Privacy Policy
This policy explains what personal data CORE collects, why, who we share it with and what you can ask us to do about it. Last updated 24 August 2026.
Who is responsible
The controller for the data described here is [to be confirmed: registered company name], whose registered office is given in our legal notice. For any question about this policy, or to exercise the rights below, write to privacy@core.report.
When you use CORE as an employee of a customer organisation, that organisation is the controller of the data in its workspace and we act as its processor. This policy then describes what we do on their instructions.
What we collect
Account data
Your name, work email address, workspace role and sign-in events. We need these to give you access and to keep an audit trail of who changed what.
Data you put into the product
The brands, competitors, markets and prompts you configure, and the answers, citations and brand mentions we collect from AI engines on your schedule. Prompts are written by you and may contain whatever you choose to put in them.
Technical data
Server logs including IP address, request path and timing, kept to operate and secure the service. Unhandled errors are captured with the exception type, a truncated message and stack frames. Answer text, prompt text and credentials are never sent to error tracking.
Product analytics
We count how the site is used, so that decisions about it are made on evidence rather than on opinion: page views, which call to action was clicked, and the steps of signing up — a sign-in link requested, a workspace created, a first prompt written. Each is recorded with the page address, the referring page, your browser and an approximate location derived from your IP address.
Identifiers in the address are removed before it is recorded, so a page address never carries a project reference or a sign-in token. To count one person rather than one person per page, a random identifier is held in your browser’s session storage and discarded when you close the tab, and a request for a sign-in link is recorded against a one-way hash of your email address rather than the address itself. If your browser sends Do Not Track or Global Privacy Control, nothing is recorded at all.
What we do not do
We do not use advertising trackers, we do not sell personal data, and we do not use your workspace content to train models of our own. Nothing we count follows you to another website, and nothing survives closing the tab.
Why we are allowed to
- Performing our contract with you or your employer, for everything needed to deliver the service you signed up for.
- Our legitimate interests in keeping the service secure, debugging failures and preventing abuse, balanced against your rights.
- Legal obligation, where we must keep records or respond to lawful requests.
Who else processes it
We use the sub-processors below. Each receives only what its purpose requires. Some are established outside the European Economic Area, and those transfers rely on the European Commission’s standard contractual clauses.
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Oracle Cloud Infrastructure | Application and scheduler hosting | Application data and logs |
| Supabase | PostgreSQL database and private file storage | All workspace and evidence data |
| Resend | Sign-in links and report delivery by email | Recipient address, links, report summary |
| WorkOS | SAML single sign-on | Authentication identity fields, connection state |
| OpenAI | Answer collection, translation and classification | Prompt text and returned answers |
| Anthropic | Answer collection with web search | Prompt and location context, answers |
| Answer collection with search grounding | Prompt and locale context, answers | |
| Perplexity | Answer collection with web search | Prompt and location context, answers |
| GitHub | Continuous integration and deployment | Repository and build artifacts |
| Stripe | Subscription payment, when a workspace subscribes | Billing name, email and card details, entered on their hosted page |
| PostHog (EU) | Product analytics: which pages are visited and where signup stops | Masked page address, referrer, browser, approximate location from IP, pseudonymous identifier |
The AI engines we query are named above because your prompt text reaches them. Write prompts as though they will be read outside your organisation, because they are.
Where it is stored
Our hosting and database are configured with European targets. We state this as our configuration rather than as a certified guarantee: a residency commitment for a specific contract is something we confirm in writing during procurement, with dated evidence for every host, store and backup involved.
How long we keep it
Each workspace has a retention period, two years by default, which an administrator can shorten to as little as 30 days. Observations, snapshots and report files older than that period are purged. Account records are kept while the account exists. A workspace can be placed under legal hold, which suspends purging until the hold is lifted.
How it is protected
- Every tenant table is isolated by row-level security, enforced per request.
- Workspace roles limit access, and role changes are recorded in an audit log.
- API keys are scoped and can be given an expiry.
- Single sign-on through SAML is available, so your identity provider stays in control.
- Database backups are encrypted; the backup job refuses to run without its key.
- Traffic is served over HTTPS under a content security policy.
We hold no SOC 2 report and have not completed an external penetration test. We would rather tell you that here than let a procurement questionnaire discover it.
Your rights
If you are in the European Economic Area or the United Kingdom you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or receive it in a portable form. Write to privacy@core.report and we will answer within one month. If your data sits in a customer’s workspace we will pass your request to that customer, who decides it.
You may also complain to your local supervisory authority. In France that is the CNIL.
Cookies
We set one cookie, to keep you signed in, and one to remember which workspace you were looking at. Both are strictly necessary to operate the product, so we do not ask for consent for them. There are no advertising or analytics cookies on this site: the analytics described above set no cookie, and the one identifier they keep in your browser lives in session storage and is gone when the tab closes.
Changes
If we change this policy we will update the date at the top, and we will tell customers directly before any change that materially affects them takes effect.