Privacy Policy
Version: 2026-07-22
Effective 22 July 2026.
This Policy explains what personal data Coordio collects, why, on what legal basis, and what you can do about it.
1. Who is responsible
The controller of personal data is Andrii Ursolov, Ukraine — the operator of https://coordio.net.
Data requests: support@coordio.net. We answer within 30 days.
2. What we process
| Category | What exactly | Source |
|---|---|---|
| Account | email, name, username, password (bcrypt hash only), avatar, bio, skills | you |
| Authentication | Google/Facebook identifier (if you sign in that way), phone number and one-time code (if you sign in by phone), time and IP of last sign-in, sign-in attempt log | you and the sign-in providers |
| Your content | messages, notes, tasks, events, boards, files, comments, reactions, bookmarks | you |
| Usage | settings, themes, language, channel read state, streaks and focus sessions | you |
| Technical | request IP address and User-Agent (abuse protection), error logs | automatically |
| Notifications | your browser's push subscription | you, after granting browser permission |
We do not use advertising trackers, do not set third-party analytics cookies, and do not buy data about you. The cookies we do set are functional: your sign-in session and your language choice.
3. Why, and on what basis
| Purpose | Basis (GDPR art. 6) |
|---|---|
| Providing the Service: account, chat, files, tasks | performance of a contract |
| Account emails (address verification, password reset) | performance of a contract |
| Abuse protection: rate limiting, sign-in log, IP blocking | legitimate interest — security of the Service and its users |
| Handling content reports | legitimate interest + performance of a contract |
| Push and email notifications about activity | your consent (switchable in settings) |
| Meeting legal requirements | legal obligation |
4. Who receives the data
We do not sell data. We use processors that handle data only on our instructions:
| Processor | Role | Location |
|---|---|---|
| Vercel Inc. | application hosting, storage of uploaded files (Blob) | US / global |
| Neon Inc. | PostgreSQL database | EU / US |
| Upstash Inc. | Redis for rate limiting (stores IP counters only) | EU / US |
| PartyKit (Cloudflare) | real-time server — message delivery and presence | global |
| LiveKit Inc. | video calls (media streams, for the duration of the call) | global |
| Resend Inc. | transactional email delivery | US / EU |
| Google LLC, Meta Platforms | Google / Facebook sign-in, if you choose it | US |
| Anthropic PBC, OpenAI OpCo LLC | processing AI-feature requests — only the text you explicitly send to such a feature | US |
Under their API terms, the model providers we use do not train models on data sent through the API.
Separately, we disclose data where the law requires it (a court or authority order), or to protect the rights and safety of users.
5. Transfers outside Ukraine and the EEA
Some processors are located in the US. Transfers rely on Standard Contractual Clauses (SCCs) and/or the provider's participation in the EU-U.S. Data Privacy Framework.
6. How long we keep it
- Content and account — as long as the account exists.
- Sign-in attempt log and technical logs — up to 90 days.
- Rate-limit counters — from a minute to a day, depending on the rule.
- After account deletion — data is deleted within 30 days; older backups roll over within 90 days.
- Messages you posted in a shared channel may remain visible to its other members as part of the conversation history — anonymised once your account is deleted.
7. Security
- Passwords are stored as bcrypt hashes; we cannot read them.
- Message bodies are encrypted in the database.
- The browser-side cache is encrypted (AES-GCM) and cleared on sign-out.
- All traffic goes over HTTPS.
- Access to data inside the Service is bounded by channel permissions; administrative technical access is used only for support and troubleshooting.
- Two-factor sign-in (TOTP) is available and can be enabled in security settings.
No system is perfectly secure. If a breach occurs that puts your rights at risk, we notify you and the supervisory authority within 72 hours of becoming aware of it.
8. Your rights
You have the right to:
- know what data we process about you and get a copy of it;
- correct inaccurate data — most of it is editable directly in settings;
- delete your account and data ("right to be forgotten");
- restrict processing or object to it;
- take your data in a machine-readable form (export);
- withdraw consent to notifications — in settings, with no effect on the rest of the Service;
- complain to a supervisory authority: in Ukraine, the Ukrainian Parliament Commissioner for Human Rights; in the EU, your country's data protection authority.
To exercise a right that has no button in the app, write to support@coordio.net.
9. Children
The Service is not intended for people under 16. If we learn that an account was created by a child below that age, we delete it.
10. Automated decisions
We make no decisions with legal effect on you by automated means alone, and we do not profile you for advertising.
11. Changes to this Policy
We announce material changes in the app or by email at least 14 days in advance. The effective date of the current version is at the top of this page.