Skip to content
ORBITARATECHNOLOGIES
CartlySmart shopping companionVelox VPNSimple everyday privacy
AboutContactExplore Cartly
← Back to Cartly

Cartly legal

Cartly Privacy Policy

Effective September 5, 2026

1. Overview

Cartly is provided by Orbitara Technologies LLC, a Wyoming limited liability company in the United States. This Privacy Policy explains how information is handled when you use Cartly. Cartly is a general-audience Android application and does not currently require a user account.

2. Information stored on your device

Shopping trips, budgets, cart items, prices, product data, shopping history, preferences, scanned or recognized text, and related shopping information may be stored locally on your device. Cartly's local Room database storage should not be treated as encrypted storage.

If you create a .cartlybackup export, that export is a plain structured backup file. Protect exported copies appropriately, including when storing, transferring, or sharing them.

3. Installation identification and authentication

Cartly creates a random installation identifier and sends it to Cartly's backend over HTTPS when server-backed functionality is used. The backend normally persists a keyed, HMAC-derived representation instead of storing the raw installation UUID as its persistent identifier.

A separate installation credential authenticates server-backed requests. On Android, that credential is protected using Android Keystore-backed encrypted storage.

4. Camera, OCR, and barcode features

Camera access is used for shopping scanning features. Camera and optical character recognition processing are generally performed locally on the device. Under Cartly's current AI architecture, camera frames and receipt images are not uploaded to Cartly AI.

Product barcode numbers may be sent to Open Food Facts to retrieve product information. Open Food Facts may handle those requests under its own privacy terms.

5. Cartly AI

Cartly AI requests first go to Cartly's backend and are then sent through OpenRouter to an eligible AI provider and model. A request may include your question and relevant structured shopping context, such as product names, prices, quantities, budget information, ingredients, barcode information, evidence excerpts, and recent conversation context.

Cartly does not send merchant or store names, Android advertising IDs, installation credentials, device camera images, or receipt images to the AI provider under the current architecture. The random installation identifier is used between the app and Cartly's backend and is not included in the OpenRouter AI request.

Production OpenRouter requests require supported request parameters, deny provider data collection, and allow routing fallbacks that satisfy those request constraints. Cartly does not promise a fixed downstream AI provider, and it does not claim that these requests have Zero Data Retention. OpenRouter account settings for input/output logging, model-training participation, prompt publishing, broadcast observability, and workspace data-use options are disabled as an operational privacy choice. Third-party providers may nevertheless have their own processing and retention obligations and policies.

Cartly's backend does not normally persist ordinary AI prompt or response content after processing. It does retain limited usage metadata, including a request identifier, pseudonymous installation association, provider and model information, token usage, cost information when supplied, and timestamps.

6. Reporting an AI response

You may choose to report an AI response. When you do, Cartly stores the reported response text, your selected reason, any optional comment you provide, the request ID, a response hash, and a pseudonymous installation association. This user-initiated report storage is separate from ordinary AI processing, where prompt and response content is not normally persisted by Cartly.

7. Optional rewarded advertising

Cartly uses Google AdMob for optional rewarded advertising. Google advertising and consent services may process device, network, advertising, consent, and ad-interaction information under Google's own policies. Where required, Cartly uses Google's consent-management flow before requesting ads.

Cartly may use server-side verification to validate rewarded-ad credits, prevent duplicate rewards, and address fraud or manipulation. Cartly does not currently include a dedicated first-party analytics or crash-reporting service. This does not prevent Google or AdMob software from collecting information under their own policies.

8. Third-party services

Cartly uses third parties where relevant to provide its functionality, including:

  • OpenRouter and eligible downstream AI providers for Cartly AI;
  • Google services, including AdMob and consent-management services;
  • Open Food Facts for barcode-based product information; and
  • hosting, infrastructure, and encrypted backup providers supporting Cartly's backend.

Information handled by a third party may also be governed by that party's terms and privacy policy.

9. Retention

Cartly's intended server-side retention periods are:

  • Ordinary AI prompt and response content: not persistently retained after normal processing.
  • AI usage metadata: up to 90 days.
  • AI reports and voluntarily submitted report content: up to 180 days.
  • Rate-limit and quota records: normally only for the applicable window, generally no more than 24 hours.
  • Rewarded-ad transaction and anti-fraud records: up to 12 months.
  • Installation authentication records and associated credit balances: while active, and they may be removed after approximately 24 months of inactivity.
  • Routine operational and security logs: up to 30 days.

Information may be retained longer when reasonably necessary for security or fraud investigations, disputes, legal obligations, or enforcement.

10. Your choices and requests

You may choose not to use optional Cartly AI, camera, or rewarded-ad functionality. Local app data may generally be removed using Android's app-storage controls or by uninstalling Cartly, subject to normal Android and platform backup behavior.

Because Cartly has no user accounts, privacy requests concerning server records may require enough information to locate records associated with a pseudonymous installation. Contact us through the route listed below to make a privacy request.

11. Children

Cartly is a general-audience application. It is not directed to children under 13.

12. Security

Orbitara uses HTTPS network encryption, restricted backend access, authorization controls, installation credential protection, and other reasonable technical and organizational safeguards. No system or transmission method can be guaranteed to be perfectly secure.

13. Sale of personal information

Orbitara does not sell personal information.

14. Changes to this policy

We may update this Privacy Policy as Cartly, its providers, or legal requirements change. The effective date at the top of this page identifies the current version.

15. Contact

For privacy questions or requests, contact Orbitara Technologies LLC through our contact page at https://orbitaratech.site/contact.

Orbitara Technologies

Building practical software
for everyday life.

Products

CartlyVelox VPN

Company

AboutContact

Legal

Cartly Privacy PolicyCartly Terms of Service

Contact

SupportPrivacy
ORBITARATECHNOLOGIES

© 2026 Orbitara Technologies LLC. All rights reserved.