LEGAL

Privacy Policy

Last updated: August 5, 2026 · Applies to every Cobenian product: Steward, Panel, Accounts, Foundry, and the Data APIs.

The short version. We never read the body of your email. We don't sell your data, and we don't share it for anyone's marketing. Your data is isolated to your workspace, connection tokens are encrypted, and you can delete everything at any time.

Cobenian Corporation ("Company," "we," "us"), a Virginia corporation, operates the Cobenian Suite — the Steward and Panel applications, the Cobenian Accounts control plane, and the Foundry and Data API platform services beneath them (together, the "Service"). This Privacy Policy explains how we collect, use, and protect your information across every product in the Suite. Product-specific detail appears in the schedules at the end.

1. Information we collect

Account information

When you create an account we collect your name, email address, and profile image from your Google or Microsoft account through OAuth authentication. We never ask for or store a password.

Email metadata

Where you connect a mailbox, we access email metadata: sender and recipient addresses, subject lines, timestamps, thread identifiers, and attachment presence indicators. We never access, request, or store the body content of your incoming or outgoing email.

Calendar data

Event titles, descriptions, times, locations, and attendee lists from a connected Google or Microsoft calendar.

Financial and time-tracking data

If you connect QuickBooks, we access customer records, invoice data (amounts, dates, statuses), and estimates. If you connect Harvest, we access time entries, projects, and client records. We use this data solely to provide the Service.

Business records you create in the Service

Records you or your team create or that the Service creates on your instruction — cases and their correspondence, questionnaire responses, documents and their status, monitoring signals and alerts, automation decisions and their audit trail.

SMS and voice data

Where your organization provisions a messaging- or voice-enabled number through us: phone numbers in E.164 format, message content (encrypted at rest), delivery metadata, call timestamps and duration, and call transcripts (encrypted at rest). Voice recordings are retained only if your administrator explicitly opts in; otherwise audio is transcribed and discarded immediately. We retain opt-in and opt-out proof records as compliance evidence under the TCPA and U.S. carrier rules (10DLC / A2P).

Chat data

If you connect Slack or Microsoft Teams, we store the conversation threads in which you interact with the Service and pointers to the business records referenced in them.

Usage data

Standard server logs including IP address, browser type, pages visited, and timestamps, for operating and improving the Service.

2. How we use it

Solely to provide and operate the Service:

  • Computing what is normal for each of your clients and detecting meaningful changes
  • Generating proposals, drafts, alerts, and inferred deadlines for your review
  • Sending you transactional notifications through the channels you connected
  • Sending outbound communications you authorize the Service to send on your behalf
  • Authenticating you and managing your account, seats, and billing
  • Diagnosing technical issues and improving the Service

3. AI processing

The Service uses third-party AI providers to classify information, generate summaries and drafts, and power conversational features. The following categories may be transmitted as needed to operate the Service: email subject lines and other metadata fields; calendar event titles; business records you create in the Service; SMS bodies sent to or by the Service; voice audio and transcripts during a live interaction; and chat content from Slack, Teams, and the in-app assistant.

Email body content is never transmitted to any AI provider, because we never collect it. Our AI providers process data under contractual data-protection terms and do not train their public models on it.

4. What we do not do

  • We do not read, access, or store email body content
  • We do not sell your data
  • We do not share your data with third parties for their marketing purposes
  • We do not use your business data to train public AI models

5. Sharing

We share personal information only in these limited circumstances:

  • Service providers. The vendors listed in our subprocessor list process data on our behalf under contractual obligations to protect it.
  • Legal requirements. Where required by applicable law, regulation, legal process, or governmental request.
  • Business transfers. In a merger, acquisition, or sale of assets your data may transfer as part of the transaction. We will notify you.

6. Security

  • OAuth tokens encrypted at rest with AES-GCM
  • SMS bodies, call transcripts, and any retained recordings encrypted at rest
  • HTTPS for all data in transit
  • Webhook signature verification on inbound and outbound delivery
  • Per-workspace data isolation and scoped, least-privilege access
  • Sign-in delegated to Google or Microsoft; we never hold your password

7. Your choices and rights

You can disconnect any integration at any time, which stops further collection from that source. You can export or delete your data, and deleting your account deletes the data associated with it. To exercise any right, or to ask what we hold about you, email privacy@cobenian.com.

8. Retention

We retain your data for as long as your account is active and for the period afterwards needed to meet legal, tax, and compliance obligations. Messaging opt-in and opt-out records are retained as carrier-compliance evidence regardless of account status.

9. Changes

We will post any change here and update the date at the top. Material changes will also be notified in-product or by email.

Schedule A — Steward

Steward reads the mailbox, calendar, invoicing, and time-tracking sources you connect in order to propose actions for your approval. Everything in sections 1–3 above applies. Steward is the only product in the Suite that connects to a mailbox, and it reads metadata only.

Steward's messaging disclosures for SMS and voice, including STOP/HELP keywords and message frequency, are published at steward.cobenian.com/sms-terms.

Schedule B — Panel

Panel holds the business records its instruments create: cases and their correspondence, questionnaire responses, monitoring signals and alerts, document status, and the decision log for any automation you enable. Panel reads connected systems (such as QuickBooks, Harvest, Jira, or GitHub) through the same connections you authorize, and does not connect to a mailbox for reading.

Where an instrument collects information from someone outside your organization — a client answering a questionnaire, a person emailing your case queue — you are the controller of that information and we process it on your behalf.

Schedule C — Cobenian Accounts

Accounts is the control plane: identity, organizations, seats, entitlements, usage metering, and billing. It holds no product data. It records the usage totals and spending caps that determine your bill, and the audit trail of administrative actions taken in your organization.

Schedule D — Platform services

Cobenian Foundry and the Cobenian Data APIs are shared infrastructure underneath the products above, not separately sold services. Foundry holds the connections you authorize, the event history the products act on, stored files, and the conversation records described in section 1; the Data APIs hold canonical business records on behalf of the product that wrote them. Everything in sections 1–8 applies to them. You interact with them only through a product you already use, and no data reaches them except by way of one.

Contact

Cobenian Corporation · privacy@cobenian.com · +1 703-828-5180