coralswarm← Back to coralswarm.com
legal

Privacy Policy

Last updated: August 1, 2026

This Privacy Policy explains how CoralSwarm ("CoralSwarm," "we," "us") collects, uses, and shares information when you use the CoralSwarm service — our desktop app, web app, the CoralSwarm plugin and MCP integration for Claude Code, our connectors to third-party workplace tools, and this website, coralswarm.com (together, the "Service"). It applies whether you're a waitlisted visitor, a signed-up user, or a member of an organization using CoralSwarm.

CoralSwarm is currently a pre-release product. This policy describes how the product behaves today; as features change we'll update it and the "Last updated" date above.

Information we collect

Account and waitlist information

When you join the waitlist or contact us through this site, we collect the name and work email you provide, any free-text message you send us, your approximate location (a country code derived from your IP address at the time of submission — we do not store the raw IP address), and first-touch attribution data your browser captures when you land on the site (the referring page and any UTM campaign parameters).

If you create a CoralSwarm account, our authentication provider, Clerk, manages sign-in and we receive the name and email address associated with your account.

Content you capture

CoralSwarm's purpose is turning your team's day-to-day work into searchable, answerable knowledge. Depending on which features you use, this includes:

  • Meeting recordings and transcripts — captured when you or someone on your team starts a recording in the CoralSwarm desktop app. Recording is always user-initiated; CoralSwarm does not silently record meetings.
  • Coding-session summaries — captured by the CoralSwarm plugin and MCP integration for Claude Code, generated from your coding sessions in that tool.
  • Content from workplace tools you connect — see "Connectors" below.

We refer to all of the above as "Captured Content." Captured Content is processed to extract discrete facts, decisions, and references ("atoms"), grouped into topics, and made searchable and answerable within your account or organization.

Connectors (third-party integrations)

Connectors only ingest content for an account or workspace that has explicitly authorized them through the provider's own OAuth consent screen. Today's connectors, and exactly what each one accesses:

  • Slack — once a workspace installs the CoralSwarm Slack app, we hold a workspace-level bot token (not a token per individual member) and can read messages and huddle transcripts in the channels CoralSwarm is invited to.
  • Microsoft — with your delegated authorization, we access Outlook mail and calendar, and Teams channels, chats, and meetings you or a Teams admin authorize, using Microsoft Graph scopes limited to Mail.Read, Calendars.Read, offline_access, openid, profile, User.Read, Team.ReadBasic.All, Channel.ReadBasic.All, ChannelMessage.Read.All, Chat.Read, OnlineMeetings.Read, and OnlineMeetingTranscript.Read.All. Separately, when a Teams admin installs the CoralSwarm Teams app to a specific channel, chat, or meeting (resource-specific consent — nothing is ingested until they do), that app holds its own scoped permissions for that channel, chat, or meeting only: ChannelMessage.Read.Group, ChatMessage.Read.Chat, TeamMember.Read.Group, ChannelSettings.Read.Group, OnlineMeetingTranscript.Read.Chat, and OnlineMeeting.ReadBasic.Chat.
  • Google — read-only access to your primary Google Calendar (the calendar.readonly scope) so CoralSwarm can show you upcoming meeting details. We do not request Gmail or any other Google scope, and calendar event content is read live to power that feature — it is not stored on our servers.

You can disconnect any connector at any time from within the product. Disconnecting revokes CoralSwarm's access token with that provider and stops further ingestion; it does not automatically delete content already captured into your account — email us at msaad@coralswarm.com to request that.

Technical and log data

OAuth access and refresh tokens for connectors are encrypted at rest. We also collect ordinary operational data needed to run and secure the Service: request logs, error and crash reports, and device or browser metadata.

Product telemetry and analytics

This website and the CoralSwarm web app use privacy-respecting, cookieless analytics (PostHog) to understand traffic and usage — no cross-site tracking cookies.

Our applications and services also collect usage telemetry: which features you use, event counts, timings, and error indicators. Telemetry is metadata only — it never includes meeting audio, transcripts, meeting titles, captured content, file names, or the text of the questions you ask.

In the CoralSwarm desktop app, telemetry can be turned off at any time from Settings ("Share usage data").

We use this data to understand which features provide value and to improve the product.

How we use information

  • To operate the Service — capturing, transcribing, extracting, indexing, and answering questions over your Captured Content.
  • To respond to your inquiries and manage the waitlist, including sending invite and confirmation emails.
  • To improve, debug, and secure the Service.
  • To comply with legal obligations.

AI processing of your content

To turn Captured Content into extracted facts, topics, and cited answers, CoralSwarm sends relevant portions of your content to Anthropic's API (Claude models) for processing. This happens as part of delivering the Service to you. We do not use your content, and Anthropic does not use it, to train models outside the terms of our agreement with Anthropic. For this automatic processing, we do not send your Captured Content to any other AI or model provider. (If you connect your own AI assistant through MCP, see "AI assistant access (MCP)" below — that is content you request, sent to a client and provider of your choosing.)

AI assistant access (MCP)

CoralSwarm runs an MCP (Model Context Protocol) server that lets you connect your own AI assistants (for example, Claude Code, or another MCP-compatible client) to query the knowledge you've captured. Access is authenticated through your CoralSwarm account via Clerk OAuth and scoped to what you've authorized: an assistant you connect can read knowledge already in your account or organization, and nothing belonging to other users or organizations. When you ask that assistant a question, CoralSwarm sends the specific searchable content, transcripts, and cited answers it requests to that client and, where applicable, its underlying model provider, under that provider's own terms and privacy policy — not CoralSwarm's.

How we share information

We do not sell your information. We share it only with the service providers ("subprocessors") that host and operate CoralSwarm, and only as needed to run the Service:

  • Cloudflare — website hosting, the waitlist database, and outbound email delivery.
  • Fly.io — application and database hosting for the CoralSwarm backend.
  • Anthropic — AI/LLM processing of Captured Content, described above.
  • Clerk — account authentication.
  • PostHog, Inc. — product analytics (US), described above.

We may also disclose information if required by law, or to protect the rights, property, or safety of CoralSwarm, our users, or others.

Data retention

We retain waitlist and account information for as long as your waitlist entry or account exists. Unsubscribing via the link included in any waitlist email removes you from future emails. You can request deletion of your waitlist entry, account, or Captured Content at any time — see "Contact us" below.

Your choices and rights

  • Unsubscribe from waitlist emails at any time via the link in the email.
  • Disconnect any connector at any time from within the product.
  • Request a copy or deletion of your data by emailing us.

CoralSwarm doesn't yet have a self-serve data export or deletion tool — requests are handled manually by emailing msaad@coralswarm.com.

Meeting recording and consent

CoralSwarm's meeting capture is initiated by you or someone on your team — it is never automatic. Many jurisdictions have laws requiring the consent of some or all participants before a conversation is recorded. You are solely responsible for knowing and complying with the recording-consent laws that apply to your meetings, including obtaining any required consent from participants, before using CoralSwarm to record or transcribe a conversation.

Security

Connector OAuth tokens are encrypted at rest, and data is transmitted over encrypted connections (TLS). We restrict internal access to Captured Content to what's needed to operate the Service. No method of storage or transmission is perfectly secure, and we can't guarantee absolute security.

Children's privacy

CoralSwarm is not directed to, and we do not knowingly collect information from, anyone under 18. If you believe a minor has provided us information, contact us and we'll delete it.

International users

CoralSwarm is operated from the United States. The subprocessors listed above may process information in the United States and other countries where they operate. By using the Service, you consent to this transfer and processing.

Changes to this policy

We may update this policy as CoralSwarm's product evolves. We'll update the "Last updated" date above, and if a change is material we'll make reasonable efforts to notify you — for example, by email.

Contact us

Questions about this policy or your data? Email msaad@coralswarm.com.