Legal

Privacy Policy

Last updated: June 28, 2026

1. Introduction

Coraleye, Inc. ("Coraleye," "we," "us," "our") operates an AI-powered customer success platform (the "Service") that helps businesses monitor customer health, generate account insights, and enact recommended actions. This Privacy Policy explains how we collect, use, store, and share information through the Service, our website, and our other interactions with you.

By using the Service, you agree to the practices described in this policy. If you use the Service on behalf of a business, you represent that you have authority to bind that business to this policy.

Controller and processor roles. For most data in the Service, our business customers decide what data to load and why; they are the controller (or equivalent) and Coraleye acts as their processor or service provider, processing data only on their documented instructions and under our customer agreement and Data Processing Addendum ("DPA"). For a limited set of data, such as account-administrator contact details, website-visitor data, and billing information, Coraleye acts as a controller and this policy governs directly. Where we act as a processor, the relevant customer's own privacy notice governs the underlying personal data, and we will direct individuals to that customer.

2. Information We Collect

2.1 Account and Authentication Information

Access to each tenant is restricted to an allowlist of authorized users maintained by Coraleye or your organization's administrator.

2.2 Customer and Business Data

On behalf of our customers, Coraleye stores business data relevant to customer support and account management, including:

This data is supplied directly by our customers or ingested automatically from systems they connect to Coraleye. Customers remain the controller of this data; Coraleye processes it only as instructed and as described here and in the DPA.

2.3 Usage and Technical Data

We do not currently use third-party analytics, advertising, or error-tracking services (for example, no Google Analytics, Segment, Mixpanel, or Sentry are integrated into the Service). If this changes, we will update this policy and, where required, give you notice or obtain consent.

3. How Information Is Used and Shared

3.1 How We Use Information

AI model fine tuning: With your authorization, we use your Customer Data to fine-tune AI models dedicated to your account. Each fine-tuned model is trained only on your tenant's data, is used only to provide the Service to you, and is never shared with or used to serve any other customer. We do not pool Customer Data across customers to train shared models, we do not train foundation models from scratch, and we do not permit our AI providers to use Customer Data to train their own generalized models. We exclude Google Workspace and other Google API data from all model training. Where fine-tuning is performed by a provider (such as OpenAI), your Customer Data is sent to that provider solely to create and host your dedicated model under its API terms. We delete models fine-tuned on your Customer Data when your data is deleted or your tenant is offboarded.

3.2 AI Model Providers

To generate summaries, insights, and conversational responses, and to create and host models fine-tuned for your account, Coraleye sends relevant conversation content and metadata to:

These providers process the data to return the requested AI output (including embeddings) and, where you have authorized fine-tuning, to create and host an AI model dedicated to your account under their API terms. They are bound by those terms, including commitments not to use Customer Data to train their own generalized models. Any model fine-tuned on your Customer Data is used solely to provide the Service to you and is never used to serve another customer. We do not use this data for advertising.

3.3 Customer-Connected Source Systems

Coraleye connects to the systems a customer designates and imports operational data from them. Depending on the customer's configuration, these sources may include:

Coraleye accesses these systems only within the scopes the customer authorizes. Credentials and access tokens are stored securely (for example, in a secrets manager) with audit logging, and data pulled from each source is ingested into that tenant's isolated data store within Coraleye.

3.4 Infrastructure Subprocessors

AWS: cloud hosting; production data is stored in a managed PostgreSQL database (AWS RDS).

A complete and current list of subprocessors is available per request. Where required, we will give affected customers advance notice of new subprocessors and an opportunity to object as set out in the DPA.

3.5 No Sale or Sharing for Advertising

We do not sell personal information or customer business data, and we do not "share" personal information for cross-context behavioral advertising, as those terms are defined under U.S. state privacy laws.

3.6 Tenant Isolation

Each customer's data is logically segregated by tenant. Coraleye personnel access is limited to what is required to operate, support, and maintain the Service.

3.7 Business Transfers

If Coraleye is involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction. We will notify affected customers before information is transferred and becomes subject to a different privacy policy.

3.8 Legal Requirements

We may disclose information if required by law or valid legal process (such as a court order or subpoena), or to protect the rights, property, or safety of Coraleye, our customers, or others. Where we act as a processor and are legally able to do so, we will notify the relevant customer before disclosing their data.

4. Data Storage and Security

No method of transmission or storage is completely secure. In the event of a data breach affecting your rights, we will notify affected parties (and, where we act as a processor, the relevant customer) as required by applicable law.

5. Data Retention

We retain account, conversation, and business data for as long as the applicable tenant relationship is active, or as needed to provide the Service, unless a different retention period is agreed with a customer or required by law. On termination, customers may request export of their data within the window stated in their agreement, after which we may delete it in accordance with our retention schedule. Demo tenant data may be reset or regenerated periodically.

6. Legal Bases for Processing (EEA/UK)

Where the EU or UK GDPR applies to processing for which we are a controller, we rely on the following legal bases:

Where we act as a processor, our customer is responsible for establishing the legal basis for the underlying personal data.

7. Your Choices and Privacy Rights

Routing of requests. If you are an individual whose personal information appears in Coraleye on behalf of one of our customers, that customer controls the underlying data; please direct access, correction, deletion, or other requests to that customer, and Coraleye will assist as needed under our agreement with them.

Depending on where you live and the role we play, you may have rights to access, correct, delete, port, or restrict processing of your personal information, to object to certain processing, to opt out of sale/sharing or targeted advertising and certain profiling, and to be free from discrimination for exercising these rights. You may also:

To exercise a right where Coraleye is the controller, contact us using Section 11. We may need to verify your identity, and we will respond within the timeframes required by applicable law. You may use an authorized agent where the law permits. If you disagree with our decision, you may appeal by replying to our response or lodge a complaint with your local data protection authority.

7.1 U.S. State Privacy Rights

Residents of California and other U.S. states with comprehensive privacy laws have the rights described above with respect to personal information for which Coraleye is the controller/business. We do not sell personal information or share it for cross-context behavioral advertising, and we do not use or disclose sensitive personal information beyond the purposes permitted by law. To exercise these rights, use the contact details in Section 11; we will not discriminate against you for doing so.

8. International Data Transfers

Coraleye is based in the United States, and your information may be processed there and in other countries where we or our subprocessors operate. Where personal data is transferred from the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum), available through our DPA.

9. Children's Privacy

The Service is intended for business use and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child's information has been provided to us, please contact us and we will take appropriate steps to delete it.

10. Changes to This Policy

We may update this policy as our practices evolve, particularly as the Service adds new integrations, AI providers, or analytics tooling. We will update the "Last updated" date above when material changes are made, and will notify affected customers in advance of changes that materially reduce their rights.

11. Contact

For questions about this policy or our data practices, or to exercise a privacy right where Coraleye is the controller, contact your Coraleye account representative or:

Coraleye
Email: chris@coraleye.ai
Website: coraleye.ai