Coreworks AI Inc. ("Coreworks", "we", "our", or "us") respects your privacy and is committed to protecting your information. This Privacy Policy explains how we collect, use, and safeguard your information when you visit our website or use our services.
1. Information We Collect
We may collect the following types of information:
Information you provide
- Name, email address, company, job title
- Any information you submit through forms, sign-ups, or communications
Usage data
- IP address, browser type, device information
- Pages visited, time spent, and interactions on our site
Connected data sources (if applicable)
- If you connect third-party tools (such as CRM, billing, or analytics systems), we may access data necessary to provide our services
2. How We Use Information
We use your information to:
- Provide and improve our products and services
- Communicate with you about updates, access, and support
- Personalize your experience
- Analyze usage and improve performance
- Comply with legal obligations
3. Data Sharing
We do not sell your personal data.
We may share information with:
- Trusted service providers (e.g., hosting, analytics, communications tools)
- Legal authorities if required by law
4. Data from Connected Systems
If you choose to connect external systems:
- We only access data required to generate outputs
- Your data is not used to train shared AI models
- Data remains associated with your account and use
5. Google User Data
Coreworks connects to Google services only when you explicitly choose to connect one, and only after you grant access through Google's own OAuth consent screen. This section describes how we access, use, store, and share Google user data.
Scopes we request and why
- Google Drive (drive.file) — read only the individual files you select yourself in the Google file picker. We cannot see any other file in your Drive.
- Google Analytics (analytics.readonly) — read-only access to list the GA4 properties you have access to and run the reports you choose. We cannot modify your Analytics configuration.
- Google Ads (adwords) — read the report data for the Google Ads accounts you select. Google publishes no read-only Ads scope, so this is the narrowest scope available; we only issue read requests.
- BigQuery (bigquery) — list the projects, datasets, and tables you have access to, and run the read-only queries you write. We do not create, modify, or delete your data. Google's narrower bigquery.readonly scope cannot run a query at all, so this is the minimum scope that works.
- Email address (userinfo.email) — identify which Google account a connection belongs to, so you can tell your connections apart and disconnect the right one.
How we use Google user data
- We fetch only the data you request, at the time you request it, to produce the spreadsheets, reports, and presentations you ask for
- Imported data lands only in your own Coreworks workspace and is visible only to you and the people you share that workspace with
- We use it for no other purpose — no cross-user analysis, no aggregation, no enrichment
How we store Google user data
- OAuth tokens are held encrypted by our authentication provider and are used only to make the API calls described above
- Imported data is stored encrypted in your workspace and is retained until you delete it or close your account
- Deleting an imported file, or disconnecting the source, removes the corresponding data from your workspace
What we never do
- We never sell Google user data
- We never use Google user data for advertising, or transfer it to advertising platforms, data brokers, or information resellers
- We never use Google user data to train, retrain, or improve generalized or shared AI/ML models
- We never allow humans to read Google user data, except with your explicit consent for a specific support request, where required by law, or where necessary for security or to comply with applicable law
Limited Use
Coreworks' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Revoking access
You can disconnect a Google source at any time from the connections area of the Coreworks app, which deletes the stored token. You can also revoke Coreworks' access directly from your Google account at myaccount.google.com/permissions. To have imported data deleted, contact us at privacy@coreworks.ai.
6. Data Retention
We retain your information only as long as necessary to provide our services and comply with legal obligations.
7. Your Rights
You may request to:
- Access, update, or delete your personal information
- Opt out of communications at any time
To make a request, contact us at: privacy@coreworks.ai
8. Cookies and Tracking
We use cookies and similar technologies to:
- Understand website usage
- Improve performance and user experience
You can control cookies through your browser settings.
9. Data Security
We implement reasonable technical and organizational measures to protect your information.
10. Third-Party Links
Our website may contain links to third-party sites. We are not responsible for their privacy practices.
11. Updates to This Policy
We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised effective date.
12. Contact Us
If you have questions about this Privacy Policy, please contact us at:
Coreworks AI Inc.
Email: privacy@coreworks.ai