Legal
Privacy Policy
In short: we collect the email you sign in with, the descriptions you type, the app code Corin generates for you, and basic billing details through Stripe — and we use them to run the service and bill you. We don’t sell your data. The data your published app collects from its own users lives in your Supabase project, which you control. See also our Terms of Service.
1. Who this covers
This policy explains how Corin (“we”, “us”) handles personal information when you use corin.build, usecorin.com and the Corin app. It does not cover how the apps you build with Corin handle data — you are responsible for those (see “Apps you build”).
2. Information we collect
- Account. The email address you sign in with. If you use “Continue with Google”, Google shares your email and basic profile with us.
- What you create. The descriptions and change requests you type, the app code and previews Corin generates, and build logs and verification results.
- Billing. Handled by Stripe. We store your credit balance, your card’s brand and last four digits, and a Stripe customer reference — never full card numbers.
- Technical. IP address, browser type, and a session cookie that keeps you signed in. We use a small number of strictly necessary cookies only.
3. How we use it
To run the service and generate and verify your apps; to sign you in and send your six-digit code; to take payment and show your balance and invoices; to email you when a build finishes; to prevent abuse and keep the service secure; and to answer support requests.
4. AI processing
To build an app, Corin sends your description — and, for a change, the current version of that app’s code — to Anthropic, which runs the model that writes the app. Under Anthropic’s API terms, this content is not used to train their models. See Anthropic’s privacy policy for how they process it.
5. Who we share it with
We do not sell personal information. We share it only with the service providers that run Corin on our behalf: Anthropic (AI generation), Supabase (accounts and database), Stripe (payments), Cloudflare and Railway (hosting and infrastructure), and our email provider (sign-in codes and notifications). We may also disclose information where required by law or to protect Corin or its users.
6. Apps you build
Each app you build stores its data in your own Supabase project, which you connect and control. For data that your published app collects from its own end users, you are the controller and this policy does not apply — you are responsible for your app’s own privacy notice and for complying with the laws that apply to it and its users.
7. Retention
We keep your account and build history while your account is open. You can delete individual apps in the app at any time. To close your account and delete your personal data, email [email protected]; we will action it within 30 days, except where we must keep certain records (such as tax and payment records) for longer.
8. Security
We use encryption in transit, access controls, and reputable infrastructure providers. No system is perfectly secure, but we work to protect your information and will notify you of a breach affecting you where the law requires.
9. International transfers
Our providers may process data in countries outside your own, including the United States. Where required, we rely on standard contractual clauses or an equivalent safeguard.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, export, or restrict the use of your personal information, and to object to certain processing. Email [email protected] and we will respond within the time the law allows. You may also complain to your local data protection authority.
11. Children
Corin is not intended for anyone under 16, and we do not knowingly collect their information.
12. Changes
We will update this page when our practices change and revise the date above. We will tell you about significant changes by email or in the app.
13. Contact
Questions about this policy: [email protected]. Data controller: Corin legal entity name and registered address.