Legal
Privacy policy
People bring this product their lab results, their tax position and their legal disputes. This page says exactly what happens to that.
Effective · Last updated
What we collect
Account data
Your email address, and a hashed password if you did not sign in with Google. Your name and profile image if you choose to provide them. Your plan, billing status and the country you signed up from.
Conversation data
The messages you send to a copilot and the responses it returns, along with which copilot you used and when. Any documents you upload for analysis.
This is the sensitive category and we treat it as such. People bring this product lab results, severance agreements, IRS notices and things they have not told anyone else.
Usage data
Which pages you visited, which features you used, approximate location derived from IP address, browser and device type, and referring site. This is ordinary product analytics and every script involved is listed in the cookie policy.
Payment data
We do not store card numbers. Payments are processed by Stripe, which holds the card details; we receive only the last four digits, the card type and whether the transaction succeeded.
Support correspondence
If you email us, we keep the thread so whoever picks it up next has the context.
What we do not do
Stated first, because these are the questions people actually have.
- We do not train models on your conversations. Not our own, and we do not permit our model providers to train on data submitted through our accounts.
- We do not sell your personal information, and we do not share it for cross-context behavioural advertising as those terms are defined under California law.
- We do not read your conversations except in the narrow circumstances set out below.
- We do not require your real name to use the service.
- We do not use conversation content to target advertising.
How we use what we collect
To run the service, and specifically to:
- Provide copilot responses, which requires sending your message to a model provider
- Keep your conversation history so you can return to a problem days later
- Authenticate you, and bill you if you are on a paid plan
- Understand in aggregate which features are used, so we know what to improve
- Detect abuse, fraud and use prohibited by the acceptable use policy
- Send service messages - a receipt, a security alert, a change to these terms
When a human might see a conversation
Three circumstances and no others: you send it to us yourself as part of a support request, an automated system flags it for safety review under the acceptable use policy, or we are legally compelled to produce it. Access is limited to staff who need it and is logged.
Marketing email
Only if you opt in, and every message carries a working unsubscribe link. Service messages about your own account are not marketing and continue while you have an account.
Legal bases for processing
If you are in the UK, the EEA or Switzerland, we process your data on these bases under the UK GDPR and EU GDPR:
- Performance of a contract - providing the service you signed up for, including sending your messages to a model provider and storing your history.
- Legitimate interests - securing the service, preventing abuse, and understanding aggregate usage, assessed against your rights and interests.
- Consent - analytics and marketing cookies, and marketing email. Withdrawable at any time with no effect on the service itself.
- Legal obligation - retaining billing records and responding to lawful requests.
How long we keep things
| Data | Retained for |
|---|---|
| Conversations | Until you delete them, or 30 days after account deletion |
| Uploaded documents | Until you delete them, or 30 days after account deletion |
| Account record | Until deletion, then 30 days in backups |
| Billing records | 7 years, as required for tax and accounting |
| Support correspondence | 3 years |
| Server and security logs | 90 days |
| Aggregate, anonymised usage | Indefinitely - it no longer identifies you |
Deletion removes data from live systems immediately and from backups within 30 days. That window is the backup rotation period rather than a delay we have chosen.
Your rights
Wherever you live you can access your data, export it, correct it and delete it - from account settings, without asking us or explaining why.
UK, EEA and Switzerland
You additionally have the right to restrict or object to processing, the right to data portability, the right to withdraw consent at any time, and the right to complain to your supervisory authority. In the UK that is the ICO; in the EEA it is your national data protection authority.
California
Under the CCPA as amended by the CPRA you have the right to know what is collected and why, to delete it, to correct it, to opt out of sale or sharing, and to limit use of sensitive personal information. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of - but the right exists and we will not discriminate against you for exercising any of it.
Other US states
Residents of Virginia, Colorado, Connecticut, Utah, Texas and other states with comprehensive privacy laws have broadly equivalent rights. We apply one process to all of them rather than operating a different standard per state.
How to exercise them
Most of it is self-service in account settings. For anything else, email privacy@copilotly.com. We respond within 30 days and will tell you if we need longer and why. We may need to verify your identity first, which protects you rather than us.
International transfers
Copilotly operates from the United States and our providers are primarily US-based, so data about users outside the US is transferred to the US.
Where we transfer personal data out of the UK or EEA we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, together with supplementary technical measures - encryption in transit and at rest, and access controls limiting who can reach the data at all.
Security
Conversations are encrypted in transit with TLS and at rest. Access to production systems requires multi-factor authentication and is limited to staff who need it. Administrative access is logged.
No system is perfectly secure, and anyone claiming otherwise is selling something. Full detail, and how to report a vulnerability, is on the security page.
If a breach affects your personal data and creates a risk to you, we will notify you and the relevant regulator within the timeframes the law requires - 72 hours to a supervisory authority under GDPR.
Children
Copilotly is not intended for anyone under 13 and we do not knowingly collect personal information from them. If we learn that we have, we delete it.
Between 13 and 18 the service should be used with a parent or guardian involved. Much of what these copilots discuss - legal exposure, health, money - is not well suited to being worked through alone at that age.
Changes to this policy
When we change this materially we will email account holders and post a notice on the site before it takes effect, rather than quietly moving the date.
Minor clarifications get a new "last updated" date. Continuing to use the service after a change takes effect means you accept it; if you do not, you can export your data and close your account.
Contact
Privacy questions, requests and complaints: privacy@copilotly.com.
Anything else: contact us. A person answers, usually within one business day.