CORE
PrivacyTermsLegal notice

Privacy Policy

This policy explains what personal data CORE collects, why, who we share it with and what you can ask us to do about it. Last updated 24 August 2026.

Who is responsible

The controller for the data described here is [to be confirmed: registered company name], whose registered office is given in our legal notice. For any question about this policy, or to exercise the rights below, write to privacy@core.report.

When you use CORE as an employee of a customer organisation, that organisation is the controller of the data in its workspace and we act as its processor. This policy then describes what we do on their instructions.

What we collect

Account data

Your name, work email address, workspace role and sign-in events. We need these to give you access and to keep an audit trail of who changed what.

Data you put into the product

The brands, competitors, markets and prompts you configure, and the answers, citations and brand mentions we collect from AI engines on your schedule. Prompts are written by you and may contain whatever you choose to put in them.

Technical data

Server logs including IP address, request path and timing, kept to operate and secure the service. Unhandled errors are captured with the exception type, a truncated message and stack frames. Answer text, prompt text and credentials are never sent to error tracking.

Product analytics

We count how the site is used, so that decisions about it are made on evidence rather than on opinion: page views, which call to action was clicked, and the steps of signing up — a sign-in link requested, a workspace created, a first prompt written. Each is recorded with the page address, the referring page, your browser and an approximate location derived from your IP address.

Identifiers in the address are removed before it is recorded, so a page address never carries a project reference or a sign-in token. To count one person rather than one person per page, a random identifier is held in your browser’s session storage and discarded when you close the tab, and a request for a sign-in link is recorded against a one-way hash of your email address rather than the address itself. If your browser sends Do Not Track or Global Privacy Control, nothing is recorded at all.

What we do not do

We do not use advertising trackers, we do not sell personal data, and we do not use your workspace content to train models of our own. Nothing we count follows you to another website, and nothing survives closing the tab.

Why we are allowed to

  • Performing our contract with you or your employer, for everything needed to deliver the service you signed up for.
  • Our legitimate interests in keeping the service secure, debugging failures and preventing abuse, balanced against your rights.
  • Legal obligation, where we must keep records or respond to lawful requests.

Who else processes it

We use the sub-processors below. Each receives only what its purpose requires. Some are established outside the European Economic Area, and those transfers rely on the European Commission’s standard contractual clauses.

Sub-processorPurposeData involved
Oracle Cloud InfrastructureApplication and scheduler hostingApplication data and logs
SupabasePostgreSQL database and private file storageAll workspace and evidence data
ResendSign-in links and report delivery by emailRecipient address, links, report summary
WorkOSSAML single sign-onAuthentication identity fields, connection state
OpenAIAnswer collection, translation and classificationPrompt text and returned answers
AnthropicAnswer collection with web searchPrompt and location context, answers
GoogleAnswer collection with search groundingPrompt and locale context, answers
PerplexityAnswer collection with web searchPrompt and location context, answers
GitHubContinuous integration and deploymentRepository and build artifacts
StripeSubscription payment, when a workspace subscribesBilling name, email and card details, entered on their hosted page
PostHog (EU)Product analytics: which pages are visited and where signup stopsMasked page address, referrer, browser, approximate location from IP, pseudonymous identifier

The AI engines we query are named above because your prompt text reaches them. Write prompts as though they will be read outside your organisation, because they are.

Where it is stored

Our hosting and database are configured with European targets. We state this as our configuration rather than as a certified guarantee: a residency commitment for a specific contract is something we confirm in writing during procurement, with dated evidence for every host, store and backup involved.

How long we keep it

Each workspace has a retention period, two years by default, which an administrator can shorten to as little as 30 days. Observations, snapshots and report files older than that period are purged. Account records are kept while the account exists. A workspace can be placed under legal hold, which suspends purging until the hold is lifted.

How it is protected

  • Every tenant table is isolated by row-level security, enforced per request.
  • Workspace roles limit access, and role changes are recorded in an audit log.
  • API keys are scoped and can be given an expiry.
  • Single sign-on through SAML is available, so your identity provider stays in control.
  • Database backups are encrypted; the backup job refuses to run without its key.
  • Traffic is served over HTTPS under a content security policy.

We hold no SOC 2 report and have not completed an external penetration test. We would rather tell you that here than let a procurement questionnaire discover it.

Your rights

If you are in the European Economic Area or the United Kingdom you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or receive it in a portable form. Write to privacy@core.report and we will answer within one month. If your data sits in a customer’s workspace we will pass your request to that customer, who decides it.

You may also complain to your local supervisory authority. In France that is the CNIL.

Cookies

We set one cookie, to keep you signed in, and one to remember which workspace you were looking at. Both are strictly necessary to operate the product, so we do not ask for consent for them. There are no advertising or analytics cookies on this site: the analytics described above set no cookie, and the one identifier they keep in your browser lives in session storage and is gone when the tab closes.

Changes

If we change this policy we will update the date at the top, and we will tell customers directly before any change that materially affects them takes effect.

Last updated 24 August 2026Back to core.report