CoralLog in

Privacy Policy

Coral by Foundative Inc.

Effective Date:

Last Updated:

On this page

1. Introduction

This Privacy Policy ("Policy") describes how Foundative Inc. ("Foundative," "Coral," "we," "us," or "our") collects, uses, stores, processes, and discloses information in connection with Coral and its websites, dashboard, iMessage assistant, connected applications, AI-powered features, and related services (collectively, the "Services").

Foundative Inc. is located at 360 S Baywood Ave, San Jose, CA 95128, United States.

By accessing or using the Services, you acknowledge the information practices described in this Policy. Where applicable law requires consent, we will obtain it separately.

Our Terms of Service (https://messagecoral.com/terms) govern your use of the Services.

2. Information We Collect

Depending on the features you use, we may collect or process the following information.

2.1 Account Information

  • Name, phone number, time zone, and account preferences.
  • Account identifiers, authentication events, and settings.
  • Family memberships, relationships, and shared-space configurations.
  • Subscription status and related billing information.

Accounts may be created when Coral is added to a supported messaging group. Creating an account does not, by itself, establish a user's consent where consent is legally required.

2.2 Conversations and User Content

We may process:

  • Text messages and conversations.
  • Group messages, including messages to which Coral does not respond.
  • Images, documents, files, and attachments.
  • Voice recordings and transcriptions.
  • Poll responses and related interactions.
  • Tasks, reminders, memories, preferences, and instructions.

Information may be retained to provide conversation history, contextual assistance, and other requested functionality.

Messages may contain information about people other than the account holder.

2.3 Connected Applications

When you authorize integrations, we may access information made available through those services within the permissions you grant.

This may include emails, attachments, calendar events, documents, spreadsheets, contacts, account identifiers, and associated metadata.

Information from connected applications may be incorporated into responses, task results, generated files, conversation history, or memories where necessary to provide the requested functionality.

2.4 Browser and Task Information

When you use browser automation or task-execution features, we may process:

  • Website content and URLs.
  • Screenshots, downloads, and uploaded files.
  • Authenticated browser sessions.
  • Information entered into website forms.
  • Transaction and order information.
  • Task instructions, results, and operational records.

Certain information may include personal, financial, or other sensitive data.

2.5 Payments and Subscriptions

Stripe processes Coral subscription payments.

We may receive customer identifiers, subscription status, billing contact information, transaction references, and renewal information.

For supported purchases, Crossmint and other payment providers may process payment credentials.

We may retain payment-method references, card brands, last four digits, and associated authorization or transaction information.

We do not ordinarily receive complete payment-card numbers from Stripe checkout or the original card details handled by Crossmint.

2.6 Location Information

When you share your location through supported services, including Apple Find My, Coral may process location information to provide requested features.

This may include coordinates, addresses, named places, sharing status, location requests, alert preferences, and arrival or departure information.

2.7 Technical and Usage Data

We may collect technical information such as device and browser characteristics, network information, authentication events, service requests, error reports, and operational logs.

This information is used to operate, maintain, troubleshoot, and secure the Services.

3. How We Use Information

We may use information to:

  1. Provide, operate, and maintain the Services.
  2. Respond to messages and fulfill user instructions.
  3. Generate AI-powered responses and task results.
  4. Maintain conversations, memories, preferences, and scheduled activities.
  5. Support authorized integrations and connected accounts.
  6. Process subscriptions and authorized transactions.
  7. Detect abuse, fraud, unauthorized access, and security incidents.
  8. Troubleshoot and improve service functionality and reliability.
  9. Comply with legal obligations and enforce applicable agreements.
  10. Protect users, third parties, and the Services.

Where required by law, processing is based on an applicable legal basis, such as contractual necessity, consent, legitimate interests, or compliance with legal obligations.

We may analyze operational and technical information to improve the Services, subject to applicable law and restrictions governing information received from third-party platforms.

4. Artificial Intelligence and Automated Processing

Coral uses third-party artificial intelligence models, infrastructure, and processing services to understand requests, generate responses, analyze content, and execute authorized tasks.

Relevant information may be transmitted to AI providers and technical subprocessors.

This information may include conversations, documents, connected-service information, website content, task instructions, and relevant contextual history.

AI processing generally occurs outside your device.

Encryption provided by an underlying messaging service does not necessarily extend to Coral's storage, processing infrastructure, or third-party AI services after messages are delivered to Coral.

Third-party providers may have their own retention, security, and model-training policies, subject to applicable contracts, configurations, and legal requirements.

We do not make a universal guarantee that all information processed through the Services is subject to zero retention or excluded from every form of model training.

Information obtained through Google APIs remains subject to Google's applicable Limited Use requirements and related restrictions.

AI-generated information may be inaccurate, incomplete, outdated, or unsuitable for particular purposes. Users should independently verify consequential information and actions.

5. Family Spaces and Shared Information

Coral supports shared spaces in which multiple users may interact with common information and functionality.

5.1 Shared Content

Depending on the relevant permissions, family members may access shared conversations, tasks, files, memories, budgets, polls, reminders, and other information.

New members may gain access to information previously stored in the shared family space.

Personal conversation history, tasks, and memories remain separate unless shared through supported functionality or otherwise disclosed by the user.

5.2 Shared Browser Sessions

Family spaces may have shared browser environments, authenticated website sessions, and saved payment methods.

Authorized members may be able to view browser activity, use authenticated sessions, initiate actions, and manage saved website credentials or payment methods.

Browser content and screenshots may expose personal information associated with connected accounts.

Users should connect only accounts and payment methods they are authorized and comfortable making available within the relevant family space.

5.3 Personal Sharing

Certain personal tasks, connected Google applications, and scheduled activities may be shared through supported permission controls.

Personal Gmail access and personal browser sessions are not shared through these controls.

Disabling sharing prevents further access through that feature but cannot necessarily retrieve information previously copied, disclosed, or used by another participant.

Your name and family relationships may be used across relevant family spaces and personal conversations.

5.4 Responsibility for Shared Access

Users are responsible for exercising care when sharing information and granting access.

Foundative cannot guarantee that other participants will not copy, retain, disclose, or misuse information they are authorized to access.

Nothing in this section excludes responsibility that applicable law imposes on Foundative.

6. Google Integrations

Coral may provide optional integrations with Gmail, Google Calendar, Google Drive, Google Docs, Google Sheets, and Google Contacts.

Access is requested through Google's authorization process and is limited to the permissions granted.

Depending on the integration, Coral may:

  • Read and summarize emails and attachments.
  • Prepare email drafts and send messages following required confirmation.
  • Read, create, modify, or delete calendar events.
  • Find, read, create, or edit authorized files and documents.
  • Retrieve contact information and manage contacts at your request.
  • Use relevant information to carry out scheduled activities and requested tasks.

Google Drive access may cover files available under the permissions granted, while writing capabilities may be restricted to files Coral creates or that are made available for editing.

We may store encrypted authorization tokens, including refresh tokens, account identifiers, email addresses, and granted permissions.

We do not receive your Google account password through the standard Google authorization process.

Google API Limited Use Compliance

Coral's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including applicable Limited Use requirements.

Google user data subject to these requirements will not be sold to data brokers, used for targeted advertising, used to determine creditworthiness, or used to develop, improve, or train generalized AI or machine-learning models.

Such information will be accessed, used, retained, and disclosed only for permitted purposes, including providing user-facing features expressly authorized by the user.

Human access to covered Google information is restricted to circumstances permitted by Google's policies.

Disconnecting Google Services

You may disconnect Google integrations through Coral's dashboard or revoke permissions through your Google account.

Disconnecting prevents new access through the revoked authorization but does not automatically reverse completed actions or delete information previously incorporated into conversations, task results, or generated files.

You may use applicable deletion controls or contact us regarding retained information.

7. Location Sharing

Coral may receive location information when you explicitly share your location with Coral through Apple Find My.

Members of your active Coral family spaces may be able to request your shared location, including from their private conversations.

You control location sharing through Apple Find My, independently of Coral's dashboard sharing controls.

Location information may be transmitted to mapping providers, including Google Maps, to calculate routes, provide place information, or estimate travel times.

Coral may retain location-related requests, named places, sharing status, alert preferences, and arrival or departure state.

Coral does not currently maintain a separate continuous location trail as part of the described functionality. However, location responses, addresses, and map links may remain in conversations or associated records.

Location information and alerts may be delayed, inaccurate, incomplete, or unavailable.

Location alerts concerning another person may require that person's authorization.

Coral is not an emergency service or guaranteed safety-monitoring system.

8. Browser Sessions, Credentials, and Payments

When Coral performs website tasks, relevant information may be processed by browser automation providers and the websites involved.

Secure-entry mechanisms may transmit passwords or authentication codes to intended website fields without intentionally storing them as reusable passwords in AI task text.

Saved website sessions may retain authenticated browser state.

Credentials submitted directly into ordinary Coral conversations may be processed as conversation content.

Users should avoid sending passwords, authentication codes, or complete payment-card numbers through chat.

For supported payment methods, Crossmint processes original payment-card details. Coral may store limited card metadata and payment-provider references.

Approved one-time payment credentials may be transmitted through Coral's infrastructure to the relevant merchant or payment provider.

External websites and merchants may independently process information under their own privacy policies.

9. Disclosure to Service Providers

We may share information with service providers where reasonably necessary to provide the Services, fulfill instructions, maintain security, or comply with legal obligations.

Depending on the feature, these providers may include:

  • Apple and Photon: Messaging infrastructure, group interactions, polls, and location-related features.
  • Vercel and Supabase: Hosting, application infrastructure, storage, analytics, and operational records.
  • AI providers: OpenAI through Vercel AI Gateway, Typesafe's Jev, and other applicable AI-processing services.
  • Browser Use: Browser automation and related task processing.
  • Stripe: Subscription billing and payment processing.
  • Crossmint: Supported payment credentials and transactions.
  • Google: Authorized integrations and mapping services.
  • External websites, merchants, banks, and payment networks: Processing information necessary to fulfill requested actions.

Provider relationships and integrations may change as the Services evolve.

We may also disclose information where legally required, reasonably necessary to investigate abuse or security threats, or necessary to establish, exercise, or defend legal claims.

Information may be disclosed or transferred in connection with a merger, acquisition, financing, restructuring, or sale of assets, subject to applicable law and provider-specific restrictions.

We do not authorize the sale or prohibited advertising use of Google API data.

10. International Data Processing

Foundative operates in the United States.

Information may be stored or processed in the United States and other jurisdictions where our service providers operate.

Those jurisdictions may have privacy laws different from those of your country of residence.

Where required, we will use legally appropriate safeguards for international transfers of personal information.

11. Cookies and Analytics

We may use cookies and similar technologies for authentication, session management, account preferences, security, and essential website functionality.

Disabling certain cookies may prevent parts of the dashboard from operating correctly.

Coral uses Vercel Web Analytics to understand website usage and performance.

Our currently described website implementation does not use advertising pixels. Website analytics may measure page visits and certain interactions without cookies and with identifying information removed from relevant page addresses where configured.

Hosting providers and external websites may independently collect technical information or use cookies under their own policies.

12. Data Security

We implement technical, organizational, and administrative safeguards designed to protect information against unauthorized access, alteration, disclosure, and loss.

These may include authentication controls, encryption, restricted access, and other appropriate security measures.

However, no system, storage method, network, or electronic communication is completely secure.

Security incidents may arise from third-party providers, compromised credentials, unauthorized activity, shared accounts, or circumstances outside our reasonable control.

Users are responsible for protecting their devices, authentication codes, credentials, and authorized connections.

We do not guarantee absolute security or that security incidents will never occur.

Nothing in this section limits obligations or liabilities that cannot lawfully be excluded.

13. Data Retention and Deletion

We retain information for as long as reasonably necessary to provide the Services, fulfill authorized tasks, maintain security, meet legal obligations, resolve disputes, or support other legitimate purposes described in this Policy.

Account details, conversations, files, memories, preferences, and task records may remain until removed through supported controls or account deletion.

Completing a task, closing a browser, canceling a subscription, or pausing Coral does not automatically erase associated records.

13.1 Resetting a Chat

Sending /reset as a standalone message initiates a reset of the relevant space.

Depending on the type of space, this clears associated history, memories, files, tasks, browser data, saved sessions, and payment-method references.

Certain account-level details, relationships, memberships, Google connections, and sharing preferences may remain.

13.2 Removing a Family

An authorized family owner may remove a family space through Settings.

This initiates removal of shared family information and disconnection of the associated group.

Members' separate personal accounts remain unless independently deleted.

13.3 Deleting an Account

You may delete your account through supported account settings.

Deletion terminates your access and initiates cleanup of associated information and authorizations.

Your personal space and family spaces you own may be deleted as part of this process.

Family spaces owned by others may remain, with your access and attributed information removed as supported by the Services.

Your Coral subscription terminates when your account is deleted.

13.4 Information That May Remain

Some information may remain following deletion, including:

  • Records required for tax, accounting, legal, or regulatory obligations.
  • Limited security and anti-abuse records.
  • Backup information awaiting deletion under applicable procedures.
  • Information independently retained by third-party providers.
  • Messages or files copied onto another person's device.
  • Completed orders, transactions, or external actions.
  • Limited technical identifiers used to prevent duplicate processing or unauthorized account recreation.

Deletion does not reverse completed actions or guarantee the removal of information outside Foundative's legal or technical control.

We will handle deletion requests in accordance with applicable law.

14. Your Privacy Rights

Depending on your location and applicable law, you may have rights to:

  • Access personal information held about you.
  • Request correction of inaccurate information.
  • Request deletion of eligible information.
  • Obtain copies of certain personal information.
  • Withdraw consent where processing relies on consent.
  • Object to or restrict certain processing.
  • Request data portability where applicable.
  • Opt out of certain information sales, sharing, or targeted advertising activities where applicable.
  • Appeal eligible privacy-request decisions.
  • Contact a relevant supervisory or regulatory authority.

These rights may be subject to identity verification, statutory exceptions, and other applicable limitations.

We will not unlawfully discriminate against individuals for exercising their privacy rights.

Certain information and permissions can be managed directly through Coral's dashboard.

For additional requests, contact mailto:support@result.dev.

We may request information reasonably necessary to verify your identity.

15. Children's Privacy

Coral does not impose a blanket minimum age across all possible uses. However, access by minors is subject to applicable law, parental authorization requirements, and connected services' age restrictions.

Children under 13 may not use Coral unless the protections, notices, and parental consent required by applicable law have been established or a lawful exception applies.

Adding Coral to a family conversation does not constitute parental consent.

Parents or guardians seeking to arrange permitted use by a child under 13 must contact mailto:support@result.dev before such use begins.

Parents and guardians may exercise applicable rights to review or request deletion of their child's information.

We may restrict access where necessary to comply with children's privacy requirements.

16. Third-Party Services

The Services may access or interact with independent websites, applications, financial institutions, merchants, and other external providers.

Those services have their own terms, security measures, and privacy practices.

Foundative does not control independent third-party information practices and is not responsible for them except where responsibility is imposed on us by applicable law.

Users should review relevant third-party privacy policies before connecting accounts or sharing sensitive information.

17. Changes to This Policy

We may update this Policy to reflect changes in our Services, information practices, legal obligations, or technology.

Updates will be published with a revised effective or last-updated date.

Where required by law, we will provide additional notice or obtain consent before material changes or newly authorized uses of personal information take effect.

18. Legal Interpretation

This Policy describes our information practices and applicable privacy rights.

It does not create guarantees of uninterrupted service, absolute security, error-free processing, or third-party performance.

Our Services are also governed by our separate Terms of Service, including applicable provisions concerning service limitations, warranties, and liability.

Nothing in this Policy excludes, restricts, or waives a statutory privacy right, remedy, or legal obligation that cannot lawfully be limited.

19. Contact Information

For privacy questions, data requests, complaints, or concerns, contact:

Foundative Inc.
360 S Baywood Ave
San Jose, CA 95128
United States
Email: mailto:support@result.dev
Website: https://messagecoral.com (https://messagecoral.com/)

We may require reasonable identity verification before fulfilling requests involving personal information.