1. Who we are
Corha is operated by Corha Technologies Ltd (“Corha”, “we”, “us”), a company registered in England and Wales under company number 17248901, with its registered office at Office 1, 1 Coldbath Square, London, England, EC1R 5HL. We provide an AI-native customer-understanding workspace that helps product, research, and customer teams turn calls, tickets, surveys, and other conversational data into living customer personas, evidence, and insights.
For the personal data we hold about our own account holders (your login and profile details, billing contact, and how you use the app), Corha is the data controller. For the customer data you upload into your workspace, Corha is your data processor (see section 9).
This policy explains what personal data we collect when you use the Corha service, how we use it, who we share it with, and the rights you have over it. If anything here is unclear, email us at info@corha.app.
2. The data we collect
2.1 Account data
When you create a Corha account we collect your email address and a password (which is hashed by our authentication provider, so we never see it in plaintext). We may also collect optional profile details if you choose to fill them in: full name, job title, phone number, location, timezone, and a short bio. We also store your notification preferences and the workspace you’re currently active in.
2.2 Workspace content you upload
Corha is designed to ingest evidence from the conversations your team has with your customers. Depending on which sources you connect or upload, this may include:
- Sales-call transcripts and metadata
- Customer-interview recordings, transcripts, and notes
- Support tickets and ticket comments
- Surveys, NPS responses, and other structured feedback
- Product or design documents you choose to share with the workspace
- CRM exports and similar tabular data
This content frequently contains personal data about your customers, not about you. Corha processes that data as your data processor (see section 9 below).
2.3 Live-call audio (stays on your device)
Corha’s Live Calls feature lets you record audio of customer calls directly in your browser. Those audio files are stored only in your browser’s local storage (IndexedDB). They are not uploaded to Corha’s servers. Only the metadata you choose to save (title, duration, your own notes) is synced to your Corha workspace. If you clear your browser data, the audio is gone.
2.4 AI-generated derivatives
From the content above, Corha generates personas, evidence summaries, insights, and answers to questions you ask the workspace agent. These derivatives are stored in your workspace and treated as your data.
2.5 Billing data
Paid plans are processed by Stripe. We pass your billing email to Stripe and store the Stripe customer and subscription identifiers Stripe returns to us. We do not store your card details. Card information is handled directly by Stripe under their PCI-DSS compliance.
2.6 Technical and usage data
We collect basic technical data necessary to operate the service: the IP address of requests to our servers, request timestamps, and error logs from our hosting provider. We do not use marketing pixels, third-party advertising trackers, or session-replay tools, and we do not set analytics cookies.
On our public marketing pages we measure aggregate traffic using our own first-party analytics (page views, time on page, the referring site, any campaign tags in the link, approximate location (country, region, and city), and device, browser, and operating system type). This is cookieless: we do not store tracking cookies or a persistent identifier on your device, we do not track you across other websites, and we do not retain your IP address (it is used only briefly to estimate your approximate location and to prevent abuse). Because this data is anonymous and does not identify you, it does not require a consent banner. For more on the cookies we do and don’t set, see our Cookie Policy.
Inside the product, once you are signed in, we record basic usage of the app (which pages and features you use, and how long) tied to your account and workspace. We use this only to operate, secure, and improve the service; we do not sell it or share it with advertisers. You can request a copy or deletion of this data as described in section 8.
3. How we use your data
We use the data described above to:
- Provide the Corha service: render your workspace, sync your data, and authenticate your sessions.
- Generate personas, evidence summaries, and insights from the content you’ve uploaded.
- Power the workspace agent that answers your questions about your data.
- Process payments and manage subscriptions through Stripe.
- Send essential service emails (sign-in confirmations, billing receipts, security notices). You can opt out of optional notifications in your profile settings.
- Detect and prevent abuse, fraud, or breaches of our terms.
- Comply with our legal obligations.
Where data-protection law requires a lawful basis for this processing, we rely on: performance of our contract with you (to provide the workspace, authenticate you, and process payments); our legitimate interests in operating, securing, and improving the service and preventing abuse; your consent where we ask for it (for example optional notifications); and compliance with legal obligations (for example keeping tax records).
Some of the content you upload, including images, PDFs, and other documents, is sent in full to our AI sub-processor (Anthropic) so it can be analysed, not just the text you type. See section 4 for who we share data with, and what each provider does with it.
We do not train AI models on your data. The AI features in Corha use third-party foundation models (see section 4) on a per-request basis; your content is not used to retrain those models beyond the duration of a single request.
4. Who we share data with (sub-processors)
To deliver Corha we rely on a small number of trusted service providers. We share only the data necessary for each one to do its job:
- Supabase: hosts our database and handles authentication. Your account and workspace data live here. EU region by default.
- Anthropic: provides the Claude models that power persona generation and the workspace agent. We send the specific workspace content needed to answer your request; Anthropic does not retain it to train their models under their commercial API terms.
- Stripe: processes payments and stores card data on your behalf. We receive billing status; Stripe receives the email and payment details you provide at checkout.
- Vercel: hosts the Corha application and serves it to your browser. Request metadata (IPs, timestamps, error logs) is processed here.
- Resend: delivers our transactional email, including sign-in verification codes, account and billing notices, and any notifications you opt in to. It receives the recipient address and the contents of that email.
- Sentry: collects error and performance diagnostics so we can find and fix faults. It receives technical data about failed requests (such as error messages, browser and device type, and limited request context). We configure it to avoid capturing the contents of your workspace where we can.
The current, canonical list of every sub-processor, what it does, the data it handles, and where it is located is kept on our Sub-processors page. We do not sell your data, and we do not share it with advertisers, data brokers, or third-party analytics providers.
5. Google user data (Gmail, Calendar, and Drive)
Connecting a Google account is optional and is never required to use Corha. If you do connect one, Corha’s use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. This section explains exactly what we access, why, and what we do with it.
5.1 What we access
We request the narrowest permission each feature can work with, and each integration is connected separately in workspace settings:
- Gmail, send only: permission to send messages from your address, so research outreach you write in Corha reaches participants from you rather than from a generic mailbox. We do not request any permission to read your mailbox, and Corha cannot open, search, or list your email.
- Google Calendar, read-only events: your upcoming events on your primary calendar, so Corha can show your customer calls on the Live Calls page and remind you when one is about to start. For each event we read the title, the start and end time, the attendee email addresses, and the video-meeting link. We skip all-day and cancelled events, and we cannot create, edit, or delete anything in your calendar.
- Google Drive, only the files you pick: Corha uses Google’s own file picker, and receives access to the individual files you select in it. Corha cannot browse your Drive, list its contents, or reach any file you have not explicitly chosen.
- Basic account identity: the email address of the Google account you connect, so we can label the connection in settings and send from the right address.
5.2 How we use it
Google user data is used only to provide the feature you connected it for. Calendar events populate your call schedule. Files you pick from Drive are imported as workspace data sources and analysed the same way as a file you upload by hand, which means the text they contain is used to generate evidence, personas, and insights inside your workspace. Gmail access is used solely to deliver messages you have written and chosen to send. We do not use Google user data for advertising, for profiling, or for any purpose you have not asked for.
5.3 How we store and share it
Google access and refresh tokens are encrypted before they are stored, and are held only for as long as the integration is connected. Content you import from Drive is stored in your workspace alongside your other data sources, in the location described in section 6 and for the periods described in section 7. Calendar event details are read when you view your schedule and are not retained beyond what is needed to display and annotate the event.
The only third party that receives Google user data is Anthropic, our AI sub-processor, and only where analysing an imported file requires it. That data is sent on a per-request basis to produce output for you, and Anthropic’s commercial API terms prohibit retaining it to train their models. We do not sell Google user data, and we do not share it with advertisers, data brokers, or analytics providers.
5.4 Limited Use commitment
Corha’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide or improve user-facing features that are prominent in the Corha interface.
- We do not transfer Google user data to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition, in which case we would give you notice first.
- We do not use or transfer Google user data for serving advertising of any kind.
- We do not allow humans to read Google user data unless we have your explicit permission (for example when you ask us to investigate a support issue), it is necessary for security purposes such as investigating abuse, we are required to by law, or the data has been aggregated and anonymised for internal operations.
- We do not use Google user data to develop, improve, or train generalised artificial-intelligence or machine-learning models. Where an imported file is processed by a foundation model to produce output for you, it is processed for that request only and is not retained for training.
5.5 Disconnecting and deleting
You can disconnect any Google integration at any time from Settings, which deletes the stored tokens immediately. You can also revoke Corha’s access directly from your Google account permissions page. Disconnecting stops all further access, but files you already imported remain in your workspace until you delete them there, in the same way as any other data source.
6. Where data is stored
Workspace data is stored in the EU (Ireland region) by default through Supabase. AI processing requests may be routed to Anthropic infrastructure in the United States. Stripe processes payments in the jurisdictions it operates in. Where personal data is transferred outside the UK or EEA, we rely on the UK International Data Transfer Addendum, the EU Standard Contractual Clauses, or equivalent safeguards. By using Corha you acknowledge the international transfers necessary to provide the service.
7. How long we keep data
We retain personal data only for as long as we need to:
- Account data: for as long as your account is open. If you delete your account, we remove personal data within 30 days, except where we need to keep limited records for legal, tax, or dispute-resolution purposes.
- Workspace content: kept while your workspace is active. Retention windows for calls, research, tickets, and evidence are configurable in workspace settings.
- Billing records: retained for the period required by applicable tax law (typically 6 years in the UK).
- Server logs: typically retained for up to 30 days for security and debugging.
8. Your rights
Where the UK GDPR or EU GDPR applies, you have rights to access, correct, delete, restrict processing of, and port your personal data, as well as to object to certain processing. You also have the right to lodge a complaint with a data-protection authority (in the UK, that’s the ICO).
To exercise any of these rights, email info@corha.app. We’ll respond within one month.
9. When Corha is a processor (not a controller)
For the customer data you upload to your workspace (call transcripts, tickets, survey responses, etc.), you are the controller and Corha is your processor. We process that data only on your documented instructions, under the terms of our Data Processing Agreement. Email info@corha.app for a counter-signed copy.
10. Security
All traffic to Corha is encrypted in transit (TLS). Workspace data is stored encrypted at rest by Supabase. Access to production systems is restricted and authenticated. We never have access to your password or your payment card. Live-call audio never leaves your device.
11. Children
Corha is a workplace tool and is not directed to children under 16. We do not knowingly collect personal data from anyone under 16.
12. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top reflects the most recent change. For material changes we will notify account holders by email or in-app.
13. Contact
Questions, requests, or complaints about this policy? info@corha.app.