Privacy policy
This policy explains how Coherence Limited (“Coherence”, “we”) handles personal data when you visit coherenceltd.com, use the Coherence workspace at app.coherenceltd.com and its tools, or appear in data our tools process. We are a company registered in the Republic of Cyprus (HE 490848), with registered office at 195 Arch. Makariou III, 3030 Limassol, Cyprus.
Contact for privacy questions and requests: office@coherenceltd.com. We have not appointed a data protection officer because the law does not require one for our processing; the email above reaches the person responsible.
1. Our role
- Controller. We decide how and why personal data is used for: accounts and sign-in, workspace membership, billing, security, usage records, our own knowledge databases, and communications with you.
- Processor. When a business uses our tools on its own data, for example briefs it writes, questions it asks, or the mailboxes and bank account it connects, we process that data on the business's behalf under our Data Processing Addendum. That business is the controller. If your data is in someone's workspace, for example because you emailed them a receipt, please contact that business first; we will help them respond.
2. What we collect and why
| Data | Where it comes from | Why we use it | Legal basis (GDPR Art. 6) |
|---|---|---|---|
| Account data: email address, name, workspaces you belong to, your role | You, or a colleague who invites you | Create your account, sign you in, run your workspace | Contract (6(1)(b)) |
| Sign-in and security records: sign-in times, IP address, browser, actions in your workspace's activity history | Your use of the Service | Keep accounts and the Service secure, investigate misuse | Legitimate interests in security (6(1)(f)) |
| Acceptance records: which terms you accepted, when, from which IP address and browser | Your acceptance | Prove what was agreed | Legal obligation and legitimate interests (6(1)(c), (f)) |
| Billing data: company name, billing contact, address, tax ID, subscription and invoice history | You and Stripe | Charge fees, issue invoices, meet tax and accounting law | Contract and legal obligation (6(1)(b), (c)) |
| Usage records: which tools your workspace used and how much | Your use of the Service | Apply plan allowances, bill, keep tax and audit records | Contract and legal obligation (6(1)(b), (c)) |
| Work you create: briefs, product facts, questions to Seller Advisor, settings | You | Provide the tools | We process it for your business (see Section 1) |
| Connected Google accounts: the account's email address and, for tools that need mail access, emails that match receipt and invoice searches, their attachments and message details (sender, subject, date) | Google, when a workspace owner or admin connects the account | Find receipts and invoices, match them to expenses, send them to your bank on your instruction | We process it for your business (see Section 1) |
| Connected Revolut Business accounts (read-only): expenses, merchants, amounts, dates, receipt status | Revolut, when a workspace owner or admin connects the account | Match receipts to expenses | We process it for your business (see Section 1) |
| Support emails: what you tell us | You | Answer you | Legitimate interests (6(1)(f)) or contract |
| Public creator and video data: public TikTok usernames, video titles, links and performance figures | Public TikTok pages and third-party data providers such as FastMoss | Build the research and ContentIQ databases behind Creator Briefs and ContentIQ | Legitimate interests in providing market research to sellers (6(1)(f)) |
| Website visits to coherenceltd.com: IP address, browser, pages requested | Your browser, via our hosting provider | Deliver and secure the website | Legitimate interests (6(1)(f)) |
You need to give us your email address to have an account. Billing details are needed to buy a licence. Everything else depends on which tools your workspace uses.
Legitimate interests. Where we rely on legitimate interests, they are keeping the Service secure, proving what was agreed, answering people who contact us, and offering sellers research built from public information. We keep public creator data to what is visible on the platform, do not contact creators through it, do not combine it with other personal data, and you can object at any time (Section 8).
No selling, no advertising. We do not sell personal data, do not share it for cross-context behavioural advertising, and do not use it for advertising.
Emails. We send sign-in codes, service messages and billing notices. If we ever send product news to customers, each email will include a way to unsubscribe.
3. Google user data
Coherence's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We request Gmail read access to find receipts and invoices, and Gmail send access only to send receipts to your own Revolut Business receipts address when you allow it.
- We use Gmail data only to provide features you can see in your workspace: finding receipts and invoices, reading their totals, matching them to your bank expenses and sending them to your bank on your instruction.
- To read and classify a document, we send its content to an AI model through Vercel's AI Gateway with zero data retention: the model provider processes it only to return the result and does not keep it or train on it.
- We do not transfer Gmail data to others except as needed to provide those features, for security, to comply with law, or as part of a merger or acquisition with notice to you.
- We do not use Gmail data for advertising, and never sell it.
- No person at Coherence reads your email unless you ask us to (for example for support), it is needed for security, or the law requires it.
- We do not use Gmail data to develop, improve or train generalised AI or machine-learning models.
If your business connects its own systems or AI assistants through our API or MCP server, receipt documents and email details from Gmail are shared with them only under a scope a workspace owner or admin enables for that key, after being told the data will leave Coherence. We require API users to follow the Limited Use requirements for that data.
You can withdraw Google access at any time under Connections in your workspace, or at myaccount.google.com/permissions. Withdrawing deletes our access token immediately.
4. AI processing
Several tools use AI models to draft briefs, answer questions and read documents. These requests go through Vercel's AI Gateway to model providers (currently Google, OpenAI and TypeSafe) with zero data retention: the providers do not keep the content or use it for training. We do not make decisions about you based solely on automated processing that have legal or similarly significant effects on you.
5. Who receives personal data
We share personal data only with providers that process it for us under contract, listed on our Subprocessors page:
- Supabase: database, file storage and sign-in, in the United States (Virginia).
- Vercel: hosting of the website and application (United States) and the AI Gateway.
- AI model providers reached through the AI Gateway (currently Google, OpenAI and TypeSafe), with zero data retention.
- Stripe: payments, invoicing and tax calculation. Stripe also acts as a controller for its own fraud-prevention and legal duties.
- Resend: sign-in and service emails, sent from its European Union region (Ireland).
- Google Workspace: our own email, when you write to us.
Systems your business connects. When your business uses our API or MCP server, for example to connect an AI assistant, we send the data its keys request to the systems it chose. Those systems are chosen and controlled by your business, not by us, and are not our subprocessors.
We also disclose data where the law requires it, to protect rights and safety, or to a buyer of our business, who would have to respect this policy.
6. International transfers
Your data is stored and processed in the United States: our database (Supabase) and application servers (Vercel) are in Virginia, and several other providers above are based there. This is a transfer outside the European Economic Area. We protect it with the EU–US Data Privacy Framework where the provider is certified (Vercel, Stripe and Resend are) and with the European Commission's Standard Contractual Clauses in every case (Supabase relies on these). You can ask us for a copy of the relevant safeguards at office@coherenceltd.com.
7. How long we keep data
| Data | How long |
|---|---|
| Account and workspace data, work you create | While the workspace is active. After it is closed, we delete it within 90 days. |
| Connected-account access tokens | Deleted immediately when the account is disconnected. |
| Documents collected by a tool (for example receipts) | Until you delete them, or the workspace owner asks us to, or the workspace is closed. |
| Sign-in and activity records | While your account exists, then deleted with it; hosting-provider request logs are kept only for the provider's short log period. |
| Billing, usage and acceptance records | Seven years after the end of the year they relate to, to meet Cyprus tax, accounting and audit obligations. |
| Support emails | Up to 24 months after the conversation ends. |
| Public creator and video data | While it is relevant to current research, and no longer than 24 months after we last collected it. |
8. Your rights
Under the GDPR (and similar laws where you live) you can ask us to:
- give you a copy of your personal data (access);
- correct it (rectification);
- delete it (erasure);
- limit how we use it (restriction);
- give it to you or another provider in a machine-readable format (portability);
- stop using it where we rely on legitimate interests, and always for direct marketing (objection).
Where we rely on consent, you can withdraw it at any time without affecting earlier processing. Email office@coherenceltd.com. We reply within one month, and may need to confirm your identity. We do not charge for requests unless they are clearly unfounded or excessive. We honour these rights for everyone, wherever they live; if you are a California or other US state resident, this includes the right to know, delete and correct, and we do not sell or share your personal information or use sensitive personal information to infer characteristics.
Complaints. You can complain to the Cyprus supervisory authority: the Office of the Commissioner for Personal Data Protection, 15 Kypranoros Street, 1061 Nicosia (P.O. Box 23378, 1682 Nicosia), Cyprus; telephone +357 22818456; commissioner@dataprotection.gov.cy; gov.cy/dataprotection. You can also complain to the authority where you live or work. We would appreciate the chance to help first.
9. Security
Access tokens and keys for connected accounts are encrypted (AES-256-GCM) before storage and cannot be read through the application's data interface. Each workspace's data is separated at the database level, API keys are stored only as hashes, and financial tools are limited to workspace owners and admins. Connections use TLS encryption. If a breach puts your rights at risk, we will tell you and the authority as the law requires.
10. Cookies
We use only cookies that are strictly necessary to sign you in and remember your workspace, and browser storage for display preferences. We do not use analytics, advertising or tracking cookies. See Cookies.
11. Children
The Service is for businesses and is not directed at anyone under 18. We do not knowingly collect data from children.
12. Changes
We will update this page when our practices change and show the date of the latest version above. If a change materially affects how we use your data, we will tell account holders by email before it takes effect.