Privacy Policy

Effective Date: April 12, 2026 · Last Updated: August 14, 2026

1. Who We Are and What This Policy Covers

Carrot Labs AI, Inc.(“Carrot Labs,” “we,” “us,” or “our”) operates SuperPenguin, an AI cost management and engineering analytics platform.

This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use the SuperPenguin website, dashboard, software development kits (“SDKs”), macOS Desktop application, integrations, assistant, and related services (collectively, the “Services”).

If an employer or other organization provides your access to SuperPenguin, that organization controls its workspace, connected tools, enabled features, member access, and its use of workforce data. The organization is responsible for providing notices and obtaining any consent required for its use of the Services. Where we process organization data on a customer's behalf, our obligations may also be governed by a customer agreement or data processing addendum.

Questions about this policy or your data may be sent to [email protected].

2. Information We Collect

2.1 Account, Organization, Billing, and Communications Data

  • Account information: Name, email address, user and authentication identifiers, sign-in method, account status, and profile information.
  • Organization information: Workspace name, membership, role, invitations, plan, feature entitlements, and organization settings.
  • Billing information: Customer, subscription, plan, invoice, and payment-status information. Stripe processes payment-card details; SuperPenguin does not store complete card numbers.
  • Communications: Messages and contact details you provide when requesting support, completing security diligence, or otherwise communicating with us.

2.2 Provider and Customer-Directed Integration Data

When an authorized customer connects an AI provider or another integration, we may collect the credentials and records needed to perform the requested operation. Depending on the integration, this can include:

  • Provider admin, billing, or usage credentials, which are encrypted at rest
  • Provider organization, account, invoice, usage, model, token, credit, and cost records
  • GitHub repository, branch, commit, pull-request, author, review, and installation information
  • Slack or Discord installation, channel, webhook, and alert delivery information

We use integration credentials only to perform operations the customer authorizes. The privacy policies of customer-selected providers and integrations also apply to their own services.

2.3 SDK Telemetry

By default, the SuperPenguin SDK collects cost and performance metadata for instrumented AI requests, including:

  • AI provider, model, route, and service tier when available
  • Input, output, reasoning, and cache token counts when available
  • Estimated cost, request latency, timestamps, and status
  • Attribution metadata supplied by the customer, such as customer, feature, team, environment, prompt key, prompt version, session, or trace identifiers

By default, the SDK does not collect prompt or response content, images, audio, tool arguments, or provider API keys. Eligible organizations may separately enable sampled SDK content capture as described in Section 2.5.

2.4 SuperPenguin Desktop and AI Coding Metadata

After a user connects SuperPenguin Desktop, the application reads local usage artifacts from supported AI coding tools, including Cursor, Claude Code, and Codex. By default, Desktop uploads content-free usage and attribution metadata that may include:

  • Tool and model identifiers; token, request, turn, and context counts; timestamps; session identifiers; and data-quality fields
  • Workspace, repository, remote, and branch identifiers, including local workspace paths when reported by the tool
  • Relative file paths, aggregate edit statistics, commit hashes, and pull-request evidence
  • Configuration metadata such as rule filenames, skill and MCP server names, tool-call counts, and configuration token counts
  • API-equivalent cost estimates, attribution results, provenance, synchronization status, and derived subscription or credit coverage categories
  • User, organization, installation, machine, and tool-version identifiers used to secure and operate sync

By default, Desktop does not upload source file contents, prompts, model responses, tool arguments or outputs, environment-variable values, provider credentials, or raw provider usage responses. For Claude Code coverage classification, Desktop keeps a bounded history of utilization percentages, reset times, account-match fingerprints, extra-usage enabled state, and a credential-route category on the device for up to 45 days. Personal workspace usage sync may upload the derived coverage category and bounded provenance. Team workspace sync uploads those fields only when sharing is company-required and acknowledged or selected by the member. It does not upload the historical observations, credential values, or extra-usage dollar amounts. The local history is removed when local usage-limit access or Claude Code collection is disabled. Where a local provider credential is needed to retrieve a usage limit, Desktop does not refresh it, persist a copy for SuperPenguin, or upload it to our servers.

2.5 Optional Content, Analysis, and Sharing Features

The following features have separate controls. Enabling one does not automatically enable another.

  • SDK content capture: Eligible organizations may opt in to sampled capture of text prompts and outcomes for offline analysis. The feature is off by default, strips images and audio, applies built-in redaction, encrypts captured content, and allows organization owners to delete it from Settings.
  • Desktop prompt storage: Each member may choose to upload redacted prompt text from supported coding tools. Storage is off by default. Stored prompts are encrypted, and disabling storage deletes that member's stored prompt records. Prompt-derived session titles are stored only when this permission allows it.
  • Semantic matching: Members may separately enable semantic matching for less-exact session and pull-request attribution. Semantic inputs are sent to a hosted model only if the member also enables remote semantic analysis.
  • Usage-limit sharing:A member may share current normalized provider allowance percentages, reset times, pace, freshness, reporting status, source type, and an account-match fingerprint with their organization. We do not include provider credentials, provider account emails, prompts, source code, raw provider responses, or extra-usage dollar amounts. Depending on the customer's plan and policy, sharing may be optional or required by the organization after an in-product disclosure and acknowledgment.
  • Session Analyze: When a user requests analysis of a selected local session, bounded prompt and response previews, tool names, and structured session signals are sent to a hosted model service to produce the requested categorization.
  • Ask SuperPenguin: When a user starts an assistant conversation, we process and store the chat, relevant conversation history, selected product documentation, and limited account context such as organization, role, plan, and connected-provider names to provide a response.

2.6 Website, Device, Cookie, and Product Analytics Data

We and our analytics providers collect information about use of the website and dashboard, including pages viewed, referring URLs, features and sections used, clicks, signup and download events, timestamps, browser and operating-system information, device and session identifiers, cookie or local-storage identifiers, and IP address.

We use PostHog for product analytics. For authenticated users, we may associate analytics with a SuperPenguin user identifier, email address, account creation time, organization identifier and name, workspace type, and organization group. Depending on our PostHog project configuration, analytics may include session replay of website or dashboard interactions. We do not use this information for third-party advertising.

3. How We Use Information

We use the information described above to:

  • Provide, operate, maintain, and secure the Services
  • Authenticate users and administer accounts and organizations
  • Sync provider billing and usage and display cost, attribution, engineering, and allowance analytics
  • Match AI coding activity to repositories, commits, and pull requests
  • Provide content capture, semantic analysis, Session Analyze, and assistant functionality when separately enabled or requested
  • Process subscriptions, invoices, and payments
  • Send authentication, service, security, and alert messages
  • Monitor reliability, detect abuse, troubleshoot, and improve the Services
  • Respond to support, privacy, and security requests
  • Comply with legal obligations and enforce our agreements and policies

4. How We Disclose Information

We may disclose information in the following circumstances:

  • Customer organizations: Organization data is available to the customer and its authorized users according to organization membership, workspace roles, feature-specific permissions, and customer configuration. An organization may receive information about workforce use of connected AI coding tools.
  • Service providers and subprocessors: We use vendors for hosting, databases, data processing, compliance, analytics, payments, email delivery, support, and hosted model processing. These include Vercel, Supabase, Google Cloud Platform, Vanta, Stripe, Resend, PostHog, and, when an optional hosted-AI feature is used, the configured model or gateway provider. They may process information only for the services we engage them to provide, subject to applicable contractual terms.
  • Customer-directed integrations: We disclose information to AI providers, GitHub, Slack, Discord, and other services when a customer connects or directs use of that integration.
  • Legal and safety reasons: We may disclose information when required by law or when reasonably necessary to protect the rights, safety, and integrity of Carrot Labs, our customers, users, or others.
  • Business transfers: Information may be transferred in connection with a merger, financing, reorganization, acquisition, bankruptcy, or sale of assets, subject to applicable law and continued protection.
  • With your direction: We may disclose information for another purpose when you or the customer directs or consents to it.

We do not sell personal information, disclose it to data brokers, or share it for cross-context behavioral advertising. Our public Trust Center provides current security-control and published subprocessor information.

5. Organization and Individual Controls

  • Workspace owners and designated roles can manage organization policies, integrations, and access. Other member visibility depends on the feature and access configuration.
  • SDK content capture is controlled by eligible organizations and is off by default.
  • Desktop prompt storage, semantic matching, and remote semantic analysis have separate member controls and are off by default.
  • Coding-tool usage-limit sharing is off by default for an individual and may be made an organization policy on eligible plans after disclosure and acknowledgment.
  • Session Analyze and Ask SuperPenguin process content only when a user invokes those features.
  • Users can disconnect Desktop, and customers can disconnect provider and customer-directed integrations.

If you use a workspace administered by your employer or another organization, contact that organization with questions about its policies, legal basis, and use of workforce data.

6. Data Retention and Deletion

We retain information only for as long as reasonably necessary to provide the Services, maintain security and business records, comply with law, resolve disputes, and enforce agreements. Specific periods may also be established in a customer agreement.

  • Account and organization data: Generally retained while the relevant account or organization is active and for a limited period afterward for legitimate business, security, legal, or compliance purposes.
  • SDK and Desktop telemetry: Generally retained while the customer workspace is active so we can provide analytics, attribution, and reporting, unless an applicable agreement or verified deletion request requires earlier deletion.
  • Desktop stored prompts: Deleted when the member disables prompt storage, subject to temporary residual copies in protected backups.
  • SDK captured content: Retained until an organization owner deletes it, the workspace is deleted, or an applicable agreement requires deletion.
  • Usage-limit sharing:Designed to retain the latest reported state rather than a historical provider-limit ledger. New shared observations stop when sharing is no longer authorized. Claude Code's device-local classification history is retained for up to 45 days and is deleted when its local collection is disabled.
  • Assistant conversations: Retained to provide conversation history until deleted through the applicable account or data-deletion process.
  • Provider and integration credentials: Removed from active systems when the integration is disconnected.
  • Analytics: Identifiable analytics is retained according to our analytics configuration. Aggregated or deidentified statistics that no longer identify an individual or customer may be retained for product and business analysis.

Data removed from active systems may remain for a limited period in encrypted or access-controlled backups, logs, fraud-prevention records, or legally required records until those records expire under applicable procedures.

7. Legal Bases and Privacy Rights

Where applicable law requires a legal basis, we process personal information as necessary to perform our contracts, comply with law, pursue legitimate interests such as securing and improving the Services, and based on consent where requested. You may withdraw consent for future processing at any time, but withdrawal does not affect processing already performed.

Depending on your location and subject to applicable exceptions, you may have the right to request access, correction, deletion, or portability of personal information, or to object to or restrict certain processing. To submit a request, email [email protected]. We may verify your identity and authority before completing a request. We respond to verified requests within 30 days unless a longer period is permitted by applicable law.

When Carrot Labs processes information on behalf of a customer organization, we may refer your request to that organization so it can respond as the responsible controller or business.

8. Cookies and Analytics Choices

We use cookies, local storage, and similar technologies for authentication, security, organization selection, signup and Desktop connection flows, and product analytics. Some identifiers operate across SuperPenguin subdomains so a session or signup flow can continue between the marketing site and application.

Most browsers allow you to delete or block cookies and local storage. Blocking required technologies may prevent sign-in or other features from working. Blocking analytics technologies may reduce our ability to connect product events or troubleshoot your experience. You may contact us with an analytics privacy request.

9. Data Security

We use administrative, technical, and organizational safeguards designed to protect information, including TLS in transit, application-level encryption for stored provider credentials and opt-in content, access controls, separated environments, secure development procedures, monitoring, backups, and continuity planning. Additional details are available on our Security page and in our Trust Center. No transmission or storage system can be guaranteed to be completely secure.

10. International Processing

Carrot Labs and its service providers may process information in the United States and other countries where they operate. These countries may have data-protection laws different from those in your jurisdiction. Where required, we use contractual or other safeguards for international transfers.

11. Children's Privacy

The Services are not directed to individuals under 16, and we do not knowingly collect personal information from children under 16. If we learn that we have done so, we will take appropriate steps to delete it.

12. Changes to This Policy

We may update this Privacy Policy as our Services or legal obligations change. We will update the “Last Updated” date above and provide additional notice through the Services or by email when required for a material change.

13. Contact Us

Contact us with privacy questions, requests, or complaints: