LEGAL
Privacy Policy
How VARJIX handles your data when you use Corolet. Written from what the system actually does, not from a template.
LAST UPDATED · 30 AUGUST 2026
1. Who processes your data
Corolet is operated by VARJIX. For the purposes of the EU General Data Protection Regulation, VARJIX is the data controller for the account and workspace data described below.
You can reach us about anything in this policy at privacy@corolet.com.
2. What we collect
Account. Your name, email address, and a hashed password. We never store your password in a readable form.
Sign-in with Google, GitHub or LinkedIn. If you use one of these, we receive your email address, name and profile identifier from that provider. We do not receive your password there and we do not post anything on your behalf.
What you create. Workspaces, agents and their instructions, skills, memory documents, stored facts, and the record of every agent run — including the prompts sent and the output returned.
Credentials you add. API keys for model providers, and access tokens for any connector you authorise. These are encrypted before they are written to disk.
Operational logs. IP address, timestamp and request path, kept for security and debugging.
We do not currently process payments, so we hold no card or billing data at all. If that changes, this policy changes first.
3. Why we are allowed to hold it
To perform the contract you entered into when you created an account — running your agents is the service you asked for. Operational logs and abuse prevention rest on our legitimate interest in keeping the service working and secure.
4. Where it is processed
On servers in Karlsruhe, Germany, operated by Contabo GmbH. Your account data, your agents and your memory documents stay in the European Union.
5. Who else sees it
Model providers. Running an agent means sending your prompt, and the context it needs, to a large language model. Depending on the model you choose, that is DeepSeek, Groq, Google (Gemini) or OpenAI. Those providers process the content of your run under their own terms, and some are outside the EU. If you supply your own API key, the request is billed to you and governed by your agreement with that provider.
Connectors and channels. If you connect Telegram, a webhook, or any other integration, data flows to that service by design — that is what connecting it does.
Hosting. Contabo GmbH, as described above.
We do not sell your data, we do not share it for advertising, and we do not use the contents of your runs to train models.
6. How long we keep it
Account and workspace data for as long as your account exists. Agent runs and their output stay until you delete them or delete the workspace. Operational logs are kept for a short period and then rotated away.
Delete your account and we remove your workspaces, agents, memory and stored credentials. Backups age out on their own cycle.
7. Your rights
If you are in the EU or the UK, you can ask for a copy of your data, ask us to correct it, ask us to delete it, object to processing, or ask for it in a portable form. Write to privacy@corolet.com and we will answer within 30 days. You also have the right to complain to your national data protection authority.
9. Changes
When this policy changes, the date at the top changes with it. If a change materially affects what we do with your data, we will tell account holders by email before it takes effect.
