Privacy Policy
CoLateral AI is an engineering workspace software product. This Privacy Policy explains what information CoLateral AI collects when you use the Product, how that information is used, stored, shared, and retained, and the rights you have over it. It applies alongside the Terms of Use, which govern your use of the Product.
1. Overview
This Privacy Policy applies to CoLateral AI and all related websites, applications, desktop applications, tools, features, files, exports, and software components (together, the "Product"). It applies to all users of the Product, including individuals, companies, engineering firms, engineers, engineering interns, students, educators, technologists, designers, contractors, consultants, and organizations.
By accessing, downloading, installing, purchasing, or using the Product, you acknowledge the practices described in this Privacy Policy. If you do not agree with these practices, do not use the Product.
2. Information Collected
CoLateral AI may collect the following categories of information:
- Account information. Name, email address, organization, and any professional details you provide during registration, purchase, or licensing.
- Project data. Engineering inputs, uploaded documents such as drawings and PDFs, project parameters, saved designs, and outputs you create, import, or generate while using the Product.
- Usage data. Feature interactions, session duration, tool usage patterns, browser type, device information, and IP address, collected automatically to operate, secure, and improve the Product.
- Communications. Messages you send to CoLateral AI, including support inquiries, bug reports, and feedback.
- Transaction information. Records of purchases, licenses, and entitlements. Payment card details are handled by the payment processor and are not stored by CoLateral AI.
Some features of the Product operate locally on your device and store project data in your browser or file system rather than transmitting it to CoLateral AI. Where that is the case, the data remains under your control and is subject to your own device and backup practices.
3. How Information Is Used
Collected information is used to:
- Provide, operate, secure, maintain, and improve the Product and its features.
- Deliver the licenses, purchases, and entitlements you have acquired.
- Personalize your experience and surface relevant tools and settings.
- Communicate about product updates, security notices, service changes, and support.
- Analyze aggregate usage trends to improve performance, accuracy, and reliability.
- Detect, investigate, and prevent fraud, abuse, security incidents, and misuse of the Product.
- Comply with legal obligations and enforce the Terms of Use.
CoLateral AI does not use your information to make automated decisions that produce legal or similarly significant effects about you.
4. Legal Bases for Processing
Where applicable data protection law requires a legal basis for processing, CoLateral AI relies on:
- Performance of a contract, to provide the Product you have purchased or registered for.
- Legitimate interests, to secure the Product, prevent misuse, and improve reliability and features.
- Consent, where consent is required and has been given, which you may withdraw at any time.
- Legal obligation, where processing is required to comply with applicable law.
5. Artificial Intelligence and Model Training
The Product may use artificial intelligence, automation, and third-party AI providers to generate or assist with outputs. Content you submit to an AI-assisted feature may be transmitted to those providers solely to produce the requested output.
CoLateral AI does not use your identifiable project data, uploaded documents, or client materials to train AI models without your explicit consent. Anonymized, aggregated usage patterns that cannot reasonably be used to identify you or your projects may be used to improve the Product.
You may opt out of any model improvement data usage by contacting privacy@colateral.engineering.
You are responsible for ensuring that you have the rights and permissions required to submit any content to the Product, and for complying with confidentiality obligations, non-disclosure agreements, client requirements, workplace policies, and professional obligations that apply to that content.
This section covers AI features CoLateral AI operates. Where you connect the Product to an AI assistant, coding agent, orchestration feature, or connector of your own choosing, that provider's practices apply instead, and Section 6 explains what that means.
6. Connected AI Assistants, Agents, and Connectors You Choose
The Product can be connected, at your option, to AI assistants, coding agents, command-line tools, orchestration features, and connectors that you select and control. This includes, without limitation, Anthropic Claude and Claude Code, OpenAI ChatGPT and the Codex CLI, other AI models and providers, agent terminals, model context protocol servers, and file or cloud connectors (each a "Connected AI Service").
These integrations are optional and off by your choice at any time. The bottom command bar can run as a plain local keyword search over your own tools and cards, with no AI assistant, no agent, and nothing about your work sent to any AI provider. You can select that mode in Account and Settings under Orchestrator, and no part of the Product requires you or your firm to adopt AI assistants, agents, or orchestration.
When you do connect one, information flows directly between your device and that provider under your own account or subscription. Depending on the integration and the permissions you grant, this may include your prompts and instructions, file names and file contents, drawings, calculations, model inputs and outputs, project and client information, canvas contents, terminal input and output, and anything else the agent or connector is able to read.
- The receiving provider decides what happens next. Their retention periods, security controls, staff access, sub-processors, storage locations, and any use of your material for model training are set by their terms, their privacy policy, and the plan and settings on your account with them. CoLateral AI is not a party to that relationship and cannot control, audit, or undo it.
- CoLateral AI does not receive a copy of this traffic simply because you used a Connected AI Service. The bottom bar's default subscription mode and the Terminal Cards run your own locally installed CLI through a loopback-only local bridge on your own machine.
- Connectors widen the surface. A connector you authorize may expose repositories, drives, mailboxes, or other systems to an agent, and an agent may pass that material on to the AI provider behind it.
- Review the provider's policies before you connect. They govern your material once it leaves your device.
You are responsible for deciding whether a Connected AI Service is permitted for your work and for obtaining any approval you need first, including under confidentiality obligations, non-disclosure agreements, client instructions, employer and workplace policies, insurance and professional requirements, privacy and data residency laws, and regulator or licensing body requirements.
6.1 Business and enterprise plans, and why the plan you connect matters
Which plan you are signed in with changes what the provider is contractually allowed to do with your engineering work. The differences are theirs to define and theirs to change, but as a general matter, the business and enterprise tiers of the major providers add commitments that consumer tiers may not:
- OpenAI. Data submitted through the OpenAI API and through ChatGPT Business, Team, and Enterprise is not used to train OpenAI's models by default. A Data Processing Addendum is available, deleted business conversations are removed within roughly thirty days, and zero data retention can be arranged for eligible organizations on supported endpoints, which is granted by OpenAI rather than switched on by you. Consumer ChatGPT accounts are governed by different settings.
- Microsoft. Azure OpenAI and Microsoft Foundry run inside your own Azure tenant: prompts, completions, embeddings, uploaded files, and fine-tuning data are not used to train Microsoft's, OpenAI's, or any third party's models, are logically isolated from other customers, and are processed in the Azure region you deploy to. Microsoft 365 Copilot carries the same enterprise data protection, GDPR, and EU Data Boundary commitments as the rest of a Microsoft 365 commercial tenant, and honours the access controls already on your files. Data residency behaviour is a tenant setting that Microsoft can change over time, so confirm the current configuration with your own administrator rather than relying on this summary.
- Anthropic. Anthropic's commercial terms state that it does not train models on customer content submitted through the Claude API, Claude for Work, and Claude Enterprise. Commercial API inputs and outputs are deleted on Anthropic's backend within roughly thirty days by default, and zero data retention is available to eligible customers by agreement. Consumer Claude accounts are governed by different settings.
CoLateral AI recommends that firms doing client work connect on a business or enterprise plan, sign the provider's data processing addendum, and ask their account team about zero data retention and about the region their traffic is processed in, before putting client material through a Connected AI Service.
CoLateral AI does not make these commitments on a provider's behalf and cannot enforce them. The summary above is offered as a starting point for your own diligence, is accurate only as far as the providers' published terms at the time of writing, and changes without notice to CoLateral AI. Which plan is connected, and whether it is the right plan for the material being sent, is your decision.
6.2 Connecting a provider with OAuth
Where a provider supports it, CoLateral AI connects to it using the OAuth 2.0 authorization code flow with PKCE, so that connecting a third party does not require you to paste a long-lived secret into the Product. In that flow you sign in with the provider directly, on their own domain, and they hand back a scoped access token. CoLateral AI never sees your password. The tokens are held on your own device, in session storage that is cleared when the browser session ends, and they are requested with the narrowest scopes the feature needs. You can withdraw a connection at any time from Account and Settings, or from the provider's own account or tenant administration, which revokes it everywhere.
A connection you authorize may let the Product, and any agent you run through it, read what that scope covers. Authorize only the accounts, tenants, drives, and repositories you intend an AI assistant to be able to read, and grant the connection through an account whose own permissions already reflect that.
By enabling, connecting, or using a Connected AI Service, an agent, an orchestration feature, or a connector, you assume the risk and the liability for any disclosure, leak, exposure, interception, unauthorized access, retention, onward transmission, or misuse of information that results from that choice, as set out in Section 6 of the Terms of Use. To the fullest extent permitted by applicable law, CoLateral AI is not responsible for the privacy, security, or data handling practices of any Connected AI Service.
The first time you enable an agent, an orchestration feature, or another Connected AI Service, the Product shows a one-time notice pointing you to this Privacy Policy and the Terms of Use before that first connection is made. That notice is a reminder to read them; it does not change what they say or reduce your responsibility under them.
7. Information Sharing
CoLateral AI does not sell your personal information. Information may be shared only in the following circumstances:
- Service providers. Third-party vendors that help operate the Product, including cloud hosting, authentication, storage, analytics, payment processing, and AI inference providers, each bound by confidentiality and data protection obligations.
- Legal requirements. Where required by law, regulation, court order, or lawful request, or where reasonably necessary to protect the rights, property, or safety of CoLateral AI, its users, or the public.
- Business transfers. In connection with a merger, acquisition, financing, or sale of assets, where information may be transferred as a business asset subject to this Privacy Policy.
- With your direction. Where you ask CoLateral AI to share information, or where you use a feature that publishes or exports information to a destination you choose.
8. International Data Transfers
CoLateral AI operates from Canada and may use service providers located in other countries. Where information is transferred outside your jurisdiction, it may be subject to the laws of the receiving country. CoLateral AI takes reasonable steps to ensure that transferred information remains protected by appropriate contractual and technical safeguards.
9. Data Security
CoLateral AI implements reasonable technical and organizational measures designed to protect information against unauthorized access, loss, alteration, and disclosure. You are responsible for maintaining the security of your account, credentials, license keys, and devices, and for promptly reporting suspected unauthorized access.
No method of internet transmission or electronic storage is completely secure. To the fullest extent permitted by applicable law, CoLateral AI does not warrant that the Product, or any information transmitted to or stored within it, will be free from unauthorized access, loss, corruption, or interception.
10. Data Retention
Information is retained for as long as your account or license is active, or for as long as needed to provide the Product. You may request deletion of your account and associated information at any time by contacting CoLateral AI. Some information may be retained for a limited additional period where required to comply with legal, accounting, tax, security, or dispute-resolution obligations. Information stored locally on your device is deleted by you.
11. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information held about you.
- Request correction of inaccurate or incomplete information.
- Request deletion of your information.
- Object to or request restriction of certain processing activities.
- Withdraw consent where processing is based on consent.
- Receive your information in a structured, commonly used, machine-readable format.
- Lodge a complaint with the data protection authority in your jurisdiction.
To exercise any of these rights, contact privacy@colateral.engineering. CoLateral AI may need to verify your identity before responding and will respond within the period required by applicable law.
12. Cookies and Local Storage
The Product may use cookies, local storage, and similar technologies to maintain session state, remember your preferences and theme, and keep you signed in. CoLateral AI does not currently use third-party advertising trackers. You can control cookies through your browser settings, but disabling them may affect the functionality of the Product.
13. Third-Party Services and Links
The Product may integrate with or link to third-party websites and services. Those services are subject to their own terms and privacy policies. CoLateral AI is not responsible for the privacy practices of third parties, and you are encouraged to review their policies independently. AI assistants, coding agents, and connectors that you choose to connect are third-party services, and Section 6 governs them in addition to this section.
14. Children's Privacy
The Product is not directed at individuals under the age of 18, and CoLateral AI does not knowingly collect personal information from minors. If you believe a minor has provided personal information, contact CoLateral AI so that it can be removed.
15. Governing Law
This Privacy Policy is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, without regard to conflict of law principles, and applies in addition to any rights you have under the data protection law of your own jurisdiction.
16. Changes to This Policy
CoLateral AI may update this Privacy Policy from time to time. When material changes are made, CoLateral AI will make reasonable efforts to notify users, such as by posting the updated policy, updating the "Last Updated" date, or providing notice within the Product. Continued use of the Product after an updated policy is posted means you accept the update.
17. Contact
Privacy questions, requests, and complaints may be sent to:
General support questions may be sent to:
Legal notices may be sent to: