English policy mirror

Privacy notice

Last updated 2026-10-02

This page renders the same English privacy notice as the main privacy page, without requiring JavaScript.

Key Carpool stores information used to coordinate your carpool. Access depends on the pool’s visibility and your role, as described below.

What is stored

Your own name and email address, asked once after a code confirms your mobile number, kept against that number and shared by every pool the number is in. Family names, contact names and phone numbers, language, message preferences, SMS consent records and sign-in code requests (number, time, purpose and the wording version shown). The manager roster: each owner’s and manager’s name, mobile number, role, who added them and when they last signed in. Kids’ first names and, optionally, a photo and a pickup point. Pickup and destination addresses with their map coordinates. The schedule, swaps, covers, gifts, absences, driver status taps and a message log.

Delivery status of text messages and the STOP or START replies received. Timestamps of manager and member actions, for accountability inside the pool.

Files, assistant drafts and results may contain the personal information you include in them. Original files saved by a manager in the pool are retained separately from temporary assistant copies and remain accessible to authorized pool members until removed.

For WhatsApp: your WhatsApp agreement and opt-out, the recent turns of your conversation with the assistant so a reply makes sense in context, the identifiers of the messages received so a repeat delivery is not acted on twice, and the reminder settings you chose, including the hour and the day you asked for. Recent conversation history is cleared after seven days of inactivity. While you ask about driving history, the question itself (its dates, unit, whose drives and which carpool) is remembered for 30 minutes so a follow-up like “last month?” works; it holds no schedule, and it is dropped when your carpools or family change. The website keeps the same for each sign-in. Minimal opt-out records are kept so a cleanup does not turn messages back on.

Files sent on WhatsApp: a photo, PDF, Word (.docx) or Excel file you send is downloaded from Twilio only to answer what you ask about it, and its contents go with your question to Anthropic’s Claude API to be read.

A copy of the file and the text read from it are stored with that request, and are scheduled for automatic deletion after seven days. The request itself (your question, the file names and the answer or draft) is scheduled for automatic deletion after thirty days. So a follow-up like “and Tuesday?” can be asked of the same file, the conversation remembers the file last answered about, with that question and answer, for 30 minutes; that note is removed with the rest of a quiet conversation after seven days. A question about a file stays private to the person who asked it.

Only when a verified manager asks to import a file or to change the carpool from it does it become a draft other managers can review in Manage. The original file is then kept among the pool’s documents, open to authorised pool members, until a manager removes it or the pool is deleted, which can be much longer than seven days. On the website the same holds for the assistant chat, and files a manager sends through Manage or the Calendar tab are kept on the pool that way.

Twilio and Meta keep their own copies of messages and media under their own terms, and database backups hold copies as described under retention; Key Carpool does not delete those.

Who sees it

Members of the same pool see each other’s names, phones, kids, pickup points and schedule. Nobody else does: every pool, however its visibility is set, requires an authorized member or organizer sign-in before showing any family, any child’s name or any part of the schedule. Without one, a pool link shows only the pool’s name, kind, season and the times of its legs — no family, no child, no address. The pool’s name is whatever the person who set it up typed, so it can say something about the group: choose one you are content for anybody holding the link to read. Managers see everything for their pool, including the message log and the manager roster with numbers masked; the owner sees the roster’s full numbers.

Mobile numbers and SMS consent are used only to send the carpool notices described in the terms and, when you ask for one, a sign-in code. They are not sold, rented, or shared with third parties or affiliates for marketing purposes.

Text messages (SMS)

If you opt in, Key Carpool sends transactional text messages about your pool: driving reminders, swap and cover requests, confirmations, driver status updates and a weekly preview. Message frequency varies with your pool’s activity. Message and data rates may apply.

Only the owner of a number can opt it in, under Pool → Edit my contacts; a manager entering your number does not. Reply STOP to any message to stop, START to resume, or HELP for help. Consent is optional and not a condition of any purchase; opting out does not remove you from the pool.

Sign-in codes are a separate purpose: one code goes to the number you type, only when you request it, delivered through Twilio Verify. Requesting a code does not change your ride-alert consent or opt-out settings, and provider or carrier restrictions can still block delivery. Each request is kept as a consent record for two years.

Service providers

Hosting and database: Modelence Cloud (MongoDB), which publishes its own data processing agreement and the list of providers it uses in turn. Your data is stored in the United States and encrypted in transit and at rest, including in backups. Processing is not all in one country: that list includes a content delivery network with servers worldwide and authorised staff working from other countries. Messages: Twilio, which receives the phone number and message text needed to deliver each one. WhatsApp messages also pass through Meta, which operates WhatsApp.

Maps: where Google keys are configured, Key Carpool uses the Google Places API for address suggestions, Geocoding to turn a saved address into a point, and the Routes API for the driving time on a day card. Those receive the address or the stops being looked up. Of what Google returns, only a point’s latitude and longitude are kept, for thirty days, and shown only beside a Google map; drive times and route shapes are never stored. Where those keys are not configured, we do not automatically send your address anywhere for geocoding: it is saved exactly as you typed it and simply has no map point, so stops have no pins and there are no drive estimates. This is about automatic lookup only. Navigating opens the maps app you pick — Google Maps, Apple Maps or Waze — and sends it whatever the link you tapped covers: one stop for a single stop, or the start, the stops in order and the destination for a whole or partial route. No maps app receives any of that until you tap one of those links; the address lookups described above are separate and are not covered by that; and an address you write into a message or a question travels the way that message does, to the recipients listed here. Key Carpool does not use any public or free geocoding service for the addresses families enter. Separately from address lookup, a trip map draws its background tiles from OpenStreetMap, which receives the area being viewed (not your saved address), and every page loads its typefaces from Google Fonts, which receives your browser’s request for them. Neither is used to look up an address.

Assistant: the text and files you send, recent conversation turns, and the carpool information needed to answer are sent to the Anthropic Claude API. The context supplied by the app is limited to pools you are authorized to access. Your own messages or uploads may contain personal data; include only what is needed for your request.

Retention and removal

Pool records stay as long as the pool exists. Message bodies are cleared after ninety days; delivery metadata and opt-out records are kept separately. A manager can remove a family, contact or kid at any time. The owner can delete the whole pool: that removes its legs, families, contacts, children, pickup addresses, schedule, swaps and covers, absences, driver taps, saved stop orders, changed pickups, guests, the manager roster, the message log, action links, the audit trail, and the documents and assistant jobs kept on it. Your own name and number are not part of a pool and are not removed with it. A phone that has replied STOP keeps its record of having done so, so that deleting a pool can never make it reachable again. Deletion runs as one pass over every store listed above, and it is not instantaneous or atomic: work already under way can finish after it, so an owner who needs certainty should ask us to confirm. Three things it does not reach. A WhatsApp conversation still in use for another pool can hold sentences mentioning the deleted one until that conversation has been quiet for seven days. Database backups hold their own copies: our hosting provider snapshots the database every six hours and keeps those snapshots on a schedule that runs out at twelve months, so a deleted record can survive in a backup until then. Those snapshots normally expire within twelve months, unless longer retention is required by law. There is no point-in-time recovery. Messages already delivered to a phone are outside Key Carpool entirely. A calendar feed address copied before this changed is not: it keeps working until the pool’s feed key is changed, which stops it for everyone holding it. A pool’s owner or manager can replace the key in the calendar section of the pool’s page, or you can ask us to. Replacing it is pool-wide: it does not remove one person’s access on its own, and members who still want the calendar subscribe again. Whatever a calendar app has already downloaded and stored is beyond our reach. Reply STOP to a text to stop messages to your number without leaving the pool. Sign-in code requests are kept for two years, then deleted.

Children

Key Carpool is used by parents and guardians. Kids are described only by first name, an optional photo and a pickup point, entered by their own family or the manager.

Contact

Your rights: from Account → Privacy, once your number is confirmed by a code, you can download a summary of what Key Carpool holds about that number across every pool it is in — your account, your family and children, your pickup addresses, your driving days, and a record that each message and sign-in happened. It is a summary and says so: the text of messages and of assistant conversations is left out, because a reminder describes the household it is about as much as the person who received it, and so are swap requests, a pool’s change history and uploaded documents. Other families are not in it. From the same place you can ask for the complete copy: a person prepares it and gives you your own personal data, holding back only what would reveal somebody else’s — not whole categories by default. You can also ask for your details to be corrected or your account deleted. Those are carried out by a person rather than a button, because your records run across pools you may organize and removing an organizer without settling who takes over would leave other families stuck; you get a reference straight away and we aim to answer within one calendar month.

For questions about your data, or to make a request without signing in, contact StartIQ LLC at h@keycarpool.com or by post at 200 Crandon Blvd, Suite 315B, Key Biscayne, Florida 33149, USA.

Privacy choices and rights

StartIQ LLC is responsible for the personal data it processes to operate Key Carpool. Information comes from you, your pool organizers and family members, and service providers described above. Where the GDPR applies, necessary account and service processing is based on providing the service you request; security and fraud prevention rely on our legitimate interest in protecting users. Optional message alerts and analytics rely on your consent, which you can withdraw.

Depending on applicable law, you may request access, correction, deletion, a portable copy, restriction of processing, or object to processing based on legitimate interests. Contact h@keycarpool.com or use Account → Privacy. We may need to verify your identity and protect other people’s information. You may also complain to your relevant data-protection authority. Requests are assessed under the applicable deadlines and exceptions; withdrawing consent does not undo earlier lawful processing.

A verified phone number and the details needed for a requested ride are necessary for the relevant features. Email, photos, optional alerts and analytics are optional. Data may be processed outside your country as described above; contact us for details of the applicable transfer safeguards. Choosing a translation does not change where data is stored.

Independent recovery backups

StartIQ LLC uses Amazon Web Services (AWS) directly to store private, encrypted recovery copies of the application database in Ohio, United States. Copies can contain account, pool, contact, child, pickup, schedule, message, consent and uploaded-file records held in that database. Re-creatable map coordinate caches are excluded. Backups are used for security, continuity and recovery, not advertising. GitHub Actions coordinates the daily backup and receives technical metadata, not database credentials or archive contents.

Each AWS backup is protected against deletion or replacement for 30 days. Deleting data in the app does not immediately remove it from a locked backup. Lifecycle rules make copies eligible for removal around day 32; processing can take longer. These copies remain access-restricted and are not used as the live database. Before any recovered copy is put back into service, we must apply subsequent deletions, corrections, messaging opt-outs and access revocations. Modelence’s separate backup schedule described above still applies.

This processing supports our legitimate interest in protecting the service and its users, subject to applicable law and your rights. AWS’s Data Processing Addendum and applicable transfer clauses govern its processing; US storage is not EU-only hosting. Contact h@keycarpool.com to request information about safeguards or exercise your rights. This database backup does not cover external services or encryption keys stored separately.

Service measurements and costs

Our private operator dashboard uses limited service records: sign-in and messaging timestamps, carpool creation and activity, AI provider and model, token counts, response time, errors and charges. It does not copy message text, prompts, children’s names, addresses or IP addresses. A keyed, pseudonymous identifier can connect a number’s service events across its pools; it is not anonymous. Records are kept for up to 400 days in our existing database. Only authorized operators can access the dashboard. Deleting a pool removes its activity and identifying associations; anonymous lifecycle totals and provider billing totals remain. Request access, deletion or object to this processing through Account → Privacy or h@keycarpool.com. Optional website analytics remain separately controlled by your analytics preference.

External AI apps you connect

Connecting an external AI app through our optional MCP connector is your choice. After verifying your phone, you choose which pools the app may read. It can receive pool names and time zones; trip dates, times and status; driver household labels; scheduled rider counts; and the type, dates and status of ride-change requests made by your household.

Connector replies exclude contact details, pickup and destination addresses or coordinates, child details, messages and uploaded documents. Pool, household and trip labels are entered by users and may themselves contain personal information. The connector cannot change schedules or send messages. We check the connection and current account and pool permissions on each request.

You can revoke a connection in Account → Connected apps. Revoking it or deleting your account stops future access through that connection. The external app or provider may retain information it already received under its own privacy policy; these actions do not delete its copies.

Analytics preferences

With your permission, we send PostHog EU page categories, language, approximate country, device category and selected completed steps or error categories. A random browser identifier lasts up to 180 days; it is not your name or account ID. This is pseudonymous usage data, not anonymous data. We do not send private URLs, names, phones, emails, addresses, messages or uploads. We do not record sessions, clicks, forms or screen contents. PostHog receives network requests; IP storage and location enrichment are disabled. Consent is optional, expires after 180 days and can be withdrawn under Analytics preferences. Global Privacy Control and Do Not Track disable collection. Declining does not affect the service. PostHog EU hosts these analytics in Frankfurt; the carpool database remains in the US. Usage counts cover consenting browsers and may miss blocked requests; they do not measure all people. For access or deletion of analytics, include the browser reference shown in Analytics preferences in your request to h@keycarpool.com. Withdrawing consent stops future collection but does not itself erase earlier events. Analytics events are retained for up to one year on our PostHog free plan.