Customer information / Privacy
Your information. Clearly explained.
What CARAIXIS processes, which services are involved, and how to ask for access or deletion.
Who handles your information
CARAIXIS is operated by Blackfyre. This notice covers our public website, readiness scans, AI Visibility workspaces and related support. Contact pedro@blackfyre.app about privacy, access, correction or deletion.
Information we handle
- Account and access: email address, password hash, account role, workspace membership, invitation and recovery records, and session records. Passwords are hashed before storage.
- Workspace information: business names, domains, buyer questions, competitor names, settings, answer observations, citations, reviews, imported reports, reported outcomes and monitoring history that you or an authorized operator provide or generate.
- Scans: the public URL you submit, fetched public-page content and technical findings needed to produce the report. The scan service contacts the target site.
- Billing: customer and subscription identifiers, plan, billing status and relevant payment events. Stripe handles payment details through its hosted services; our application does not collect your full card number.
- Support: messages and contact details you send. The contact form processes name, email, optional company and site, message and browser user-agent; when configured, it delivers these through Resend.
- Operations: service requests, timestamps, failures and access or audit records. Hosting providers may process IP addresses, browser information and request logs to deliver and protect the service.
Do not submit passwords, payment details, sensitive personal information or confidential material as buyer questions or scan URLs.
How information is used
We use this information to provide reports and workspaces, run requested or scheduled checks, manage access and billing, respond to support, investigate errors and misuse, and maintain service records. Authorized operators can access information when needed to administer or support your workspace.
Configured AI providers receive question text and the context included in a check. Their answers may contain personal information or errors. Review what you submit and review generated results before relying on them.
Services involved
- Vercel: public website hosting and website request handling.
- Railway: application hosting, storage and operational backups.
- Stripe: checkout, recurring billing and the billing portal.
- OpenAI and other configured answer providers: processing monitoring questions and returning answers when a workspace is activated and the provider is enabled.
- Resend, when configured: contact and account email delivery. Direct support email is handled through our email service.
- Google Fonts: the website requests fonts from Google, which receives the associated network request information.
- Calendly: scheduling if you choose to open the external booking link.
These services process information under their applicable terms and policies, and processing may occur outside your country. We may disclose information when required by law or to investigate abuse or protect rights. External links and customer websites have their own privacy practices.
Cookies and browser storage
Authenticated access uses a session cookie. The public site stores your motion preference in local browser storage so animations stay paused if you choose. The current public website code does not include advertising pixels or a third-party analytics script. Infrastructure request logs and external font requests still occur.
You can clear browser storage or restrict cookies through your browser; restricting session cookies can prevent sign-in. Opening a Stripe or scheduling page may introduce that service’s own cookies.
Retention and backup copies
We retain operational account and workspace records while needed to provide the service, handle support, maintain security and meet applicable recordkeeping obligations. There is no universal automatic purge period for application records. Cancelling a subscription does not itself delete your account or workspace history.
Native backup copies expire according to their backup schedule: daily copies after 6 days, weekly copies after 27 days and monthly copies after 89 days. Separately retained manual off-host recovery copies currently have no automated expiration schedule. A deletion request therefore requires review of both active records and recovery copies; deletion from the active service does not mean every backup copy disappears immediately.
We will explain any information we must retain and the practical limits that apply to your request. We do not promise a fixed deletion deadline beyond requirements that apply by law.
Access, correction and deletion
Email pedro@blackfyre.app from your account address with the workspace and the request. We may need to verify your identity and authority. Depending on applicable law, you may have rights to access, correct, delete or obtain a copy of information, or object to or restrict particular processing. Workspace administrators should contact us for requests involving information they provided about others.
We use access controls and hashed passwords, but no system can promise absolute security. Report suspected unauthorized access to the same support address without sending passwords or secret keys.
Changes to this notice
We update this page when relevant practices change and revise the date above. For material changes affecting existing accounts, we will provide notice through an available account communication channel. Contact us if you need clarification about a previous version.