Privacy policy
How we collect, use and protect your data.
In short
copadre contains no analytics or tracking code, on this site or in any copadre agent anywhere. We don’t use non-essential cookies (this site has none). There is no sign-in required and nothing connecting a copadre agent to who you are. The only way you stop being anonymous is by saying who you are in your own messages.
What is kept: what you and the agent said (encrypted), and your time zone, if your browser reports it.
What is kept temporarily: if a conversation is blocked for abuse or for hitting its turn limit, the IP address it came from, held for the duration of the block.
The business that runs the agent can read the conversation. That is what the platform is for.
The rest of this page is the full policy. Conversations with a customer’s agent are covered by our data processing agreement.
This policy covers copadre as the controller of personal data — our own account holders, their team members, and visitors to this site. Personal data belonging to our customers’ website visitors is covered by our data processing agreement, where we act as processor.
Who we are
This Company (Digital) Limited, trading as copadre, is the controller of the personal data described in this policy. We are registered in England and Wales (Company No. 11365195) and comply with the UK GDPR and the Data Protection Act 2018.
We are registered with the Information Commissioner’s Office, registration number ZA937080.
For data protection queries, write to hello@copadre.com.
What we collect
If you hold a copadre account
- your name and email address (encrypted at rest)
- your role (owner, developer, editor or viewer) and your time zone
- your sign-in credentials — passkey records and single-use magic-link tokens. We do not store passwords.
- session records: IP address, browser user agent, sign-in time and last-active time
- your Anthropic API key (encrypted at rest)
- your account settings: allowed domains, IP whitelist, cooldown and block durations, your own fallback wording, and notification recipients
If you use one of our own assistants
We run copadre assistants on our own services. Each is an ordinary copadre agent, so you are talking to an AI assistant rather than a person. What you type is stored as a conversation, encrypted at rest, along with — if your browser reports it — your time zone. If a conversation is blocked — for hitting the turn limit or for abuse — we also record the IP address it came from. To generate a reply, your message is sent to Anthropic’s API on our own Anthropic account, and Anthropic may process it outside the UK under its own terms. We are the controller for those conversations, in the same way our customers are the controller for theirs. We run no advertising and no third-party analytics on our services.
Diagnostics
We log token counts for each conversation turn for our own diagnostics. These records contain no conversation content.
If you connect an AI tool to your account
copadre runs an MCP server, so an account holder can connect an AI tool such as Claude to their copadre account from inside that tool. The connection is made by you, from your own AI tool, and you approve it on a copadre sign-in page before it is granted. It acts as you: it can reach only your organisation’s agents, conversations, usage and notification events, and only what your role in the portal allows. It cannot read your API key, manage your team or change your account settings.
For each request the tool makes through the connection, we record who made it, which operation was called, whether it succeeded, and how long it took. We do not record the request’s contents or any conversation text. Each connection is listed on your account page, with when it was last used and a button to revoke it, which cuts off access immediately. Access tokens issued to the tool expire after an hour and are renewed automatically; the approval itself lasts a year, after which you are asked to approve again.
What the AI tool and its provider do with the data they read through the connection is governed by your agreement with that provider, not by this policy. Our data processing agreement covers this in more detail.
Cookies
This site sets no cookies. We run no advertising, no third-party analytics and no tracking of any kind.
How we use it
- to provide and operate copadre
- to sign you in and keep your account secure
- to send the notifications you have configured — new conversation, out of knowledge, visitor blocked, inactive agent requested, routing broken
- to respond when you contact us
Legal basis
- Contract — providing the service you have signed up for
- Legitimate interests — security, abuse prevention, keeping the platform running, and answering questions from people who use our assistants
- Legal obligation — where the law requires it
Who we share it with
We do not sell or rent personal data, and we do not use advertising networks or third-party analytics.
copadre is hosted by Unlimited Web Hosting UK Limited, a UK hosting company acting as our sub-processor. They are Cyber Essentials certified, and they are our only sub-processor. Their details are in the data processing agreement.
Our email — sign-in links and service notifications — is sent from our own server. We do not use a third-party email service.
We may disclose personal data where required by law or in response to a valid legal request. Where we are permitted to, we will tell you first.
Where it is stored
Your data is stored on UK infrastructure, under UK jurisdiction. copadre runs on a UK virtual server dedicated to This Company (Digital) Limited — the hosting company provides the infrastructure, but day-to-day administration is ours alone, and no other business has administrative access. Within that server, copadre sits in its own isolated account, with its own files and database, separate from everything else we host. Backups are held in the UK too. Your account, your agents and your conversations stay in the UK: we do not transfer them outside it.
Agents run on your own Anthropic API key, under your own agreement with Anthropic, so messages sent to Anthropic to generate a reply are covered by that agreement rather than this policy. Our data processing agreement explains this.
There is one exception, and it applies only to our own assistants across the copadre services. Those run on our own Anthropic account, so if you chat to one, what you type is sent to Anthropic to generate a reply and may be processed outside the UK under Anthropic’s terms. This concerns conversations with our own assistants and nothing else — no copadre account, agent definition or customer conversation leaves the UK because of it.
How long we keep it
We keep account data and conversations — including conversations with our own assistants — for as long as the account is open, or until you ask us to delete them. When an account is closed, its data is deleted within 30 days, unless the law requires us to keep it.
Sign-in sessions and login links are cleared as soon as they expire. The IP address recorded when a conversation is blocked is deleted once the block has expired. Records of notifications we have sent you are kept for 180 days, and diagnostic token logs for 2 years. Records of requests made through a connected AI tool are kept for 90 days; revoked or expired connections are removed from your account page 30 days after they end.
Security
This Company (Digital) Limited holds Cyber Essentials certification, the UK government-backed scheme owned by the National Cyber Security Centre.
Personal data is encrypted at rest (AES-256-GCM), as are your agents’ instructions — both the published version and every draft revision. copadre is HTTPS-only. Sign-in is passwordless — passkeys with a magic-link fallback, rate-limited, using single-use, short-lived tokens. Each customer’s data is isolated from every other customer’s.
Our staff can access accounts to provide support and keep the platform running. They are bound by confidentiality obligations.
Your rights
Under the UK GDPR you can ask us for a copy of your data, correct it, delete it, restrict or object to how we use it, or have it ported elsewhere — including a conversation you have had with one of our assistants. Write to hello@copadre.com.
If you are a visitor to one of our customers’ websites, your rights sit with that business — they decide what their agents do and what happens to your conversation. If you contact us, we will pass your request to them.
Complaints
You can complain to the Information Commissioner’s Office at ico.org.uk (opens in a new tab) if you think your data has been handled incorrectly.
Changes
We may update this policy. We will email registered users about significant changes before they take effect.
Last updated 21 September 2026.