Privacy Policy
Effective Date: 08/18/2026
This Privacy Policy explains how Coordinator, LLC ("COORDINATOR," "we," "us," or "our") collects, uses, shares, and protects information in connection with the COORDINATOR platform, website, and related services (the "Service"). By using the Service, you agree to the practices described here.
Information We Collect
We collect the following categories of information:
- Account information: name, email address, organization and team details, role, phone number, and authentication data (such as two-factor settings).
- Customer Content: the tasks, comments, workspace artifacts, chat messages, uploads, and other materials you submit to the Service.
- Voice, video & audio: when you use voice or video sessions, we process and may record the audio and video of the session and generate written transcripts, which are stored as part of your Customer Content.
- Health & fitness data: if you connect a wearable or fitness provider (such as Strava, Oura, WHOOP, Withings, Suunto, Google Health, Apple Health, Samsung Health, Hevy, or MyFitnessPal), we receive the data you authorize, which may include workouts, sleep, heart rate and heart-rate variability, recovery and readiness metrics, steps, body measurements, and nutrition. This is sensitive information, collected only after you connect the provider.
- Motion & performance data: when you upload or record athletic activity (such as a golf swing) for analysis, we process the media to produce motion and pose data (for example, skeletal keypoints) and related performance feedback. This is sensitive information.
- Integration data: data we access from third-party systems you connect, such as Notion, Google Drive, Slack, Discord, and SharePoint, limited to the scopes you authorize.
- Usage and device information: log data, IP address, browser and device characteristics, and information about how you interact with the Service. To meter usage and prevent abuse (particularly for guest sessions), we generate a device identifier from your browser and device characteristics.
- Marketing and inquiry information: information you provide through our website forms, early-access requests, or communications, such as your name, email, company, and message.
- Billing information: subscription and transaction details. Payment card data is handled by our payment processor and is not stored by us.
Sensitive Information
Health, fitness, and motion/performance data are sensitive categories of personal information. We collect them only when you choose to connect a provider or submit media for analysis, and we use them to provide the analysis, coaching, and coordination features you request. Your health and fitness data is strictly account-scoped by default: it is not visible to other members of your organization, team, or group unless you give explicit, revocable consent to share it. You can withdraw that consent, or disconnect a provider, at any time in your settings.
Account scoping controls who inside COORDINATOR can see this data. It does not prevent the data from being processed by an AI model when it is relevant to a request you make, including a third-party model. See "AI models and providers" below.
How We Use Information
We use information to:
- provide, maintain, secure, and improve the Service;
- power the AI layer that reads across your connected data to generate summaries, suggestions, and proposed actions;
- authenticate users and enforce roles and permissions;
- process payments and manage subscriptions;
- communicate with you about the Service, including security and administrative notices;
- send marketing communications where you have opted in; you can opt out at any time using the unsubscribe link in our emails; and
- comply with legal obligations and enforce our terms.
AI Processing
COORDINATOR runs a proprietary agentic AI framework. When you use AI features, relevant Customer Content and integration data are processed to generate Output. We do not use your Customer Content to train our own models. AI-proposed actions that write to your systems require human approval before they are executed.
AI models and providers
COORDINATOR does not rely on a single AI model. Some models run on infrastructure we operate, where your content stays within our systems. Others are third-party models, including models from Google (Gemini), OpenAI, Anthropic, DeepSeek, Alibaba (Qwen), and NVIDIA, which we reach through a model gateway that forwards the request to whichever provider serves that model. The engine selects a model for each turn based on what you are asking, so the set of models and providers involved changes over time and from request to request.
This means that Customer Content relevant to your request, including chat messages, uploaded files, data from integrations you have connected, and health, fitness, or motion data where it is relevant to what you asked, may be transmitted to the third-party provider serving that turn.
Once your content reaches a third-party model provider, that provider's own terms and privacy policy govern how it is handled. Providers differ in how long they retain prompts, whether staff may review them, and whether they use submitted content to improve their own models. We select providers and configure routing, but we do not control their internal practices and we cannot guarantee that every provider that may serve a request offers zero retention or excludes your content from model training. If this matters for your data, review the policies of the providers listed above, avoid submitting content you do not want processed by them, or contact us at [email protected] to discuss a deployment restricted to self-hosted models.
Image and video generation
Image and video generation works the same way and involves the same kind of third parties. When you ask for a picture or a clip, the prompt, along with any image you supply or that the assistant selects as a reference, which may be a photo you uploaded, is transmitted to the third-party image or video model serving that request, and that provider's own terms and privacy policy govern how it handles what it receives. We do not own, operate, or train those models. Generated media is returned to us, marked or labeled as AI-generated, and stored in our object storage alongside the conversation it belongs to, where it is retained and deleted on the same terms as your other Customer Content.
To provide continuity across conversations, the AI layer may retain a long-term memory derived from your Customer Content, including embeddings and summaries used to recall relevant context. Content you mark as private or use in an incognito conversation is excluded from this shared memory. Messages screened for safety may be briefly retained in excerpt form to enforce our terms.
Files you add to your personal library are treated differently from files you simply attach to a conversation. When you upload to your library, COORDINATOR reads the file's contents and distills what it learns into that long-term memory, so the information can be recalled in later conversations without you re-uploading the file. Attaching a file to a single conversation does not do this. That file is used to answer the request at hand and is not distilled into memory. Because reading a library file is a full AI request, it counts toward your AI usage in the same way a message does.
You can delete a library item at any time. Deleting it removes the stored file and the search index built from it. Facts COORDINATOR already learned from that file remain in your long-term memory until you remove them, which you can do entry by entry in your memory settings. If you want everything derived from a file cleared at once, email us at [email protected] and we will handle it as a deletion request.
Third-Party Integrations
When you connect a third-party system, you authorize COORDINATOR to access data within the scopes you grant. We access this data to provide the Service and handle it in accordance with this Policy. The third-party provider's own privacy practices govern data on their side; review their policies before connecting.
Google user data
What we access. If you connect Google Drive, we request the drive.file scope, which grants access only to files you specifically choose through the Google file picker and to files COORDINATOR itself creates, never your entire Drive. For those files we access the file name, MIME type, size, and contents. We also receive your email address and basic profile from openid email profile to identify the connected account. We request no other Google permissions: no Gmail, no Calendar, and no access to Drive files you have not chosen.
How we use it. We use Google user data solely to provide the features you invoke: attaching a file to a conversation so COORDINATOR can reference it, reading a Doc or Sheet you ask about, and creating Docs and Sheets when you export your work. We do not use it for advertising, profiling, or credit decisions.
How we share it.We do not sell or rent Google user data, and we do not transfer it to third parties for advertising or for any independent commercial use of their own. Content from a file you select is processed by AI models in order to answer your request. As described in "AI models and providers" above, depending on how a request is routed this may include third-party model providers reached through our model gateway; those providers process the content to generate a response under their own terms. We do not use Google user data to develop, improve, or train our own AI/ML models, and we do not transfer it to anyone for the purpose of training theirs. Google user data is never used for any purpose beyond serving the request you made.
How we protect it. Google data is transmitted over TLS, stored in access-controlled systems, and reachable only by your authenticated account. OAuth credentials are held server-side and never exposed to your browser except as required by the Google file picker.
Retention and deletion. Files you import are retained until you delete them, disconnect Google Drive, or delete your account. Disconnecting Google Drive revokes our access token with Google and deletes the file content we imported from your Drive. Deleting your account removes it along with the rest of your data.
COORDINATOR's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How We Share Information
We do not sell your personal information. We share information only:
- Within your organization: Customer Content is visible to members of your organization and teams according to their roles and permissions.
- With service providers: vendors who process data on our behalf (for example, hosting, payment processing, email, and logging) under contractual confidentiality obligations.
- With AI model providers: the model gateway and third-party model providers that process your content to generate Output, as described in "AI models and providers" above.
- For legal reasons: when required by law or to protect the rights, safety, and security of COORDINATOR, our users, or others.
- Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this Policy.
Deployment & Data Location
COORDINATOR may be deployed on infrastructure operated for or by your organization. Where the Service is deployed on your own infrastructure, your Customer Content resides on that infrastructure and is subject to your organization's controls. The location and handling of your data depend on your deployment configuration.
Data Retention
We retain information for as long as your account is active or as needed to provide the Service, and thereafter as required to comply with legal obligations, resolve disputes, and enforce our agreements. Some records are retained in a deactivated or historical form after you delete them or disconnect a provider, for example, if you disconnect a wearable inside COORDINATOR, we keep the activity data already received so your training history stays intact.
If instead you revoke COORDINATOR's access from the provider's own settings, we treat that as a request to stop holding that provider's data entirely: we delete our access credentials and erase the activity data we received from them. Deleting an activity at the provider deletes it here as well. You may also request deletion of your data as described below.
Data Security
We use technical and organizational measures designed to protect information against unauthorized access, loss, or misuse, including encryption in transit, access controls, and authentication safeguards. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Your Rights & Choices
Depending on your location, you may have rights to access, correct, delete, or port your personal information, or to object to or restrict certain processing. You can exercise many of these directly in your account settings, including updating your profile, disconnecting integrations and wearables, deleting content, and deleting your account.
To request a copy of your personal information (data export) or the deletion or erasure of your data beyond what account settings allow, email us at [email protected] from the email address associated with your account. We will verify your identity and respond within the timeframe required by applicable law (generally within 30 days, or 45 days where permitted). Some information may be retained after a deletion request where we are required or permitted to keep it, for example, to comply with legal obligations, resolve disputes, prevent abuse, or enforce our agreements. If you are part of an organization, certain requests may need to be directed to your organization administrator, who controls that organization's data.
Cookies
We use cookies and similar technologies to operate and improve the Service. For details, see our Cookie Policy.
International Transfers
Where information is transferred across borders, we take steps to ensure appropriate safeguards are in place consistent with applicable data protection laws. Note that the AI model providers described above operate in a number of countries, so content processed by AI features may be handled outside your country of residence.
Children's Privacy
The Service is intended for users who are at least 18 years old, or the age of majority in their jurisdiction. It is not directed to minors, and we do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us information, contact us at [email protected] so we can remove it.
Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will provide notice through the Service or by other reasonable means. The effective date above reflects the most recent revision.
Contact Us
Questions or requests regarding your privacy? Contact us at [email protected].