CRBON LABS INC.
CRBONFREE FOR AI HEAVY WORKLOADS
PRIVACY POLICY
Last Updated: August 31, 2026
IMPORTANT - PLEASE READ CAREFULLY. These Terms & Conditions ("Agreement") govern your access to and use of the CrbonFree for AI Heavy Workloads web application (the "App"), operated by Crbon Labs Inc. ("Crbon Labs," "we," "us," or "our"). By creating an account, submitting an API key, participating in a private or public beta, subscribing to paid services, or otherwise accessing or using the App, you ("User," "you," or "your") agree to be legally bound by this Agreement.
1. DEFINITIONS
"API Key" means an administrative or developer API credential issued by a third-party AI service provider.
"AI Account" means a User-controlled account with a third-party AI service provider.
"Carbon Credit Product" means a voluntary carbon credit (measured in CO2e) sourced from projects developed by Crbon Labs or selected by Crbon Labs at its sole discretion.
"Carbon Estimates" means estimated greenhouse gas emissions associated with AI usage.
"Usage Data" means AI usage metadata such as token counts, model identifiers, timestamps, and volumes.
"Beta Services" means features or services identified as alpha, beta, preview, early access, or similar.
2. ELIGIBILITY & ACCOUNT TYPES
You must be legally capable of entering into this Agreement. The App supports Personal and Enterprise accounts. Regardless of account type, these Terms apply equally unless otherwise agreed in writing.
3. BETA SERVICES DISCLAIMER
The App may be offered as a Private Beta or Public Beta. Beta Services are provided on an "AS IS" and "AS AVAILABLE" basis, may contain errors, and may be modified or discontinued at any time without notice. Crbon Labs disclaims all warranties related to Beta Services to the maximum extent permitted by law.
4. APP FUNCTIONALITY
The App retrieves Usage Data to generate Carbon Estimates for informational purposes only. Estimates are approximate, non-certified, and subject to methodological change.
5. API KEY ACCESS & PERMISSIONS
By submitting an API Key for a server-side connection, you grant Crbon Labs permission to access Usage Data solely for carbon estimation. Crbon Labs' server-side API-key integrations do not access prompts, outputs, or training data. The separate browser-extension disclosure in Section 10B explains the limited local processing performed by the CrbonFree browser extension. API Keys are encrypted and access is restricted. You are responsible for safeguarding your API Key.
6. SUBSCRIPTIONS & PAYMENTS
Carbon footprint data may be accessed for free. Optional paid subscriptions allow Users to purchase and retire Carbon Credit Products. Payments are processed via Stripe. Fees are billed in advance and are non-refundable except where required by law.
7. CARBON CREDITS & CLAIMS
Crbon Labs may select carbon credit projects at its sole discretion. Use of the App does not confer carbon neutral or net zero status. The App may not be used as the sole basis for environmental claims.
8. AGGREGATED & ANONYMIZED DATA
Crbon Labs may collect, use, and publish aggregated and anonymized benchmark data derived from Usage Data for research, reporting, and product improvement, provided such data cannot reasonably identify any User.
9. WEBSITE ANALYTICS & TRACKING
When you access our websites and applications, we and our infrastructure, hosting, and content-delivery providers (including Cloudflare) may automatically collect limited technical and usage information - such as pages visited, links clicked, referring website, approximate location, device type, browser type, and IP address - for analytics, security, fraud prevention, and service-improvement purposes. We use privacy-preserving, cookieless analytics and do not use this information to personally identify you or to serve targeted advertising. You may further limit collection through your browser settings. Where required by applicable law (including the GDPR and CCPA), you may exercise your rights, including opting out of certain processing, by contacting us at support@crbonlabs.com. By using our websites and applications, you acknowledge the collection and use of information as described here and in our Privacy Policy.
10. DATA PROTECTION & PRIVACY
Crbon Labs complies with PIPEDA, GDPR, and applicable U.S. privacy laws. Personal data is processed in accordance with our Privacy Policy.
10B. CRBONFREE BROWSER EXTENSION
This section applies when you install and use the CrbonFree browser extension on supported AI chat services, currently ChatGPT, Claude, and Gemini.
a) Data the Extension Processes
To provide its in-page AI-usage and environmental-estimate features, the extension processes the rendered text of the current chat and, where supported, the text of attachments available within that chat. This processing occurs locally in your browser to calculate token estimates. The extension does not store raw chat text or attachment text in Chrome extension storage and does not send raw prompt, response, or attachment text to Crbon Labs.
The extension stores locally the minimum metadata needed to display and maintain usage estimates, including the supported provider, provider conversation and message identifiers, message role, model identifier, token counts, timestamps, estimated usage and emissions data, extension settings, and—when you sign in—the selected organization, project, and CrbonFree account identifier. The extension processes only the supported AI-chat pages needed for this functionality; it does not access general browser history, unrelated websites, mouse movement, scrolling, clicks, or keystrokes.
b) Authentication and Technical Data
The extension uses Clerk to synchronize your CrbonFree web-app session. Clerk session cookies and short-lived authentication tokens are used only to determine sign-in state and authenticate requests. The extension does not collect your CrbonFree password. When the extension communicates with Crbon Labs or Clerk over HTTPS, our services and infrastructure providers may receive technical information such as IP address, browser/device information, and request logs for security, fraud prevention, reliability, and service operation, as described in Section 9.
c) Usage Reporting and Service Providers
If you are signed in and select an organization or project as the destination for browser-extension usage, the extension sends usage metadata to Crbon Labs to save that usage under your selected organization and project. This metadata may include provider and conversation/message identifiers, model identifiers, token counts, message roles, timestamps, and the selected organization/project identifiers. It does not include raw chat or attachment text.
Crbon Labs uses Clerk to provide authentication and session synchronization. Crbon Labs and its service providers process browser-extension data only as necessary to provide, secure, maintain, and support CrbonFree, including the infrastructure providers listed in Section 10A(c). Crbon Labs does not sell browser-extension data or use it for advertising, behavioral profiling, creditworthiness, or lending.
d) Limited Use
Crbon Labs uses browser-extension data only to provide and improve the user-facing AI-usage tracking, reporting, and environmental-estimation features described in this Policy. We transfer such data only when necessary to provide, maintain, secure, or support those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets. We do not use or transfer this data to serve personalized, retargeted, or interest-based advertising. We do not permit people to read raw chat or attachment content because the extension does not transmit that content to Crbon Labs; any exception would require your consent or another legally permitted basis.
e) Your Choices
You can stop local browser-extension processing by disabling or removing the extension and can remove locally stored extension data through your browser's extension data controls. Signing out stops authenticated browser-extension usage reporting to your CrbonFree organization or project. For requests concerning data held by Crbon Labs, contact hello@crbonfree.com.
10A. GOOGLE USER DATA DISCLOSURES
This section describes how Crbon Labs handles Google user data when you use the "Connect Google Cloud" feature to connect Gemini Enterprise Agent Platform (formerly Vertex AI), including Gemini models, to CrbonFree for usage tracking. These disclosures apply when you choose to connect your Google Cloud account to CrbonFree. Users first sign in to CrbonFree and then connect their Google Cloud account through Google's authorization screen.
a) Google User Data We Access
When you authorize CrbonFree through Google's authorization screen, we may access:
- Your Google account email address and stable Google account identifier returned by Google's authorization server.
- Information about Google Cloud projects your connected Google account is authorized to access, including project IDs and project names.
- Google Cloud Monitoring metrics related to Gemini Enterprise Agent Platform usage across accessible projects, including token counts, model identifiers, request volumes, and timestamps.
- OAuth access and refresh tokens issued by Google, which allow CrbonFree to make subsequent read-only Google API requests on your behalf.
CrbonFree does not collect your Google password.
b) How We Use Google User Data
CrbonFree uses Google user data only to provide and operate the Google Cloud connection:
- Google account email and identifier are used to identify the connected Google account, associate the connection with the correct CrbonFree account, display connection information, and support connection diagnostics.
- Google Cloud project information is used to automatically discover the Google Cloud projects the connected account is authorized to access and determine where available Gemini Enterprise Agent Platform usage metrics can be retrieved. CrbonFree does not require you to select a single project; available projects are discovered and processed using read-only access.
- Cloud Monitoring metrics are used to calculate and display Gemini Enterprise Agent Platform usage, token consumption, estimated costs, estimated energy consumption, and estimated carbon emissions.
- OAuth access and refresh tokens are used only to authenticate read-only requests to supported Google Cloud APIs.
CrbonFree does not use Google user data to run model inference, train artificial intelligence models, modify Google Cloud projects, modify monitoring settings, or serve advertising.
c) Sharing, Transfer, and Disclosure of Google User Data
CrbonFree does not sell, rent, or share Google user data for advertising or marketing purposes.
Google user data may be processed by service providers acting on behalf of Crbon Labs only as necessary to operate, secure, and maintain CrbonFree. These providers include:
- Vercel, which hosts and delivers the CrbonFree frontend application.
- Railway, which hosts the CrbonFree backend services and operational logs.
- Amazon Web Services, including Amazon RDS, which provides managed database infrastructure used to store application and connection data.
- Cloudflare, which provides domain-name and DNS services and, where enabled, network delivery, proxy, and security services.
These providers process data only as necessary to provide infrastructure and operational services to CrbonFree and are subject to applicable confidentiality, privacy, and security obligations.
Crbon Labs may also disclose Google user data when required by applicable law, court order, subpoena, warrant, or other valid legal process. Where permitted, disclosure will be limited to the information reasonably necessary to comply with the request.
Crbon Labs does not otherwise disclose or transfer Google user data to unrelated third parties.
d) Protection of Google User Data
Crbon Labs uses technical and organizational safeguards designed to protect Google user data, including:
- HTTPS/TLS encryption for data transmitted between users, CrbonFree, and Google.
- Access-controlled database and hosting infrastructure with encryption at rest enabled.
- Restricted access to OAuth credentials and Google user data for authorized backend services and personnel who require access to operate or support the service.
- Access controls and secure credential-management practices.
- Read-only and minimum-privilege Google authorization scopes.
- Protection against unauthorized authorization requests through a state parameter and CSRF protections in the Google connection flow.
- Operational logging practices designed to avoid recording raw OAuth access tokens, refresh tokens, authorization codes, or ID tokens.
CrbonFree does not collect or store Google passwords.
e) Retention and Deletion of Google User Data
CrbonFree retains Google user data only for as long as reasonably necessary to maintain the Google Cloud connection and provide the related usage, reporting, energy-estimation, and carbon-estimation features.
- Users may disconnect their Google Cloud account through Settings - Connections.
- Disconnecting disables CrbonFree's use of the stored OAuth credentials and stops CrbonFree from collecting new Google Cloud data for that connection. Users may separately revoke CrbonFree's authorization through their Google Account permissions page at https://myaccount.google.com/permissions.
- Stored OAuth access and refresh tokens, Google account identifiers, and associated Google Cloud project information will be deleted or anonymized within thirty (30) days after disconnection or a verified deletion request, unless retention is required by applicable law. OAuth credentials are deleted rather than anonymized.
- Historical imported usage records associated with a disconnected connection may be retained so previously generated reports and estimates remain available. Following a verified deletion request, identifiable historical usage records will be deleted or anonymized within thirty (30) days, unless retention is required by applicable law.
- Users may request deletion of Google user data by contacting hello@crbonfree.com.
- Residual copies may temporarily remain in secured backups until those backups expire under the applicable backup-retention schedule.
- Aggregated or de-identified statistics may be retained only when they cannot reasonably identify a user, Google account, or Google Cloud project and are used to provide or improve CrbonFree's user-facing usage and environmental-estimation features.
CrbonFree's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
11. INTELLECTUAL PROPERTY
Crbon Labs retains all rights to the App and methodologies. Users retain ownership of their Usage Data subject to a limited processing license.
12. LIMITATION OF LIABILITY & INDEMNIFICATION
To the maximum extent permitted by law, Crbon Labs' total liability shall not exceed fees paid in the preceding twelve (12) months. Crbon Labs is not liable for indirect or consequential damages. Users agree to indemnify Crbon Labs for misuse or legal violations.
13. TERM & TERMINATION
This Agreement continues until terminated. Crbon Labs may suspend or terminate access at any time for risk, misuse, or non-payment.
14. GOVERNING LAW
This Agreement is governed by the laws of Alberta and Canada, without regard to conflict of laws principles.
Crbon Labs Inc.
Calgary, Alberta, Canada
support@crbonlabs.com