Legal
Privacy
Last updated August 2026
This is not the binding privacy policy. That will be published here before general availability — we would rather leave it blank than publish text we have not had reviewed. Everything below is a factual description of what the product does today.
1.What the enquiry forms store
The name, email, company, company size and message you send. Nothing else — no tracking identifier is attached to the submission, and the form does not read anything from your browser that you did not type into it.
2.How workspace data is separated
Every row carries the workspace it belongs to, and the separation is enforced by the database rather than by the application — a query that forgets the condition returns nothing, instead of returning somebody else's rows.
The mechanism is described in full on the security page, in enough detail for your engineer to poke holes in it.
3.When we can see inside a workspace
Support access is off by default. Turning it on requires a stated reason, is read-only, expires after 60 minutes, and is written into that customer's own audit trail — so the record of us looking is held by the customer, not by us.
4.What we have not built yet
There is no cookie-based analytics on this site, no third-party tracking script, and no advertising integration. If any of those arrive, this page changes first.
Questions in the meantime: hello@corepilott.com · How the isolation model works