Navigation

Login to see more
Back to Coordio

Privacy Policy

Version: 2026-07-22

Effective 22 July 2026.

This Policy explains what personal data Coordio collects, why, on what legal basis, and what you can do about it.

1. Who is responsible

The controller of personal data is Andrii Ursolov, Ukraine — the operator of https://coordio.net.

Data requests: support@coordio.net. We answer within 30 days.

2. What we process

Category What exactly Source
Account email, name, username, password (bcrypt hash only), avatar, bio, skills you
Authentication Google/Facebook identifier (if you sign in that way), phone number and one-time code (if you sign in by phone), time and IP of last sign-in, sign-in attempt log you and the sign-in providers
Your content messages, notes, tasks, events, boards, files, comments, reactions, bookmarks you
Usage settings, themes, language, channel read state, streaks and focus sessions you
Technical request IP address and User-Agent (abuse protection), error logs automatically
Notifications your browser's push subscription you, after granting browser permission

We do not use advertising trackers, do not set third-party analytics cookies, and do not buy data about you. The cookies we do set are functional: your sign-in session and your language choice.

3. Why, and on what basis

Purpose Basis (GDPR art. 6)
Providing the Service: account, chat, files, tasks performance of a contract
Account emails (address verification, password reset) performance of a contract
Abuse protection: rate limiting, sign-in log, IP blocking legitimate interest — security of the Service and its users
Handling content reports legitimate interest + performance of a contract
Push and email notifications about activity your consent (switchable in settings)
Meeting legal requirements legal obligation

4. Who receives the data

We do not sell data. We use processors that handle data only on our instructions:

Processor Role Location
Vercel Inc. application hosting, storage of uploaded files (Blob) US / global
Neon Inc. PostgreSQL database EU / US
Upstash Inc. Redis for rate limiting (stores IP counters only) EU / US
PartyKit (Cloudflare) real-time server — message delivery and presence global
LiveKit Inc. video calls (media streams, for the duration of the call) global
Resend Inc. transactional email delivery US / EU
Google LLC, Meta Platforms Google / Facebook sign-in, if you choose it US
Anthropic PBC, OpenAI OpCo LLC processing AI-feature requests — only the text you explicitly send to such a feature US

Under their API terms, the model providers we use do not train models on data sent through the API.

Separately, we disclose data where the law requires it (a court or authority order), or to protect the rights and safety of users.

5. Transfers outside Ukraine and the EEA

Some processors are located in the US. Transfers rely on Standard Contractual Clauses (SCCs) and/or the provider's participation in the EU-U.S. Data Privacy Framework.

6. How long we keep it

  • Content and account — as long as the account exists.
  • Sign-in attempt log and technical logs — up to 90 days.
  • Rate-limit counters — from a minute to a day, depending on the rule.
  • After account deletion — data is deleted within 30 days; older backups roll over within 90 days.
  • Messages you posted in a shared channel may remain visible to its other members as part of the conversation history — anonymised once your account is deleted.

7. Security

  • Passwords are stored as bcrypt hashes; we cannot read them.
  • Message bodies are encrypted in the database.
  • The browser-side cache is encrypted (AES-GCM) and cleared on sign-out.
  • All traffic goes over HTTPS.
  • Access to data inside the Service is bounded by channel permissions; administrative technical access is used only for support and troubleshooting.
  • Two-factor sign-in (TOTP) is available and can be enabled in security settings.

No system is perfectly secure. If a breach occurs that puts your rights at risk, we notify you and the supervisory authority within 72 hours of becoming aware of it.

8. Your rights

You have the right to:

  • know what data we process about you and get a copy of it;
  • correct inaccurate data — most of it is editable directly in settings;
  • delete your account and data ("right to be forgotten");
  • restrict processing or object to it;
  • take your data in a machine-readable form (export);
  • withdraw consent to notifications — in settings, with no effect on the rest of the Service;
  • complain to a supervisory authority: in Ukraine, the Ukrainian Parliament Commissioner for Human Rights; in the EU, your country's data protection authority.

To exercise a right that has no button in the app, write to support@coordio.net.

9. Children

The Service is not intended for people under 16. If we learn that an account was created by a child below that age, we delete it.

10. Automated decisions

We make no decisions with legal effect on you by automated means alone, and we do not profile you for advertising.

11. Changes to this Policy

We announce material changes in the app or by email at least 14 days in advance. The effective date of the current version is at the top of this page.

12. Contact

support@coordio.net

Terms of ServicePrivacy Policy