co|op is built around a simple principle: the sensitive data we help you protect should never touch our servers. Detection happens locally in the browser. This policy explains what we do and don't collect.
We do not collect, store, or transmit the actual sensitive content that the extension detects. When an employee types an SSN, credit card, or API key into an AI tool, that text is scanned in the browser and never sent to us.
We collect limited metadata needed to operate the Service:
We use the information we collect to provide the dashboard, scope incidents to your organization, send account-related emails, and improve the Service. We do not sell your data.
Every organization's data is isolated. Your incidents, team, and settings are scoped to your account and are never visible to other organizations.
We use trusted infrastructure providers to host the Service and send transactional email. These providers process data only as needed to operate co|op.
Incident metadata is retained according to your plan's history window. You may request deletion of your organization's data by contacting us.
You may access, correct, or request deletion of your organization's data at any time. Contact us to exercise these rights.
If you have any questions about this document, contact us at syphir26@gmail.com.