Legal

Privacy Policy

Last updated: 25 June 2026

Caroluma ("we", "our", or "us") is a Chrome extension that replaces your new tab page with a photo frame. This policy describes what data we collect, why we collect it, and how it is used. We do not sell your data to third parties.

1. Who this policy applies to

This policy applies to users of the Caroluma Chrome extension and the caroluma.com website. By installing the extension or using the website, you agree to this policy.

2. Data we collect and why

Google account information. When you sign in with Google, we receive your name, email address, and profile photo URL via Google OAuth. This information is used to identify you within the extension and to associate your photos, library, and album memberships with your account. Your Google access token is stored locally in Chrome's storage and is sent to our backend only to verify your identity when you perform actions that require authentication (such as uploading a photo or joining an album).

Photos you upload. Photos you upload to your personal library or a shared album are stored on our servers (Supabase, hosted in the EU). We use these photos solely to display them in your new tab and to share them with other members of any shared album you belong to. We do not scan, analyse, or use your photos for any other purpose.

Album and membership data. We store the albums you create or belong to, the members of each album, and album settings. This data is stored on our servers and is used to power the shared album feature.

Extension preferences. Settings such as which widgets are visible, your preferred search engine, and your photo source are stored in Chrome's sync storage. These preferences are synced across your Chrome devices by Google and are not transmitted to our servers.

Location (weather widget). If you enable the weather widget, the extension requests your device's GPS location via the browser's Geolocation API. Your coordinates are sent to Open-Meteo (an open-source weather service) to retrieve the current weather, and to Nominatim (OpenStreetMap's geocoding service) to look up your city name. Your location is not stored on our servers.

Analytics. We use PostHog (hosted in the EU) to collect basic usage analytics and session replay. Data collected includes: events such as "new tab opened", a pseudonymous identifier derived from your Google ID, your browser and OS type, and screen recordings of your session with all text inputs masked. We use this data to understand how the extension is used and to diagnose issues. Analytics data is not linked to your name or email address outside of our own systems, and is not shared with third parties.

3. Data we do not collect

4. Third-party services

Caroluma uses the following third-party services to operate. Each service processes data as described in its own privacy policy.

5. Data retention and deletion

Your photos and account data are retained for as long as you have an account with Caroluma. You can delete your account at any time from the extension's Settings → Account tab. Deleting your account permanently removes your photos, library, and all album data associated with your account from our servers.

Analytics data collected via PostHog is retained according to PostHog's data retention policy (currently 1 year for session replays and events).

6. Data security

Photos are stored in a private storage bucket and are only accessible via short-lived signed URLs generated by our backend. All communication between the extension and our backend uses HTTPS. We apply row-level security policies to our database to ensure users can only access data they are authorised to see.

7. Children's privacy

Caroluma is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us and we will delete it.

8. Changes to this policy

We may update this policy from time to time. When we do, we will update the "Last updated" date at the top. Continued use of the extension after changes are posted constitutes your acceptance of the revised policy.

9. Contact

If you have questions or requests regarding your data, contact us at carolumaplatform@gmail.com.