Back

Privacy Policy

Effective September 26, 2026 · updated for Chat and Google Drive

This Privacy Policy explains what personal data Coburg collects when you use the website coburg.ai, why, how long we keep it, and what rights you have. We keep it short because, at this stage, we collect very little.

Coburg is currently in an invitation-only early-access phase. Only people whose email address we have added to our list of invited users can sign in. This policy describes the service as it works today and will be updated before new features that use other data are introduced.

Who we are

The controller of your personal data is:

Hard Carbon Iberia S.L.
Calle Padre Joaquín Belón, núm. 1, esc. 1, puerta 1
29602 Marbella (Málaga), Spain
NIF B22571335 · EU VAT ES B22571335

For any question about this policy or your personal data, write to support@coburg.ai. To report a security issue, write to security@coburg.ai.

What we collect

When you sign in with Google

You sign in through Google. Google asks you to confirm that Coburg may receive your basic profile and save your chats in your own Google Drive. We then receive from Google:

  • your Google account identifier (a number that does not change),
  • your email address and whether Google has verified it,
  • your name as shown in your Google account.

We never see your Google password. We do not request access to your Gmail, contacts or any other Google data.

Your chats in your Google Drive

Coburg saves your chats in your own Google Drive, in a folder called CoburgAI with three folders inside: Threads, Documents and Pictures. Each chat is one file in Threads that you can open and read in Google Drive, and delete there if you want. Your Google Drive is the only place your chats are kept.

  • Coburg asks Google only for the narrowest Drive permission (drive.file): it can see and change only the folders and files that Coburg itself created, never your other files.
  • To keep writing to your Drive while you use Coburg, we store a long-term access key from Google (a “refresh token”) on our server, encrypted with a key that is kept separately from our database and its backups. Short-lived access keys are kept only in memory.
  • Coburg uses only the Drive account you signed in with. If the CoburgAI folder or a chat file is shared with anyone else, Coburg stops writing to it and tells you.
  • You can remove Coburg’s access at any time in your Google Account (Security → Third-party apps). Your files stay in your Drive.
  • If you rename or move the CoburgAI folder or its three folders, Coburg puts the names back; if you delete one of them, Coburg creates it again, empty. Chats you delete are not restored.
  • Coburg’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use the Drive access only to save and show your chats; we do not use it for advertising, do not sell it, and do not use it to train AI models.

From this we create a small account record: the identifier, email address, verification status, name, and the times the record was created and you last signed in.

While you are signed in

When you sign in, your browser receives a random session identifier in a cookie. On our server we store only a one-way fingerprint (hash) of it, together with the time the session started, when it was last used and when it ends. A session ends when you log out, after 7 days without use, after 30 days at the latest, or when you sign in on another browser (Coburg allows one signed-in browser at a time).

Security and abuse prevention

  • To limit repeated sign-in attempts, we count attempts per network address. We do not store your IP address for this: only a keyed fingerprint from which the address cannot be read back, kept for at most two hours.
  • Our servers keep short technical error logs. These may contain your IP address. They do not contain your sign-in codes or cookies, and they are deleted after at most 90 days.

Invitation list

During early access we keep a list of the email addresses of invited users, so that only they can sign in. If you are on the list, your email address is stored there even before you sign in for the first time.

When you use Chat

When you send a message in Chat, Coburg sends it, together with the earlier messages of the same conversation, to the AI provider that answers it. Today that is OpenAI; you can see which model answered under each answer. Coburg’s servers only pass your conversation through: we do not store the content of your messages or of the answers on our servers, and they never appear in our logs. The conversation is saved only in your own Google Drive (see above): your message before it goes to the AI provider, the answer when it is finished or when you press Stop.

To keep track of your credit, we store for every answer only numbers: your account, the model, the number of tokens (pieces of text) it used, its cost, and when it happened. We also keep your plan, its period and the credit added to it.

Your browser remembers the model you last chose (in its local storage, not in a cookie), so it is preselected next time. It is not sent to us except as part of a message you send.

When you write to us

If you email us, we receive your email address and whatever you write, and use it only to answer you.

Why we use it

PurposeDataLegal basis (GDPR)
Letting you sign in and keeping you signed inAccount record, session dataPerformance of our agreement with you (Art. 6(1)(b))
Allowing only invited users during early accessInvitation list, email addressOur legitimate interest in running a controlled early-access phase (Art. 6(1)(f))
Protecting the service against abuse and attacks, and fixing faultsAttempt counters, technical error logsOur legitimate interest in keeping the service secure (Art. 6(1)(f))
Answering your Chat messages through an AI providerYour messages in the conversationPerformance of our agreement with you (Art. 6(1)(b))
Keeping track of your plan and creditUsage records (numbers only), plan, creditPerformance of our agreement with you (Art. 6(1)(b))
Answering your messagesYour email and messageOur legitimate interest in responding to you (Art. 6(1)(f))

We do not sell your personal data, we do not use it for advertising, and we do not make decisions about you based solely on automated processing.

Cookies

Coburg uses only the two cookies it needs to work. There are no analytics, advertising or third-party cookies, and no tracking of any kind.

CookiePurposeDuration
__Host-coburg_loginLinks your browser to a sign-in that is in progress, so it cannot be completed from another browser10 minutes, deleted when sign-in finishes
__Host-coburg_sessionKeeps you signed inUntil you log out; at most 30 days

These cookies are strictly necessary, so they do not require consent. They are sent only to coburg.ai, only over an encrypted connection, and cannot be read by scripts on the page.

Who processes it for us

  • Hetzner Online GmbH (Germany) hosts our servers in Nuremberg and Falkenstein, Germany, and stores our encrypted database backups in Helsinki, Finland.
  • OpenAI (OpenAI Ireland Ltd and OpenAI OpCo, LLC, USA) generates Chat answers. It receives only the conversation you send. Under its API terms, OpenAI does not use this data to train its models, and may keep it for up to 30 days to detect abuse before deleting it.
  • Google provides the sign-in and Google Drive. When you sign in, you interact with Google directly, and Google processes your data under its own privacy policy. Your chats are stored in your own Google Drive under your agreement with Google. Our business email is also hosted by Google Workspace.

Everything Coburg stores on its own servers is stored in the European Union. Your chats in Google Drive are kept wherever Google stores your Drive. The only data Coburg sends out of the EU is the conversation you send in Chat, which goes to the AI provider in the United States. This transfer is protected by the EU–US Data Privacy Framework and the European Commission’s Standard Contractual Clauses.

How long we keep it

  • Account record: as long as your account exists. If you ask us to delete it, we delete it without undue delay.
  • Sessions: until they end (see above); a record that a session was ended is kept for one more day, so that the browser concerned can be told why it was signed out.
  • Sign-ins in progress: at most 10 minutes.
  • Chat messages and answers: not stored on Coburg’s servers; they are in your Google Drive until you delete them.
  • Encrypted Google Drive access key: as long as your account exists and you have not removed Coburg’s access. If Google tells us the access was removed, the key can no longer be used; it is deleted with your account.
  • Usage records, plan and credit: as long as your account exists, and afterwards as long as accounting law requires.
  • Technical error logs: at most 90 days.
  • Backups: our database is backed up every night. Backups are encrypted and deleted automatically about a month after they are made (after 30 days they are released, and deletion follows within two days). Data you have asked us to delete disappears from backups when they expire.

Your rights

Under the GDPR you have the right to access your personal data, to have it corrected or deleted, to restrict or object to its processing, and to receive it in a portable format. To exercise any of these rights, write to support@coburg.ai. We may ask you to confirm that the request comes from you.

You also have the right to lodge a complaint with a data protection authority: in Spain, the Agencia Española de Protección de Datos (www.aepd.es), or the authority in the country where you live or work.

Age

Coburg is intended for people aged 18 and over. We do not knowingly collect personal data from anyone younger.

Security

All connections to coburg.ai are encrypted. Session identifiers are stored only as fingerprints, the database is reachable only from our own servers, and backups are encrypted before they leave the server.

Changes to this policy

We will update this policy when Coburg starts to process other data, for example when new features are added. The date at the top shows when it last changed.