Documents
Monitoring & the Law →
Which laws apply to employee AI monitoring — ECPA, state notice duties, state privacy rights, GDPR, and the EU AI Act — who carries each obligation, and how Coapro makes the compliant path the default.
What We Don't Collect →
The narrowness of collection, stated concretely and verifiably: no biometrics, no non-AI surfaces, no file contents, no stored secrets, no screen reading — and exactly where monitoring does happen.
Privacy Policy →
The complete data map: what is recorded, what is never recorded, retention periods, who is shared with, and a section written for the people whose work is monitored.
Terms of Service →
The contractual terms, including the deployment conditions and the responsibilities that remain with the deploying organization.
Sub-processors →
Every third party that processes customer or employee data — three, each named with what it does and what it does not — with a 30-day change-notice commitment.
Model Training →
What our models learn and from what: trained by us, on our infrastructure, on redacted features — never verbatim prompts, never third-party training runs.
Data practices, in numbers
Category, not content
By default we store the category of sensitive content detected — never the matched value and never raw prompt text.
Seven-day default, hard ceiling
Verbatim prompt content is deleted after a customer-configured window: seven days by default, never more than thirty.
Employee-facing transparency
Every employee sees everything collected about them, on their own page, without asking anyone.
Notice recorded before collection
No content is ingested until an administrator attests, on the record, that everyone affected received written notice.
Least-privilege access
Managers see patterns about direct reports — never prompts. Verbatim text is role-restricted, and every access is logged.
Encrypted, isolated
AES-256 at rest, TLS 1.3 in transit, row-level security keeping each organization's data separated.
Where our security posture is honest about gaps
We do not currently hold a SOC 2 report. SOC 2 is a procurement gate, not a licence to operate — no law requires it, and no document here claims an audit that hasn’t happened. What we offer in its place is verifiable narrowness: every “don’t collect” claim on these pages is testable by installing the product, and a dedicated page lists them with the mechanisms that enforce them. A completed questionnaire with candid not yet answers is available on request — a uniformly green questionnaire usually means it wasn’t read.
If a reviewer needs something these pages don’t cover, ask. The honest answer to a security question builds more trust than an adjective.
Contact
Data-protection questions, DSAR assistance, and security questionnaires: privacy@coapro.org. If your employer uses Coapro and you want to know what is recorded about you, ask them first — they decide what is collected and who can see it.