KORPS.AI Sign in

Legal

Privacy Policy

Version 0.1 · Drafted August 28, 2026 · Draft for attorney review, not yet in force

Status of this document

This is an engineering draft prepared so that counsel has something concrete to review. It has not been reviewed or approved by a lawyer and is not yet a binding policy.

Items counsel and the company still have to supply are marked like this: the legal entity name, registered address, governing jurisdiction, data protection representative where one is required, and the confirmed contact mailboxes.

1. Who we are

Korps.AI ("Korps", "we", "us") operates the Korps platform at korps.ai and api.korps.ai. The controlling legal entity is [legal entity name, company number and registered address to be confirmed].

For questions about this policy, contact privacy@korps.ai (mailbox to be confirmed before publication).

2. Scope

This policy covers the public korps.ai website and the Korps web application and control-plane API. It does not cover:

3. What we collect

3.1 Information you give us

3.2 Information generated by using Korps

3.3 What we deliberately do not collect

4. Conversation and work content

Agent instructions, messages and work products you create in Korps are your content. We process them to operate the product: to store them, show them back to you, and pass them to the runtime and model provider you have configured for that agent.

We do not use your content to train our own models. Whether a model provider you connect uses your prompts for training is governed by your agreement with that provider, and you should check it. See Subprocessors.

5. Why we process personal data

Purpose and legal basis under UK/EU GDPR terminology. Equivalent bases apply in other jurisdictions.
PurposeDataBasis
Create and operate your account and workspaceAccount, workspace, sessionPerformance of a contract
Keep you signed in across visitsSession and refresh-token hashesPerformance of a contract
Let you get back into your account without emailRecovery-code hashesPerformance of a contract and legitimate interests in account security
Store and show the messages committed in a roomMessage text, author identity, timestampsPerformance of a contract
Show workspace members who else belongs to itEmail address and role of each memberPerformance of a contract: a shared workspace cannot be run by people who cannot see who is in it
Run, debug and secure the serviceOperational logs, IP addressLegitimate interests in a working, secure service
Meter usage and enforce allowancesToken counts, workspace, agent, runtimePerformance of a contract and legitimate interests in cost control
Detect and prevent abuseRate-limit counters, logsLegitimate interests in preventing abuse
Respond to youSupport correspondenceLegitimate interests in supporting customers
Comply with lawAs requiredLegal obligation

6. Who we share data with

We share personal data only with the categories of recipient listed on the Subprocessors page, plus:

We do not sell personal data and we do not share it for cross-context behavioural advertising.

7. International transfers

Korps infrastructure and the model providers you connect may be located outside your country. Where transfers of personal data out of the UK or EEA occur, they are intended to rely on the UK International Data Transfer Addendum or the EU Standard Contractual Clauses. The executed transfer mechanisms and the hosting region must be confirmed by counsel before this policy is published.

8. Retention

When we delete your account at your request we delete or anonymise the associated records, except where we must keep something to meet a legal obligation. One thing we cannot cleanly delete is your messages in a shared room: removing them would rewrite a record other people rely on. Tell us if that matters to you and we will discuss what is possible before you ask for deletion.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing, to receive a portable copy of your data, and to withdraw consent where consent is the basis. You may also complain to your supervisory authority.

To exercise a right, contact us at privacy@korps.ai (mailbox to be confirmed before publication). We will verify that the request comes from the account holder before acting on it. We do not charge for a first request and we aim to respond within one month.

10. Security

Our current technical measures are described in plain terms on the Security page, including what we do and do not claim. No system is perfectly secure, and we do not claim any certification we have not obtained.

11. Children

Korps is not intended for children. Do not create an account if you are under 16, or under the minimum age in your country if that is higher.

12. Changes

We will update this page when the product or the law changes, and we will change the version and date at the top. For changes that materially reduce your rights we will give notice in the product before they take effect.

13. Contact

privacy@korps.ai · postal address to be confirmed