Coresource — Privacy Policy
Effective Date: May 2, 2026
Company: coresourceai, Inc.
Service: Coresource
Contact: legal@coresource.ai
This Privacy Policy explains how coresourceai, Inc. ("Coresource," "we," "us," or "our") collects, uses, discloses, and retains personal information in connection with Coresource and related websites, software, APIs, cloud services, agents, support, billing, and communications.
Coresource provides AI-powered agents, software, and cloud services. It may process repository data, task descriptions, prompts, logs, command output, generated code, saga state, cloud sandbox data, and related development information to provide the Service.
1. Scope
This Privacy Policy applies to personal information we collect or process in connection with Coresource, including account management, billing, support, security, analytics, communications, service administration, agent execution, and product improvement.
Unless Coresource expressly agrees in a separate signed written agreement, Coresource does not undertake special regulated-data, industry-specific compliance, or customer-specific data-handling obligations beyond those stated in this Privacy Policy and the Terms. You are responsible for ensuring that you have all rights, permissions, notices, consents, and legal authority necessary to submit personal information or other Customer Content to Coresource.
2. Geographic Availability and EU/EEA Restrictions
Coresource is not currently offered for use in the European Union or European Economic Area. Coresource does not currently provide EU AI Act compliance, EU/EEA data protection compliance, EU representative services, EU-specific transfer mechanisms, or EU-specific compliance terms.
You may not access or use Coresource if you are located in, ordinarily resident in, or organized under the laws of the European Union or European Economic Area. You may not submit personal information of individuals located in the European Union or European Economic Area, or submit personal information or other Customer Content to Coresource in a way that would require Coresource to comply with EU or EEA legal requirements, unless Coresource expressly agrees in writing.
3. Personal Information We Collect
We may collect the following categories of information.
Account and Profile Information. This may include name, email address, display name, organization, role, account settings, authentication method, OAuth identity, organization membership, invite links, and related profile information.
Authentication and Security Information. This may include API key metadata, API key prefixes or hints, session identifiers, cookies, bearer tokens, tenant IDs, organization IDs, login events, IP addresses, device information, security logs, and access records. We do not intentionally store full plaintext API keys after issuance unless required to provide a specific feature.
Repository and Development Information. Depending on your use of Coresource, we may process source code, file names, directory structures, manifests, branch names, commit hashes, repository archives, diffs, dirty state, generated changes, test output, dependency information, build logs, runtime logs, and other software development context.
Task and Saga Information. This may include task descriptions, planning notes, clarifying questions, user instructions, investigation findings, plan artifacts, execution state, saga descriptions, features, assertions, milestones, progress logs, approvals, intervention states, and status transitions.
Agent and AI Interaction Data. This may include prompts, model messages, tool calls, shell command output, file-read results, file-edit results, assistant responses, subagent results, summaries, checkpoints, transcripts, model names, token usage, cost estimates, and related metadata.
Cloud Execution Information. This may include sandbox IDs, container names, saga IDs, worker session IDs, heartbeat data, runtime errors, handoff files, sandbox minutes, execution logs, queue events, WebSocket events, and saga completion and cleanup information.
Billing and Commercial Information. This may include credit purchases, credit balances, usage records, invoices, billing contact details, payment status, Stripe customer identifiers, payment identifiers, top-up information, token counts, model multipliers, sandbox records, and cost estimates. Payment card details are processed by our payment processing provider and are not stored directly by Coresource except for limited metadata. Our payment processing provider may store payment method details, payment tokens, and related billing information to process credit purchases, refunds, disputes, taxes, fraud prevention, and compliance.
Communications and Support Information. This may include messages you send us, support requests, bug reports, feedback, survey responses, sales communications, and administrative communications.
Optional Web and External Tool Information. If enabled or requested, Coresource may process web search queries, fetched URLs, external tool outputs, package registry information, documentation pages, issue tracker data, code hosting metadata, or other third-party information needed for a task.
Sensitive Information. Coresource may process sensitive information if it appears in repositories, command output, logs, prompts, files, or user instructions. This may include secrets, credentials, private keys, environment variables, certificates, regulated personal information, security vulnerabilities, or confidential business information. You should avoid providing sensitive information unless necessary and authorized.
4. Sources of Personal Information
We collect information from:
- you, when you create an account, configure the Service, submit tasks, contact us, purchase credits, or use Coresource;
- your organization, administrators, teammates, or authorized users;
- repositories, sagas, agents, tools, and integrations you connect or authorize;
- OAuth providers, identity providers, code hosting services, payment processing providers, infrastructure providers, AI providers, and other third-party services;
- logs, cookies, telemetry, and security systems generated through use of the Service.
5. How We Use Personal Information
We use personal information to:
- provide, operate, and maintain Coresource;
- authenticate users and manage accounts, organizations, roles, sessions, and API keys;
- plan, execute, resume, monitor, and troubleshoot agent tasks and sagas;
- process repositories, prompts, logs, command output, model messages, and generated outputs;
- run cloud sandboxes, queues, workers, storage systems, WebSocket updates, and durable execution state;
- provide AI inference, tool use, web search, web fetch, and other agent capabilities;
- enforce permissions, budgets, rate limits, credit limits, usage limits, and security controls;
- detect, prevent, and investigate abuse, fraud, misuse, security incidents, and policy violations;
- provide support, debugging, reliability improvements, and customer communications;
- process payments, invoices, taxes, usage records, credits, and related billing operations;
- analyze usage, performance, cost, reliability, and product quality;
- improve the Service, including agent workflows, user experience, documentation, and operational systems;
- generate, use, retain, and make available Aggregated De-Identified Data as described below;
- comply with law, legal process, accounting obligations, sanctions, export rules, and contractual obligations;
- protect the rights, safety, and property of Coresource, users, customers, and third parties.
6. AI Processing, Model Training, and Aggregated De-Identified Data
Coresource sends Customer Content, including prompts, code, task descriptions, logs, tool outputs, transcripts, and agent outputs, to AI inference providers and infrastructure vendors as needed to provide the Service.
Customer Content and foundation model training. Coresource will not use raw Customer Content to train Coresource or third-party foundation models, except with your explicit opt-in or as separately agreed in writing. AI inference providers and infrastructure vendors may retain limited Customer Content or metadata for abuse monitoring, security, debugging, application-state, legal compliance, or similar operational purposes according to their commercial terms and applicable configurations. Coresource does not authorize AI inference providers to use raw Customer Content for foundation model training except as expressly enabled by you or agreed in writing.
Aggregated De-Identified Data. Coresource may internally use and modify Customer Content for the purposes of providing the Service and generating Aggregated De-Identified Data. "Aggregated De-Identified Data" means data submitted to, collected by, or generated by the Service in connection with use of the Service, but only in aggregate, de-identified form that cannot reasonably be linked specifically to you or your organization. Coresource may freely use, retain, and make available Aggregated De-Identified Data for Coresource's business purposes, including without limitation, for purposes of improving, testing, operating, promoting, and marketing the Service and other Coresource products and services.
Coresource will maintain Aggregated De-Identified Data in de-identified or aggregate form and will not attempt to reidentify it except to test whether its deidentification processes satisfy applicable requirements. Coresource will require recipients of Aggregated De-Identified Data to maintain it in de-identified or aggregate form and not attempt to reidentify it.
Limited human review. Coresource may review limited Customer Content when necessary for support, debugging, abuse prevention, security investigation, legal compliance, or with your authorization.
Feature-specific terms. If a specific AI provider, product feature, or configuration has different data handling terms, those terms will be disclosed in the applicable agreement, feature notice, or configuration.
7. How We Disclose Personal Information
We may disclose personal information to the following categories of recipients.
Vendors and Infrastructure Providers. We may disclose information to vendors, contractors, infrastructure providers, and technology providers that support cloud hosting, storage, compute, databases, queues, containers, payment processing, AI inference, analytics, logging, security, customer support, email, and other operational functions.
These providers may include cloud infrastructure providers, payment processing providers such as Stripe, OAuth or account-linking providers such as Google and GitHub, AI model or inference providers, and web search or web fetch providers.
Your Organization and Authorized Users. If your account belongs to an organization, administrators and authorized users may access information associated with that organization, including users, sagas, usage, logs, repository references, billing, and security settings.
Integrations and Third-Party Tools You Authorize. We may disclose information to code hosting platforms, package registries, issue trackers, development tools, web services, APIs, or other integrations that you connect, configure, or instruct Coresource to use.
Aggregated De-Identified Data. We may use, retain, and make available Aggregated De-Identified Data for Coresource's business purposes as described in this Privacy Policy.
Legal, Safety, and Compliance Recipients. We may disclose information when we believe disclosure is necessary to comply with law, legal process, sanctions, export rules, tax obligations, security requirements, or requests from public authorities; to protect rights, safety, or property; or to enforce our agreements.
Business Transactions. We may disclose information in connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, subject to appropriate confidentiality protections.
8. Cookies and Similar Technologies
We may use cookies, local storage, session tokens, and similar technologies to operate the Service, authenticate users, remember settings, secure accounts, measure usage, and improve performance.
Where required by law, we will obtain consent for non-essential cookies. You may control cookies through your browser settings, but disabling cookies may affect Service functionality.
9. Retention
We retain personal information for as long as reasonably necessary to provide the Service, comply with law, resolve disputes, enforce agreements, maintain security, and support legitimate business purposes.
The criteria we use to determine retention periods include the type and sensitivity of the information, the feature or account context in which it was collected, the length of your relationship with Coresource, operational needs for sagas and support, security and abuse-prevention needs, applicable legal requirements, accounting and tax requirements, backup and deletion cycles, and whether retention is needed to protect the rights, safety, or property of Coresource, users, customers, or third parties.
We may retain billing, invoice, tax, credit, and accounting records for as long as required or appropriate for accounting, tax, legal, and compliance purposes. We may retain security logs and abuse-prevention records for as long as reasonably necessary to investigate, prevent, or respond to misuse, security incidents, fraud, or legal claims. We may retain Aggregated De-Identified Data indefinitely.
10. Deletion and Account Controls
The Coresource UI may provide controls to delete sagas, sessions, transcripts, and uploaded repositories. For account-level deletion or formal privacy requests, email legal@coresource.ai. We respond within the timeframes required by applicable law.
Deletion may not be immediate in all systems. We may retain information where necessary to:
- provide the Service;
- complete transactions;
- comply with law;
- maintain security and prevent abuse;
- resolve disputes;
- enforce agreements;
- preserve backups until deletion cycles complete;
- retain billing, tax, credit, accounting, or legal records;
- retain and use Aggregated De-Identified Data.
If you use Coresource through an organization, some deletion requests may need to be directed to your organization administrator.
11. Security
We use reasonable technical and organizational safeguards designed to protect personal information. These safeguards vary based on the nature of the information, the feature, the environment, and operational needs.
No security measure is perfect. You are responsible for using appropriate security practices, including least-privilege access, repository hygiene, secret management, account security, and review of agent permissions.
12. International Processing
We may process and transfer personal information in the United States and other countries where we or our vendors operate. These countries may have data protection laws different from those in your jurisdiction.
Coresource is not currently offered in the European Union or European Economic Area, and we do not currently provide EU/EEA-specific transfer mechanisms unless expressly agreed in writing.
13. Your Privacy Rights
Depending on your location and applicable law, you may have rights to:
- access personal information;
- correct inaccurate personal information;
- delete personal information;
- receive a copy of personal information;
- opt out of certain sales, sharing, targeted advertising, or profiling, where applicable;
- limit certain uses or disclosures of sensitive personal information, where applicable;
- appeal a denied request, where applicable.
To exercise rights, contact us at legal@coresource.ai. We may need to verify your identity and authority before responding.
14. California Privacy Notice
This section applies to California residents where the California Consumer Privacy Act, as amended, applies.
Categories Collected. In the past 12 months, we may have collected the following categories of personal information:
- identifiers, such as name, email address, account identifiers, IP address, and OAuth identifiers;
- commercial information, such as credit purchases, invoices, billing status, and usage records;
- internet or network activity, such as login events, device information, usage logs, web requests, and security logs;
- professional or employment-related information, such as organization membership, role, team, or work repositories;
- inferences or usage analytics derived from use of the Service;
- sensitive personal information, if included in Customer Content, repositories, logs, or user instructions.
Purposes. We collect and use these categories for the purposes described in this Privacy Policy, including providing the Service, processing AI agent tasks, securing the Service, billing, support, compliance, product improvement, and generating Aggregated De-Identified Data.
Disclosure. We may disclose these categories to vendors and infrastructure providers, your organization, integrations you authorize, legal recipients, and business transaction recipients as described above.
Sale or Sharing. Coresource may make available Aggregated De-Identified Data as described in this Privacy Policy. Coresource does not intend Aggregated De-Identified Data to be personal information because it cannot reasonably be linked specifically to you or your organization. Coresource publicly commits to maintain and use Aggregated De-Identified Data in de-identified or aggregate form and not to attempt to reidentify it except to test whether its deidentification processes satisfy applicable requirements. Coresource requires recipients of Aggregated De-Identified Data to maintain it in de-identified or aggregate form and not attempt to reidentify it. Coresource does not sell personal information or share personal information for cross-context behavioral advertising unless we provide a specific notice and opt-out mechanism.
Sensitive Personal Information. We do not use sensitive personal information to infer characteristics about you. Sensitive information may be processed if you or your organization includes it in Customer Content or uses features that require it.
California Rights. California residents may have the right to know, access, correct, delete, receive information about certain disclosures, limit certain uses of sensitive personal information, and opt out of sale or sharing where applicable. You also have the right not to be discriminated against for exercising privacy rights.
Requests may be submitted to legal@coresource.ai. Authorized agents may submit requests where permitted by law, subject to verification.
15. Children
Coresource is not directed to children or minors under eighteen (18), and users must be at least eighteen (18) years old or the age of majority in their jurisdiction. We do not knowingly collect personal information from children under 13. If you believe a child or minor has provided personal information to us, contact us at legal@coresource.ai.
16. Separate Written Agreements
If you use Coresource under a separate signed written agreement with Coresource, that agreement may include additional or different terms governing confidentiality, retention, security, support, data handling, billing, deletion, or other matters. If there is a conflict between this Privacy Policy and that signed written agreement, the signed written agreement controls to the extent of the conflict.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If changes are material, we will provide notice as required by law or the applicable agreement. The updated Privacy Policy will be effective as of the date stated above.
18. Contact
Questions or requests about this Privacy Policy may be sent to:
coresourceai, Inc.
2261 Market Street STE 68771
San Francisco, CA 94114
Email: legal@coresource.ai