Skip to content
Coco
How it works Why Coco Is it safe? Build it Pricing Blog Changelog Help FAQ
Back to home prompted by Jorge Herrera

Privacy Policy

What Coco knows about you, and what it does with it.

Effective June 4, 2026 · Last updated June 4, 2026

Coco reads your inbox and calendar so it can run your day. That only works if you trust it, and trust starts with being plain about what is collected, where it lives, and who can reach it. This is that, in plain English.

Contents

  1. Who this covers
  2. What Coco collects
  3. What Coco does not collect
  4. The Google permissions, and why
  5. How and where it is stored
  6. Who can see your data
  7. Third parties we rely on
  8. How to delete your data
  9. How long we keep things
  10. Children
  11. Changes to this policy
  12. Contact

Who this covers

Coco is a personal admin that reads your Gmail and Google Calendar, writes you a morning brief, drafts replies in your voice, and — only when you approve — sends a reply or adds an event. This policy describes how Coco handles your information when you sign in and use it. It applies to the Coco application and the account you create when you connect your Google account.

Throughout, "Coco," "we," and "us" mean the people operating the Coco service. "You" means the signed-in person whose Google account is connected.

What Coco collects

Coco collects only what it needs to do its job. That falls into four buckets:

  • Your Google account basics — the email address, name, and profile photo on the Google account you sign in with. This is how Coco knows who you are and addresses the brief to you.
  • Your Gmail messages — Coco reads your mail so it can fold a noisy inbox into one topic per real thing, pull dates out of flyers, and notice the people who keep coming up. It reads; it does not send anything you have not approved.
  • Your calendar events — Coco reads your Google Calendar so the brief reflects what your day actually looks like, and so a drafted reply can notice a conflict before you commit to a meeting.
  • The replies you approve, and the things you tell it — when you approve a draft, Coco keeps a record of what was sent on your behalf. And the entries you add about your life — who matters, what you are working on, the context you want it to remember — are stored so the next brief is sharper than the last.

Coco also keeps a basic audit log of the actions it takes for you — a brief generated, a draft written, a reply you approved and it sent — so you can always read back what it did and when.

What Coco does not collect

Some things Coco never touches:

  • Your password. You sign in through Google. Coco never sees your Google password and could not store it if it tried — Google handles the login and hands Coco a revocable token, nothing more.
  • Your payment details. If you subscribe, billing runs through Stripe. Your card number, expiry, and security code go to Stripe and stay with Stripe. Coco sees only what Stripe tells it — that a subscription is active, and a reference ID — never the card itself.
  • People who have not emailed you. Coco does not crawl your contacts or build a profile of people outside your inbox. The only people it knows about are the ones already corresponding with you.

And to be unambiguous about the thing people worry about most: Coco does not use your data to train AI models. Your mail, your calendar, and the notes you write are used to serve you, and for nothing else.

The Google permissions, and why

When you connect your Google account, Coco asks for a specific set of permissions. Each one maps to a thing you can see Coco doing. Nothing is requested "just in case."

Read your Gmail
So it can read the day's mail and synthesize your brief — merging threads, reading dates, drafting the replies that are owed. Read access is the heart of what Coco does.
Send Gmail
So it can send a reply you have read and approved. Coco never auto-sends. A draft sits and waits until you say go; the send permission is only exercised on your explicit okay.
Read your Calendar
So the brief reflects your real day, and so a draft can flag a scheduling conflict before you reply.
Create and modify Calendar events
So it can add an event you ask it to add. As with email, this only happens on your confirmation — never on Coco's own initiative.

You can review and revoke these permissions at any time from your Google account permissions page. Revoking them stops Coco from reading or acting on your behalf immediately.

How and where it is stored

Your data lives on Coco's own infrastructure in the United States — application hosting on Vercel and a Postgres database on Neon. It is encrypted at rest, and every byte of it is isolated to your account through database Row-Level Security, so one user's data is never reachable from another user's session.

Connections between you and Coco, and between Coco and the services it relies on, are encrypted in transit. The Google access token that lets Coco read your mail is stored encrypted and is scoped to exactly the permissions listed above.

Who can see your data

Two things can see your data: you, and Coco's automated systems running on your behalf. That is the whole list.

No human at Coco reads your email. The synthesis that turns your inbox into a brief is done by automated systems and a language model (see the next section); it is not a person reading over your shoulder. We do not browse your messages, and we do not sell, rent, or share your data with anyone for advertising or any other purpose.

The narrow exceptions are the ordinary ones: if the law compels us through valid legal process, or if we genuinely must access something to investigate abuse or keep the service running, we may do so — and we will hold that to the minimum necessary. We will never do it to monetize your information.

Third parties we rely on

Coco is a small service standing on a few larger ones. Each sees only the slice of data it needs, and each has its own privacy commitments, which we link to so you can read them directly.

Anthropic
The language model that synthesizes your brief and drafts your replies. Relevant slices of your mail and calendar are sent to Anthropic's API to generate that output. Anthropic does not train its models on data submitted through its API. Anthropic privacy policy.
Google
The source of your mail and calendar, and the identity provider you sign in with. Google privacy policy.
Stripe
Handles billing if you subscribe. Stripe holds your payment details; Coco does not. Stripe privacy policy.
Vercel
Hosts the Coco application in the United States. Vercel privacy policy.
Neon
Provides the Postgres database, in the United States, where your data is stored encrypted. Neon privacy policy.

Coco's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

How to delete your data

You can delete everything, and it is not buried.

  • Sign in to Coco.
  • Go to Settings → Delete Account.
  • Confirm.

When you do, we delete your Coco data — your stored mail and calendar content, your notes, your audit log, and your account — within 30 days. Deleting your account also revokes Coco's access to your Google account; you can additionally revoke it yourself from your Google permissions page at any time.

The one thing that does not vanish on day one is billing history. Where we are legally required to retain financial records — invoices, tax records — Stripe and we keep those for the period the law requires, and no longer. Those records are billing facts, not your inbox.

How long we keep things

While your account is active, Coco keeps your data so it can keep doing its job — a brief is only as good as the context behind it. When you delete your account, the deletion described above runs within 30 days. Billing records are retained only as long as legal and tax requirements demand. We do not keep your mail or calendar content around after you have left.

Children

Coco is not intended for anyone under 18, and we do not knowingly collect information from anyone under 18. If you believe a minor has created an account, contact us and we will remove it.

Changes to this policy

If we make a substantive change to how we handle your data, we will notify users at least 30 days before it takes effect, so you have time to read it and decide. Minor clarifications that do not change what we collect or how we use it may be made without that notice, and the "last updated" date above will always reflect the current version.

Contact

Questions about your privacy, or want your data deleted and would rather ask a person? Email jorge.herrera.rojas@gmail.com.

This is an honest first-pass policy written to describe how Coco actually works today. It will be reviewed by counsel before public launch; if anything here conflicts with how the product behaves, the more privacy-protective reading governs, and we will fix the text. See also our Terms of Service.

Coco
  • Live demo
  • Source
  • Built with Claude
  • Pricing
  • Blog
  • Changelog
  • Help
  • Privacy
  • Terms