Copilotly

Legal

Privacy policy

People bring this product their lab results, their tax position and their legal disputes. This page says exactly what happens to that.

Effective · Last updated

What we collect

Account data

Your email address, and a hashed password if you did not sign in with Google. Your name and profile image if you choose to provide them. Your plan, billing status and the country you signed up from.

Conversation data

The messages you send to a copilot and the responses it returns, along with which copilot you used and when. Any documents you upload for analysis.

This is the sensitive category and we treat it as such. People bring this product lab results, severance agreements, IRS notices and things they have not told anyone else.

Usage data

Which pages you visited, which features you used, approximate location derived from IP address, browser and device type, and referring site. This is ordinary product analytics and every script involved is listed in the cookie policy.

Payment data

We do not store card numbers. Payments are processed by Stripe, which holds the card details; we receive only the last four digits, the card type and whether the transaction succeeded.

Support correspondence

If you email us, we keep the thread so whoever picks it up next has the context.

What we do not do

Stated first, because these are the questions people actually have.

  • We do not train models on your conversations. Not our own, and we do not permit our model providers to train on data submitted through our accounts.
  • We do not sell your personal information, and we do not share it for cross-context behavioural advertising as those terms are defined under California law.
  • We do not read your conversations except in the narrow circumstances set out below.
  • We do not require your real name to use the service.
  • We do not use conversation content to target advertising.

How we use what we collect

To run the service, and specifically to:

  • Provide copilot responses, which requires sending your message to a model provider
  • Keep your conversation history so you can return to a problem days later
  • Authenticate you, and bill you if you are on a paid plan
  • Understand in aggregate which features are used, so we know what to improve
  • Detect abuse, fraud and use prohibited by the acceptable use policy
  • Send service messages - a receipt, a security alert, a change to these terms

When a human might see a conversation

Three circumstances and no others: you send it to us yourself as part of a support request, an automated system flags it for safety review under the acceptable use policy, or we are legally compelled to produce it. Access is limited to staff who need it and is logged.

Marketing email

Only if you opt in, and every message carries a working unsubscribe link. Service messages about your own account are not marketing and continue while you have an account.

Who we share data with

We share data with service providers who process it on our behalf, under contract, for purposes we specify and nothing else. The current list and what each one sees is on the subprocessors page.

The categories are model providers, cloud hosting, payment processing, analytics, email delivery and customer support.

Legal disclosure

We may disclose data where legally required - a valid subpoena, court order or equivalent. Where we are permitted to notify you, we will, so you have the opportunity to object.

Copilotly is not a law firm, a medical provider or a financial institution. Your conversations are not privileged. They are not protected by attorney-client privilege, doctor-patient confidentiality or HIPAA. That is a real limitation and worth understanding before putting something in writing you would not want produced.

Business transfer

If Copilotly is acquired or merges, data may transfer as part of that transaction. You would be notified, and the acquirer would be bound by this policy until it is changed with notice.

How long we keep things

DataRetained for
ConversationsUntil you delete them, or 30 days after account deletion
Uploaded documentsUntil you delete them, or 30 days after account deletion
Account recordUntil deletion, then 30 days in backups
Billing records7 years, as required for tax and accounting
Support correspondence3 years
Server and security logs90 days
Aggregate, anonymised usageIndefinitely - it no longer identifies you

Deletion removes data from live systems immediately and from backups within 30 days. That window is the backup rotation period rather than a delay we have chosen.

Your rights

Wherever you live you can access your data, export it, correct it and delete it - from account settings, without asking us or explaining why.

UK, EEA and Switzerland

You additionally have the right to restrict or object to processing, the right to data portability, the right to withdraw consent at any time, and the right to complain to your supervisory authority. In the UK that is the ICO; in the EEA it is your national data protection authority.

California

Under the CCPA as amended by the CPRA you have the right to know what is collected and why, to delete it, to correct it, to opt out of sale or sharing, and to limit use of sensitive personal information. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of - but the right exists and we will not discriminate against you for exercising any of it.

Other US states

Residents of Virginia, Colorado, Connecticut, Utah, Texas and other states with comprehensive privacy laws have broadly equivalent rights. We apply one process to all of them rather than operating a different standard per state.

How to exercise them

Most of it is self-service in account settings. For anything else, email privacy@copilotly.com. We respond within 30 days and will tell you if we need longer and why. We may need to verify your identity first, which protects you rather than us.

International transfers

Copilotly operates from the United States and our providers are primarily US-based, so data about users outside the US is transferred to the US.

Where we transfer personal data out of the UK or EEA we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, together with supplementary technical measures - encryption in transit and at rest, and access controls limiting who can reach the data at all.

Security

Conversations are encrypted in transit with TLS and at rest. Access to production systems requires multi-factor authentication and is limited to staff who need it. Administrative access is logged.

No system is perfectly secure, and anyone claiming otherwise is selling something. Full detail, and how to report a vulnerability, is on the security page.

If a breach affects your personal data and creates a risk to you, we will notify you and the relevant regulator within the timeframes the law requires - 72 hours to a supervisory authority under GDPR.

Children

Copilotly is not intended for anyone under 13 and we do not knowingly collect personal information from them. If we learn that we have, we delete it.

Between 13 and 18 the service should be used with a parent or guardian involved. Much of what these copilots discuss - legal exposure, health, money - is not well suited to being worked through alone at that age.

Changes to this policy

When we change this materially we will email account holders and post a notice on the site before it takes effect, rather than quietly moving the date.

Minor clarifications get a new "last updated" date. Continuing to use the service after a change takes effect means you accept it; if you do not, you can export your data and close your account.

Contact

Privacy questions, requests and complaints: privacy@copilotly.com.

Anything else: contact us. A person answers, usually within one business day.