Legal
Privacy Policy
Last updated: 25 June 2026
Caroluma ("we", "our", or "us") is a Chrome extension that replaces your new tab page with a photo frame. This policy describes what data we collect, why we collect it, and how it is used. We do not sell your data to third parties.
1. Who this policy applies to
This policy applies to users of the Caroluma Chrome extension and the caroluma.com website. By installing the extension or using the website, you agree to this policy.
2. Data we collect and why
Google account information. When you sign in with Google, we receive your name, email address, and profile photo URL via Google OAuth. This information is used to identify you within the extension and to associate your photos, library, and album memberships with your account. Your Google access token is stored locally in Chrome's storage and is sent to our backend only to verify your identity when you perform actions that require authentication (such as uploading a photo or joining an album).
Photos you upload. Photos you upload to your personal library or a shared album are stored on our servers (Supabase, hosted in the EU). We use these photos solely to display them in your new tab and to share them with other members of any shared album you belong to. We do not scan, analyse, or use your photos for any other purpose.
Album and membership data. We store the albums you create or belong to, the members of each album, and album settings. This data is stored on our servers and is used to power the shared album feature.
Extension preferences. Settings such as which widgets are visible, your preferred search engine, and your photo source are stored in Chrome's sync storage. These preferences are synced across your Chrome devices by Google and are not transmitted to our servers.
Location (weather widget). If you enable the weather widget, the extension requests your device's GPS location via the browser's Geolocation API. Your coordinates are sent to Open-Meteo (an open-source weather service) to retrieve the current weather, and to Nominatim (OpenStreetMap's geocoding service) to look up your city name. Your location is not stored on our servers.
Analytics. We use PostHog (hosted in the EU) to collect basic usage analytics and session replay. Data collected includes: events such as "new tab opened", a pseudonymous identifier derived from your Google ID, your browser and OS type, and screen recordings of your session with all text inputs masked. We use this data to understand how the extension is used and to diagnose issues. Analytics data is not linked to your name or email address outside of our own systems, and is not shared with third parties.
3. Data we do not collect
- We do not collect your browsing history.
- We do not read the content of web pages you visit.
- We do not collect passwords or payment information.
4. Third-party services
Caroluma uses the following third-party services to operate. Each service processes data as described in its own privacy policy.
- Supabase (EU, Ireland) — database and file storage for photos and album data. Privacy policy.
- PostHog (EU) — product analytics and session replay. Privacy policy.
- Open-Meteo — weather data retrieved using your GPS coordinates. No account or identifier is sent. Terms.
- Nominatim / OpenStreetMap — city name lookup using your GPS coordinates. No account or identifier is sent. Privacy policy.
- Spotify — if you enable the Spotify widget, an embedded Spotify player is loaded in your new tab. Spotify may collect data according to their own privacy policy. Privacy policy.
- Google OAuth — used for sign-in and to retrieve your Google Photos albums. Privacy policy.
5. Data retention and deletion
Your photos and account data are retained for as long as you have an account with Caroluma. You can delete your account at any time from the extension's Settings → Account tab. Deleting your account permanently removes your photos, library, and all album data associated with your account from our servers.
Analytics data collected via PostHog is retained according to PostHog's data retention policy (currently 1 year for session replays and events).
6. Data security
Photos are stored in a private storage bucket and are only accessible via short-lived signed URLs generated by our backend. All communication between the extension and our backend uses HTTPS. We apply row-level security policies to our database to ensure users can only access data they are authorised to see.
7. Children's privacy
Caroluma is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us and we will delete it.
8. Changes to this policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top. Continued use of the extension after changes are posted constitutes your acceptance of the revised policy.
9. Contact
If you have questions or requests regarding your data, contact us at carolumaplatform@gmail.com.