account working, manage purchases, understand first-party referrals, and improve the product. Specifically:
- Account identifiers. You can create an account with an email address and password, or sign in with Google. Authentication is provided by Supabase. If you use Google sign-in, we receive only your basic profile (your Google user ID, email address, and display name) through the standard OpenID Connect (openid, email, profile) scopes. We do not request YouTube or any other extended Google scopes.
- Purchase and entitlement records. Payments are processed by Polar.sh, our merchant of record, so we never see or store your card details. Polar tells us whether your account has an active subscription or a lifetime purchase, and we store that entitlement (plan, status, expiry, and Polar customer reference) in our database so the App knows whether your account has Full Access.
- Session information. Your Supabase session token is stored in your browser's local storage so you stay signed in between visits, and it is sent with API requests as a bearer token. We do not use tracking cookies.
- Basic traffic analytics. We use Vercel Analytics and Vercel Speed Insights to understand aggregate traffic (page views, load times, device type). These tools do not track you across other websites and do not use advertising cookies.
- Google Analytics (when enabled). Our pages can load Google Analytics 4 to measure aggregate page views and traffic sources. If it is enabled, Google sets first-party _ga cookies to tell returning browsers apart. We configure it with every advertising signal denied (no ad storage, no ad personalization, no ad user data), so it measures usage in aggregate and does not feed cross-site advertising. Google processes this data as our service provider under its own privacy policy.
- Anonymous first-party product analytics. The App creates a random identifier for the current browser session and records a small, fixed set of product events, such as starting a session, using a feature, creating a deployment, importing or placing units, creating or opening a share link, and exploring more than one shared battlefield. These events may include mobile or desktop, an allowlisted import method or placement source, a referring website's hostname (or a fixed category for one of our own pages), and fixed source or medium buckets derived from utm_source and utm_medium. Campaign and creative measurement uses the first-party forwarding links described below instead of storing arbitrary UTM text in product analytics. Product events do not include your account ID, email address, IP address, unit or model names, faction, board name, share ID, saved-board contents, or other text you enter. The random session identifier is stored in session storage and is not connected to your account. A session count therefore is not a count of identified or active users.
- First-party forwarding-link attribution. We may publish links beginning with 40-carrot.app/go/ on places such as newsletters, Reddit, Instagram, or YouTube. When one of these links is opened, we record the link, a random click ID, the time, and whether the request appears to be a known bot. The redirect places the click ID and link slug in reserved URL parameters; a first-party script moves them into this tab's session storage for no more than 24 hours and removes only those reserved parameters from the visible URL. If a new account signs in in that tab while the token is eligible, we connect the click and the link's admin-defined attribution label to that account. Forwarding attribution uses no tracking cookies or cross-site advertising identifiers. For these forwarding-click records, we do not store IP addresses or raw browser strings, including raw user-agent strings. A browser header may be inspected transiently to classify known bots, but the raw string is not retained.
- Referral and affiliate codes. A first-party link may include a code query parameter for a referral discount. The App normalizes that code and stores it in your browser's local storage for up to 30 days so it can be sent to our checkout and credited to the appropriate partner. This is our own referral attribution, not third-party advertising tracking.
- Feedback you send us. If you submit a bug report or feature request from inside the App, we store what you wrote, your account email so we can reply, and basic technical context: App version, your plan, your browser's user-agent string, your window size, and counts of the objects on your board. If you tick the box to include a picture of your board, we store that image too. If you attach your own image, such as a photo or screenshot, we store that alongside your report the same way. If you answer the in-App rating prompt, we store your 1–5 rating and any optional comment. We store a self-chosen display name only when you explicitly consent to possible publication; ratings of 1–3 cannot carry publication consent. Nothing submitted through the prompt is published automatically.
What we don't collect
- We don't store your boards, armies, terrain setups, or snapshots on our servers except where you ask us to. Three features do: cloud saves (Full Access, stores the saves you choose so they sync between your devices), share links (stores the snapshot you choose to share; free links expire and Full Access links are permanent until revoked), and bug reports where you've ticked the box to include a picture of your board. Outside those three, all of that game state lives locally in your browser's storage and never leaves your device unless you export it yourself.
- We don't sell data to anyone, ever. There is no advertising network, data broker, cross-site advertising identifier, or third-party advertising tracker. We do use the first-party forwarding links and referral codes described above to understand which of our own links led to visits or signups and, where applicable, to credit a referral partner.
- We don't collect payment card numbers or billing addresses. Those go directly to Polar.sh, our payment processor.
- We don't access your YouTube data, Google contacts, calendar, drive, or any other Google service.
How we use what we collect
We use the data above only to:
- Sign you in and keep you signed in.
- Determine whether your account has Full Access (via an active subscription, a lifetime purchase, or a complimentary grant) so we can provide the right access.
- Measure visits and signups from our own forwarding links and credit referral partners, without claiming those click totals represent unique visitors.
- Understand anonymous session-level adoption and how the App is being used in aggregate, so we can fix bugs and improve the product without joining product events to accounts.
- Review ratings and feedback, and publish a testimonial only after the person who submitted it explicitly consented and we approved it by hand.
How long we keep your data
We keep your account identifier and entitlement record for as long as your account exists. Lifetime purchases in particular mean we retain enough information to recognize you the next time you sign in, even years later. You can ask us to delete your account at any time (see below).
Sessions expire on their own schedule and are renewed automatically when you sign in again.
We retain anonymous first-party product events as historical aggregate measurement records. Their random session identifiers are not linked to account records and cannot be used by us to identify or contact an account holder.
A forwarding token stays only in the current tab's session storage and expires after at most 24 hours. We retain forwarding links and click records as historical first-party campaign records so an old slug is never reassigned. If an attributed account is deleted, the account association is removed while the historical click time and claim time may remain.
A free shared board expires after 24 hours. A Full Access shared board stays until you revoke its link or delete your account. Feedback stays until you ask us to delete it or delete your account. Deleting your account removes your remaining shared boards and feedback.
Who we share data with
We share data only with the service providers needed to run the App:
- Supabase Inc. provides authentication and hosts our database (account identifiers, entitlement records, cloud saves, shared boards, anonymous product events, owner-authored aggregate experiment records, and feedback you send us).
- Polar Software Inc. (Polar.sh) processes payments as our merchant of record and handles checkout, receipts, invoices, and subscription management under its own privacy policy.
- Google LLC provides the optional "Sign in with Google" flow and, when enabled, the Google Analytics measurement described above.
- Vercel Inc. hosts the App, its APIs, and the analytics described above.
We do not share your data with anyone else. We do not sell it. We do not use it for advertising.
Your rights
You have the right to:
- Ask what personal information we hold about you.
- Request that we correct or delete your information.
- If you used Google sign-in, revoke the App's access to your Google account at any time through your Google Account permissions page.
- Withdraw consent at any time, which you can do by signing out (and, for Google sign-in, revoking access as above).
- Withdraw testimonial publication consent by emailing privacy@40-carrot.app.
You can delete your account yourself at any time from inside the App: open Settings → Billing & Plan → Delete account. This permanently removes your account, cloud saves, shared boards, and feedback. If you have an active monthly subscription, cancel it first via the customer portal so you aren't billed again.
To exercise any of these rights another way, email privacy@40-carrot.app. We'll respond within 30 days.
Google API Services User Data Policy
If you sign in with Google, 40 Carrot's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We receive only your basic profile (Google user ID, email address, and display name) for authentication, use it for no other purpose, do not transfer it to third parties except as necessary to provide the App, do not allow humans to read it except with your explicit consent or as required by law, and do not use it for serving advertisements.
Children
40 Carrot is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us information, email privacy@40-carrot.app and we will delete it.
Changes to this policy
If we make material changes to this policy, we'll update the "Last updated" date at the top of this page and, where appropriate, notify signed-in users the next time they open the App.
Contact
Questions about this policy, or about how we handle your data, can be sent to privacy@40-carrot.app or by mail to the address listed above.