Privacy Policy
Last updated: 2026-07-15
Overview
Coordn8r (“we”, “us”, or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use our website and application (collectively, the “Services”).
We design our Services to collect only what is needed to operate and improve the product, and we do not sell personal information.
This policy is intended to comply with:
- Canada: Personal Information Protection and Electronic Documents Act (PIPEDA)
- United States: Applicable state privacy laws, including the California Consumer Privacy Act (CCPA/CPRA)
Information We Collect
Information you provide
We collect information you choose to provide, including:
- Name, email address, and contact details
- Company or organization name
- Account credentials
- Project, task, scheduling, and communication data entered into the app
- Messages, feedback, or support requests
Information collected automatically
When you use the Services, we may automatically collect:
- IP address and general location (city/region)
- Browser type, device type, and operating system
- Usage data (pages viewed, actions taken)
- Log and diagnostic information for security and performance
Integrations and third-party services
If you connect third-party services (such as Google Calendar):
- We access only the data required to provide the requested integration
- We do not access unrelated personal content
- Access can be revoked at any time through the third-party provider
Google user data we access
When you sign in with Google and connect Google Calendar, Coordn8r accesses only the following Google user data:
- Basic account information — your name, profile picture, and the email address on your Google Account. Used to create and identify your Coordn8r account.
- Your calendar list — the names and identifiers of the calendars on your account, so we can identify your primary calendar.
- Availability from your primary calendar — your free/busy times, and the timing of events on your primary calendar. We also subscribe to change notifications on that calendar so your availability stays accurate in real time. This is used solely to determine when you are busy so the scheduler can plan around commitments you have already made.
- A dedicated Coordn8r calendar we create on your account — a separate, secondary calendar created by Coordn8r, the task events we write to it, and attendee responses (accepted/declined) to those Coordn8r-created events.
We do not modify, create, or delete events on your primary calendar or on any calendar other than the Coordn8r-created calendar. We do not access Gmail, Drive, Contacts, Photos, or any other Google service.
Calendar data is processed within our own scheduling logic as internal availability information. How it interacts with our AI features — and the strict limits that apply — is described in AI and Automated Processing and Google User Data and Limited Use below.
How We Use Information
We use personal information to:
- Provide, operate, and maintain the Services
- Create and manage projects, tasks, and schedules
- Sync schedules and updates with connected services
- Communicate about accounts, updates, or support
- Improve functionality, reliability, and user experience
- Detect, prevent, and address security or technical issues
- Comply with legal obligations
We do not use personal information for unrelated purposes.
AI and Automated Processing
Some features use AI to assist with:
- Project and task generation
- Organization and prioritization
- Scheduling suggestions
These AI features are provided using a third-party hosted AI service (currently OpenAI, accessed through the OpenAI API). This is the only third-party AI/ML provider our application integrates with.
AI features:
- Operate only on data relevant to the requested function
- Are designed to assist users, not make final decisions on their behalf
- Are provided by vetted third-party providers under confidentiality and data-protection commitments
How your Google Calendar data interacts with AI. Your Google Calendar data is used almost entirely within our own deterministic (non-AI) scheduling logic, which treats calendar free/busy purely as internal numeric availability and makes no calls to any AI service. Raw Google Calendar data — including event titles, descriptions, attendee identities, attendee responses, and individual event start and end times — is never transmitted to any third-party AI service. The only calendar-derived information that may be sent to our AI provider is an aggregated, rounded summary of free and booked hours per day (for example, “4.0 hours booked, 3.5 hours free” on a given date), and only when you explicitly ask our in-app assistant about your availability. No raw calendar content is included.
No training on your data. Under OpenAI’s API data usage policy, data submitted through the OpenAI API is not used to train or improve OpenAI’s models, and is retained only transiently for abuse monitoring before deletion. No Google Workspace user data — whether raw, aggregated, or derived — is used to create, train, or improve any foundational or generalized AI/ML model.
Google User Data and Limited Use
Coordn8r’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Any Workspace user data processed by AI/ML services is used solely to provide user-facing features and is never used to train or improve generalized AI/ML models.
Specifically, for data obtained through Google APIs:
- We limit our use of this data to providing and improving the user-facing features you have chosen to use (such as scheduling around your calendar availability)
- We do not transfer this data except as necessary to provide or improve those features, to comply with applicable law, or in connection with a merger or acquisition with appropriate notice
- We do not use this data for serving advertising
- We do not allow humans to read this data unless we have your affirmative consent, it is necessary for security or to comply with applicable law, or the data has been aggregated and anonymized
- We do not use this data — raw, aggregated, or derived — to develop, train, or improve any generalized or foundational AI/ML model
How We Share Information
We share personal information only as necessary:
- With trusted service providers (such as hosting, analytics, email, and AI/ML processing) who are bound by confidentiality and security obligations
- With integration partners you explicitly authorize
- If required by law or to protect the rights, safety, or security of users or the Services
We do not sell personal information and do not share it for cross-context behavioral advertising.
Data Retention
We retain personal information:
- For as long as an account is active
- As needed to provide the Services
- As required to meet legal, security, or operational requirements
You may request deletion of your account and associated data, subject to reasonable retention requirements.
Google user data retention and deletion
- Availability data derived from your Google Calendar is retained only while your calendar is connected and your account is active, so we can schedule around your commitments.
- OAuth tokens are retained only while your calendar connection is active. When you disconnect, we revoke the authorization with Google and delete the tokens from our systems.
- You can disconnect at any time from within Coordn8r (Settings → Business Settings → Permissions → Google Calendar). Doing so revokes Coordn8r’s authorization directly with Google and deletes our stored credentials. You may also revoke our access from your Google Account at myaccount.google.com/connections.
- On disconnection, we stop our calendar change subscriptions, revoke the grant with Google, and delete the stored credentials, ending all access to your calendar. The Coordn8r-created calendar and its events remain on your Google Account under your control; you may delete that calendar yourself at any time.
- On account deletion, all Google user data associated with your account — tokens and derived availability data — is deleted from our production systems within 30 days. Residual copies in encrypted backups are purged on our normal backup rotation, and are not used for any purpose in the interim.
Security Safeguards
We use reasonable administrative, technical, and physical safeguards to protect personal information, including:
- Access controls
- Secure infrastructure
- Encrypted connections where appropriate
No system is completely secure, but we work to reduce risk and protect information.
How we protect Google user data
Google user data receives the safeguards above, and additionally:
- OAuth access and refresh tokens are encrypted at rest using authenticated symmetric encryption, and are never exposed to end users or shared with third parties.
- All data in transit between Coordn8r and Google APIs is encrypted using TLS.
- Access is restricted to authorized personnel on a least-privilege basis.
- We do not allow humans to read your Google user data unless we have your affirmative consent, it is necessary for security or to comply with applicable law, or the data has been aggregated and anonymized.
- Google user data is stored on secure cloud infrastructure and is never sold, and never shared with advertisers or data brokers.
Your Rights (Canada & United States)
Canada (PIPEDA)
You have the right to:
- Access your personal information
- Request corrections to inaccurate information
- Withdraw consent, subject to legal or contractual limitations
United States (including California)
Depending on your state, you may have the right to:
- Know what personal information we collect and how it is used
- Access your personal information
- Request deletion of your personal information
- Correct inaccurate personal information
- Opt out of certain data sharing (note: we do not sell personal information)
We will not discriminate against you for exercising these rights.
Cookies and Analytics
We may use cookies or similar technologies to:
- Understand how the Services are used
- Improve performance and reliability
You can control cookies through your browser settings.
Children’s Privacy
The Services are not intended for children under 13, and we do not knowingly collect personal information from children.
International Data Transfers
Your information may be stored or processed outside your province, state, or country, including in Canada or the United States. We take reasonable steps to ensure appropriate safeguards are in place.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date and, where appropriate, providing notice through the Services.
Contact Us
If you have questions or wish to exercise your privacy rights, contact us at:
Email: privacy@coordn8r.com
Company: Coordn8r Software Inc.
Location: Toronto, Ontario, Canada