Legal
What we collect, why, who it reaches, and what we do not do with it.
Draft, not yet reviewed by a lawyer
This document is published so its structure and facts can be checked. It has not been through legal review and should not be relied upon as a binding agreement until this banner is gone.
Last updated: 4 August 2026
This policy explains how Codas Labs, LLC(“Codas Labs,” “we,” “us”) handles information in connection with Tore (the “Service”), at tore.ai and the applications and help centers we host for our customers.
Codas Labs, LLC is a North Carolina limited liability company. We are the controller of information we collect about you directly: your account, your billing details, and how you use the Service. Contact: privacy@codaslabs.com.
For the information inside the content our customers put into Tore, meaning their support conversations, their customers’ details and their bug reports, we act as a processor and our customer is the controller. Our obligations in that role are in the data processing addendum.
If you are a member of the public who contacted a company that uses Tore, that company decides what happens to your information and is the right place to send a request. We will help them answer you, and we say below what we do if you write to us instead.
We have not yet appointed representatives in the United Kingdom or the European Union under Article 27 of the UK and EU GDPR, and we do not have a statutory Data Protection Officer. Neither is currently required of us. Where one becomes required, it will be appointed and named here.
When our customer uses Tore to run their support, we process the content of that support on their behalf. That includes conversations and the contact details of the people in them, knowledge-base articles, feedback posts and votes, error reports forwarded from their monitoring tools, and bug captures.
A bug capture can include a session replay, browser console output, a record of network requests, and details of the device, browser and release the reporter was on. It can also include a screenshot and, where the reporter explicitly agrees to it, a screen recording. This is the most sensitive thing the Service handles, so we describe the mechanism precisely rather than in reassuring generalities.
Redaction of this kind is pattern matching, and pattern matching is never complete. It will miss things. Customers should treat capture configuration, not our redaction, as the primary control, and can delete any capture at any time.
Where the UK or EU GDPR applies, we need a lawful basis for each use. Ours are:
| What we do | Basis |
|---|---|
| Create and run your account, and provide the Service | Performance of a contract |
| Support you and answer what you ask us | Performance of a contract, and legitimate interests |
| Take payment and keep financial records | Contract, and legal obligation |
| Keep the Service secure, prevent abuse and fraud | Legitimate interests |
| Keep audit records of security-relevant actions | Legitimate interests, and legal obligation |
| Improve the Service using aggregate usage patterns | Legitimate interests |
| Send product and marketing email to account holders | Legitimate interests, with a right to object at any time |
| Advertising and analytics cookies on our website | Consent, where consent is required |
| Answer privacy requests and verify who is asking | Legal obligation |
| Respond to legal demands and defend legal claims | Legal obligation, and legitimate interests |
| Process customer content, including sending it to AI models to triage, draft, summarize and investigate | On our customer’s documented instructions, as their processor |
We do not rely on vital interests or on the performance of a public task. We do not knowingly process special category data, and we do not ask for it.
Where we rely on legitimate interests, those interests are: running a secure and reliable service, preventing fraud and abuse, understanding which parts of the product work so we can fix the parts that do not, and protecting our legal position. We have weighed those against your rights in each case and do not believe our interests override them. You can object to any processing based on legitimate interests. Ask us for our balancing assessment at privacy@codaslabs.com and we will send it.
Where we rely on your consent, such as advertising and analytics cookies, you can withdraw it at any time and it is as easy to withdraw as it was to give. Withdrawing does not make anything we did beforehand unlawful, and it does not affect processing that rests on a different basis.
Tore sends content to AI models to triage conversations, draft replies, summarize errors and investigate code. The vendors we use are named in the subprocessor list.
We use those vendors through paid business interfaces under terms where your content is not used to train their models. We do not use free or consumer tiers, which generally do permit training. If a vendor changes its terms in a way that would allow training on customer content, we will move off that vendor or tell you before the change takes effect.
We do not use customer content to train models of our own, and we do not sell personal information or share it for cross-context behavioral advertising.
If you connect your own AI provider key, that work runs against your own account with that vendor, under your agreement with them rather than ours.
We do not make decisions about you by automated means that produce legal effects or similarly significant effects, and we do not profile you for that purpose. Article 22 of the UK and EU GDPR, and the equivalent US state provisions on profiling, are about decisions such as refusing credit, refusing employment, or cutting off access to a service. Tore does none of those things.
What the AI in Tore actually does, and what it does not:
The common thread is that a person approves every output that leaves the product. If we ever build a mode where that is not true, we will change this section and tell account holders before it is switched on, and any such mode would be something a customer opts into rather than something that appears by default.
You can still ask a human to look at anything an AI feature produced about you. Write to privacy@codaslabs.com.
We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not disclose customer content to anyone for their own purposes.
We are based in the United States and our providers are primarily in the United States. If you are in the United Kingdom, the European Economic Area or Switzerland, that means your information leaves your country. The mechanisms we rely on are:
Alongside those clauses we apply supplementary measures: encryption in transit and at rest, access limited to named staff, and a commitment to challenge any government access request that we believe is unlawful and to tell the affected customer where we are legally permitted to.
We are not certified under the EU to US Data Privacy Framework and we do not rely on it. The specific modules, options and annexes are set out in our data processing addendum, and you can ask us for a copy of the safeguards we rely on at privacy@codaslabs.com.
We keep information for as long as it is needed for the purpose it was collected for, and no longer, except where the law makes us keep it. The periods below are what the Service is built to do. Where a customer sets a shorter retention period for their own content, theirs wins.
| Category | How long |
|---|---|
| Account details | For as long as the account exists, then deleted with the account |
| Billing and financial records | Up to 7 years after the transaction, because tax and accounting law requires it |
| Customer content: conversations, knowledge-base articles, feedback, error reports | For as long as the customer’s account is active, subject to the retention settings they choose |
| Conversation activity records | Up to 400 days from the event |
| Bug captures and their recordings | Set by the customer, deletable by them at any time, and deleted with the account |
| Quarantined captures | Not served at all, and deleted on the same schedule as the capture they belong to |
| Sign-in sessions | Expire on their own, and the record is removed within 30 days |
| Technical exhaust: delivery records, inbound webhook and email events, diagnostics | 30 to 90 days depending on the record |
| Audit records | For the life of the account, and afterwards where we need them to show what happened. They cannot be edited or deleted in place |
| Marketing suppression list | Kept after you unsubscribe, because it is the record that stops us contacting you again |
When an account is closed we delete or irreversibly anonymize its content within 30 days, except where we are required to keep something longer. Deletion runs as a verified pass: it counts the rows and stored files that remain and does not report itself complete while any are left.
Backups are the honest exception. Deleted data can survive in database backups until the restore window it falls inside closes, because a backup cannot be edited without destroying its integrity. We do not restore a backup in order to bring deleted data back. The length of that window is set out in our data processing addendum.
Depending on where you live you may have the right to access a copy of your information, to correct it, to delete it, to restrict or object to how we use it, to receive it in a portable format, to withdraw consent, and to complain to a regulator. You will not be treated worse for exercising any of them.
Email privacy@codaslabs.com with the words “privacy request” and tell us what you want. We will verify who you are before we act, normally by confirming you control the email address on the account, and we will ask only for what is necessary to do that.
We respond within 30 days where the UK or EU GDPR applies and within 45 days where a US state law sets that period. If a request is complex we may extend once, by up to a further 60 days under the GDPR or 45 days under US state law, and we will tell you why before the first deadline passes. There is no charge unless a request is manifestly unfounded or excessive, and if we intend to charge or to refuse, we will say so and explain.
You may use an authorized agent. We may ask for proof of their authority and may still ask you to confirm your own identity.
If your request concerns content held by one of our customers, we pass it to them rather than acting on it ourselves. That content is theirs to control, we are only their processor for it, and acting unilaterally on their data is exactly what a processor must not do. We will tell you that we have passed it on, and we assist them in answering you.
If you live in a US state with a consumer privacy law, you have rights under it. Those states currently include California (CCPA as amended by the CPRA), Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island. The list keeps growing, so if your state has such a law and is not named here, we will still honor the rights it gives you. Those rights are to:
You have the right to appeal if we refuse a request. Virginia, Colorado, Connecticut, Texas, Montana, Oregon and several other states require us to offer this, and we offer it to everyone rather than checking your address first. If we turn a request down, email privacy@codaslabs.com with the words “privacy appeal” within a reasonable time. A different person than the one who made the original decision will review it, and we will reply in writing with our reasoning within 45 days. If we still refuse, we will give you a link or address for complaining to your state attorney general.
We do not sell personal information and we have not sold it in the preceding twelve months. Where you have agreed to advertising cookies on our website, our advertising providers may receive an identifier for your browser so we can show our own ads elsewhere. Some US state laws count that as sharing for cross-context behavioral advertising, so we disclose it plainly rather than argue about the definition. Opt out with the cookie link in our footer. This applies to our marketing website only, never to content inside the product.
We honor the Global Privacy Control signal where your browser sends one, and treat it as an opt-out of both analytics and advertising for that browser. No further action is needed from you.
Tell us first and we will try to put it right. You do not have to come to us first, and you can go straight to a regulator.
If you create an account, we will send you product news and occasional marketing email as well as the messages needed to run your account. Every marketing email carries a one-click unsubscribe, and we act on it immediately. You can also object at any time by writing to privacy@codaslabs.com. Transactional messages, meaning receipts, security alerts and service notices, are not marketing and continue regardless. We keep a record that you unsubscribed, because that record is what prevents us from emailing you again.
Information is encrypted in transit and at rest. Each customer organization’s data is isolated at the database level rather than by application code alone, which means the isolation does not depend on a developer remembering to apply a filter. Access by our staff is limited, logged, and granted only where needed to operate the Service or to help a customer who has asked for help. Our security page sets out what is enforced today, and what we do not claim.
We do not hold a SOC 2 report, an ISO 27001 certificate, or any other third-party security certification, and we have not signed a HIPAA business associate agreement. We would rather say that than let a reader assume otherwise. Tore is not an appropriate place for protected health information.
No system is perfectly secure. If you think you have found a vulnerability, or that an account has been compromised, write to security@codaslabs.com. We will not pursue you for reporting something in good faith.
A personal data breach means a security failure that leads to personal information being destroyed, lost, altered, disclosed or accessed without authorization. If one happens:
The full contractual version of this commitment, including the parts our customers can hold us to, is in the data processing addendum.
Tore is a business tool. It is not directed at children, it is not designed for them, and we do not knowingly collect information from anyone under 16.
We do not knowingly collect personal information from a child under 13 in the United States, which is the threshold the Children’s Online Privacy Protection Act uses, and we do not run age verification because we do not offer the Service to children in the first place. We do not sell or share the personal information of anyone under 16, which some US state laws would require opt-in consent for. We do not use anyone’s information to advertise to children.
A member of the public can, of course, contact a company that uses Tore, and that company controls whatever they say. If you are a parent or guardian and you believe a child has given us information, write to privacy@codaslabs.com. We will delete it, and where the information sits inside a customer’s account we will tell that customer so they can do the same.
We will change this policy as the product changes. When we do, we update the date at the top of the page and keep the previous version available on request.
For a material change, we will tell account holders by email or in the product at least 30 days before it takes effect. A material change means one that widens what we collect, what we use it for, or who we give it to. If the change requires your consent, we will ask for it rather than assume it, and the new use will not start until you agree. If you do not want to accept a material change, you can close your account before it takes effect and ask us to delete your data.
Minor changes, such as fixing a typo, clarifying wording or updating a contact address, take effect when posted. We will not use a minor edit to slip in a material one.
Codas Labs, LLC, North Carolina, United States.
Privacy and data rights: privacy@codaslabs.com
Legal: legal@codaslabs.com
Security reports: security@codaslabs.com
Abuse: abuse@codaslabs.com