Coraleye
HomeProductIntegrationsAboutRequest a Demo
Request a Demo
Legal

Privacy Policy

Last updated: June 28, 2026

1. Introduction

Coraleye, Inc. ("Coraleye," "we," "us," "our") operates an AI-powered customer success platform (the "Service") that helps businesses monitor customer health, generate account insights, and enact recommended actions. This Privacy Policy explains how we collect, use, store, and share information through the Service, our website, and our other interactions with you.

By using the Service, you agree to the practices described in this policy. If you use the Service on behalf of a business, you represent that you have authority to bind that business to this policy.

Controller and processor roles. For most data in the Service, our business customers decide what data to load and why; they are the controller (or equivalent) and Coraleye acts as their processor or service provider, processing data only on their documented instructions and under our customer agreement and Data Processing Addendum ("DPA"). For a limited set of data, such as account-administrator contact details, website-visitor data, and billing information, Coraleye acts as a controller and this policy governs directly. Where we act as a processor, the relevant customer's own privacy notice governs the underlying personal data, and we will direct individuals to that customer.

2. Information We Collect

2.1 Account and Authentication Information

  • Email address, name, role, and avatar (where provided by your identity provider);
  • For tenants using Google OAuth sign-in: your Google account email and profile information, and OAuth access/refresh tokens (stored encrypted);
  • Session information: a session cookie, valid for 30 minutes, used to keep you signed in (HTTPS-only and HTTP-only in production).

Access to each tenant is restricted to an allowlist of authorized users maintained by Coraleye or your organization's administrator.

2.2 Customer and Business Data

On behalf of our customers, Coraleye stores business data relevant to customer support and account management, including:

  • Contact records, including name, email, phone, title, and department;
  • Account records, including company name, domain, industry, user information, usage data, revenue figures, renewal dates, and assigned owners;
  • Support conversations and message transcripts, including the channel on which they occurred (email, chat, etc.).

This data is supplied directly by our customers or ingested automatically from systems they connect to Coraleye. Customers remain the controller of this data; Coraleye processes it only as instructed and as described here and in the DPA.

2.3 Usage and Technical Data

  • Records of AI/LLM API calls (model used, token counts, and the feature that triggered the call);
  • Locally stored browser preferences (e.g., sidebar state, selected tenant, column/filter preferences), kept in your browser's local storage; and
  • Audit logs of authentication and OAuth token activity.

We do not currently use third-party analytics, advertising, or error-tracking services (for example, no Google Analytics, Segment, Mixpanel, or Sentry are integrated into the Service). Information submitted through our website's demo-request form (name, company, email, and phone) is sent to HubSpot, which processes it as our processor to route and follow up on your request. If this changes, we will update this policy and, where required, give you notice or obtain consent.

3. How Information Is Used and Shared

3.1 How We Use Information

  • Authenticate users and enforce tenant-level access controls;
  • Provide core product functionality: support-conversation review, account health analysis, and reporting dashboards;
  • Generate AI-assisted summaries, insights, and recommendations using large language model providers;
  • Operate scheduled data ingestion pipelines that keep customer data up to date;
  • Maintain security audit trails (e.g., OAuth token usage); and
  • Diagnose, secure, and improve the Service.

AI model fine tuning: With your authorization, we use your Customer Data to fine-tune AI models dedicated to your account. Each fine-tuned model is trained only on your tenant's data, is used only to provide the Service to you, and is never shared with or used to serve any other customer. We do not pool Customer Data across customers to train shared models, we do not train foundation models from scratch, and we do not permit our AI providers to use Customer Data to train their own generalized models. We exclude Google Workspace and other Google API data from all model training. Where fine-tuning is performed by a provider (such as OpenAI), your Customer Data is sent to that provider solely to create and host your dedicated model under its API terms. We delete models fine-tuned on your Customer Data when your data is deleted or your tenant is offboarded.

3.2 AI Model Providers

To generate summaries, insights, and conversational responses, and to create and host models fine-tuned for your account, Coraleye sends relevant conversation content and metadata to:

  • Anthropic, PBC (Claude models); and
  • OpenAI (GPT and embedding models).

These providers process the data to return the requested AI output (including embeddings) and, where you have authorized fine-tuning, to create and host an AI model dedicated to your account under their API terms. They are bound by those terms, including commitments not to use Customer Data to train their own generalized models. Any model fine-tuned on your Customer Data is used solely to provide the Service to you and is never used to serve another customer. We do not use this data for advertising.

3.3 Customer-Connected Source Systems

Coraleye connects to the systems a customer designates and imports operational data from them. Depending on the customer's configuration, these sources may include:

  • Customer support and ticketing platforms;
  • Team messaging tools;
  • Email mailboxes designated for operational correspondence;
  • Account usage data aggregators;
  • Payment processors and ERP systems; and
  • Call and meeting recordings and their transcripts.

Coraleye accesses these systems only within the scopes the customer authorizes. Credentials and access tokens are stored securely (for example, in a secrets manager) with audit logging, and data pulled from each source is ingested into that tenant's isolated data store within Coraleye.

3.4 Infrastructure Subprocessors

AWS: cloud hosting; production data is stored in a managed PostgreSQL database (AWS RDS).

A complete and current list of subprocessors is available per request. Where required, we will give affected customers advance notice of new subprocessors and an opportunity to object as set out in the DPA.

3.5 No Sale or Sharing for Advertising

We do not sell personal information or customer business data, and we do not "share" personal information for cross-context behavioral advertising, as those terms are defined under U.S. state privacy laws.

3.6 Tenant Isolation

Each customer's data is logically segregated by tenant. Coraleye personnel access is limited to what is required to operate, support, and maintain the Service.

3.7 Business Transfers

If Coraleye is involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction. We will notify affected customers before information is transferred and becomes subject to a different privacy policy.

3.8 Legal Requirements

We may disclose information if required by law or valid legal process (such as a court order or subpoena), or to protect the rights, property, or safety of Coraleye, our customers, or others. Where we act as a processor and are legally able to do so, we will notify the relevant customer before disclosing their data.

4. Data Storage and Security

  • Production data is stored in a managed PostgreSQL database (AWS RDS) within AWS infrastructure;
  • OAuth tokens are stored encrypted at rest, with audit logging of token-related actions;
  • Session cookies are transmitted over HTTPS in production and are HTTP-only; and
  • Access to underlying infrastructure and databases is restricted to authorized Coraleye personnel.

No method of transmission or storage is completely secure. In the event of a data breach affecting your rights, we will notify affected parties (and, where we act as a processor, the relevant customer) as required by applicable law.

5. Data Retention

We retain account, conversation, and business data for as long as the applicable tenant relationship is active, or as needed to provide the Service, unless a different retention period is agreed with a customer or required by law. On termination, customers may request export of their data within the window stated in their agreement, after which we may delete it in accordance with our retention schedule. Demo tenant data may be reset or regenerated periodically.

6. Legal Bases for Processing (EEA/UK)

Where the EU or UK GDPR applies to processing for which we are a controller, we rely on the following legal bases:

  • Contract: to provide the Service and administer accounts;
  • Legitimate interests: to secure, operate, and improve the Service and prevent fraud or misuse, balanced against individuals' rights;
  • Legal obligation: to comply with law and respond to lawful requests; and
  • Consent: where required, for example for certain communications, which you may withdraw at any time.

Where we act as a processor, our customer is responsible for establishing the legal basis for the underlying personal data.

7. Your Choices and Privacy Rights

Routing of requests. If you are an individual whose personal information appears in Coraleye on behalf of one of our customers, that customer controls the underlying data; please direct access, correction, deletion, or other requests to that customer, and Coraleye will assist as needed under our agreement with them.

Depending on where you live and the role we play, you may have rights to access, correct, delete, port, or restrict processing of your personal information, to object to certain processing, to opt out of sale/sharing or targeted advertising and certain profiling, and to be free from discrimination for exercising these rights. You may also:

  • Clear locally stored preferences at any time by clearing your browser's site data for the Coraleye domain;
  • Ask a tenant administrator to revoke a user's access, which disables their ability to sign in.

To exercise a right where Coraleye is the controller, contact us using Section 11. We may need to verify your identity, and we will respond within the timeframes required by applicable law. You may use an authorized agent where the law permits. If you disagree with our decision, you may appeal by replying to our response or lodge a complaint with your local data protection authority.

7.1 U.S. State Privacy Rights

Residents of California and other U.S. states with comprehensive privacy laws have the rights described above with respect to personal information for which Coraleye is the controller/business. We do not sell personal information or share it for cross-context behavioral advertising, and we do not use or disclose sensitive personal information beyond the purposes permitted by law. To exercise these rights, use the contact details in Section 11; we will not discriminate against you for doing so.

8. International Data Transfers

Coraleye is based in the United States, and your information may be processed there and in other countries where we or our subprocessors operate. Where personal data is transferred from the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum), available through our DPA.

9. Children's Privacy

The Service is intended for business use and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child's information has been provided to us, please contact us and we will take appropriate steps to delete it.

10. Changes to This Policy

We may update this policy as our practices evolve, particularly as the Service adds new integrations, AI providers, or analytics tooling. We will update the "Last updated" date above when material changes are made, and will notify affected customers in advance of changes that materially reduce their rights.

11. Contact

For questions about this policy or our data practices, or to exercise a privacy right where Coraleye is the controller, contact your Coraleye account representative or:

Coraleye
Email: chris@coraleye.ai
Website: coraleye.ai

Coraleye
coraleye.ai About Security Privacy Terms Contact us

Coraleye, Inc. · New York

© 2026 Coraleye. All rights reserved.