Privacy Policy

Effective Date: September 3, 2026

Definitions

  • "Coherence OS™" or "Coherence" refers to the Coherence software platform (the "Service").
  • "Brightyard," "we," "us," or "our" refers to Brightyard, Inc., a Delaware corporation that owns and operates Coherence.

Coherence OS ("Coherence") is a software platform operated by Brightyard, Inc., a Delaware corporation. This Privacy Policy explains how we collect, use, and share information about you when you use the Coherence platform (the "Service").

1. Information We Collect

1.1 Information You Provide

When you create an account, we collect your name, email address, payment information, and any other information you provide. This includes:

  • Account Information: Name, email address, password, company name, and job title
  • Profile Information: Avatar, preferences, and settings you configure
  • Payment Information: Credit card details and billing address (processed securely by our payment provider)
  • Customer Data: Contacts, companies, deals, and other business data you enter into the Service
  • Support Requests: Information you provide when contacting our support team

1.2 Information We Collect Automatically

We collect information about your use of the Service, including:

  • Device information (e.g., IP address, browser type, operating system)
  • Usage data (e.g., pages visited, features used, time spent in the Service)
  • Log data (e.g., access times, error logs, referring URLs)

1.3 Cookies

We use two kinds of cookies and similar technologies:

  • Strictly necessary, which keep you signed in, remember your preferences, protect against abuse, and record your cookie choice. These do not require consent.
  • Analytics and advertising, which you can turn off: product analytics and session replay (PostHog) on our website and in the application; the Meta pixel on our website; and the OpenAI advertising pixel on our website and, for a single completed-signup event, in the application.

On our public website, if you are visiting from a country whose law requires your prior consent for analytics and advertising cookies (the European Economic Area, the United Kingdom, Switzerland, Australia, New Zealand, Canada, Brazil, Japan, South Korea, and the other countries listed in our Terms as places where the Service is not offered), we ask for your choice in a consent notice on your first visit and set no analytics or advertising cookie until you accept. Declining is remembered. We work out where you are visiting from using your browser's time zone and an offline lookup of your IP address; the address is not stored. Everywhere else, these cookies are set when you visit, as described in this policy, and you can turn them off at any time from "Cookie preferences" in the website footer.

In the application, product analytics and masked session replay are on by default under the Terms of Service you accept when you create an account, because the Service is not offered in the countries whose law requires prior consent for them. You can turn them off at any time under Data & Privacy in the application's settings. Where we have admitted a workspace from one of those countries under a written agreement, analytics and session replay are off in that workspace until you accept them in a notice shown in the application, and the same setting turns them off again. Blocking cookies in your browser also works, though it may affect signing in. The one exception is our interactive product demo, which is instrumented so we can see how the guided walkthrough performs; entering the demo is itself the choice to be measured, and nothing from a demo session is linked to a real account.

1.4 Advertising Measurement

Our public website loads the Meta pixel (Meta Platforms, Inc.) and the OpenAI advertising pixel (OpenAI, L.L.C.) so we can tell which of our advertisements brought visitors to the site. They record a page visit and an identifier for your browser. Visitors from the countries listed in 1.3 are asked first and neither pixel loads until they accept; other visitors can turn both off from "Cookie preferences" in the footer. The Meta pixel is never loaded in the application. The OpenAI pixel is loaded in the application unless you have turned analytics off under Data & Privacy, and records a single completed-signup event so we can attribute the signup to the advertisement.

1.5 Product Analytics (PostHog)

We use PostHog to understand how you interact with the Service, subject to the choices described in 1.3. PostHog collects usage events, page views, feature interactions, device type, browser information, and masked session replays in which your data is replaced by placeholders. This helps us improve the Service, identify issues, and prioritize new features. PostHog data is processed on servers located in the United States and is governed by our data processing agreement with PostHog, Inc.

1.6 Error Monitoring (Sentry)

We use Sentry to monitor application errors and performance. When an error occurs, Sentry may collect technical diagnostic data including stack traces, browser type, operating system, IP address (anonymized), and the actions that led to the error. This data is used solely for debugging and improving the reliability of the Service. Sentry data is processed in accordance with our data processing agreement with Functional Software, Inc.

1.7 Information from Third Parties

When you connect third-party services to Coherence, we may receive:

  • Email Data: Email messages, metadata, and contacts from connected email accounts (Gmail, Outlook)
  • Calendar Data: Events and attendee information from connected calendars
  • Integration Data: Data from other connected applications (Zapier, Slack, etc.)

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Process payments and manage subscriptions
  • Communicate with you about your account
  • Send technical notices, updates, security alerts, and support messages
  • Personalize your experience
  • Monitor and analyze trends, usage, and activities
  • Detect, investigate, and prevent fraudulent transactions and abuse
  • Comply with legal obligations
  • Develop new products and features

3. Artificial Intelligence & Data Processing

Coherence uses artificial intelligence to power features such as AI assistants, email summarization, record insights, automated task planning, and memory extraction. Your data may be processed by the following AI service providers:

3.1 Anthropic (Claude)

We use Anthropic's Claude models as our primary AI provider for conversational AI, document analysis, task planning, and content generation. When you interact with AI features, relevant context (such as record data, conversation history, and document content) may be sent to Anthropic's API for processing. Anthropic does not use your data to train their models under our commercial API agreement. Data is processed in the United States.

3.2 OpenAI

We use OpenAI's models as a supplementary AI provider for certain features. Similar to Anthropic, relevant context may be sent to OpenAI's API when AI features are used. Under our enterprise API agreement, OpenAI does not use your data to train their models. Data is processed in the United States.

3.3 MiniMax

By default, Coherence uses MiniMax's M3 model as the primary AI provider for copilot, agent, autopilot, content, site, and image generation features due to its favorable cost and speed characteristics. The MiniMax API platform is operated by Nanonoble Pte. Ltd., a Singapore company that is part of the MiniMax group, which is headquartered in China. Its privacy policy states that API data is stored in a data center in the United States. When this provider is active, relevant context (such as record data, conversation history, task instructions, and image prompts) is sent to MiniMax's API for processing.

MiniMax's terms of service permit it to use API inputs and outputs to provide, maintain, develop, and improve its services, and its privacy policy permits it to mine and commercially use a de-identified or anonymised database built from the data it collects. MiniMax's published training-content summary for its M3 model, filed under the EU AI Act, states that API user inputs and prompts were not used to train that model. We have no agreement with MiniMax that goes beyond its published terms. If those terms are not acceptable for your data, select Anthropic or OpenAI as described in 3.4.

3.4 Your AI Provider Choice

Account administrators can change the default AI provider at any time in account settings. Selecting Anthropic or OpenAI as your default ensures all AI processing occurs in the United States and no data is sent to MiniMax. This option is recommended for accounts subject to GDPR, CCPA, or other data residency requirements.

Workspaces in the European Economic Area, the United Kingdom, or Switzerland never use MiniMax. We identify these workspaces from the billing or card country on file, the time zone captured at signup, or a jurisdiction flag set by our support team, and for them the "Auto" setting runs only on Anthropic and OpenAI. There is no way to enable MiniMax for such a workspace. If you believe your workspace is in one of these jurisdictions and is not being treated as such, contact [email protected].

If you are in a region where Coherence is not offered and you ask us to tell you when that changes, we store only the email address you give us, the country we infer from your connection's network address, and any message you add, solely to contact you once about availability and to see where demand is. We delete that record on request to [email protected].

3.5 AI Memory & Learning

Coherence's AI features may extract insights, preferences, and patterns from your interactions to provide more personalized assistance over time. These "memories" are stored within your account and are not shared with AI providers or third parties. You can view, manage, and delete AI memories at any time through your account settings. AI memory extraction requires your consent and can be disabled.

3.6 AI Data Safeguards

  • Your data is never used to train third-party AI models
  • AI processing is performed via secure API calls with encryption in transit (TLS 1.2+)
  • AI providers are contractually prohibited from retaining your data beyond the processing window
  • You can opt out of AI features at any time without affecting core Service functionality
  • All AI interactions are logged in your account's audit trail

4. How We Share Your Information

We do not sell your information. We may share your information with:

  • Service providers who assist us in operating the Service, including:
    • DigitalOcean — cloud hosting and database infrastructure (United States)
    • Stripe — payment processing (PCI DSS compliant)
    • Postmark — transactional email delivery
    • Anthropic — AI processing (Claude models)
    • OpenAI — AI processing (GPT models, United States)
    • MiniMax (Nanonoble Pte. Ltd., Singapore) — AI processing (default provider; API data stored in the United States; part of the MiniMax group headquartered in China — opt out available in account settings and applied to every AI feature)
    • PostHog — product analytics
    • Sentry — error monitoring and performance

    The complete and current list of sub-processors, including what each one processes and where, is published on our Sub-processors page. Our contractual commitments as a processor are set out in our Data Processing Addendum.

  • Other members of your organization, according to your organization's privacy settings
  • Third-party integrations you explicitly connect
  • Legal authorities, if required by law, regulation, legal process, or governmental request

5. Connected Account Data (Google & Microsoft)

Coherence integrates with Google Workspace and Microsoft 365 to provide a unified view of your communications, calendar, and contacts. This section describes how we handle data from these connected accounts.

4.1 Google Workspace Data

When you connect your Google account, Coherence may access the following data with your explicit authorization:

  • Gmail: Email messages, labels, metadata, and attachments
  • Google Calendar: Events, attendees, and calendar metadata
  • Google Contacts: Contact names, email addresses, phone numbers, and associated metadata

Coherence's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

4.2 Microsoft 365 Data

When you connect your Microsoft account, Coherence may access the following data with your explicit authorization:

  • Outlook Mail: Email messages, folders, metadata, and attachments
  • Outlook Calendar: Events, attendees, and calendar metadata
  • Outlook Contacts: Contact names, email addresses, phone numbers, and associated metadata

4.3 Storage & Security

Connected account data is stored on our servers to provide the Service. We implement the following security measures to protect this data:

  • All data is encrypted at rest using AES-256 encryption
  • All data in transit is encrypted using TLS 1.2 or higher
  • Access to stored data is restricted to authorized personnel and systems
  • OAuth tokens are stored securely and can be revoked at any time

4.4 Usage

Connected account data is used solely to provide the features of the Coherence platform, including:

  • Displaying your emails, calendar events, and contacts within the Coherence interface
  • Automatically linking communications to relevant records (contacts, companies, deals, etc.)
  • Generating AI-powered summaries of email threads and conversations
  • Creating tasks and follow-ups based on email content
  • Syncing calendar events with your Coherence activity timeline
  • Importing and enriching contact records

4.5 Sharing & Limited Use

We do not share your connected account data with third parties except as follows:

  • With other members of your organization, according to your organization's sharing settings
  • With AI service providers (such as OpenAI) to power features like email summarization—in these cases, data is processed in accordance with our data processing agreements and is not used to train AI models
  • As required by law, regulation, or legal process

We do not use your connected account data for advertising purposes. We do not sell your data.

4.6 Your Controls

You have full control over your connected accounts:

  • Disconnect: You can disconnect any connected account at any time through your account settings
  • Revoke access: You can revoke Coherence's access directly from your Google or Microsoft account security settings
  • Data deletion: Upon disconnection or account deletion, we will delete your connected account data from our servers within 30 days

6. Data Security

We implement technical and organizational measures to protect your information from unauthorized access, loss, or misuse, including:

  • Encryption of data at rest and in transit (TLS 1.2+)
  • Regular security assessments
  • Access controls and authentication requirements
  • Employee security training
  • Regular backups and disaster recovery procedures

7. Data Retention

We retain your information for as long as your account is active or as needed to provide you with the Service. We may retain certain information as required by law or for legitimate business purposes.

When you delete your account, we will delete or anonymize your information within 90 days, except where we are required to retain it by law or for legitimate business purposes such as preventing fraud.

Inactive free and trial workspaces

A free or trial workspace may be terminated for inactivity under the lifecycle described in our Terms of Service. Before termination we pause connected email, calendar, and contact synchronization; no data is deleted until the cancellation and export period in the Terms has ended. Once deletion begins, we delete or anonymize the workspace's data on the same 90-day schedule as an account you delete yourself.

8. Your Rights

Depending on your location, you may have the following rights:

  • Access: Request a copy of your personal information
  • Correction: Request correction of inaccurate information
  • Deletion: Request deletion of your personal information
  • Export: Request a portable copy of your data
  • Opt-out: Unsubscribe from marketing communications
  • Restrict Processing: Object to or restrict certain data processing

To exercise these rights, please contact us at [email protected] or through your account settings.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. Our primary infrastructure is located in the United States (DigitalOcean). AI processing occurs in the United States (Anthropic, OpenAI, and MiniMax's US data center), and for MiniMax the operating company is in Singapore within a group headquartered in China, depending on your account's AI provider setting.

You can restrict AI processing to US-only providers by changing your default AI provider in account settings. We ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy and applicable data protection laws.

For transfers of personal data from the European Economic Area, the United Kingdom, and Switzerland on behalf of our customers, we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, as incorporated in our Data Processing Addendum. The processing location of each sub-processor is listed on our Sub-processors page.

10. GDPR Compliance (European Users)

If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):

  • Right to lodge a complaint with a supervisory authority
  • Right to withdraw consent at any time
  • Right to object to processing based on legitimate interests
  • Right to data portability (export your data in a machine-readable format)
  • Right to erasure ("right to be forgotten")

Our legal bases for processing personal information include: performance of a contract, legitimate interests, compliance with legal obligations, and consent (where applicable).

Where a customer organisation uses Coherence to process personal data about its own contacts, that organisation is the controller and we act as its processor under our Data Processing Addendum, which is incorporated into our Terms of Service.

You can exercise your data rights directly through Coherence:

  • Data Export: Request a complete export of your personal data through your account settings or by contacting your account administrator
  • Data Erasure: Request anonymization and deletion of your personal data. Core audit records are preserved (with PII removed) for legal compliance
  • Consent Management: View and manage your consent preferences for optional data processing (e.g., AI features, analytics, marketing) through your account settings

Data subject requests are processed within 30 days as required by GDPR. You may also contact us directly at [email protected].

11. CCPA Compliance (California Residents)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information is collected
  • Right to know if personal information is sold or disclosed
  • Right to opt-out of the sale of personal information (we do not sell personal information)
  • Right to non-discrimination for exercising your rights

12. Children's Privacy

The Service is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will take steps to delete such information.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be effective when posted, and your continued use of the Service after changes are posted constitutes your acceptance. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Effective Date."

Contact Us

If you have questions about this Privacy Policy, please contact us at:

Brightyard, Inc.
Operator of the Coherence platform

Email: [email protected]
Privacy inquiries: [email protected]