Scope, controller, and workspace roles
This Privacy Policy applies to Coul's websites, applications, creator workspaces, AI tools, public-data features, and related support. It covers registered users, workspace members, visitors, waitlist contacts, and non-users whose information from approved public-profile sources appears in Coul.
Coul is the controller and, where the statutory criteria apply, the business for account administration, security, billing, Coul's product analytics, public or competitor-data collection, prediction research, Coul's own service decisions, and legal compliance. The controller is the Coul service operator identified in the Service and transaction record. A production launch must also display that operator's verified legal name and geographic address directly in this policy and at checkout. Do not submit payment if those details are absent.
Coul acts as a processor or service provider only when it handles workspace, customer, client, or campaign content solely on the customer's documented instructions. The customer organization is then the controller and, where the statutory criteria apply, the business, and its instructions and data-processing agreement also apply. If Coul uses that content for its own purpose beyond those instructions, Coul must identify its separate role and provide the notice, choice, and legal basis the purpose requires. Contact the organization first for a request about content it controls; Coul will assist it as required.
Account, workspace, and relationship data
Coul collects information you provide when joining the waitlist, creating or verifying an account, setting up a profile, joining a workspace, selecting a niche or audience, contacting support, or communicating with Coul.
Name or display name, email address, password hash, verification and recovery records, account status, language, time zone, and preferences.
Workspace name, membership, invitation, role and permission records, seat assignments, and actions by owners or administrators.
Onboarding choices such as target audience, niche, selected competitors, goals, brand voice, and content preferences.
Waitlist, support, feedback, survey, and legal-request communications, including attachments you choose to send.
Session, sign-in, verification, IP address, user-agent, security, rate-limit, and audit events used to protect accounts and investigate misuse.
Uploads and derived media data
When you upload or link content you are authorized to analyze, Coul may process the original video, image, audio, script, caption, or other file and create service artifacts needed for analysis, editing, accessibility, preview, and publishing.
File name, type, size, duration, dimensions, frame rate, codec, hashes, upload state, and other technical metadata.
Private stored originals, optimized versions, clips, thumbnails, previews, requested edits, and publishing variants.
Audio and speech transcripts, timing and beat data, visual descriptions, tags, suggested alt text, captions, and media quality or malware-scan results.
Virality reports, component scores, retention risks, recommendations, edit decisions, and links between media and a workspace, project, calendar item, or report.
Prompts, outputs, embeddings, and memory
Coul processes prompts, instructions, selected context, generated scripts and ideas, AI edits, model responses, feedback, safety results, usage and cost telemetry, and error information to provide AI features and troubleshoot them.
Coul can create embeddings and semantic summaries from authorized content, transcripts, profiles, templates, reports, preferences, and prior outputs so the Service can retrieve relevant context and personalize later work. An embedding linked to a person or workspace is personal data; it is not treated as anonymous merely because it is numerical.
Workspace-scoped memory is separated by account or workspace controls. Workspace owners and authorized members may be able to see or use shared memory, content, and outputs according to their roles.
Analytics, schedules, and publishing data
Coul processes connected-account metrics, normalized public metrics, comparisons, reports, dashboard filters, exports, and derived insights. These may include estimates and snapshots rather than live platform facts.
For calendars and publishing, Coul processes drafts, media, captions, target accounts, network, time zone, scheduled time, recurrence or automation settings, approval state, provider identifiers, attempts, retries, responses, errors, and delivery outcome. Publishing records help prevent duplicates, show status, and investigate failures.
Daily AI recommendations use your goals, niche, audience, prior activity, and permitted competitor patterns. Automatic publishing occurs only when separately enabled; Coul keeps the instruction and execution record needed to perform and audit it.
Competitor and public-profile data
Coul uses Bright Data and supported source links to collect and normalize information it is permitted to obtain from approved public sources on Instagram, TikTok, X, and other sources identified in the product. This can concern Coul users or people who have never created a Coul account. Public accessibility alone does not establish permission for every collection or reuse.
The source is usually the public profile or post, a user-supplied public link, or a public-data provider. Public availability does not make content public domain or eliminate privacy rights. The Public/Competitor Data Notice explains legal purpose, model use, retention, correction, and the non-user removal process.
On a verified request, Coul provides available source URLs, collection or snapshot dates, categories of data, and available origin information. Coul gives direct notice to a person whose data it obtains indirectly when applicable law requires it, unless Coul documents a valid legal exception. Coul does not intentionally select children's profiles for competitor tracking or prediction research.
Profile or post identifiers, handle, display name, biography, avatar and source URLs, verification status, and public account attributes.
Follower, following, post, view, like, comment, share, and other publicly visible counts or rates, plus dates and snapshots.
Post text, captions, hashtags, mentions, thumbnails, media references, format, source link, and other publicly visible post metadata.
Derived summaries, categories, trend signals, hook or format patterns, comparisons, embeddings, and relevance scores.
Billing and transaction data
Stripe processes checkout and payment credentials. Coul receives and stores transaction metadata needed to manage service access, such as Stripe customer and subscription identifiers, plan, status, billing period, trial information, usage, invoice or receipt references, and billing/webhook events.
Coul does not need to receive a full card number or card security code from Stripe-hosted payment fields. Stripe independently processes payment details under its own privacy terms. Coul may process billing contact information, tax or location data, last-four-digit or payment-method descriptors, chargeback information, and support communications when supplied by Stripe or you.
Device data, browser storage, cookies, and logs
Coul and its infrastructure process IP address, user-agent, device and browser type, operating system, approximate region derived from IP, language, timestamps, requested route, referrer where available, interaction and performance events, crash or error data, security signals, and identifiers needed for sessions and abuse prevention. The public waitlist uses Google reCAPTCHA Enterprise as strictly necessary abuse protection; the browser obtains a short-lived risk token from Google and Coul sends that token, the registered site key, and the expected waitlist action to Google Cloud for assessment before accepting an address. When analytics consent is active, PostHog receives scrubbed page routes and selected product-lifecycle events under the limits described in the Cookie Policy; it does not receive Coul prompts, captions, uploads, emails, usernames, or provider credentials through this integration.
The web app uses browser storage for signed-in session data, OAuth attempts, preferences, drafts, personalization, and other continuity features. Cookies or equivalent technologies may be essential, functional, analytics, or advertising technologies. The Cookie Policy lists what is actually enabled, its provider and duration.
Non-essential analytics or advertising technology must remain disabled until Coul provides the required notice and choice. As of the effective date, Coul does not sell personal data for money or other valuable consideration and does not share personal data for cross-context behavioral advertising, as those terms are defined by applicable law. Disclosures to contracted service providers for the business purposes described here are not treated as a sale or advertising share where law permits that distinction. If the practice changes, Coul will update this policy before it begins and provide any required opt-out, including support for legally recognized preference signals.
Where information comes from
Directly from you, including account forms, uploads, prompts, settings, support, and rights requests.
From workspace owners, administrators, teammates, clients, or people who share content or invite you.
From social platforms you connect or instruct Coul to access, and from their APIs and webhooks.
From public profiles, public posts, user-supplied source links, and public-data providers such as Bright Data.
From payment, email-delivery, infrastructure, security, and other providers supporting the Service.
Through your browser, device, and use of Coul, and through inferences or outputs generated from the permitted data above.
Why Coul uses information and applicable legal bases
Coul uses personal data only for described, compatible purposes. Where GDPR or UK GDPR applies, the legal basis depends on the purpose and relationship; the same activity may have a different lawful basis in another context.
Contract: create and secure an account, provide requested analysis, editing, generation, memory, collaboration, analytics, scheduling, publishing, support, and paid-plan administration.
Legitimate interests: protect accounts and the Service; prevent fraud and infringement; maintain reliability; measure limited product performance; improve usability; and provide carefully assessed public-data benchmarking and prediction research. Coul balances these interests against people's rights and offers objection where required.
Consent: optional cookies or marketing, an optional private-content training choice, and another activity when law requires consent. Consent can be withdrawn without affecting earlier lawful processing.
Legal obligation: tax and accounting duties, valid legal process, sanctions or fraud controls, regulator responses, and privacy or consumer-rights requests.
Legal claims and safety: establish, exercise, or defend rights and protect users, Coul, platforms, and the public where necessary and lawful.
Who receives information
Coul shares only what is reasonably needed for the purpose, subject to contracts and access controls where applicable.
Infrastructure and operations providers for hosting, PostgreSQL, Redis, S3-compatible object storage, Qdrant vector memory, email delivery, observability, security, and support.
PostHog for consent-gated product analytics, limited to scrubbed page routes, pseudonymous or internal user identifiers, device/browser context, and selected product-lifecycle properties described in the Cookie Policy.
Google Gemini API for configured AI inference and generation; Google reCAPTCHA Enterprise for waitlist abuse assessment; Bright Data for public social-data collection; and Stripe for checkout, subscriptions, invoices, and payment events.
Instagram/Meta, TikTok, X, and another supported platform when you connect it, request data, or instruct Coul to publish.
Authorized workspace members, owners, administrators, template users, or public recipients, according to your settings and the feature used.
Professional advisers, auditors, insurers, authorities, courts, or counterparties when necessary for compliance, safety, or legal claims.
A buyer, investor, affiliate, or successor in a financing, reorganization, merger, or sale, subject to appropriate confidentiality and notice where required.
AI processing and model-training choices
Coul uses private uploads, prompts, outputs, transcripts, and workspace memory to perform the feature you request and personalize retrieval inside the authorized account or workspace. Coul does not use that private content to train a shared or general-purpose model unless it first presents a separate, specific opt-in that explains the data, model, purpose, retention, and how to withdraw.
Coul may use aggregated or deidentified service measurements and deliberately contributed evaluation examples to test safety, quality, and calibration. Deidentified means Coul has applied measures intended to prevent the information from being linked back to a person and does not attempt to reverse them; merely hashed or embedded information is not called anonymous.
As of the effective date, Coul does not use public-profile personal data—including creator identifiers, media, captions, or profile-linked embeddings—to train a shared, general-purpose, generative, or Coul prediction model. Public data may be used at request time for retrieval, benchmarking, inspiration, and analytics. Coul may use genuinely aggregated or deidentified performance statistics and deliberately contributed evaluation examples for quality and calibration, but not to recognize a person or reproduce a creator's video. Coul will give advance notice and establish an applicable legal basis and choice before beginning a materially different training use.
AI providers receive prompts and context for inference. Before production processing, Coul must verify that the selected provider tier, contract, region, retention, and data-use controls match this policy. Coul will not claim that a provider never retains or trains on data until those settings are verified and disclosed.
How long information is kept
Coul keeps information for the shortest period reasonably needed for the described purpose, then deletes, deidentifies, aggregates, or isolates it unless law, security, a dispute, or a valid legal hold requires longer. The period depends on account status, user settings, plan, record type, provider limits, and legal obligations.
Active account and workspace records: while needed to provide the selected feature or maintain the relationship. Deleting an item removes it from active use through the relevant workflow; account or workspace closure triggers the staged deletion process below, subject to specifically disclosed legal, security, shared-copy, and backup exceptions.
Account/workspace deletion: normally scheduled with a 30-day restoration grace period; the confirmation must show the actual purge date. Cleanup can take longer when a provider fails and retries or a legal exception applies.
Raw Bright Data result artifacts: 90 days by default; a production configuration may shorten this to no less than 30 days. Normalized public records remain only while relevant and necessary, subject to refresh, source removal, objection, and the Public Data Notice.
Stripe and social webhook payloads: sensitive payload content is ordinarily redacted after 24 hours; limited event metadata may remain for security, audit, reconciliation, and legal duties.
Profile export files: 7 days. Canvas autosave patches: 30 days. Pending OAuth state: about 10 minutes.
Expired or revoked session/refresh-token records: maintenance deletion after about 30 days. Expired verification challenges: maintenance deletion after about 7 days.
Billing, tax, fraud, chargeback, audit, legal-request, deletion-tombstone, and dispute records: for the applicable statutory, limitation, or security period, with access restricted to that purpose.
Backups: deletion removes data from active systems first. Isolated backup copies age out on the verified production backup cycle; if a backup is restored for disaster recovery, the deletion is reapplied before the data returns to ordinary use.
Deletion and disconnection mechanics
When account or workspace deletion is scheduled, Coul disables the context and revokes active sessions. During the displayed grace period, restoration may be possible; after cleanup starts, it is not. A person who is the last active owner must transfer or delete the workspace before personal deletion can complete.
The cleanup process cancels scheduled work, attempts social-provider revocation and Stripe-customer deletion where appropriate, erases encrypted secret material, deletes object-storage files and versions, Redis artifacts and Qdrant points, and deletes or redacts database records. Provider operations can fail and retry, so deletion is not always instantaneous everywhere.
Coul may retain bounded records for tax, payment, fraud prevention, safety, legal claims, request evidence, and suppression of removed public data. Shared template copies created by other users can remain without retaining the original author's private media. The Data Rights page explains requests, status, exceptions, and appeal.
International data transfers
Coul and its providers may process information in countries other than where you live. Laws in those places may differ. Where EU, EEA, UK, Swiss, or other transfer restrictions apply, Coul uses a lawful mechanism appropriate to the actual flow, such as an adequacy decision, approved standard contractual clauses, the UK Addendum or IDTA, or a narrow statutory exception, together with supplementary measures where required.
Coul will rely on a Data Privacy Framework certification only for an entity and transfer that are actually covered. The production subprocessor register must identify relevant locations and safeguards. You may request information about the applicable mechanism through the Data Rights page.
Your privacy rights and choices
Depending on where you live and Coul's relationship with you, you may have rights to know or access personal data, receive a portable copy, correct it, delete it, restrict or object to processing, withdraw consent, opt out of sale, sharing, targeted advertising or certain profiling, limit certain sensitive-data uses, and receive equal service without unlawful discrimination.
The Data Rights page explains the available channels, verification steps, timing, exceptions, and appeals. Before public launch, Coul must activate and test a monitored intake that issues receipt and status information and accepts both account-holder requests and non-user public-data removal requests. A static page or administrator-only deletion tool is not that intake.
Use the channel identified on the Data Rights page once it is marked active. You do not need a Coul account to request removal of public-profile data.
Coul may verify identity and authority proportionately. An authorized agent can act where law permits, but Coul may request proof and direct confirmation.
A request can be limited or denied when an exception applies, another person's rights would be harmed, identity cannot be verified, or Coul must retain the record. Coul will explain the reason where required.
Where applicable, you can appeal a refusal through the route in the response and complain to your local data-protection, privacy, or consumer authority.
Workspace-controlled content requests may be referred to the organization that controls the data, with Coul assisting as its processor.
Profiling and automated decisions
Coul uses profiling to estimate virality, personalize ideas, compare performance, detect security or misuse signals, and recommend content. Viral scores and recommendations do not ordinarily make a decision with legal or similarly significant effects about a person; they support a creator's own decision and can be ignored or edited.
Security systems may automatically rate-limit or temporarily block suspicious activity. Consequential account suspension should include notice, a reason, and human review or appeal where required. If Coul introduces solely automated decisions with legal or similarly significant effects, it will provide a specific notice about logic, consequences, and safeguards before use.
How Coul protects information
Coul uses technical and organizational safeguards appropriate to the data and risk, including tenant-scoped access, role controls, encrypted social-token envelopes, audited secret access, authorization-gated signed media links, file type and size validation, rate limits, durable job records, deletion workers, and monitoring. The Security/Trust page explains these measures, deployment dependencies, and known gaps without claiming certifications Coul has not earned.
No service can guarantee absolute security. Keep credentials private, use available account protections, review workspace members and connected scopes, and contact Coul promptly if you suspect unauthorized activity.
Children and sensitive information
Coul is for people who are at least 18 and the age of legal majority where they live. Coul does not knowingly offer accounts to children. If you believe a child created an account or appears in public data in a way that should be removed, use the Data Rights page.
Do not submit highly sensitive information unless it is necessary, lawful, and appropriate for the selected feature. Media and prompts can incidentally reveal health, political, religious, sexual-orientation, precise-location, biometric-like, or other sensitive facts. Coul does not intentionally infer sensitive traits or identify people from faces or voices for advertising or eligibility decisions.
Changes, questions, and contact
Coul may update this policy when data practices, providers, features, or law change. The updated date will change, and Coul will give advance or prominent notice of a material change where required. A new purpose that requires consent will not rely only on continued use.
The /data-rights page explains access, export, correction, objection, deletion, appeal, token-revocation, and non-user public-data removal options, but must not be presented as an active tracked intake until the monitored workflow described above is live. For general questions, email privacy@coul.app. Before public launch, Coul must verify that this mailbox is monitored and add the controller's legal name, geographic address, and any legally required DPO or EU/UK representative details—without inventing roles that have not been appointed.
Contact
Ask a privacy question
The Data Rights page explains request options. For a general privacy question, contact the privacy team and include only the information needed to understand your concern. Coul must activate and test a monitored rights-request intake before launch.
Connected social accounts and OAuth data
When you connect a supported social account, the platform sends Coul the information and permissions shown during authorization. Coul processes it to display connected profiles, retrieve authorized analytics, refresh access, and perform publishing actions you request.
Platform, account and provider identifiers; handle, display name, profile URL or avatar; connection and publishing status.
Authorization state, granted scopes, token type, issue and expiry information, and encrypted access or refresh tokens. Coul audits access to token secrets and does not place plaintext tokens in ordinary metadata.
Connected-profile posts and metrics, audience or performance insights, sync status, provider rate limits, and errors.
OAuth callback and state data used briefly to complete and protect the connection. Pending OAuth state normally expires after about 10 minutes.