๐Ÿ”’

Encrypted in Transit

All data transmitted between you and Cooper uses TLS 1.2+ encryption.

๐Ÿ—„๏ธ

Cloudflare KV Storage

Data is stored in Cloudflare's globally distributed, secure infrastructure.

๐Ÿšซ

No Data Selling

We never sell, rent, or trade your personal data to third parties.

1

Introduction & Scope

Cooper AI LLC ("Cooper AI," "we," "us," or "our") operates the AI concierge platform available at meetcooper.ai ("the Service"). This Data Security Policy describes the types of information we collect, how we use and protect it, how long we retain it, your rights over your data, and how we respond to security incidents.

This policy applies to all users of the Cooper AI platform and any services offered under the meetcooper.ai domain. By using our Service, you agree to the practices described in this policy.

Who we are: Cooper AI LLC is a Texas limited liability company. Our registered address is in Austin, Texas. Questions about this policy should be directed to: privacy@meetcooper.ai

2

Data We Collect

We collect only the data necessary to provide and improve the Service. Here is a complete breakdown:

Data Type What It Includes Why Collected Storage
Account Data Email address, name, agent name chosen during onboarding Account creation and identification Encrypted KV
Email Content Emails you forward to your agent address; subject, body, sender/recipient metadata Core product function โ€” AI processing and response Encrypted KV TLS
OAuth Tokens Microsoft/Google OAuth access tokens (if connected) Read inbox, calendar, contacts as authorized Encrypted KV
Usage Data Feature usage, session timestamps, error logs, API call counts Service improvement, debugging, billing Cloudflare Analytics
AI Interaction Logs Prompts sent to Cooper AI's AI model; responses generated Service delivery; not used for model training (see ยง5) Temporary
Device / Browser Data IP address, browser type, device type (via standard web logs) Security, fraud prevention, analytics Cloudflare Logs

What We Do NOT Collect

  • Payment card numbers (handled by Stripe, not stored by Cooper AI)
  • Passwords to your external email accounts
  • Files, documents, or attachments not explicitly shared with the Service
  • Biometric data, health data, or financial account data
  • Data from accounts you have not explicitly authorized
3

How Data Is Stored & Protected

Infrastructure

All user data is stored using Cloudflare Workers KV, Cloudflare's globally distributed key-value store. Cloudflare maintains SOC 2 Type II compliance, ISO 27001 certification, and operates under strict data protection standards.

Encryption

  • In transit: All data transmitted between your device and Cooper AI, and between Cooper AI and third-party services, is encrypted using TLS 1.2 or higher.
  • At rest: Sensitive data stored in Cloudflare KV is encrypted at rest by Cloudflare's infrastructure. Particularly sensitive fields (OAuth tokens, email content) are additionally encrypted at the application layer before storage.

Access Controls

  • Access to production data is restricted to authorized personnel only.
  • All internal access to user data requires multi-factor authentication.
  • Principle of least privilege is applied โ€” each system component can access only the data it requires.
  • No Cooper AI employee reads your email content in the normal course of business.

Third-Party AI Processing

Anthropic API โ€” API Data is NOT Used for Training Cooper AI uses Anthropic's Claude API to power AI responses. Under Anthropic's commercial API terms, your data sent through the API is NOT used to train Anthropic's models. Anthropic acts as a data processor on behalf of Cooper AI LLC. Your email content and interactions are processed by Anthropic's API only to generate responses, then discarded. See Anthropic's Privacy Policy at anthropic.com/legal/privacy for full details.

OAuth & Third-Party Integrations

When you connect Microsoft or Google accounts, we receive OAuth access tokens with the specific scopes you authorize (email read, contacts, calendar). These tokens are stored encrypted. You can revoke access at any time through Microsoft or Google account settings โ€” this immediately invalidates our stored token.

4

Retention Periods

Data Type Retention Period Notes
Account Data Until account deletion + 30 days 30-day grace period for recovery
Email Content 90 days (rolling) Older emails purged automatically. Pro plans may have extended retention.
AI Interaction Logs 30 days Used for debugging and service continuity; then deleted
OAuth Tokens Until revoked or account deleted Automatically purged if revoked from Microsoft/Google
Usage/Analytics Data 12 months Aggregated, anonymized after 90 days
Billing Records 7 years Required by IRS regulations for business records
Security/Incident Logs 12 months Retained for security auditing purposes

You may request early deletion of your data at any time by contacting privacy@meetcooper.ai. We will process deletion requests within 30 days, subject to legal retention requirements (e.g., billing records).

5

AI Models & Data Training

โœ… Clear Policy: We Do Not Train on Your Data Cooper AI does not use your email content, personal data, or AI interactions to train or fine-tune any AI models โ€” ours or Anthropic's. Your data is used solely to generate responses for you and is not retained for model improvement purposes.

Cooper AI uses the Anthropic Claude API (an enterprise API product). Under Anthropic's commercial API terms, API customer data is not used to train Anthropic's models. Cooper AI is the data controller; Anthropic is the data processor.

In the future, if Cooper AI develops proprietary AI models, any training on user data would require explicit, opt-in consent from users and this policy would be updated accordingly.

6

Your Rights

Regardless of your location, Cooper AI provides the following rights to all users:

RightWhat It MeansHow to Exercise
Access Request a copy of all personal data we hold about you Email privacy@meetcooper.ai โ€” 30-day response
Deletion Request deletion of your account and all associated data Email privacy@meetcooper.ai or account settings
Correction Correct inaccurate personal data we hold Account settings or email us
Portability Receive your data in a machine-readable format (JSON/CSV) Email privacy@meetcooper.ai with subject "Data Export"
Revoke OAuth Disconnect Microsoft/Google integration immediately Via Microsoft/Google account settings; takes effect immediately
Opt Out of Marketing Unsubscribe from non-essential communications Unsubscribe link in emails or email privacy@meetcooper.ai
Close Account Delete your account entirely Account settings or email us; processed within 30 days

California residents: You have additional rights under the California Consumer Privacy Act (CCPA). Texas residents and residents of other US states with comprehensive privacy laws may have similar rights. Contact us to learn more.

7

Incident Response

In the event of a data security incident (breach, unauthorized access, or data loss), Cooper AI will follow this response protocol:

  1. Detection & Containment (0โ€“4 hours): Upon discovering or being notified of a potential breach, we will immediately isolate affected systems to prevent further unauthorized access. Affected credentials or tokens will be revoked.
  2. Assessment (4โ€“24 hours): We will determine the scope of the incident โ€” what data was accessed, which users are affected, and the root cause. Forensic logs will be preserved.
  3. Notification โ€” Internal (24 hours): The Cooper AI LLC manager and any relevant legal counsel will be notified within 24 hours of confirmed breach.
  4. User Notification (72 hours): Affected users will be notified via email within 72 hours of confirming a breach that affects their personal data. Notification will include: what happened, what data was involved, what we are doing, and what you can do to protect yourself.
  5. Regulatory Notification: Where required by law (e.g., GDPR's 72-hour rule, state breach notification laws), appropriate regulators will be notified. Texas businesses must notify the Office of the Attorney General for breaches affecting 250+ Texas residents.
  6. Remediation & Post-Mortem: We will implement fixes, conduct a full post-incident review, and publish a summary of what happened and what we changed. Security improvements will be implemented within 30 days.

To report a security vulnerability: Email security@meetcooper.ai with subject "Security Vulnerability." We follow responsible disclosure principles and will respond within 48 hours.

8

Third-Party Services

ProviderPurposeData SharedTheir Policy
Anthropic AI model (Claude API) Email content, prompts (processed, not retained for training) anthropic.com/legal/privacy
Cloudflare CDN, KV storage, Workers All data (infrastructure provider) cloudflare.com/privacypolicy
Microsoft OAuth (if connected) Access token, email/calendar scopes you authorize privacy.microsoft.com
Google OAuth (if connected) Access token, Gmail/Calendar scopes you authorize policies.google.com/privacy
Stripe Payment processing Payment info (handled directly by Stripe; not stored by us) stripe.com/privacy

We do not sell, rent, or share your personal data with any third party for their marketing purposes.

9

Changes to This Policy

We may update this policy from time to time. When we do:

  • We will update the "Effective Date" at the top of this page.
  • For material changes affecting your rights, we will notify you via email at least 14 days before the changes take effect.
  • Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
  • Previous versions of this policy are available upon request.

Questions or Concerns?

We take privacy seriously. Contact our data team at any time.

๐Ÿ“ง privacy@meetcooper.ai  |  ๐Ÿ” security@meetcooper.ai

Cooper AI LLC ยท Austin, Texas ยท meetcooper.ai