Privacy
Effective 15 August 2026
This describes what Coeleste collects while you use the product. It is not a HIPAA Notice of Privacy Practices. We are not your Business Associate in this version.
What we collect
Account data: name, email, workspace name. Usage: sign-ins, pages opened, MCP calls, audit of what was queried. Connected-system data: the records you authorize us to sync. Transcripts, notes, and source dumps are stored encrypted at rest. Identifiers, dates, and amounts used for dashboards remain typed columns. Mail bodies in structured mode are still stripped.
Platform packet requests: we collect your name, email, the requested packet version, and request dates to provide the download and keep a record of the request. Downloading the packet does not enroll you in the early-access waitlist or send you email. You can ask us to delete your request using the contact below.
Who sees it
People you invite to the workspace. The running product decrypts bodies to serve dashboards, sync, and answers-- that is the pipeline, not a standing human console. Subprocessors that have to run the product: authentication (Clerk), hosting and database (when we are hosted), transactional email for invites and sign-in codes. We do not send your documents to an embedding or LLM vendor. We do not sell your data. We do not use customer records to train public models.
Retention
We keep workspace data until you delete the workspace or a record is removed at the source and a later sync drops it. Backups lag deletes. Ask and we will delete a workspace and confirm when it is gone from backups.
Health information
Do not send us patient health information. If it gets in, tell us and we will delete it. Connecting a mailbox or a ticket system that contains that material is how it gets in.
Contact
Privacy questions: the owner of this instance (the operator who invited you, or [email protected] for the dogfood host).
