👻 Carted — Privacy Policy

Effective: September 6, 2026 · previous version August 17, 2026

Carted is a simulated "window shopping" experience: you browse fictional restaurants, place orders that are never real, and keep your money. Our privacy posture matches the product: we want as little of your data as possible.

No email or password sign-up

Mort's name, your quests, earned coins, outfits, scrapbook, counter decorations, and pretend-order progress are stored on your device. They are not a cloud backup. Optional community features use a private, automatically issued connection token so another person cannot claim your notes or nickname just by knowing an analytics identifier. See “Your community connection” below.

What we do collect

To understand which features work and whether people come back, the app sends pseudonymous usage analytics to our server:

Analytics do not include your community connection token, note text, legal name, email, contacts, or photos. Outfits currently use earned in-app coins, not real-money purchases. Honesty note: pseudonymous does not mean fully anonymous; events from the same device link together. We do not connect this identifier to an Apple ID or advertising ID.

"Near me" and your location

If you tap "Near me," your device asks for permission and then your coordinates are sent to OpenStreetMap's services — Nominatim (to turn them into a neighborhood name) and Overpass (to find real places near you to fictionalize). Those services see the coordinates and your IP address, as any website you visit does; they run under the OpenStreetMap Foundation's privacy policy. We never send your location to our own server, never store it, and never attach it to analytics. Skip the feature and no location ever leaves the device.

What we never do

Service providers we use

These are all of them, and what each one sees. Providers process data to run Carted, not for their own purposes (public services like OpenStreetMap operate under their own policies):

If you email support, your message and email address are also available to us so we can reply. Please do not send passwords, private connection tokens, or sensitive personal information.

Notifications

If you opt in on iOS, the app schedules a local reminder on your device and reschedules it after you play. In a supported web browser, opting in may instead create a web push subscription stored with our server so a reminder can reach that browser. You can turn notifications off in Carted or in your device/browser settings.

Your community connection

When a community feature needs a connection, our server creates a random member identifier and a private connection token. The token stays in the app's local storage (and its native on-device preferences backup); the server stores a one-way hash, not the token itself. Requests for your community notes, nickname changes, reactions, reports, and friend connections send the token securely to our server. It is separate from the analytics identifier and is never included in analytics or invitation links.

A connection expires after 365 days and can be revoked earlier for safety. Losing the token or clearing app data creates a new community identity; it does not let anyone reclaim an old identity using an exposed device identifier. Your existing on-device Mort progress is separate. Older friend connections cannot be transferred this way: old invitation links may remain readable, but a new secure invitation is needed to participate. Anyone holding a private Booth link can read that Booth; share invitations only with people you intend to invite.

Tonight's community table

Mort's notes, stories, and postcards are authored fictional content, separate from human community notes. Before your first human note, you choose a persistent community nickname. When you post, your nickname and note are shown to participants and stored with your server-issued community member identifier, not your analytics identifier. You may correct the nickname once immediately; later changes have a 30-day cooldown for that community identity. There are no public profiles, direct messages, or random matching. Do not include private personal information in a note.

Before a note publishes, its text and nickname pass built-in server-side checks for recognizable abuse and spam. Optional enhanced screening is described above. Automated checks can miss harmful content or reject harmless wording; use report and mute controls when needed. A separate check looks for language suggesting the writer may be in crisis; if it fires, we show that writer a card with support details. This is not comprehensive crisis detection. We never notify another participant.

Your selected Mort outfit identifier is saved with each note and displayed to its readers. It describes that note's appearance, not your entire wardrobe or progress. Changing outfits does not change previously posted notes.

Ordinary community notes are removed from our server within 36 hours. A copy of your own accepted note lives in your device's local storage for the nightly window. Your community nickname and cooldown history remain on the server so the connection keeps a consistent identity. Connection expiry does not automatically delete all associated records.

Safety exceptions: a report hides a note for the reporter and queues review; it does not automatically hide the note for everyone. Unresolved reported or moderator-hidden content may be retained for up to 90 days for safety review, but is no longer returned in community lists after 36 hours. Content and report records subject to legal preservation are kept for the required period and may be disclosed when legally required.

Children

Carted is not directed at children under 13. Do not use community features to share children's personal information. If you believe a child has provided personal information through Carted, contact us.

Data retention & deletion

To request deletion of server-held data, contact us before clearing the app if possible so we can arrange an ownership check. Do not email your private connection token. Because we do not use email sign-in, an email address alone does not identify your app activity. Deleting the app or clearing website storage removes local progress but does not itself send a server deletion request; safety and legal-preservation exceptions still apply.

Contact

Questions, requests, or concerns: localcardhouse@gmail.com

Dish names and photos are licensed from TheMealDB. All restaurants in Carted are fictional; the cities are real. No real orders are ever placed and nothing is ever charged.