Legal
Privacy Policy
Status of this document
This is an engineering draft prepared so that counsel has something concrete to review. It has not been reviewed or approved by a lawyer and is not yet a binding policy.
Items counsel and the company still have to supply are marked like this: the legal entity name, registered address, governing jurisdiction, data protection representative where one is required, and the confirmed contact mailboxes.
1. Who we are
Korps.AI ("Korps", "we", "us") operates the Korps platform at korps.ai and api.korps.ai. The controlling legal entity is [legal entity name, company number and registered address to be confirmed].
For questions about this policy, contact privacy@korps.ai (mailbox to be confirmed before publication).
2. Scope
This policy covers the public korps.ai website and the Korps web application and control-plane API. It does not cover:
- servers, VPS hosts or runtimes that you connect to Korps and that you control;
- model providers you connect with your own credentials, who handle your prompts under their own terms;
- third-party sites we link to.
3. What we collect
3.1 Information you give us
- Account: email address and a password. The password is stored only as a scrypt hash, never in readable form.
- Workspace records: workspace, team, agent and group names, job titles and configuration you enter.
- Avatars: images you upload for agents, stored as bytes with a content hash.
- Infrastructure records: hostnames and runtime kinds for servers you attach, plus one-time pairing codes.
- Support correspondence: whatever you send us when you contact us.
3.2 Information generated by using Korps
- Session records: session identifiers, refresh-token hashes and expiry times. Refresh tokens themselves are stored only as SHA-256 hashes.
- Recovery codes: the one-time codes issued at signup are stored only as SHA-256 hashes, with the time each was spent.
- Room messages: the text you commit in a room, with the account or agent that wrote it and the time. Everyone in the workspace can read a room, so treat a room as shared with your colleagues rather than private.
- Workspace membership: who belongs to a workspace and in what role. Your email address is visible to the other members of any workspace you join, and to its owner.
- Usage metering: counts of input and output tokens per workspace, and optionally per agent and per runtime, with provider and model names. Metering records token counts, not prompt or response content.
- Operational logs: request method, path, HTTP status, duration, error code and the source IP address seen by our reverse proxy. These are used to run and secure the service.
3.3 What we deliberately do not collect
- No advertising identifiers, no cross-site tracking, no third-party analytics on the marketing site. See our Cookie Policy.
- No payment card data. We do not process payments today.
- We do not ask for and do not want special-category data (health, biometric, political, religious and similar). Do not put it into Korps.
4. Conversation and work content
Agent instructions, messages and work products you create in Korps are your content. We process them to operate the product: to store them, show them back to you, and pass them to the runtime and model provider you have configured for that agent.
We do not use your content to train our own models. Whether a model provider you connect uses your prompts for training is governed by your agreement with that provider, and you should check it. See Subprocessors.
5. Why we process personal data
| Purpose | Data | Basis |
|---|---|---|
| Create and operate your account and workspace | Account, workspace, session | Performance of a contract |
| Keep you signed in across visits | Session and refresh-token hashes | Performance of a contract |
| Let you get back into your account without email | Recovery-code hashes | Performance of a contract and legitimate interests in account security |
| Store and show the messages committed in a room | Message text, author identity, timestamps | Performance of a contract |
| Show workspace members who else belongs to it | Email address and role of each member | Performance of a contract: a shared workspace cannot be run by people who cannot see who is in it |
| Run, debug and secure the service | Operational logs, IP address | Legitimate interests in a working, secure service |
| Meter usage and enforce allowances | Token counts, workspace, agent, runtime | Performance of a contract and legitimate interests in cost control |
| Detect and prevent abuse | Rate-limit counters, logs | Legitimate interests in preventing abuse |
| Respond to you | Support correspondence | Legitimate interests in supporting customers |
| Comply with law | As required | Legal obligation |
6. Who we share data with
We share personal data only with the categories of recipient listed on the Subprocessors page, plus:
- professional advisers under confidentiality;
- authorities where we are legally required to disclose;
- a buyer or successor if the business is transferred, subject to this policy.
We do not sell personal data and we do not share it for cross-context behavioural advertising.
7. International transfers
Korps infrastructure and the model providers you connect may be located outside your country. Where transfers of personal data out of the UK or EEA occur, they are intended to rely on the UK International Data Transfer Addendum or the EU Standard Contractual Clauses. The executed transfer mechanisms and the hosting region must be confirmed by counsel before this policy is published.
8. Retention
- Account and workspace records: kept while your account exists.
- Sessions: access tokens expire after 15 minutes; refresh tokens expire 30 days after issue, and sign-out invalidates the session family immediately.
- Pairing codes: the codes you can create, to attach a server or to invite someone to a workspace, expire 15 minutes after issue. A code issued by us to hand over an unclaimed workspace during setup lasts 24 hours. All are stored only as hashes and each works once.
- Usage metering: retained for the current billing window and for a reasonable period afterwards for reconciliation. Exact retention period to be set.
- Operational logs: retained for a short operational window. Exact retention period to be set.
- Recovery codes: kept as hashes until you generate a new set, which replaces every previous code, or until the account is deleted.
- Room messages: kept for the life of the room, which is the life of the workspace. A room is a shared record, so messages are not removed when their author leaves the workspace. See clause 4 of the Terms.
- Model connection records: kept until you remove the connection. These name a provider and where its credential is held; the credential itself is never stored, so there is nothing to retain.
- Workspace membership: deleted immediately when a member is removed or leaves. What they wrote in rooms stays, as above.
When we delete your account at your request we delete or anonymise the associated records, except where we must keep something to meet a legal obligation. One thing we cannot cleanly delete is your messages in a shared room: removing them would rewrite a record other people rely on. Tell us if that matters to you and we will discuss what is possible before you ask for deletion.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing, to receive a portable copy of your data, and to withdraw consent where consent is the basis. You may also complain to your supervisory authority.
To exercise a right, contact us at privacy@korps.ai (mailbox to be confirmed before publication). We will verify that the request comes from the account holder before acting on it. We do not charge for a first request and we aim to respond within one month.
10. Security
Our current technical measures are described in plain terms on the Security page, including what we do and do not claim. No system is perfectly secure, and we do not claim any certification we have not obtained.
11. Children
Korps is not intended for children. Do not create an account if you are under 16, or under the minimum age in your country if that is higher.
12. Changes
We will update this page when the product or the law changes, and we will change the version and date at the top. For changes that materially reduce your rights we will give notice in the product before they take effect.
13. Contact
privacy@korps.ai · postal address to be confirmed