CoraPilot ("CoraPilot", "we", "us") provides a secure connector that lets AI clients you control (such as Claude or ChatGPT, over the Model Context Protocol) access services you connect — currently WhatsApp and Google Ads. This policy explains what we handle and why. If you don't agree with it, please don't use the service.
Information we collect
- Account details. Your name, email address, and a securely hashed password. Optional profile details you provide.
- Subscription & billing. Your plan, subscription status and renewal dates. Card payments are processed by Stripe; we do not see or store your full card number.
- WhatsApp data (only if you connect WhatsApp). Messages, contacts, group names and sender names that arrive while you're connected, so your AI can search and summarise them. We connect via a WhatsApp "linked device" (QR pairing).
- Google Ads data (only if you connect Google Ads). With your OAuth authorisation, we access your Google Ads accounts to read performance data and, only where you enable it, make changes you ask for. We store a Google refresh token and the connected Google account's email so the connection persists.
- Usage & audit logs. Records of key actions (sign-in, subscription changes, messages/changes made on your instruction) for security and support.
- Technical data. Basic connection metadata and server logs.
How we use your information
- To provide the connector and let the AI you authorise read and act on the services you connect.
- To operate accounts, subscriptions, trials and billing.
- To secure the service, prevent abuse, and provide support.
- To send service and lifecycle emails (welcome, trial reminders, connection alerts). We don't sell your data or use it for advertising.
What we don't do
- We don't store AI API keys. You connect your own Claude/ChatGPT — there's no model key for us to hold.
- We don't store plaintext passwords (hashed only) or full card details (handled by Stripe).
- We don't act without your instruction. Nothing is sent on WhatsApp and no Google Ads change is made unless you ask — there are no auto-replies, and Ads changes require you to enable them and confirm.
- We don't sell your personal data.
Google user data
CoraPilot's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We only request the Google Ads scope needed to read and (where you enable it) manage the ad accounts you connect; we use that data solely to provide features you request, we do not use it for advertising, and we do not transfer or sell it to third parties. You can revoke CoraPilot's access at any time in the portal or via your Google account permissions.
Sharing & subprocessors
We share data only with providers that help us run the service, under contract:
- Stripe — payment processing.
- SMTP2GO — transactional email delivery.
- A WhatsApp gateway — to maintain your linked-device WhatsApp connection.
- Google — the Google Ads API, when you connect Google Ads.
- Cloud hosting — to run the service.
We may also disclose information if required by law.
Data retention & deletion
- Disconnecting WhatsApp deletes the stored WhatsApp messages for a clean slate.
- Disconnecting Google removes the stored Google refresh token.
- A paused, unsubscribed account is deleted after 14 days (with reminders first).
- You can delete your account and data at any time, or email us to request deletion.
Security
Access uses OAuth 2.1 sign-in (the connector link alone grants no access), data is encrypted in transit, passwords are hashed, and sensitive actions are audit-logged. No system is perfectly secure, but we design to minimise risk.
Your rights
Depending on where you live, you may have rights to access, correct, export or delete your personal data, and to object to or restrict certain processing. To exercise them, contact us at the address below.
Cookies
The portal keeps your session token in your browser's local storage to keep you signed in. We don't use third-party advertising or cross-site tracking cookies.
Children
CoraPilot is not intended for anyone under 18, and we don't knowingly collect their data.
Changes
We may update this policy; we'll change the "last updated" date above and, for material changes, notify you.
Contact
Questions or requests: support@corapilot.com.
This policy is provided for transparency and is not legal advice.