ColloAI

Privacy

Last updated 11 August 2026

ColloAI runs conversations on behalf of the organisations that use it, and scores those conversations against criteria the organisation sets. This page explains what that means for your data, in plain terms.

ColloAI is operated by [COMPANY LEGAL NAME], registered at [REGISTERED ADDRESS]. For anything on this page, write to privacy@colloai.com.

Two kinds of people

Organisers sign up, create conversations and read the reports. For their account data, we are the data controller.

Participants are the people who have the conversation. They are usually invited by an organiser and never create an account. For their conversation data, the organiser is the controller and we act as their processor: we handle it on their instructions, and requests about it are best addressed to whoever invited you. We will always help.

What we collect

From organisers:

  • Name and email address, and a password if you set one
  • The workspace name, and the events, criteria and settings you create
  • Credit and plan history, so we can bill correctly

From participants:

  • Whatever you type or say during the conversation, kept as a transcript. If voice is switched on, your speech is transcribed to text; we do not keep the audio recording after transcription.
  • The name and email address the organiser supplied when inviting you, if they supplied one. Public links collect neither.
  • The AI’s scores and written summary of the conversation, which the organiser can read.
  • A one-way hash of your IP address, used only to stop one person opening conversation after conversation. It cannot be turned back into an IP address, and it is salted per event so the same visitor cannot be recognised across different organisers.

We do not run advertising, we do not sell data to anyone, and we do not build profiles of people across the organisations that use us.

Why we are allowed to hold it

  • Performing our contract with the organiser — running the conversation, producing the report, taking payment.
  • Legitimate interests — keeping the service secure, preventing abuse of public links, and keeping accounts working.
  • Legal obligation — keeping billing records for as long as tax law requires.

Who else sees it

We use a small number of suppliers. Each one only receives what it needs to do its job.

  • Supabase — the database holding accounts and transcripts. Hosted in Paris (eu-west-3); your data sits at rest in the European Union.
  • Vercel — runs the application itself.
  • Anthropic — the AI model that conducts the conversation and writes the scores. Conversation text is sent to Anthropic to generate each reply. Anthropic does not use it to train its models.
  • OpenAI — speech-to-text and text-to-speech, and only for organisations that have voice switched on. Voice is off by default.
  • [EMAIL PROVIDER] — sends sign-in links and account emails.

Some of these process data outside the European Economic Area, in the United States. Where that happens it is covered by the European Commission’s standard contractual clauses.

The AI writes the scores

Every score and summary in a report is generated by an AI model reading the transcript. It can be wrong, and it can miss things. Our terms require organisers not to treat a score as the sole basis for a decision about you, and not to make a decision with legal or similarly significant effects on you automatically. If a report about you looks wrong, you can ask the organiser for a human to look at it.

How long we keep it

  • Conversation transcripts and reports: for as long as the organiser keeps the event, and until they or we delete it.
  • Organiser accounts: until the account is closed.
  • After an account is closed: 30 days, then permanent deletion, except billing records we are required to keep.
  • Abuse-prevention hashes: 30 days.

Your rights

If you are in the UK, the EU or another place with similar law, you can ask for a copy of your data, ask us to correct it, ask us to delete it, object to what we are doing with it, or ask for it in a portable form. You can also complain to your national data protection authority.

Write to privacy@colloai.com and we will answer within 30 days. If you are a participant, tell us the organisation that invited you so we can find the right record — we will pass the request on to them where they are the controller, and act on it ourselves where we can.

Cookies

Two, and no more. One keeps you signed in. One remembers which language you chose for the interface. There is no analytics, tracking or advertising cookie on this site, which is why there is no cookie banner.

Security

Every organisation’s data is separated in the database itself, so one customer’s queries cannot reach another’s rows. Conversation links are random tokens, stored only as hashes and expiring on a date the organiser sets. Traffic is encrypted in transit and data is encrypted at rest.

Children

ColloAI is not intended for anyone under 16. We do not knowingly collect data about children; if you believe we have, write to us and we will delete it.

Changes

If we change anything material here we will update the date at the top and email account holders. Continuing to use ColloAI after that means accepting the new version.

See also our terms of service.