Privacy Policy
Last updated September 28, 2026
coLab is a workspace where teams keep their projects, tasks, notes and conversations together, with AI agents that can help. This policy explains what personal information coLab collects, why, who it is shared with, and the choices you have. It covers the coLab website at colab.neurasense.io and the coLab iOS app, which this policy calls "coLab" or "the service". "We" and "us" mean the people who run coLab.
The short version
- We collect what we need to run your account and your workspaces: your name, email address and sign-in credentials, and everything you and your teammates put into coLab.
- We do not sell your personal information, we do not show ads, and we do not track you across other companies' apps and websites.
- We do not use what you put into coLab to train AI models.
- Some features send content to other companies that process it for us, such as the AI model that answers an agent. They are listed below.
- You can delete your account yourself, in the iOS app or on the web.
Information we collect
Information you give us
- Account. Your name, your email address, and a password, a passkey, or both. Passwords are stored only as a one-way hash, never in readable form. A passkey is a public key we store; your fingerprint or face never leaves your device.
- Your content. Projects, tasks, milestones, notes, decisions, comments, chat messages and reactions, files and images you attach, documents and hosted previews you upload, LaTeX projects, and the instructions you give to agents. What you write in a workspace is visible to the people who have access to that workspace or project, under the roles its owners set.
- Invitations and guests. When you invite someone, we store their email address, and their name if you give one, to send the invitation. A guest invited to review a hosted preview has an email address, a name, and the comments they write.
- Billing. Where a workspace has a paid plan, payment is handled by Stripe on its own pages; we do not receive or store card numbers. We keep the plan, its status, Stripe's identifiers for the customer and subscription, and a record of usage against the plan's allowance.
- Messages to us. If you write to support, we keep the conversation.
Information collected as you use coLab
- Sign-in. A cookie named sw_session keeps you signed in. It is essential to the service and is not used for advertising. If you create an API token, we store only a one-way hash of it.
- Activity in your workspace. Who is viewing a project, typing indicators, who joined a huddle, notifications and whether you have read them, and a log of what agents did and who asked them to.
- Devices and notifications. For the iOS app: the device's name (such as "iPhone 16"), platform, app version, when it was last used, and the push token Apple and Expo use to reach it. For the web: the push subscription your browser gives us. These are used only to deliver notifications to you.
- Technical data. Our hosting provider logs requests, including IP address, browser and device type, and the pages requested, for security and reliability. We use Vercel Web Analytics to count page views; it does not set cookies.
- Preferences on your device. Your theme and hint settings are kept in your browser's storage. The iOS app keeps drafts of messages you have not sent on your phone.
- Reports and blocks. When you report a message, we keep a copy of it, who wrote it, where it was posted, the reason you gave and your name, so that we can review it. The person who wrote it is not told who reported it. When you block someone, we keep a record that you did, so that we can hide them from you; they are not told.
- Link previews. When a message contains a web link, our servers fetch that page to show a preview card (title, description and image) and keep it with the message.
Information from services you connect
Only if you, or an owner of your workspace, connect them:
- Slack. To send notifications and to let you sign in with Slack. We receive your Slack name and user identifier and store a bot token, encrypted.
- Telegram. To send notifications. We store the identifier of the Telegram chat you link.
- Microsoft Outlook Calendar. To show and schedule meetings. We store the access needed to keep the connection working and the calendar events we display.
- GitHub. To connect a repository to a project. Agents and background jobs can read the code and issues that connection allows.
How we use information
- To provide, secure and operate coLab: to sign you in, enforce who can see what, and show your content to your teammates.
- To deliver notifications by push, email, Slack or Telegram, as you have chosen.
- To run agents and AI features that you or your teammates use (see below).
- To send service email: invitations, password resets and notification email. We do not send marketing email.
- To process payments and apply plan limits.
- To detect abuse, fix problems and keep the service reliable. This includes checking messages for slurs and abusive language before they are posted, which happens on our own servers, and reviewing messages people report.
- To answer your questions, and to comply with the law.
AI features
- Agents. When you message an agent, mention one, or an automation wakes one, coLab sends the message and the project context the agent needs (for example the conversation, related tasks and notes, and files it is allowed to read) to OpenAI, which produces the reply and any actions. Agents act only with the access their workspace gives them, and some actions wait for approval.
- Jev. coLab uses a fast model from TypeSafe, called Jev, to decide whether a message actually asks an agent for something, to answer simple questions from your workspace, and to suggest next steps such as turning a message into a task or a meeting. The text of the message being judged is sent to TypeSafe, and in the web app that includes text you are writing in a channel when you pause typing, before you send it.
- Coding tasks. When an agent works on a connected repository, the work runs in an isolated sandbox, on Vercel or on a machine your workspace connects, and may use models from Anthropic.
- LaTeX. LaTeX projects are stored and compiled on an Overleaf server operated for coLab.
- We do not use your content to train models. These providers process it under their own API terms.
- AI can be wrong. Please check what it produces before you rely on it.
Who we share information with
- People in your workspace. Your name, your content, and your activity are visible to the members who have access to the project or conversation concerned.
- Service providers. Companies that process information for us to run coLab:
- Vercel: hosting, page-view analytics and sandboxes.
- Neon: our database.
- Cloudflare: private storage for attachments.
- Resend: sending email.
- Expo, with Apple and Google: delivering push notifications.
- LiveKit: carrying the audio of huddles in real time. We do not record huddles.
- Liveblocks: live co-editing of notes.
- OpenAI, TypeSafe and Anthropic: the AI features above.
- Stripe: payments for paid plans, where they are offered.
- Services you connect, such as Slack, Telegram, Microsoft and GitHub, receive what is needed for the feature you turned on.
- Legal and safety. We may disclose information if the law requires it, or to protect people, the service, or our rights.
- A change of ownership. If coLab is transferred to another owner, your information goes with it, and this policy continues to apply until you are told otherwise.
We do not sell personal information, and we do not share it for advertising.
Where it is processed
Our providers operate in several countries, so your information may be processed outside the country where you live.
How long we keep it
We keep information while your account and the workspaces you belong to exist.
When you delete your account, it happens at once. Your profile, sign-in sessions, passkeys, tokens, workspace memberships, notifications, devices, and links to Slack and Telegram are deleted. What you wrote for your team, such as messages, tasks, notes and comments, stays in the workspace so that its history still makes sense, and your name on it is replaced with "Deleted user". Unanswered invitations sent to your email address are deleted.
A workspace that nobody else belongs to is deleted along with your account, with everything in it. You cannot delete your account while you are the only owner of a workspace that has other members; make one of them an owner first. Nor while a workspace only you belong to has a paid subscription; cancel it first. Copies may remain in backups and logs for a limited time after deletion. A report of a message is kept after the message or either account is deleted, with the reported text and the names involved, as the record of how it was handled.
Your choices and rights
- Edit your profile and settings in the app, and turn notifications off in the app or in your device's settings.
- Disconnect Slack, Telegram or Outlook from your account settings.
- Delete your account: on the web under Account settings, or in the iOS app under Settings, then Delete account.
- Depending on where you live, you may have the right to ask for a copy of your information, to correct it, to delete it, to object to or restrict how we use it, and to complain to your data protection authority. Write to us at the address below and we will respond within 30 days.
Security
Traffic to coLab is encrypted in transit. Passwords are hashed, API tokens are stored as hashes, credentials you give us for integrations are encrypted, and attachments are kept in private storage. No system is perfectly secure, so please use a strong, unique password or a passkey.
Children
coLab is not directed to children under 16, and we do not knowingly collect their information. If you believe a child has given us personal information, write to us and we will delete it.
Changes to this policy
When we change this policy we will update the date at the top, and for material changes we will tell you in the app or by email before they take effect.
Contact
Questions, requests, or concerns about privacy: ssm123ssm@gmail.com.