Privacy Policy

Effective

This explains what coauthored collects, why, who else sees it, and what you can ask us to do about it. It is written to be read.

1. Who we are

coauthored is operated by Derek Ekberg, an individual trading as coauthored (“we”, “us”). We are the controller of the information described here. You can reach us at privacy@coauthored.io for anything in this document, or support@coauthored.io for everything else.

This policy covers the coauthored web application and the emails we send you. It does not cover the model providers’ own products, or any site we link to.

2. What we collect

What you give us when you sign up. An email address, which is required — it is how you sign in and how invitations reach you. A display name, which starts as the part of your email before the @ and which you can change. Optionally, an avatar image.

What you and your collaborators put in threads. Messages, replies, reactions, thread and folder names, and any files you upload. Text files are stored as text; images, PDFs and other files are stored as uploaded. This is the substance of the product and it is the great majority of what we hold.

A record of every model call. For each one we store which model was used, which company served it, which range of the thread was sent as context, which earlier model responses were included, whether the thread had zero data retention enabled, the number of tokens in and out, what the call cost, and the provider’s response in full.

That record is detailed because a model call is otherwise impossible to account for afterwards. Knowing exactly which slice of a thread was sent, to whom, and under what policy is what lets us answer why two calls made seconds apart produced different answers, bill you correctly, and tell you what left the system if you ever ask.

Subscription details, if you pay. Stripe handles the payment and we keep only what tells us your plan is active: a Stripe customer and subscription identifier, the status, and the date the current period ends. We never receive your card number.

Ordinary technical records. Our hosting and database providers keep server logs, which include IP addresses, timestamps and the requests made. When you submit the sign-in form, Vercel BotID runs a check to tell a person from a script.

3. What we use it for

  • Running the product — showing you your threads, delivering messages to the people in them, making model calls, and storing what comes back.
  • Signing you in — sending the 8-digit code to your email and checking it. We do not store passwords because there are none.
  • Billing and usage limits — taking payment through Stripe, and adding up what your calls cost so we can apply the limits in our terms.
  • Keeping the service up and unabused — rate limiting, bot detection at sign-in, investigating faults, and defending against attacks.
  • Writing to you about the service — invitations, sign-in codes, billing receipts, and notices about outages or changes to this policy. These are not marketing and you cannot unsubscribe from them while you have an account.
  • Meeting legal obligations — tax and accounting records, and responding to lawful requests.

If you are in the UK or EEA, our legal bases are performance of a contract for running the product, signing you in, billing, and the service emails; legitimate interests for keeping the service up and unabused; and legal obligation for tax records and lawful requests. We do not rely on consent for anything above, because nothing above is optional to the service — which is also why there is no consent banner.

4. A thread is shared, and that is the point

coauthored is a shared workspace. Everything you write in a thread is visible to every other member of that thread, attributed to you by display name, along with when you wrote it. Files you upload can be opened and downloaded by them. Model responses you invoke are visible to everyone, not only to you.

Two things are not shared. Your folders are a private filing layer — a thread you have filed appears to everyone else exactly where it always was. And your spend is yours: a member can see that a model was called, but not what anyone else’s calls cost or what their total is.

Inviting someone to a thread gives them the whole thread, including everything written before they arrived. Anyone in a thread can invite anyone else.

If you put someone else’s personal information into a thread, that is your decision and your responsibility. You need a lawful basis to share it, and the people you share it with will be able to read it, keep it and act on it. Because entries are immutable, you cannot take it back afterwards — so this is a decision to make before you send, not after. Information about other people is worth thinking twice about, and special categories of it — health, beliefs, biometrics — are worth keeping out entirely.

We process what you put in a thread on your instruction, and we do not review it. What other members post is theirs, and what they do with what they read there is between you and them. The terms set out how that responsibility is allocated.

5. Models, and what we send them

When you invoke a model, we send that thread’s conversation to OpenRouter, which routes it to the company serving that model. We may send parts or the whole of the thread, not just the message, including any of the thread’s files, images, or PDFs.

The only thing identifying you that leaves with the call is a salted one-way hash of your account identifier, which lets OpenRouter isolate one account’s behavior from another’s without receiving an identifier that means anything outside our system. Your email address and display name are not sent.

We do not train models on your content, and neither do our providers. Every call is sent with a parameter instructing OpenRouter to refuse any provider that would train on it, and we restrict routing to a fixed list of companies that each report that they do not. This is enforced on each request rather than promised in a settings page, and a company cannot be added to the list by anyone but us.

A call may be served by any of the following, and each has its own privacy terms:

Providers that are not on this list cannot be given your conversation, including ones OpenRouter adds later. Unless a thread has zero data retention turned on, the company serving the call may hold what we sent for a limited period — typically 30 to 55 days — for their own abuse monitoring, and then delete it.

6. Zero data retention

Any thread can be switched to zero data retention, which restricts that thread’s calls to providers that keep nothing at all after answering. It is off by default. Any member of a thread can turn it on, and any member can turn it off.

The setting is recorded on each model call at the moment the call is made, so the record always shows the policy the call actually ran under rather than the setting as it stands today. Turning it on does not reach back: calls already made were made under the policy in force then.

It changes where a call goes, not what we keep. We still store the thread, the response and the usage record described in section 2.

7. Who else processes your data

We use a small number of companies to run the service. Each acts on our instructions, and none of them is permitted to use your content for their own purposes.

CompanyWhat it does
VercelHosting, content delivery, and bot detection on the sign-in form.
SupabaseDatabase, authentication, file storage, and realtime delivery.
OpenRouterRoutes each model call to one of the providers below.
StripeSubscription payments. Card details go to Stripe and never to us.
ResendSign-in codes and thread invitations.
Google WorkspaceOur own support and business mailboxes, so anything you email us.

Beyond these, we disclose information only where the law requires it, where we need to establish or defend a legal claim, or — if coauthored is ever sold or merged — to the acquirer, who would be bound by this policy until it told you otherwise.

We do not sell your personal information, and we do not share it for advertising. There are no advertising platforms, analytics vendors or session-recording tools in this product.

8. Cookies

We set cookies to keep you signed in, and Vercel BotID sets one when you submit the sign-in form so it can tell a person from a script. That is all of them.

There are no analytics, advertising or preference cookies, so there is no consent banner and nothing to opt out of. Blocking the sign-in cookies will stop you from being able to sign in.

9. How long we store data

coauthored keeps each thread as a record whose entries are immutable (for users). There is no way to edit or delete what you have written — not for you, not for anyone else in the thread. This is deliberate rather than a missing feature. Model responses are produced from the exact text that stood at the time, and other people in the thread have read and replied to it, so a conversation that can be rewritten afterwards is one nobody can rely on. Write accordingly.

We keep a narrow ability to remove content — where it is unlawful, where the law requires it, or where leaving it in place would put someone at risk. It is a right we hold rather than a service we offer, and section 8 of the terms sets out its limits.

Threads, messages, files and model responses are kept for as long as the thread exists. A thread exists while it has at least one member.

Usage and billing records are kept for as long as we need them for accounting and tax, which is generally six years.

Server logs are kept on our hosting and database providers’ ordinary schedules, which are measured in days to weeks rather than years.

Invitations expire, and are kept as a record of who invited whom.

10. Deleting your account, and what it does not delete

You can ask us to delete your account at any time by writing to privacy@coauthored.io. When we do:

  • Your email address, display name and avatar are erased, and cannot be restored.
  • You are removed from every thread. Where you owned a thread, ownership passes to its longest-standing remaining member.
  • Your private folders are deleted. The threads filed in them are not — they belong to their members, not to your filing.
  • Any invitations you sent that nobody has accepted are revoked.
What you wrote in a thread stays in that thread. Because entries are immutable, your messages, files and model calls remain visible to the other members, but are no longer attributed to a named person — the account behind them is gone and cannot be recovered or re-identified by us.

In extreme cases we may delete your contributions to threads you were a member of. That will be judged on a case by case basis.

11. Your rights

Wherever you are, you can ask us to:

  • Give you a copy of the personal information we hold about you, in a portable format.
  • Correct anything inaccurate. Your display name you can change yourself, in your profile.
  • Delete your account, subject to section 10.
  • Object to or restrict processing we carry out on the basis of legitimate interests.
  • Complain to a data protection regulator. In the UK that is the ICO; in the EEA it is your national authority.

Write to privacy@coauthored.io. We answer within one month, and we do not charge for it. We may need to confirm you control the email address on the account before acting, which is a safeguard rather than an obstacle — the alternative is deleting an account for whoever asks.

12. If you are in the United States

California, Colorado, Connecticut, Virginia, Texas and other states with comprehensive privacy laws give their residents rights to know, correct, delete and port their personal information, and to be free from discrimination for exercising them. The mechanism is the same: write to privacy@coauthored.io.

The categories we collect, in the vocabulary those laws use:

CategoryCollectedSold or shared
Identifiers (email, display name, account ID)YesNo
Commercial information (subscription, usage, spend)YesNo
Internet activity (server logs, IP address, requests)YesNo
User content (messages, files, model responses)YesNo
Biometric, precise geolocation, inferencesNoNo

We have never sold or shared personal information as those laws define it, and we do not process sensitive personal information for the purpose of inferring characteristics. There is no “Do Not Sell or Share” link because there is nothing for it to switch off.

13. Where your data is processed

coauthored runs on infrastructure in the United States, and model calls may be served from data centers in the United States, the European Union or other regions depending on which company handles the call.

If you are in the UK or EEA, transfers out of your region rely on the UK International Data Transfer Addendum or the European Commission’s Standard Contractual Clauses, which our providers incorporate into their terms.

14. Security

Data is encrypted in transit and at rest. Access to a thread is enforced in the database itself, by row-level security policies evaluated on every read, rather than only in application code — so a mistake in the app cannot hand one person another person’s thread. Sign-in is by one-time code, so there is no password to reuse or leak. Provider credentials are held server-side and never reach your browser.

No service is perfectly secure. If we discover a breach affecting your personal information, we will tell you and the relevant regulator as the law requires.

15. Children

coauthored is for adults. You must be at least 18 to hold an account, and we do not knowingly collect information from anyone younger. If you believe a child has an account, write to privacy@coauthored.io and we will delete it.

16. Changes to this policy

We will post any change here and update the effective date. If a change materially affects how we handle your information, we will email you at least 30 days before it takes effect, so you can leave before it applies to you.

17. Contact

Privacy and data requests: privacy@coauthored.io
Everything else: support@coauthored.io