Back to home
Legal

Privacy Policy

Last updated: April 13, 2026

Thank you for choosing COET. Safeguarding your privacy and the confidence you place in us is fundamental to how we build and run our service. This Privacy Policy describes what personal data we gather, how we put it to use, and the options available to you.

We are committed to keeping your information safe. Your data is yours — when you remove your notes, recordings, images, or any other content, that data is permanently erased from our servers.

If you disagree with any part of this Policy, please stop using the Service. Terms not defined here carry the meanings assigned in the COET Terms of Service.

1. Information We Collect

1.1 Account and Contact Information

When you create or manage an account, we collect:

  • Email address and authentication details, including identifiers from Apple Sign-In or email/password registration.
  • Billing-related information such as payment token identifiers when you purchase credits or a subscription through the App Store.

1.2 Creative Inputs and Outputs

To deliver the Service, we process text prompts, reference photos, audio recordings, notes, and AI-generated content (transcriptions, rewritten text, generated images). This data is collected directly from your input when you type, record audio, or select photos within the app. We store this content as long as necessary to provide features such as history, editing, and cross-device synchronization.

1.3 Device and Usage Information

We automatically collect technical data when you use the Service, including device type, operating system, app version, and system language. We also gather diagnostics such as crash logs, performance data, and anonymized interaction events to improve the app.

1.4 Support and Communications

When you reach out to us via email or submit in-app feedback, we collect the information you share — including attachments and message content — so we can respond and enhance the service.

2. How We Use Your Information

We use the data we collect to:

  • Provide, personalize, and maintain the Service.
  • Generate and deliver AI-powered results based on your inputs — including chat responses, transcriptions, rewritten notes, and images.
  • Process payments and manage subscriptions and credits.
  • Synchronize your data across your devices.
  • Send you updates, security alerts, and support responses.
  • Track usage patterns, troubleshoot issues, and guard against fraud or misuse.
  • Build new features and improve existing ones, using aggregated or de-identified data wherever possible.
  • Meet legal obligations and enforce our Terms of Service.

3. Technology Partners and Third-Party AI Services

COET acts as the data controller and relies on the third-party processors listed below to operate the Service. Each processor acts solely as a data processor on our behalf under a signed Data Processing Agreement (DPA), providing protections equal to those stated in this Policy. None of these processors use your content to train foundation models or for model improvement. AI processing occurs only after you grant explicit in-app consent for each AI feature on the dedicated consent screen (also available in Settings → Privacy & AI Consent). You may withdraw consent at any time.

  • Firebase (Google Cloud): Provider: Google LLC. Data sent: account identifiers (email, Apple Sign-In ID), authentication tokens, your notes, transcripts, generated images, chat history, app settings, and device diagnostics. Purpose: authentication, encrypted data and file storage, cloud functions, hosting, and crash reporting. Google Cloud processes data under the Google Cloud Data Processing Addendum and does not use Customer Data to train its foundation models. Data is encrypted at rest and in transit.
  • Groq: Provider: Groq, Inc. Data sent: the text of your note, chat message, or rewrite request — without your name, email, or account identifier. Purpose: generating chat replies, rewriting notes, and producing titles and summaries. Retention: prompts and outputs are processed in-memory to produce a response and are not retained beyond the request under Groq's enterprise terms. Groq does not use customer content to train its models. Covered by a signed DPA.
  • AssemblyAI: Provider: AssemblyAI, Inc. Data sent: the audio recording of the voice note you choose to transcribe. No account identifiers, metadata, or other content is included. Purpose: speech-to-text transcription. Retention: audio and transcripts are deleted from AssemblyAI's servers immediately after the transcription request completes. AssemblyAI does not use customer audio to train its models. Covered by a signed DPA.
  • Replicate: Provider: Replicate, Inc. Data sent: your text prompt, selected aspect ratio, chosen model, and any reference image you attach. No account identifiers are included. Purpose: AI image generation and editing. Replicate hosts and runs Google Gemini 2.5 Flash Image (also known as "Nano Banana") as the underlying image model on our behalf; Google acts as a sub-processor. Retention: inputs and outputs are automatically deleted from Replicate within one hour. Neither Replicate nor Google uses customer content to train their models. Covered by a signed DPA.
  • RevenueCat: Provider: RevenueCat, Inc. Data sent: an anonymous RevenueCat user identifier and App Store receipt data. No notes, chats, audio, images, or AI content is shared. Purpose: verifying purchases and managing subscriptions and credit balances. RevenueCat does not use customer data for advertising or model training. Covered by a signed DPA.

4. Sharing Your Information

We do not sell your personal data. We only share information with:

  • Service providers and third-party AI processors that help us run COET (listed in Section 3). These partners may only access data to perform services on our behalf under signed Data Processing Agreements, are contractually prohibited from using your content to train AI models or for any purpose other than providing the service to us, and are required to provide the same or equal protection of user data as stated in this Privacy Policy.
  • Legal authorities when we believe disclosure is needed to comply with the law, defend our rights, prevent fraud or misuse, or respond to a lawful request.
  • Business transfers — in the event of a merger, acquisition, or asset sale, we will inform you before personal data is transferred and becomes subject to a different privacy policy.

5. Data Retention

We keep personal data for as long as it is needed to provide the Service, fulfill legal obligations, resolve disputes, and enforce agreements. When you delete content — notes, recordings, images, or chat messages — it is permanently removed from our servers. Deleting your account (available in the app settings) erases all associated data. Server logs are retained for 14 days before automatic deletion. When data is no longer required, we delete or anonymize it.

6. Data Security

We employ technical, organizational, and administrative safeguards to protect personal information from unauthorized access, loss, misuse, or alteration. These include:

  • Encryption at rest and in transit.
  • Authenticated access — your data is reachable only through your account.
  • Strict access controls across all infrastructure.
  • Periodic security reviews.

No online service can guarantee absolute security. Please use strong passwords, keep your software up to date, and let us know right away if you suspect your account has been compromised.

7. International Data Transfers

We may process data using servers or service providers based in different countries. When personal data is transferred internationally, we rely on appropriate safeguards to protect your rights.

8. Your Rights and Choices

Depending on where you are located, you may have the right to:

  • Access, correct, or delete the personal data we hold about you.
  • Object to or restrict certain processing activities.
  • Obtain a copy of your data in a portable format.
  • Withdraw consent for processing when consent is the legal basis.

To exercise these rights, email us at the address below. We may need to verify your identity and can decline requests that are excessive, unfounded, or restricted by law. You can also delete your account directly from the app settings at any time.

9. Children's Privacy

COET is not intended for children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has shared personal data without appropriate consent, please contact us so we can remove it.

10. Third-Party Links and Services

The Service may contain links to or integrations with websites and platforms that we do not control. This Privacy Policy does not cover those third parties. Please review their policies before sharing personal information.

11. Changes to This Policy

We may revise this Policy to reflect changes in laws, technology, or our practices. When we make material changes, we will notify you by email, in-app notice, or by posting an update on our website, and we will update the "Last updated" date at the top. Continued use of the Service after the effective date means you accept the revised Policy.

12. Contact Us

If you have questions, requests, or concerns about this Privacy Policy or our data practices, contact us at car.ai.contacto@gmail.com.

We will respond within the timelines required by applicable law.

© 2026 COET Systems

Terms of Service