1. Scope
This Privacy Policy explains how Corners collects, uses, and protects information when you use Corners websites, web and desktop apps, APIs, Model Context Protocol integrations, notifications, and related services.
Corners is built for business and workplace use. If your employer, workspace, or another organization gives you access to Corners, that organization may control the workspace content and account settings associated with your use.
2. Information we collect
Account information. We collect details used to create and manage accounts, including workspace names, organization names, user names, handles, email addresses, roles, profile information, avatar images, authentication methods, and related account settings.
Workspace content. We process the content you and your workspace provide or generate in Corners, including messages, workstreams, checkpoints, questions, learnings, tasks, documents, datatables, calendar events, meeting notes, transcripts, files, attachments, reactions, comments, and other collaboration records.
Connected-service information. When you connect external services, Corners may receive data from those services, such as Slack workspace, channel, user, message, and thread data; email addresses, headers, message bodies, and attachments; calendar event, attendee, reminder, and RSVP data; and other data made available by integrations you authorize.
Device, usage, and diagnostic information. We collect information needed to run, secure, debug, and improve the service, including IP addresses, request metadata, browser and device information, app version, routes visited, performance signals, subscription connection diagnostics, crash or client-error reports, logs, telemetry, notification delivery data, and approximate usage volume.
Payment and administrative information. If billing features are enabled for your workspace, we may process billing contacts, usage records, audit events, and account administration metadata. Payment processors may collect payment details directly under their own terms.
3. How we use information
We use information to provide, secure, maintain, and improve Corners; authenticate users; route users to the right workspace; support collaboration features; sync connected services; provide search, notifications, and real-time updates; create and manage files and meetings; troubleshoot issues; prevent abuse; measure product usage; and communicate with you about the service.
We may use aggregated, de-identified, or workspace-level operational data to understand adoption, reliability, and product performance, and to develop or improve Corners features.
4. AI features and customer content
Corners uses AI to help summarize, search, draft, classify, route, and act on workspace content. AI features may process prompts, messages, documents, calendar events, meeting transcripts, files, connector data, and other workspace context needed to provide the requested feature.
Corners may use customer content and interaction data to provide, evaluate, and improve Corners AI features and product behavior. We do not sell customer content to advertisers.
Google Workspace API data is handled under the additional limits in Section 6. Corners does not use Google Workspace API data to train or improve generalized artificial intelligence or machine-learning models.
Some workspaces may configure their own AI provider keys. When they do, relevant content may be sent to that provider using the workspace's configured key. Otherwise, Corners may use platform-configured AI providers such as OpenAI or similar subprocessors.
5. Connected services
If you connect Slack, email, calendar, meeting, storage, developer, document, project-management, or other external services, Corners will process the data those services provide according to your settings and the permissions granted during connection.
You can disconnect supported integrations from Corners settings. Disconnecting a service may stop new syncs, but previously imported workspace records may remain until deleted by an authorized user or handled through a deletion request. Google Workspace API data follows the more specific retention and deletion rules in Section 6.
6. Google Workspace API data
What Corners accesses. If you connect a Google account, Corners accesses only the Google products, capabilities, and resources you authorize. This may include Drive files or folders you select; Gmail messages and metadata returned by an on-demand query or by owner-selected labels or saved-query rules; and events on calendars you select. Google grants OAuth scopes to the connected product, while Corners enforces the narrower Corner, resource, audience, and read/write rules you configure.
How Corners uses and shares it. Corners uses Google Workspace API data only to provide the user-facing integration, search, synchronization, drafting, write, and AI-assisted features you request. When you invoke an AI feature, relevant Google data may be sent to the AI provider configured for your workspace solely to return the requested result. Corners does not sell Google Workspace API data, use it for advertising, use it to determine creditworthiness, or transfer it except to provide those visible features with your consent, for security, to comply with law, or as otherwise permitted by the Google User Data Policy. Human access is prohibited except with your explicit consent for specific data, when necessary for security, or when required by law.
Gmail and Calendar retention. Gmail message bodies, subjects, attachments, and transient search results, as well as Calendar event details and attendee information, are fetched and processed only for the live request. Corners does not retain that content in its database, queues, logs, traces, analytics, conversations, embeddings, search caches, retry records, or dead-letter storage. A content-free marker may record that a transient Google result was viewed. If you explicitly choose Save to Corner after reviewing a preview, Corners stores only the derived output you approve as a new user-authored Corner artifact; it does not silently copy the source payload.
Drive retention. For Drive resources you select, Corners may retain encrypted extracted text, current file metadata and revision identifiers, and access-controlled search embeddings to provide browsing, search, synchronization, and performance. Corners does not retain raw Drive binaries or revision history, replaces prior extracted revisions atomically, denies access immediately after deselection or revocation, and cryptographically deletes the final unreferenced cached derivative within 24 hours.
Integration metadata and sharing. Corners may retain encrypted OAuth credentials, selected resource identifiers and rules, watch or history cursors, health state, consent and approval records, and content-free security and write audit records. A Google integration is owner-only by default. If its owner explicitly shares it with a Corner and a Corner manager approves, current and future Corner members and Corner-scoped AI may use only the approved resources and actions while acting as the named Google identity. The owner sees a detailed warning before sharing. Workspace administrators may reduce, pause, revoke, disconnect, or purge permitted integrations, but cannot browse Google content or use a member's credentials.
Your controls and deletion. You can pause or remove a Corner attachment, narrow its resources and capabilities, disconnect an individual Google product, or revoke Google access. Revocation disables affected Corner grants and provider watches immediately, deletes the encrypted product credential, and schedules deletion of retained Drive derivatives. You may also contact privacy@corners.app for help managing or deleting Google-derived data.
The use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
7. Cookies and local storage
Corners uses cookies and similar browser storage for authentication, workspace routing, preferences, layout state, theme settings, drafts, notification device identifiers, meeting or guest access flows, and reliability features.
The primary session cookie is used to keep you signed in and is set with security controls such as HttpOnly, SameSite, and Secure where appropriate. Local storage and session storage may be used for non-secret preferences and app recovery state.
8. Analytics, telemetry, and logs
Corners collects operational telemetry and logs to understand reliability, performance, realtime connection health, rendering issues, product usage, and abuse or security events.
We may add product analytics or marketing measurement over time. When we do, we will use that data to understand how people find and use Corners, improve the service, and communicate with interested users.
9. How we share information
We share information with service providers and subprocessors that help us operate Corners, including cloud hosting, databases, storage, logging, email delivery, push notifications, AI providers, video and transcription providers, analytics, security, and customer support tools.
Current infrastructure and product integrations reflected in Corners include Google Cloud hosting, Cloud SQL, Cloud Storage, Cloud Logging, Firebase push services, Resend email, Slack, AI providers such as OpenAI, and meeting or transcription providers such as LiveKit. Additional connected services may process data when your workspace authorizes them.
We may disclose information if required by law, to protect rights and safety, to investigate abuse or security issues, or as part of a merger, financing, acquisition, or similar business transaction.
We do not sell personal information. We may add analytics or marketing measurement, but we do not share customer content for cross-context behavioral advertising.
10. Security
Corners uses administrative, technical, and organizational safeguards designed to protect information, including encrypted transport, access controls, workspace scoping, signed or time-limited URLs for private files where appropriate, credential encryption for selected integration tokens, monitoring, and structured security logging.
No online service can guarantee complete security. Please use strong credentials, protect access to your workspace, and tell us promptly if you believe an account or integration has been compromised.
11. Retention and deletion
We keep information for as long as needed to provide Corners, maintain your workspace, comply with legal obligations, resolve disputes, enforce agreements, secure the service, and preserve operational records.
Workspace owners and authorized users may delete certain content inside Corners. You may also contact us to request access, correction, export, or deletion. We will honor requests where required and feasible, subject to backups, security records, legal obligations, abuse-prevention needs, and records that must be retained for legitimate business purposes.
12. Your choices and rights
You may update profile and workspace settings in the app, disconnect supported integrations, change notification preferences, request an export or deletion, or ask us to correct inaccurate personal information.
Depending on where you live, you may have rights to know, access, correct, delete, or receive a copy of personal information. California residents may have additional rights under California privacy laws, including the right to know categories of personal information collected, used, disclosed, or shared; request deletion or correction; and not be discriminated against for exercising privacy rights.
To make a privacy request, contact privacy@corners.app. We may need to verify your identity and workspace authority before acting on a request.
13. International use
Corners is operated from the United States. If you access Corners from outside the United States, your information may be processed in the United States and other countries where Corners or its service providers operate.
14. Age limits
Corners is intended for business use by adults and authorized workplace users. Corners is not intended for personal use by children or users under 18.
15. Changes to this policy
We may update this Privacy Policy as Corners evolves. If changes are material, we will provide notice through the app, by email, or by updating this page with a new effective date.
16. Contact
Questions or privacy requests can be sent to privacy@corners.app.