1. Who we are
Cofleet AB (org. nr. 559594-0965), Stockholm, Sweden is the controller for the personal data described in this policy. You can reach us about anything on this page at markus@cofleet.dev.
Cofleet is a product development platform. A team sets direction on a shared board, AI agents build against it, and the team reviews the result. To do that, Cofleet reads from the tools a team already works in.
2. Two different roles, and why it matters
When you visit our website or sign up, we decide what to collect and why. We are the controller, and this policy governs.
When your team connects a source and Cofleet ingests its content, your organisation decides what to bring in and why. Your organisation is the controller and we act as a processor on its instructions. Our data processing agreement governs that relationship, and this policy describes it only so you can see what actually happens to the data.
That distinction matters because connected sources carry other people's personal data. A Slack channel, a meeting transcript, a pull request thread or a support ticket contains the words of people who never signed up for Cofleet. Your organisation is responsible for having a lawful basis to bring that content in and for telling those people. We give you the controls; we cannot make that decision for you.
3. What we collect
Account data. What you give us to have an account.
- Your name, email address and Google account identifier. Sign-in is through Google, so we never see or store a password. Google learns that you signed in to Cofleet and acts as its own controller for that; its own privacy policy governs it.
- The workspace and organisation you belong to, and your role in it
- Invite codes and the account that invited you
- Your email preferences, which in practice means a record of whether you have unsubscribed from our product email. We keep that record precisely so the unsubscribe keeps working.
Workspace content. What your team brings into Cofleet, either directly or through a connected source.
- Boards, directions, notes, comments and uploaded files
- Messages, threads and channel content from connected chat tools
- Meeting transcripts and summaries from connected meeting tools
- Repository content, pull requests, issues and commit history from connected code hosts
- Design files, tickets, support conversations and survey responses from other connected tools
- Access tokens for those connections, encrypted at rest
Usage data. How the product is used, so we can tell what is working.
Our servers separately record which features ran for your account: identifiers and counts, no cookies involved. Our servers send three kinds of telemetry to PostHog's EU cloud (eu.i.posthog.com):
- AI call metadata: account id, workspace id, run id, model name, token counts and latency. This describes the model call, never the question, answer or memory content.
- Product usage events: an account being created or approved, a workspace being joined, a source being added, a chat turn being asked, an invite being sent, a question being answered or an integration being connected. Events carry the account id and workspace id where applicable, timestamps, fixed category labels and yes-or-no values. Source labels distinguish a shortcut, the composer, the web app, a file, Drive, SharePoint, MCP, chat, onboarding or a question answer. They do not contain the source itself.
- Daily model-cost totals per workspace: the day's spend in USD, split between generation and embeddings, the month-to-date spend, attempt count and input and output token totals. These use the same figures as the admin console and are tied to the workspace and day, not to an individual account.
These events contain no message text, memory content, names, email addresses, URLs or window titles. Account-linked events are still personal data because we can connect the account id to you. There is no browser analytics SDK, analytics cookie, session replay or analytics consent banner. Organizations can opt out of PostHog telemetry by contacting us. This covers product usage events, AI call metadata and daily model-cost totals. There is no per-user switch; we rely on the legitimate interests described in section 4. You can object on grounds relating to your situation as explained in Your rights.
We also collect:
- Product feedback you choose to send: your message, the page you were on, the pages you visited just before, and any error your browser reported. The report goes directly to Cofleet and is not shared with a subprocessor.
- Server logs: IP address, user agent, requested path, timestamp and response status. These are security and reliability records, not analytics.
Demo requests and waitlist data. When you submit your email from this website, we keep your address, whether you expressed design-partner interest, the date you asked, and the date we invited you if we have. We use this information to respond to your request. The current forms ask only for your email; we may also hold company-size selections and descriptions of needs previously submitted through our questionnaire. Submitting also subscribes you to occasional product updates, as explained next to the submit button, and we keep a record of when you joined and when you stopped. Unsubscribing removes your address and any questionnaire answers and takes you off the waitlist entirely: no updates, and no invitation. We collect nothing about how you browsed the site, and keep this information separately from any account you later create.
Correspondence. Anything you send us by email, and our replies.
We do not ask for special category data (health, biometrics, political opinions and the rest), we do not sell personal data, and we do not run advertising or profiling for advertisers.
4. Why we use it, and our legal basis
| What we do | Legal basis | GDPR article |
|---|---|---|
| Run your account, your workspace and the features you use | Performance of a contract | 6(1)(b) |
| Send service messages about your account, security or availability | Performance of a contract | 6(1)(b) |
| Keep the service secure: rate limiting, abuse detection, audit and server logs | Legitimate interests: keeping the service safe | 6(1)(f) |
| Hold your address on the waitlist, confirm that we have it, and tell you when a place opens up | Your request: you asked to be told | 6(1)(b) |
| Send product updates to a waitlist address: what we shipped and what is coming | Consent: the line under the form says joining sends them, and you can withdraw in one press from any mail we send | 6(1)(a) |
| Diagnose faults and improve reliability | Legitimate interests: a reliable service | 6(1)(f) |
| Server-side product usage events, AI call metadata and daily model-cost totals per workspace, as described in section 3. Identifiers, fixed categories, timestamps, yes-or-no values, counts, timings and USD totals, with no message text or memory content | Legitimate interests: understanding feature use, reliability and the cost of running the service. Uses nothing stored on your device; you can object on grounds relating to your situation | 6(1)(f) |
| Act on product feedback you choose to send | Legitimate interests: acting on a report you chose to send | 6(1)(f) |
| Answer your emails and respond to demo requests | Legitimate interests: replying to you and preparing the conversation you requested | 6(1)(f) |
| Send you product email: release notes, what we are building, and occasional news about Cofleet | Legitimate interests: telling our own business users about our own service. Object at any time, and every message carries an unsubscribe link | 6(1)(f) |
| Meet accounting, tax and other legal duties | Legal obligation | 6(1)(c) |
Where we rely on legitimate interests we have weighed them against your rights and concluded they do not override yours. Ask us and we will share that assessment.
5. Automated processing and AI models
Cofleet sends workspace content to a large language model so it can summarise context, draft direction and produce code. That model is Google's Gemini, served through Vertex AI on the same cloud our service runs on, under terms that forbid Google training models on your content. We do not train models on it either.
If we ever offer a model from another provider, the trust page will name it and where it processes before any content goes there.
None of this processing produces a decision with a legal or similarly significant effect on a person, so Art. 22 does not apply. Model output is a draft for your team to review, never an automatic decision about anyone.
7. Where it is stored
Your account data and workspace content are stored in the European Union.
Two things can leave it. Our edge provider terminates TLS on a global network, so request metadata may be handled outside the EU. And calls to the Gemini model may run on Google infrastructure outside the EU, under our agreement with Google Cloud and its standard contractual clauses. Ask us at markus@cofleet.dev for a copy of any of these.
8. How long we keep it
| Data | Kept for |
|---|---|
| Account data | As long as the account exists, then 30 days before deletion |
| Workspace content, including ingested source content | As long as the workspace exists, then 30 days before deletion |
| Product feedback | As long as the account exists, then 30 days before deletion |
| Integration access tokens | Deleted when the integration is disconnected |
| Demo request, design-partner interest or waitlist entry (email address, signup type, any historical questionnaire answers and dates) | Until the beta opens to everyone, or until you ask us to remove it, whichever comes first |
| Session records | 30 days, then expired and swept |
| Server logs | 90 days |
| Server-side product usage events, AI call metadata and daily workspace model-cost totals in PostHog | 12 months |
| A record of subscribing to, or stopping, product updates | Kept indefinitely: it is how we can show you asked, and how we remember that you stopped. Forgetting it would start the email again |
| Invoices and accounting records | 7 years, as Swedish bookkeeping law requires |
The 30 day window is a grace period against accidental deletion. Ask us and we will purge immediately instead.
9. Your rights
Under the GDPR you can ask us to:
- Tell you what we hold about you, and give you a copy
- Correct anything inaccurate
- Delete it, where we have no overriding reason to keep it
- Restrict how we use it while a dispute is resolved
- Export it in a portable, machine readable format
- Stop processing based on legitimate interests, on grounds relating to your situation
- Stop sending you product email, at any time and without giving a reason. Unlike the line above, this one is absolute: Art. 21(2) leaves us nothing to weigh against it, so there is no balancing to do and no case we can make for carrying on
- Withdraw consent, at any time, without affecting what happened before
Write to markus@cofleet.dev. We answer within one month and will not charge you for it. If your data reached us through your employer's workspace, we will point you at them, because they decide, but we will help either way.
If we get it wrong you can complain to your local data protection authority. Ours is Integritetsskyddsmyndigheten (IMY), at https://www.imy.se.
10. How we protect it
The measures we take are described on the trust page. No system is perfectly secure, but if a breach is likely to put your rights at risk we will notify the supervisory authority within 72 hours and tell you without undue delay.
11. Children
Cofleet is a tool for workplaces and is not directed at children. We do not knowingly collect data from anyone under 16. Tell us if you think we have, and we will delete it.
12. Changes to this policy
We will update this page when the way we handle data changes, and move the date at the top. If a change is significant we will tell account holders by email before it takes effect.