PRIVACY POLICY
Core
Product: Core (the “Service”)
This Privacy Policy explains how Core (“we,” “us,” or “our”) collects, uses, discloses, and protects information when business customers and their authorized users (“you”) use Core, including our websites, web app, desktop/mobile applications, and related services.
1Information We Collect
We collect information in the following categories:
A. Account and customer information
- Name, business email address, phone number (if provided)
- Organization name, role/title (if provided)
- Authentication information (e.g., SSO identifiers, tokens)
B. User content and instructions
- Prompts, notes, tasks, messages, and other content you submit to Core
- Content you choose to paste or upload into Core for processing
- Feedback and support communications
C. Data from connected services (only if enabled by you or your organization)
If you connect Core to third-party services (for example, Google Workspace services such as Gmail, Calendar, Drive; or other integrations), Core may access and process data from those services as authorized. This may include:
- Email content and metadata (e.g., sender/recipient, subject, body, timestamps)
- Calendar events and attendee information
- Documents/files you choose to access or process
- Contacts and directory information used to address messages and schedule events
D. Device, log, and usage data
- Device type, OS, browser type, app version
- IP address, approximate location (e.g., country/region)
- Feature usage and interaction logs (e.g., actions requested, timestamps)
- Diagnostics, crash reports, and performance metrics
E. Cookies and similar technologies
We may use cookies/local storage to maintain sessions, remember preferences, and understand usage trends for performance and reliability.
2How We Use Information
We use information to:
- Provide, operate, and maintain Core and its features
- Authenticate users and administer accounts
- Execute your requests (e.g., drafting communications, generating summaries, scheduling events, preparing documents)
- Provide customer support and respond to inquiries
- Monitor, prevent, and investigate security incidents, abuse, and fraud
- Improve performance, reliability, and user experience
- Comply with legal obligations and enforce our agreements
3AI / Automated Processing
Core may use automated systems, including machine learning and AI, to process inputs and permitted connected-service data to generate outputs (e.g., drafts, summaries, classifications, suggested actions).
Outputs may be inaccurate and should be reviewed by you before use, especially before sending externally or making decisions.
4How We Share Information
We do not sell personal information.
We may share information as follows:
A. Service providers
We use vendors to provide hosting, storage, monitoring, analytics, customer support tooling, and integration infrastructure. They may process data on our behalf under contractual obligations to protect it and use it only for providing services to Core.
B. At your direction (integrations)
If you connect third-party services, Core will exchange data with those services as needed to perform requested actions.
C. Legal, safety, and compliance
We may disclose information if we believe disclosure is required by law or necessary to protect rights, safety, and security of Core, our customers, users, or the public.
D. Business transfers
If Core is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction, subject to appropriate safeguards.
5Data Retention
We retain personal data for as long as necessary to:
- Provide the Service
- Meet contractual and legal obligations
- Resolve disputes and enforce agreements
- Maintain security and prevent abuse
Retention periods vary based on the data type and applicable law.
6Security
We maintain reasonable administrative, technical, and organizational safeguards designed to protect personal data against unauthorized access, loss, misuse, or alteration. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7Your Rights and Choices
Depending on your location, you may have rights such as:
- Accessing, correcting, or deleting personal data
- Objecting to or restricting certain processing
- Requesting data portability
- Withdrawing consent where processing is based on consent
- Lodging a complaint with a supervisory authority
To exercise rights, contact us through the support channel or settings within the Service. We may need to verify your identity and/or authority.
8California Privacy Rights (CCPA / CPRA)
California residents may have rights to:
- Know what personal information is collected, used, and disclosed
- Request deletion (subject to exceptions)
- Correct inaccurate personal information
- Opt out of “sale” or “sharing” of personal information (we do not sell personal information)
- Non-discrimination for exercising privacy rights
Requests may be made through the support channel or settings within the Service.
9International Data Transfers
Core may process data in countries other than where you live or where your organization is located. Where required, we use appropriate safeguards for international transfers.
10Children’s Privacy
Core is intended for business use and is not directed to children. We do not knowingly collect personal information from children under 13 (or the minimum age required by local law).
11Changes to This Privacy Policy
We may update this Privacy Policy periodically. We will post the updated version and revise the Effective date above. If changes are material, we may provide additional notice through the Service or other appropriate means.
12Contact
For privacy questions or requests, contact support within the Service or reach out through your organization administrator.
