Legal
Privacy Statement
Last updated August 19, 2026
This statement explains what Karrou (operated by Karrou Labs, New York City — “we”, “us”) collects when you use karrouhq.com, why we collect it, and the control you have over it. The short version: we collect what we need to run your profile, we don't sell your data, and we don't show ads.
What we collect
Account information. When you sign up we store your email address, name, and optional avatar image so we can create and secure your account.
Date of birth. At sign-up we ask for your date of birth for one reason: to verify that you are 18 or older. We compute your age on the server, record only the moment the check passed, and discard the date itself. It is never written to our database and never logged. Karrou does not knowingly collect data from anyone under 13; if you believe a minor has created an account, email us and we'll remove it.
Profile content. Everything you put on your profile — username, display name, bio, headline, what you're working on, your widgets and any links or descriptions on them, and your customization settings (palette, typography, layout). Your public profile is, by design, public.
Machine-readable profile. Every profile is also published at karrouhq.com/{username}.md, a text version meant for AI agents. You can turn this off in the editor; when off, both the .md URL and the in-page Machine view return 404. Your profile also appears in the daily Discovery edition (/discover) when there's something new to surface; turning the machine-readable profile off also excludes you from /discover.md.
Discoverable by employers. Every profile is discoverable by employers searching Karrou by default. “Discoverable” means an employer using our search surface can find your profile by name, headline, skills, and the other fields you have published — nothing more. An employer sees only what any visitor to karrouhq.com/{username} sees: your public profile. Your email, date-of-birth check timestamp, connected-service tokens, résumé-import counter, Mochi counter, and any other private field stay private and are never shared. You can turn employer discoverability off any time in the editor under Visibility; when off, your profile stays public at its URL but is excluded from employer search results. If you also turn the machine-readable profile off, employer discoverability is automatically off — employer matching is grounded on the machine-readable projection, so a profile without one cannot be matched.
Connected services. If you connect a service like GitHub or Spotify, we ask for read-only access (for example: your public GitHub profile, your currently playing and recently played Spotify tracks) and store the access tokens encrypted at rest. We only use them to render your widgets. You can disconnect a service at any time, which removes its tokens.
Waitlist. If you join the waitlist, we store your email, where you signed up from, and the referring page — only to let you know when we launch features.
Mochi. Mochi is an opt-in agent you can turn on at /app/mochi. It is off by default, and only the profile owner can ask it questions — it is not a visitor feature. When you ask Mochi a question, two things go to a third-party model provider (currently OpenRouter, using free-tier models): the text of your question, and the public machine-readable version of the profile you're asking about (your own, or someone else's .md if the target hasn't opted out). Free-tier model providers may log prompts and use them to train future models. Karrou only stores a per-user daily counter (your user id, the date, and how many questions you've asked today) so we can enforce the per-day limit — we do not store the questions or the answers. Turning Mochi off in /app/mochi stops all of it.
Résumé import. If you use the “Import from résumé” feature (during onboarding or from the editor), the PDF you upload is read into server memory to extract fields — headline, bio, work history, skills, project links — and then discarded. We do not store the file, we do not keep a copy of the extracted text, and we do not log its contents. The extracted text and your résumé filename are sent to the same third-party model provider Mochi uses (OpenRouter, free tier), which may retain and train on the request; if that matters to you, skip the import and fill in the editor manually. Karrou only keeps a per-user daily counter (your user id, the date, and how many imports you've done today) so we can enforce the per-day limit.
Preferences. Your theme choice (light/dark) is stored locally in your browser, not on our servers.
What we don't do
We don't sell or rent your personal data. We don't show ads or share your data with advertisers. We don't use your connected-service data for anything other than displaying the widgets you configured.
Who processes your data
Karrou runs on infrastructure providers who process data on our behalf: Vercel (hosting) and Supabase (database and authentication). If you turn Mochi on and ask it a question, that question and the target profile's public machine-readable view are sent to OpenRouter, our model provider, which routes to the underlying model. Because Mochi runs on free-tier models, OpenRouter and the model may retain and train on those prompts — if that matters to you, keep Mochi off. Connected services (GitHub, Spotify, and others you choose to link) share data with us only after you authorize them, under their own privacy policies.
Company suggestions. When you're editing a role in your work history, the “Company” field offers suggestions from other Karrou profiles AND from Clearbit's public company directory. We proxy the Clearbit lookup through our own server — your typing and IP address are not sent to Clearbit directly. What we forward is only the query string (typically a few characters of a company name), never your identity. The field is a free-text input: nothing stops you from ignoring the suggestions and typing anything you want.
Your rights and control
You can edit or remove your profile content at any time, disconnect any linked service, turn Mochi off at /app/mochi, turn employer discoverability off in the editor under Visibility, and delete your account — which removes your profile, customization data, connected-service tokens, your Mochi usage counter, and your résumé-import usage counter. To exercise any data right (access, correction, deletion, export), email aryaman@karrouhq.com.
Changes
If we make material changes to this statement, we'll update the date above and, for significant changes, notify you by email or on the site.