Privacy Policy
Last updated 9 September 2026
CoreSpeed is the harness AI agents run on. It gives an agent one authenticated surface for language models, tools, and connections to the apps you already use, so you do not have to register a separate API application for every service.
This policy explains what data CoreSpeed collects, why, who processes it, and how you can reach, correct, or remove it. It covers the corespeed.io website, the CoreSpeed dashboard, and the CoreSpeed API and connectors.
Website visits
Browsing corespeed.io requires no account and collects nothing beyond the analytics described below. Creating an account happens in the CoreSpeed dashboard. If you book an intro call, the scheduling is handled by Cal.com and you provide your details to them directly.
Product analytics
We use PostHog (US cloud) to understand how the site, dashboard, and service are used. Analytics requests are proxied through a corespeed.io path, and the destination is still PostHog.
Marketing site. We record pages viewed, interactions, campaign and referrer data, full page URLs, device and browser information, and approximate location derived from IP. PostHog project settings may enable session replay; form inputs are masked.
Authenticated Product analytics. Product analytics is on by default. You can turn it off in Dashboard Privacy settings. When off, we do not send Dashboard browser events or server-side PostHog events attributed to your WorkOS user ID. The Dashboard identifies you only by that user ID, does not send your email to PostHog, and does not use session replay. Dashboard automatic click capture, heatmaps, dead clicks, and performance capture are off, and URL query strings and fragments are stripped before events are sent.
Workspace usage analytics. Workspace usage analytics is on by default. Workspace members can see the setting, and workspace administrators can change it. It controls personless, workspace-attributed PostHog events and does not override the Product analytics choice of any member.
Cookies and local storage. Browser analytics keeps an identifier in local storage and in a cookie so repeat visits are recognised as the same visitor. Signing in also sets a session cookie, which is required for the dashboard to work. We set no advertising cookies.
Service records. These analytics choices do not disable records required to provide and protect the service, including activity and usage records, billing and ledger records, notifications, audit and security records, and abuse-prevention signals.
Your CoreSpeed account
Accounts and sign-in are handled by WorkOS, which acts as our identity provider. From WorkOS we receive your email address, your first and last name, your profile picture URL, and your organization membership and role. Your signed-in session is held in an encrypted cookie.
You can sign in to CoreSpeed with your Google account. When you do, Google tells us the email address, name, and profile picture of the account you chose, and we use them to create and identify your account and to show who is signed in. We never receive your Google password. The exact permissions this uses are listed under Google user data and Limited Use.
In our own database we keep only the identifiers we need to run the service: your user identifier, your organization memberships, and the email address of an organization's creator. Your name and profile picture are read from WorkOS when needed rather than copied into our database.
What you send through CoreSpeed
- Prompts and model responses
- Requests you make to a language model are routed through Vercel AI Gateway to the provider you select, which may be Anthropic, OpenAI, Google, xAI, DeepSeek, or another supported provider. CoreSpeed does not store your prompts or the model's responses. We record only metadata about the call: the time, the organization and user, the model and provider, token counts, latency, whether it succeeded, and a shortened-then-hashed IP address alongside the user agent your client sent. Prompt and response bodies are never written to our logs. Once a request leaves CoreSpeed, the gateway's and the provider's own terms govern what they retain.
- Memory
- Content you save through the memory capability is stored in a Postgres database dedicated to your organization, hosted by Neon. To make it searchable, that content is sent to Google's Gemini API to generate embeddings, and background jobs that organize and enrich memory also use a Gemini model.
- Media generation
- Prompts you give the media capability are sent to fal.ai, which generates the images or video, and the results are stored in Cloudflare R2.
- Media you ask us to interpret
- When you ask a question about a video, image, or audio file, that file is processed by Google Gemini. If you give a link, Google fetches it directly from wherever it is hosted; if you upload a file, the bytes are uploaded to the Google Files API. Either way the media leaves CoreSpeed and is handled under Google terms. This is the largest transfer of your content to a third party that CoreSpeed performs, so only pass files you are comfortable sending to Google.
- Web search
- Search queries made through the web capability are sent to Exa.
- Activity log
- We keep an audit log of actions taken on your account so you and your organization's administrators can see what happened. It holds metadata only, never prompts, model output, or tool argument content. The name of a tool argument may be recorded; its value is not. Your IP address is shortened and then irreversibly hashed before it is stored, and short identifying values such as email addresses are replaced with a keyed hash rather than kept in readable form.
- Billing
- Payments are processed by Stripe. Card details are entered with Stripe and never reach CoreSpeed. We store your Stripe customer identifier and our own record of credit balance and usage.
Accounts you connect
Connectors let an agent act in a third-party service on your behalf. Connecting one is always something you initiate: you are sent to that service to sign in, you see the permissions being requested, and you grant them.
We store the resulting access and refresh tokens encrypted with AES-256-GCM in our database. We use them only to perform the actions you or your agent request, and only within the permissions you granted. You can disconnect a connector at any time from the dashboard, which deletes the stored credential and, where the provider supports it, tells the provider to revoke the token.
Important. If you ask an agent to work with data from a connected account — to summarize a message or draft a reply, for example — the relevant content is sent to the language model provider you have selected so it can produce the response. That is how the feature works, and it is the main way data from a connected account leaves CoreSpeed.
Google user data and Limited Use
CoreSpeed's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
CoreSpeed requests access to your Google account for one thing: signing you in. It asks for three basic sign-in permissions and nothing else.
- openid
- Confirms which Google account completed the sign-in.
- profile
- Provides your name and profile picture, so the dashboard can show who is signed in.
- Provides your email address, which identifies your CoreSpeed account and is where we send service notices.
CoreSpeed does not request access to Gmail, Google Drive, Google Calendar, Google Ads, YouTube, or any other Google service. Signing in with Google grants CoreSpeed no ability to read your mail, your files, or your calendar.
Google is also one of our service providers, separately from sign-in. Google Gemini generates the embeddings that make stored memory searchable, and it processes media you ask CoreSpeed to interpret. Those uses run on CoreSpeed credentials rather than your Google account, and no permission you grant at sign-in is involved. They are listed under What you send through CoreSpeed and Who processes data for us.
How this data is used. Your Google name, email address, and profile picture are used only to create and identify your account and to display who is signed in. We do not use them for advertising or ad retargeting, we do not sell or transfer them, we do not use them for credit assessment or lending, and we do not use them to train generalized artificial intelligence or machine learning models. No CoreSpeed employee reads your Google data except where it is necessary for security or to comply with the law, or where the data has been aggregated and de-identified for internal operations.
Removing access. You can disconnect Google from your CoreSpeed account at any time.
Visit myaccount.google.com/permissions and remove CoreSpeed. Revoking access means you can no longer sign in with Google; email us if you would also like your CoreSpeed account and its data deleted.
Who processes data for us
These providers process data on our behalf so we can run the service. Which of them are involved depends on which parts of CoreSpeed you use.
- Cloudflare
- Hosting, the request layer, storage of stored files, queues, bot protection, and request logs.
- WorkOS
- Accounts, sign-in, organizations, and invitation emails.
- Neon
- The Postgres databases holding platform records and per-organization memory.
- Railway
- Hosts the ClickHouse database that stores the activity log.
- PostHog
- Product analytics, US cloud.
- Vercel
- AI Gateway, which routes model requests to the provider you select.
- Model providers
- Anthropic, OpenAI, Google, xAI, DeepSeek and other supported providers receive the prompts you send to them.
- Signs you in, generates the embeddings that make stored memory searchable, and interprets media you ask us to analyse.
- fal.ai
- Image and video generation.
- Exa
- Web search queries.
- Stripe
- Payments and billing.
- Resend
- Transactional email such as receipts, low-balance warnings, and payment failure notices.
- Mailchimp
- Marketing audience segmentation. It receives your email address and lifecycle tags, and is not used to send receipts or service notices.
- Cal.com
- Intro-call scheduling.
CoreSpeed is operated from the United States and these providers may process data in the United States and other countries. Using CoreSpeed involves transferring your data to those locations.
How long we keep data
- Activity log entries
- One year. The hashed IP address and user agent inside each entry are cleared after 90 days, while the rest of the entry remains.
- Links to generated files
- A download link expires 12 hours after it is issued. The underlying file remains in storage until it is deleted.
- Deleted memory databases
- Purged after a seven-day grace period, so an accidental deletion can be reversed. Deletion is not instant physical erasure: for as long as our database provider retains point-in-time backup history, deleted memory can still exist in that history until the window ages out.
- Credit hold records
- Seven days. These are our internal holds against your credit balance, not card authorizations — card data never reaches CoreSpeed.
- Account, organization, memory, and connector data
- Kept while your account is active.
Where this policy does not state a fixed period, we keep the data for as long as your account is active or as needed to provide the service, resolve disputes, and meet legal obligations, and we delete it when you ask us to.
Security
Connector credentials and database passwords are encrypted with AES-256-GCM before they are stored, and database connection strings are assembled at request time rather than stored in readable form. Traffic is encrypted in transit. API keys are scoped and can be revoked individually. Request logging is written to exclude prompts, model output, and credentials, and IP addresses in the activity log are shortened and hashed rather than stored as-is.
No system can be guaranteed completely secure. If you believe you have found a vulnerability or that your account has been accessed without your permission, email contact@corespeed.io.
Access, correction, and deletion
You can act on your own data at any time:
- Memory
- Delete individual entries or clear all stored memory from the dashboard or through the memory tools.
- Connected accounts
- Disconnect any connector to delete its stored credential, and revoke access with the provider directly.
- API keys
- Revoke any key you have issued.
- Name and profile details
- Update them with the identity provider you signed in with.
For anything else — a copy of your data, a correction, or deleting your account entirely — email contact@corespeed.io and we will handle it. Account deletion is currently done by request rather than through a button in the dashboard. One email is enough; you do not need to explain why.
Children
CoreSpeed is a tool for developers and businesses and is not directed to children. We do not knowingly collect personal information from children. If you believe a child has given us personal information, email us and we will delete it.
Changes to this policy
We will update this page when our practices change and revise the date at the top. If a change materially affects how we handle your data, we will tell account holders directly rather than relying on this page alone.
Contact
CoreSpeed · contact@corespeed.io