Last updated: July 27, 2026
Corebee Chat LTD ("Corebee," "we," "our," or "us") respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered customer support platform at corebee.aiand any related services (collectively, the "Service").
Corebee is the data controller for personal data collected through our website, marketing activities, and account management. This includes data from website visitors, account holders, and marketing contacts. We process this data for the purposes of managing our relationship with you, operating our business, and complying with legal obligations.
When our customers use Corebee to provide support to their end-users, the customer is the data controller and Corebee acts as a data processor. In this capacity, we process personal data only in accordance with the customer's instructions and our Data Processing Agreement. This Privacy Policy does not govern our processing of personal data as a data processor on behalf of our customers. If you are an end-user seeking information about how your data is processed, please contact the organization that uses Corebee for their customer support.
If you choose to connect a Google account so that Corebee can send support replies from your own email address, Corebee requests only the https://www.googleapis.com/auth/gmail.send scope. This permission lets Corebee send outbound support replies on your behalf, and nothing more. We do not read, list, modify, label, or delete the contents of your Gmail mailbox, and we do not request any Gmail read scope. The only Google Account data we store is the email address of the connected mailbox and the OAuth tokens needed to send on your behalf; those tokens are stored encrypted at restand are used solely to send your outbound support replies. You can disconnect the mailbox at any time from your channel settings, which revokes Corebee's access; you may also revoke access directly from your Google Account permissions.
Corebee's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, do not use it for advertising, and do not transfer it except as necessary to provide the Corebee support features you request, to comply with applicable law, or as part of a merger or acquisition with equivalent protections.
We process your personal data on the following legal bases under the GDPR:
We process limited business contact information about individuals at companies we believe may benefit from Corebee. This is limited to name, job role, employer, business email address, and publicly available information about the company.
Lawful basis.We rely on legitimate interests (Article 6(1)(f)) to contact business representatives about products relevant to their professional role. We have assessed that this processing is necessary for our business development and proportionate in its impact, on the basis that the contact is professional rather than personal in nature, relates directly to the recipient's role, and can be stopped immediately on request. Where required, we contact corporate subscribers in accordance with the applicable electronic marketing rules in the recipient's jurisdiction.
Sources. Publicly available business sources such as company websites and public business directories, and commercial data and email verification providers. We do not purchase consumer data, and we do not process special category data for this purpose.
Your rights. You may object to this processing at any time and we will stop contacting you immediately. Every message includes a means of opting out, and you can also write to jonathan@corebee.ai. When you object, we add your address to a suppression list retained solely to ensure we do not contact you again. If you would prefer erasure instead of suppression, tell us and we will delete your details rather than retain them on that list.
Retention. Business contact data is retained for up to 24 months from the date of last contact, after which it is deleted. Suppression list entries are retained indefinitely, as deleting them would risk re-contacting someone who has asked us not to.
We use the information we collect to:
Our Service uses artificial intelligence, including third-party large language models, to generate responses to customer queries. Here is how your data is handled in connection with AI features:
With your consent, we use the following analytics and marketing technologies on our website. No tracking cookies or scripts are loaded until you provide consent via our cookie banner. For a complete list of cookies, see our Cookie Policy.
We use Google Analytics 4, provided by Google LLC, to understand how visitors interact with our website. GA4 collects information such as pages visited, session duration, device type, and traffic source. IP addresses are anonymized by default for visitors in the EU/EEA. We have configured a data retention period of 14 months.
Legal basis: Consent (GDPR Article 6(1)(a)). Opt-out: Google Analytics Opt-out Browser Add-on.
We use PostHog, provided by PostHog Inc., for product analytics and (separately) optional session replay. Our PostHog instance runs on EU Cloud (Frankfurt, Germany); all data is stored and processed within the European Union. PostHog does not collect passwords, credit card numbers, or other sensitive form data.
We split PostHog usage into two separate consent categories because EU data protection authorities (CNIL, Garante, Datatilsynet) treat session replay as higher-risk than ordinary analytics:
/api/auth/*,/api/billing/*, /api/conversations/*, and /api/account/* are masked before being sent. Retained 30 days. For website visitors, replay is off unless you explicitly opt in via the cookie preferences modal. For signed-up account holders, replay is enabled by default on authenticated product surfaces so our support team can diagnose errors and help you resolve issues — you can turn it off at any time via the cookie preferences modal linked in the footer.You can change either toggle at any time via the cookie preferences modal (accessible from any page footer). Revoking consent stops future collection and deletes your person record when you close your account via the account-deletion flow. For more information, see the PostHog Privacy Policy. Legal basis: Website-visitor analytics and replay — Consent (GDPR Article 6(1)(a)). Post-signup replay on authenticated product surfaces — Legitimate interest (GDPR Article 6(1)(f)) for product support and debugging, with an in-product opt-out available at all times.
We use the Meta Pixel (client-side) and Meta Conversions API (server-side), provided by Meta Platforms, Inc., to measure the effectiveness of our advertising on Facebook and Instagram. The Pixel collects page view and conversion events. The Conversions API sends event data server-side, including SHA-256 hashed email addresses for conversion attribution.
Important: Hashing is not anonymization. Meta can match hashed identifiers against its user database to attribute conversions to specific users. This data processing only occurs with your marketing consent.
For more information, see Meta's Data Policy. You can manage your ad preferences through your Facebook Ad Preferences. Legal basis: Consent (GDPR Article 6(1)(a)).
We use Google Ads conversion tracking, provided by Google LLC, to measure the effectiveness of our advertising campaigns. When you click on a Google ad and subsequently take an action on our website (such as signing up), a conversion is recorded. For more information, see Google's Advertising Privacy Policy. Legal basis: Consent (GDPR Article 6(1)(a)).
We implement Google Consent Mode v2, which communicates your consent choices to Google services in real time. When you deny consent, Google Analytics and Google Ads operate in a cookieless mode that collects no personally identifiable information. Google may use these cookieless signals for modeled (estimated) reporting only.
When you first visit corebee.ai, we present a cookie consent banner with three equal options: Accept All, Reject All, or Customize. No non-essential cookies are placed on your device until you provide consent. You can change your preferences at any time via the "Cookie Settings" link in the footer.
If your browser sends a Global Privacy Control (GPC) signal, we honor it as an opt-out of all non-essential cookies, as required by applicable US state privacy laws (including the California Consumer Privacy Act).
When you sign in to Corebee using Google ("Sign in with Google"), we access the following information from your Google account:
We do not sell, rent, or trade Google user data. We do not use Google user data for advertising. Google user data is only shared with infrastructure providers (Supabase, Vercel) as necessary to operate the service.
You may revoke Corebee's access to your Google account at any time through your Google Account permissions. To request full data deletion, contact jonathan@corebee.ai.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing to subcontractors in support services, such as customer service or messaging delivery, is permitted. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
If you opt in to receive SMS/text messages from Corebee (for example, by agreeing on a phone call to have your free-trial link texted to the number you provided), your mobile phone number and your SMS consent will not be sold, and will not be shared with third parties for their own promotional or marketing purposes. You may opt out of text messages at any time by replying STOP to any message. Message and data rates may apply, and message frequency may vary. Reply HELP for help.
We do not sell your personal information. We may share your data with the following categories of recipients:
For a complete and current list of sub-processors, see our Data Processing Agreement.
Where your data is hosted. The Corebee application runs on infrastructure physically located in Mumbai, India:
bom1 region (Mumbai, India).ap-south-1 (Mumbai, India). Backups remain in the same region.ingest.us.sentry.io).Cross-border transfer mechanisms. India has not received an adequacy decision from the European Commission, so transfers from the European Economic Area (EEA), the United Kingdom, or Switzerland to our Indian hosting providers, and any onward transfer to the United States, are treated as third-country transfers under Chapter V of the GDPR. We rely on the following safeguards:
You may request a copy of the applicable SCCs, the UK Addendum, or the Transfer Impact Assessment summary by contacting us at jonathan@corebee.ai.
We implement industry-standard security measures to protect your data, including:
No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security. If we become aware of a security breach that affects your personal data, we will notify you and any applicable regulatory authority in accordance with applicable law (including within 72 hours for GDPR-regulated breaches where feasible).
We retain your personal information for as long as your account is active or as needed to provide services. Specific retention periods:
You can request deletion of your data at any time by contacting us. When there is no ongoing legitimate business need or lawful legal ground to retain your data, we will delete, anonymize, or securely isolate it until deletion is possible.
Self-service account deletion: authenticated users can delete their account directly via POST /api/account/delete(called from the account settings page). This cascades to your organization's contacts, conversations, knowledge base, and PostHog person record. An audit log is retained for three years per compliance requirements; all other personal data is irrecoverably deleted within 30 days.
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights:
We respond to all data subject requests within 30 days. If we need additional time (up to a further 60 days for complex requests), we will inform you within the initial 30-day period. Contact jonathan@corebee.ai to exercise any of these rights.
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
We do not sell personal information. We do not use or disclose sensitive personal information for purposes other than providing the Service. We honor Global Privacy Control (GPC) signals as a valid opt-out request under California law. You can also exercise your right to opt out at any time via the "Do Not Sell or Share My Personal Information" link in our website footer, which opens the cookie preferences modal where you can disable analytics and marketing cookies.
Categories shared with advertising partners (with your consent): identifiers, internet or electronic network activity information, and approximate geolocation. Under California law, the use of certain advertising technologies may constitute "sharing" of personal information. You may opt out at any time via the cookie consent banner or GPC signal.
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with comprehensive privacy laws have similar rights to access, correct, delete, and opt out of certain processing of personal data. We honor these rights consistent with the applicable state laws. To exercise your rights, contact us at jonathan@corebee.ai.
The Service is not directed at children under 16 and we do not knowingly collect personal data from children under 16. Children under 13 should not submit any personal information through the Service. If you believe we have collected information from a child under 16, please contact us immediately and we will delete it promptly.
In the event of a confirmed security breach affecting your personal data, we will promptly notify you and any applicable regulatory authority in accordance with applicable law. For breaches subject to GDPR, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach where feasible, and will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. Notifications will describe the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures taken or proposed to address the breach.
When you use our onboarding assistant, you may designate a third-party developer, agency, or technical installer (a "Designated Developer") to complete installation of Corebee on your behalf by providing that person's email address. This section describes how we process personal data in connection with that feature.
Controller. Corebee is the data controller for Designated Developer email addresses and related processing activities described in this Section.
Categories of data processed.recipient email address; the originating customer's company domain; the timestamps of the initial setup email and any follow-up; the delivery, open, click, and bounce status of those emails (where available from our email service provider); and the unsubscribe status associated with the recipient email.
Purpose. to deliver the one-time setup email requested by the customer, to send at most one operational follow-up email approximately two (2) days later to facilitate completion of the installation, and to suppress future emails to recipients who unsubscribe or bounce.
Legal basis. Legitimate interests under GDPR Article 6(1)(f) and equivalent provisions of the UK-GDPR. Our legitimate interest is the operational delivery of a B2B setup workflow that the customer has expressly requested and where the Designated Developer is identified as a professional technical contact with a pre-existing relationship to the customer. We have assessed the balance of interests and determined that the limited frequency (at most two emails), operational subject matter, clearly visible unsubscribe mechanism, and absence of marketing content mean that the processing does not override the rights and freedoms of the recipient. Where applicable, we also rely on the functional-unsubscribe and sender-identification requirements of the CAN-SPAM Act, and on the business-to-business exemptions under CASL.
Retention. Email delivery and follow-up tracking records (including send timestamps, open, click, and bounce events) are retained for 30 days after the initial send, after which they are deleted or aggregated into anonymous analytics. Unsubscribe records — consisting of the recipient email address (hashed where technically feasible) and the timestamp of the unsubscribe request — are retained for as long as necessary to prevent re-emailing, for the sole purpose of ensuring that the recipient is not re-emailed by Corebee or any of our customers using this feature.
Right to object. If you are a Designated Developer who received a setup or follow-up email from Corebee, you may object to further processing at any time by using the unsubscribe link included in the email (in the form https://corebee.ai/unsubscribe/{token}) or by emailing privacy@corebee.ai. Upon receipt of an objection, we will stop sending further emails to you under this feature and will add your email to our suppression list described above. You also retain all rights described in Section 14 (Your Rights Under GDPR) and applicable US state privacy laws.
Transmission.Setup and follow-up emails are sent from a Corebee-operated or Corebee-designated sending domain through our transactional email sub-processor, which acts as a processor on our behalf under a data processing agreement and in accordance with the international-transfer safeguards described in Section 11. The customer that designated you warrants that it has the authority to share your email address with Corebee; a customer's misuse of this feature does not affect your rights under this Privacy Policy or applicable law.
The onboarding assistant maintains conversational state and related technical data to support the setup experience. This section supplements Sections 3, 5, and 13 above with specifics for that feature.
Assistant Conversational State. We store transient conversational state (question responses, branching context, and progress markers) in a field called assistant_flow_state. Anonymous sessions are retained for up to 30 days from the last interaction; authenticated sessions are retained for up to 90 days or the lifetime of your account, whichever is shorter. This data is processed on the legal basis of contract performance (GDPR Article 6(1)(b)) for authenticated users and legitimate interests (GDPR Article 6(1)(f)) for anonymous setup flows, with the interest being the operation of a stateful onboarding experience that resumes correctly across page reloads.
Cross-Device Magic Resume Tokens. To let you resume an in-progress setup on a different device, we generate short-lived resume tokens that are delivered to you via email or magic link. Only a cryptographic hash of each token is stored in our database; the raw token is never persisted server side. Resume tokens expire seven (7) days after creation and are single-use. The legal basis for this processing is contract performance (GDPR Article 6(1)(b)) or, where the setup flow is pre-account, legitimate interests (GDPR Article 6(1)(f)) in providing a continuous onboarding experience.
Company Domain Enrichment. Where technically enabled for your onboarding session, we may enrich your company email domain with publicly available firmographic information (such as company name, industry, and approximate size) via a third-party enrichment provider. This enrichment is performed at the domain level only — we do not submit individual names, personal email addresses, or other personal identifiers to the enrichment provider for this purpose. Enrichment results are used solely to tailor the onboarding experience (for example, to suggest relevant templates) and are retained for the duration of your account plus the retention periods described in Section 13.
Behavioral Analytics During Onboarding. Assistant interactions generate behavioral events (such as step completions, drop-off points, and latency measurements) that are sent to our product analytics provider (PostHog; see Section 7). Before transmission, these events pass through a runtime personally-identifiable-information redaction filter that removes free-text answer content, email addresses, and other identifiers from the event payload. Events are used to measure onboarding completion rates and diagnose issues, and are governed by the retention, legal-basis, and opt-out provisions set out in Section 7.
We may update this privacy policy from time to time. We will notify you of changes by posting the new policy on this page and updating the "Last updated" date. If we make material changes that affect how we process your personal data, we will notify you by email or through a prominent notice on our website at least thirty (30) days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
If you have any questions about this privacy policy, our data practices, or wish to exercise your privacy rights, please contact us: