Privacy Policy
Caadit is built so you can send something personal without handing over your life. This page explains, in plain language first, exactly what we collect, why, and what stays in your control.
In plain words
- You can create and send moments without an account. A random guest token, not your name, keeps your drafts together.
- We collect very little data, only what is needed to make your moments work. There are no ads, no tracking pixels and no cross-site tracking.
- We never sell your information to anyone, ever, and we do not train AI models on your personal photos.
- Voice cloning only ever happens when you explicitly ask for it, and you can delete a clone at any time.
- You control your content and can request deletion at any time. We are GDPR, CCPA, and COPPA compliant.
1. What information we collect and why
We follow a simple principle: collect only what we need, nothing more. Here is exactly what data we gather and why we need it.
Information you actively provide
When you create a moment on Caadit, you choose what to share:
Moment content
- The words you type into your moment
- Audio you record directly in your browser
- Photos you upload to personalize your moment
- Names or dedications you include (optional)
- Colors, styles, and templates you choose
This is your moment content. We cannot create it without this information.
Contact information (optional)
- Email address, if you choose to share your moment via email, create an account, or receive essential service communications
- Phone number, WhatsApp number, or Telegram handle, if you choose to receive or send moments via those channels, or for account authentication purposes
Contact details are used only for the purpose you provide them: delivering your moment, verifying your identity, or essential service communication. We will never use your phone number or messaging handles for marketing unless you explicitly opt in.
Payment information (entirely optional)
- Billing name and address, as required by payment processors
- Transaction history for purchases you make, such as gift cards or optional premium features
- We never see or store your credit card numbers. Those are handled entirely by our payment processors
Caadit is free to use. You can create and send unlimited moments at no cost, with no account required. Payment details are only collected if you choose to purchase an optional add-on such as an attached gift card or a premium feature. Nothing about the core moment experience requires payment.
Signing in with Google
Creating a moment never requires an account. If you choose to sign in with Google so your moments follow you between devices, Google asks for your permission and then shares a limited set of information with us.
Google user data we access
We request only the three basic sign-in scopes, openid, email and profile. Through them we receive:
- Your email address
- Your name and profile picture, where you have set one
- A Google account identifier that lets us recognize you on your next visit
We do not request access to Gmail, Drive, Contacts, Calendar, or any other Google service, and we cannot read them.
How we use it
- To create your Caadit account and sign you back in
- To show your name and picture in your own account area
- To attach the moments you create to your account so you can find them again
- To send you service messages you have asked for, such as a delivery receipt
How we store and share it
- It is stored on our servers alongside your account and protected the same way as the rest of your data, as described in section 4.
- We never sell it, never use it for advertising, and never pass it to a third party for their own purposes.
- Caadit's use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
- You can disconnect Caadit at any time from your Google account permissions page, and you can ask us to delete your account and its data as described in section 7.
Information automatically collected
Like most websites, we automatically collect minimal technical information to keep Caadit running properly:
Device and browser information
- Browser type and version (Chrome, Safari, Firefox, etc.)
- Operating system (iOS, Android, Windows, macOS)
- Screen resolution, to deliver responsive designs that look right on your device
- Device type (mobile, tablet, or desktop) for experience optimization
This helps us ensure your moments display properly on any device and lets us debug issues specific to certain browsers.
Anonymous usage data
- Which sections of Caadit you visit (homepage, moment creator, etc.)
- Features used, such as voice recording, music generation, or template selection
- How long moment creation takes, so we can optimize the experience
- Where users tend to pause or get confused, for UX improvements
All analytics are aggregated and anonymized. We analyze patterns, not individuals.
IP address and general location
- Your device's IP address, logged temporarily
- General city and country level location, not precise GPS coordinates
Used for security, fraud prevention, and verifying compliance with regional privacy laws like GDPR.
Cookies (minimal and functional)
- Session cookies that remember your moment creation progress so a page refresh does not lose your work
- Preference cookies for settings like Simple Mode and language preference
- Security cookies to prevent fraud and cross-site request forgery
We do not use third-party advertising cookies, social media tracking pixels, or cross-site tracking. See section 8 for full cookie details.
Information we do not collect
Your privacy protections include the following:
- No social media tracking pixels (no Facebook Pixel, no Google Ads remarketing)
- No third-party advertising cookies, because we are ad-free
- No precise geolocation data, only city and country level
- No browsing history from outside Caadit
- No microphone access without your explicit permission
- No background data collection when you are not actively using the site
- No selling or renting of user data under any circumstances
Guest tokens instead of identity
You do not need an account. When you create without one, we issue a random guest token that is stored on your device. It links your drafts and moments together so you can come back to them, and it carries no name, email or phone number. If you later sign up, moments made under your guest token can be claimed into your account.
2. Your voice and voice cloning
Voice is what makes Caadit personal, so it gets its own section.
Voice recordings
When you record a voice note for a moment, the recording is stored with that moment and played to the people you share it with. It is processed to sync playback with the moment (for example word-by-word highlighting) and to mix it into the downloadable video.
Voice cloning
If you choose the voice cloning feature, your voice sample is processed by a specialist third-party speech provider acting on our behalf to build a synthetic voice that reads your message. This happens only when you explicitly start it, never silently. Three rules apply:
- We only build a clone from a sample you provide for that purpose, with your consent.
- You may only clone your own voice, or the voice of someone who has given you their permission. Cloning someone without their permission breaks our Terms.
- You can delete a voice clone at any time, and we remove it from our systems and instruct our provider to do the same.
We do not use your voice, cloned or recorded, to train machine learning models, and we do not sell it to anyone.
3. How we use your information
We use your information for one primary purpose: to provide and improve Caadit. Here is a full breakdown of every way we use your data.
Core service delivery
- Processing your text, voice, and photos through our Creative Intelligence Engine to generate personalized moment designs
- Using your mood preferences to generate custom soundtracks via Meta MusicGen
- Sending your audio to ElevenLabs for noise reduction and quality improvement
- Creating secure, unique sharing URLs for each moment
- Storing and delivering your moments to recipients you choose
Communication and sharing
- Sending your moment URL to recipients via email, when you request it
- Responding to your support questions and troubleshooting issues
- Notifying you about major feature launches or important service changes, not marketing spam
Service improvement and analytics
- Understanding which features are popular and where users get stuck
- Monitoring load times, error rates, and server performance
- Testing design variations to improve the user experience (always anonymized)
- Prioritizing new features based on what users actually need
All analytics are aggregated and anonymized. We analyze trends, not individual users.
Security and fraud prevention
- Identifying bots, spam, and malicious activity
- Detecting stolen credit cards, chargebacks, or fraudulent gift card purchases
- Removing prohibited content such as hate speech or harassment
- Blocking DDoS attacks and other security threats
Legal compliance
- Fulfilling our obligations under GDPR, CCPA, COPPA, and other applicable regulations
- Providing information when required by valid court orders or subpoenas
- Investigating violations of our Terms of Service
- Maintaining transaction records for tax and accounting purposes
What we do not do with your data
- Sell your data to advertisers, data brokers, or anyone else
- Use your voice or photos in Caadit marketing without your permission
- Share voice recordings publicly. Only the recipients you choose can hear them
- Train AI models on your personal photos
- Track you across other websites
4. How we store and protect your data
Your data security is our top priority. We implement industry-leading security practices to protect your information from unauthorized access, theft, or loss.
Where your data lives
Infrastructure providers
Your data is hosted on servers provided by Contabo, a European infrastructure provider known for reliable, privacy-conscious hosting. Network traffic and security are handled by Cloudflare, which protects against DDoS attacks, filters malicious traffic, and ensures fast, reliable delivery of content to users worldwide.
- Primary servers located in the United States and Europe
- Cloudflare's global network adds an additional layer of security and performance
Encryption
- All data in transit uses TLS 1.3 encryption. Your voice recordings, photos, and text are protected during transmission, the same standard used in online banking.
- Data stored on our servers is encrypted at rest. Even if storage media were physically compromised, your data would not be readable.
- Encryption keys are managed separately from the data they protect, with regular rotation.
Backup and redundancy
- Complete system backups run every 24 hours
- Moments are replicated to multiple data centers in real time
- Backups are retained for 30 days in case you accidentally delete something
- Data is stored in at least two separate geographic locations
Security measures
Access controls
Strict role-based access controls ensure only authorized Caadit team members can access production systems. All access is logged and monitored. Multi-factor authentication is required for all admin accounts.
Security audits and penetration testing
We conduct quarterly security audits and annual third-party penetration testing to identify and resolve vulnerabilities before they can be exploited.
Continuous monitoring
Automated systems monitor for suspicious activity, unauthorized access attempts, and unusual traffic patterns around the clock. Alerts trigger immediate review by our security team.
Regular updates
All software, libraries, and dependencies are kept current with the latest security patches. Automated vulnerability scanning runs daily.
Incident response
In the unlikely event of a data breach, we have a detailed incident response plan that includes immediate containment, forensic analysis, user notification within 72 hours as required by GDPR, and clear remediation steps.
An honest note on security
While we implement industry-leading security measures, no system is completely immune to attack. The internet itself carries inherent risks, and we cannot guarantee absolute protection against sophisticated threats.
Please avoid including highly sensitive information in your moments: Social Security numbers, credit card details, passwords, or medical records. Caadit is designed for emotional expression, not for storing confidential data.
5. Third-party services and data sharing
Caadit integrates with a range of trusted third-party services to deliver AI-powered features, analytics, infrastructure, and payments. We carefully vet all partners and share only the minimum data necessary. As our platform grows, we may introduce additional AI providers or tools. When we do, this section will be updated to reflect them. We apply the same data-minimization principles to every partner, named or future.
Google Gemini (Creative Intelligence)
Purpose: Powers our Creative Intelligence Engine for moment design generation, text processing, and layout optimization.
Data shared: Text messages you write, occasion type, and design preferences. Voice recordings, personal photos, and contact details are not shared with Gemini.
Retention: Google processes text in real-time and does not retain your moment messages per our agreement with them.
Privacy Policy: Google Privacy Policy
ElevenLabs (voice enhancement)
Purpose: Enhances voice recording quality by removing background noise, normalizing volume, and improving clarity.
Data shared: Your raw voice recording, sent securely via HTTPS, along with audio processing preferences.
Retention: ElevenLabs processes your recording and immediately deletes it from their servers, typically within seconds. They do not store or use your voice for AI training.
Privacy Policy: ElevenLabs Privacy Policy
Meta MusicGen (AI music generation)
Purpose: Creates original, royalty-free background music tailored to your moment's emotional tone.
Data shared: Music style preferences, duration requirements, and occasion type. No personal information is shared.
Privacy Policy: Meta Privacy Policy
Payment processors (Stripe and PayPal)
Purpose: Process optional purchases such as gift cards or premium feature upgrades.
Data shared: Billing name, address, transaction amount, and email for receipts.
Caadit never sees or stores your credit card numbers. Payment data goes directly to Stripe or PayPal using PCI-DSS Level 1 compliant encryption.
Privacy Policies: Stripe Privacy | PayPal Privacy
Google Analytics
Purpose: Understand how users navigate Caadit, which features are most used, and where experience improvements are needed.
Data shared: Page views, session duration, device type, and general location (country/region). This data is aggregated. Google does not receive information that identifies you personally in connection with your moment content.
Cookies: Google Analytics sets cookies to distinguish sessions. You can opt out using the Google Analytics Opt-out Browser Add-on or by adjusting cookie preferences in your browser.
Privacy Policy: Google Privacy Policy
Cloudflare (network and security)
Purpose: Protects Caadit against DDoS attacks, filters malicious traffic, and ensures fast, reliable content delivery to users worldwide.
Data shared: Network traffic passes through Cloudflare's infrastructure, which means Cloudflare can see IP addresses and request metadata for security purposes. Cloudflare does not receive your moment content.
Privacy Policy: Cloudflare Privacy Policy
Additional and future AI providers
Caadit is an evolving platform. Beyond the services listed above, we may integrate additional AI providers for capabilities such as image generation, language translation, content moderation, accessibility features, or other creative enhancements. These may include providers such as OpenAI, Anthropic, Stability AI, or others in the rapidly developing AI ecosystem.
Our commitment in all cases: We share only what is necessary for the specific task, we do not authorize partners to use your personal content for their own model training, and we will update this section whenever a new significant integration is added.
If you have questions about a specific integration not listed here, contact us at hi@caadit.com.
A note on third-party responsibility
While we carefully select partners who share our privacy values, Caadit is not responsible for third-party privacy practices. We encourage you to review their policies linked above. If you have concerns, reach out at hi@caadit.com.
6. Bot protection (Cloudflare Turnstile)
To keep anonymous creation free without letting bots abuse it, we use Cloudflare Turnstile, including its invisible mode, on actions such as rendering a video. Turnstile evaluates limited device and browser signals to tell humans and automated traffic apart, without tracking you across the web and without showing you puzzle CAPTCHAs.
Turnstile is operated by Cloudflare, Inc. and processes this data as described in the Cloudflare Turnstile Privacy Addendum, which supplements the Cloudflare Privacy Policy. Because we use the invisible widget mode, this notice serves as the disclosure that Turnstile may run on a page even when no challenge is shown.
7. Your privacy rights and how to exercise them
Depending on where you live, you have specific legal rights regarding your personal data. We honor these rights globally, even when local law does not strictly require it.
GDPR rights (for EU, EEA, and UK users)
If you are in the European Union, European Economic Area, or United Kingdom, the General Data Protection Regulation grants you the following rights:
Right to access (Article 15)
Request a copy of all personal data we hold about you. We will provide it in a machine-readable format (JSON or CSV) within 30 days, free of charge.
Right to rectification (Article 16)
Correct any inaccurate or incomplete personal information, such as an email address or a typo in moment content.
Right to erasure (Article 17)
Request deletion of your moments and associated data. We will permanently delete your moments, voice recordings, photos, text, email address, and any usage data linked to you.
Exception: We may retain transaction records for gift card purchases for up to seven years as required for tax and accounting purposes, but we will anonymize your personal details.
Right to data portability (Article 20)
Export your data in a structured, machine-readable format to transfer to another service. This includes moment content, voice files, and images.
Right to object (Article 21)
Object to certain data processing activities such as analytics or marketing. We will stop processing your data for those purposes unless we have compelling legitimate grounds.
Right to restrict processing (Article 18)
Request that we limit how we use your data while we investigate a complaint or dispute.
Right to withdraw consent (Article 7)
If you consented to specific processing such as email marketing, you can withdraw that consent at any time.
Right to lodge a complaint
File a complaint with your national data protection authority if you believe we have violated GDPR. Find your authority at the EU DPA Directory.
CCPA and CPRA rights (for California residents)
If you are a California resident, the California Consumer Privacy Act and California Privacy Rights Act grant you the following rights:
Right to know
Request disclosure of what personal information we collect, how we use it, who we share it with, and how long we retain it. This Privacy Policy already discloses most of this.
Right to delete
Request deletion of your personal information, equivalent to the GDPR Right to Erasure.
Right to opt out of sale
Caadit does not sell your personal information, so there is nothing to opt out of. We have never sold user data and we never will.
Right to non-discrimination
We will not discriminate against you for exercising your CCPA rights. You will receive the same service quality whether or not you request data deletion.
Right to correct (CPRA)
Under the newer CPRA, you can request correction of inaccurate personal information we hold.
Right to limit use of sensitive information (CPRA)
Caadit does not collect sensitive personal information as defined by CPRA, such as Social Security numbers, financial account details, or precise geolocation. If that ever changes, you will have the right to limit its use.
How to exercise your rights
Contact our Privacy Team
Email: hi@caadit.com
Subject line format: "Privacy Rights Request: [Your Request Type]"
Please include:
- The specific request (access, deletion, correction, etc.)
- Moment URLs if you are requesting deletion of specific moments
- Email address associated with your moments, if applicable
- Proof of identity to prevent unauthorized requests. We will guide you through this
Response time: We acknowledge your request within 48 hours and fulfill it within 30 days under GDPR or 45 days under CCPA, unless the request is unusually complex.
Privacy rights requests are always free of charge unless they are clearly excessive or repetitive.
9. Children's privacy
Caadit is for people 13 and over, and 16 where local law sets the higher bar. It is not directed to children under 13, and we do not knowingly collect personal information from them. A younger child is welcome to make a moment together with a parent or guardian, on that adult's device and under that adult's account: the adult is the user, and anything collected is the adult's.
If we learn a child has provided information
If we learn that a child under 13 has given us personal information on their own, such as an email address or a voice recording, we delete it. A parent or guardian who believes this has happened can write to us and we will confirm what was removed.
Parents' rights
If your child has taken part in a moment made under your account, you can:
- Request a copy of the moments and any associated data
- Request their immediate deletion
- Ask us what, if anything, we hold that relates to your child
Parents: contact us
If you have questions or requests about your child's privacy, please reach out:
Email: hi@caadit.com
Subject: "Child privacy request"
We respond within 24 to 48 hours and prioritize requests related to children's privacy.
10. International data transfers
Caadit is based in Wyoming, United States, but we serve users worldwide. If you use our service from outside the US, your data may be transferred to, stored in, and processed in the United States or other countries where our service providers operate.
GDPR safeguards for EU users
For users in the EU, EEA, and UK, we use the following legal mechanisms to protect your data during international transfers:
Standard Contractual Clauses
We use EU-approved Standard Contractual Clauses with all third-party processors to ensure your data receives GDPR-level protection even when transferred outside the EU.
Where your data is stored
Your data is stored with the providers named in "Where your data lives" above, in the United States and Europe, and replicated between locations for durability. We do not offer storage limited to a single region. If you have a question about where your data is held, email hi@caadit.com.
Additional safeguards
All data is encrypted in transit and at rest. We maintain strict access controls, conduct regular security audits, and hold GDPR-compliant data processing agreements with all vendors.
If you are in the EU and have concerns about international data transfers, you can file a complaint with your national data protection authority.
11. How long we keep your data
We only retain your data as long as necessary to provide our service or meet legal obligations. Here is exactly how long we keep different types of data.
Moments (text, voice, photos)
Retention: 2 years from creation date
Moments are meant to be revisited over time: anniversary messages, birthday moments, memorials. Two years gives recipients the opportunity to come back to them.
You can request early deletion at any time by emailing us the moment URL. We will remove it permanently within 48 hours.
Analytics data
Retention: Aggregated and anonymized after 90 days
After 90 days, detailed logs are converted into aggregate statistics such as "1,000 birthday moments created in October" and individual identifiers are deleted.
Payment and transaction records
Retention: 7 years
Legally required for tax, accounting, and fraud prevention under IRS regulations and payment processor requirements. We anonymize personal details such as name and address after 2 years but retain transaction amounts and dates for compliance.
Email communications
Retention: 3 years
Retained for customer support history, potential legal disputes, and service improvement such as analyzing common questions to improve our documentation.
Backup copies
Retention: 30 days
Backups protect against server failure, accidental deletion, or cyberattacks. They are encrypted and stored securely. When you request deletion, your data is removed from active systems immediately but may remain in backup copies for up to 30 days before being permanently erased.
12. Changes to this privacy policy
As Caadit evolves, we may need to update this Privacy Policy. When we do, we commit to the following:
- Updating the "Last Updated" date at the top of this page
- Displaying a prominent notice on our website for at least 30 days if the changes are significant
- Emailing you about major changes that affect your rights, if you have provided an email address
- Maintaining a changelog that shows what changed and why
Continued use of Caadit after changes are posted means you accept the updated Privacy Policy. If you disagree with the changes, you can stop using Caadit, request deletion of your data before they take effect, or contact us at hi@caadit.com to discuss your concerns.
We will never make retroactive changes that apply to data collected before a policy update. Your existing moments are always governed by the policy in effect when you created them.
13. Contact us about privacy
We are here to answer your privacy questions, concerns, or requests. Please do not hesitate to reach out.
Caadit Privacy Team
Privacy inquiries: hi@caadit.com
General support: hi@caadit.com
Data protection officer: hi@caadit.com
Response time: We typically respond within 24 to 48 hours for general inquiries, and within 30 days for formal privacy rights requests under GDPR or CCPA.
Urgent requests: Include "URGENT" in your subject line for time-sensitive issues such as unauthorized access or child safety concerns.
Our privacy promise
At Caadit, we believe privacy is a fundamental human right, not a premium feature, not a bargaining chip, and not something we will ever compromise for profit.
We are committed to collecting only what we need to make your moments beautiful, protecting what we collect with strong security practices, being transparent about every piece of data we touch, never selling your information, and respecting your rights under GDPR, CCPA, COPPA, and beyond.
Your trust is the foundation of Caadit. Thank you for letting us be part of your most meaningful moments: birthdays, weddings, sympathy, celebrations, and everything in between. We will never take that trust for granted.
With gratitude and respect for your privacy,
The Caadit Team