Legal
Privacy Policy.
Your data, kept in its corner.
Last updated October 1, 2026
What we collect, why, who helps us run Corner, and how to reach us about your information.
01Who we are
Corner is operated by Global Tech Stream LLC, 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, United States (“we”). This policy explains what personal information we handle, why, and the choices you have.
There are two groups of people it covers:
- Customers: people who sign up for Corner and use the dashboard. For your account information, we are the controller.
- Visitors: people who chat with a Corner assistant on a customer's website. For visitor information, the website owner is the controller and we process it on their behalf, following their instructions.
02What we collect
From customers: your name, email address and password (stored securely hashed), or your Google or GitHub sign-in; your workspace and team details; the content you add (website pages, files, answers); billing details such as your billing name, address and tax ID. Card details are entered directly into Stripe and never reach our servers.
From visitors: the messages and files they send; the name, email or phone number they choose to leave; an email address they confirm to receive a copy of their chat; the page they were on; an approximate country and device type; and a random identifier kept in the browser's local storage so a returning visitor can continue their conversation. Their IP address is used briefly to prevent abuse.
Automatically: basic technical logs (such as request times and errors) to keep the Service secure and working.
03How we use it
- to provide the Service: answering visitors, showing conversations and leads, sending the emails you ask for;
- to run your account and billing, including receipts and invoices;
- to keep Corner secure and prevent abuse and fraud;
- to improve Corner, using usage totals and the feedback you give us;
- to meet legal and tax obligations.
We rely on our contract with you, our legitimate interest in running a secure service, and legal obligations. We don't sell personal information, we don't share it for advertising, and we don't use your content or your visitors' conversations to train AI models.
04Who we share it with
We use a small number of providers to run Corner. Each one only receives what it needs for its job, under a contract that protects the information.
| Provider | What for | Where |
|---|---|---|
| Anthropic | Writes the assistant's answers (AI model) | United States |
| Voyage AI | Turns your content into search vectors so the assistant finds the right page | United States |
| Stripe | Payments, invoices and fraud prevention | United States |
| Neon | Database hosting | Germany (EU) |
| Hetzner | Server hosting, including the encrypted storage of files sent in chats | Germany (EU) |
| Cloudflare | Network, security and email forwarding | Global |
| Resend | Sending account and notification emails | Ireland (EU) |
We may also share information if the law requires it, to protect people's safety, or as part of a sale or merger of our business (in which case this policy continues to apply).
05AI tools you connect
If you connect Corner to an AI tool such as Claude, ChatGPT or Cursor through our MCP server, the tool can use Corner on your behalf within the one workspace you choose and with your role's permissions. We receive what the tool sends when it uses Corner, such as a question to test, an answer to teach or a setting to change, and we keep a record of the connection (the tool's name and when you connected) until you disconnect it in Settings > AI tools or leave the workspace. We never receive your conversations with the AI tool, its memory or your files.
The AI tool receives the results it asks for, which can include your visitors' messages, the contact details they left and your team's internal notes on a conversation. The tool's provider, for example Anthropic or OpenAI, handles that information under its own terms and privacy policy, as a service you chose. We leave out visitors' device details and file names, and we never send files visitors attached. We don't use any of this to train AI models.
06International transfers
We're a US company, and some of our providers are in the United States. When information from the EU, UK or elsewhere is transferred, we rely on safeguards such as the European Commission's Standard Contractual Clauses in our providers' terms.
07How long we keep it
We keep account information while your account is open. Conversations, leads and content stay until the business deletes them or closes the workspace: owners and admins can delete a conversation, with its files, at any time, for example to answer a privacy request. Ending a chat, or a chat closing itself after a quiet period, deletes nothing. Files sent in chats are deleted sooner, on the schedule the business chooses (see below).
After a workspace is deleted, its data is removed from our live systems straight away and from database backups within 30 days. Files sent in chats have no backups at all, so they are gone at once.
We keep billing records for as long as tax law requires, which is usually several years.
08Files and copies of chats
Visitors and the business's team can send each other images (PNG, JPEG, WebP or GIF) and PDFs of up to 10 MB in a chat. Before a file is kept, we check its type from its content, scan it for viruses, and save images again from their pixels alone, which drops location and camera details. PDFs that contain scripts or embedded files are refused.
Files are stored encrypted (AES-256) on our servers in Germany (Hetzner, in the table above). Only the visitor who sent or received a file, in their own chat, and the business's team, signed in to Corner, can open it. Files never get a public link.
Each business chooses how long files are kept: 30 days, 90 days (the default) or a year. After that a file is deleted for good, and the chat shows that it was removed. A file goes sooner if the team deletes it or its conversation, and with the workspace. These files are not backed up, so a deleted file can't be brought back.
When the business offers it, a visitor can download a copy of their chat or ask for one by email. An email copy only ever goes to an address the visitor confirmed through a link we send, whether they asked for it or the business's team sent it. We keep the confirmed address with that visitor for 30 days, so a later copy can go straight to it, and use it for nothing else; every emailed copy carries a link that stops further copies to that address. A visitor's copy holds the messages and the names of files, never the files themselves or the team's internal notes.
When a visitor leaves their email address on the business's form and the team replies after they've left the chat, we email them that reply on the business's behalf, if they haven't seen it in the chat within a few minutes. The email holds only what the team wrote, never the visitor's own messages, and every one carries a link that stops further reply emails to that address.
A business on a paid plan can connect Slack or a webhook (for example Zapier) in its settings. When it does, we send the details of new leads and of visitors asking for a person to the address it chose, signed so it can check they came from us. That address is then the business's own processor, under its own terms.
10Your choices and rights
Depending on where you live (for example under the GDPR, UK GDPR or California law), you can ask to access, correct, delete or export your personal information, or object to or restrict how we use it. You can update most account details yourself in the dashboard.
You can see and disconnect the AI tools connected to your workspace at any time in Settings > AI tools.
To make a request, write to [email protected]. If you were a visitor on a customer's website, please contact that website first; we'll help them respond. You can also complain to your local data protection authority.
11Security
We protect information with encryption in transit, encryption at rest for files sent in chats, access controls and hashed passwords, and we limit who on our side can access it. No service can be perfectly secure; if a breach affects your information, we'll tell you without undue delay.
12Children
Corner is not meant for children under 16, and we don't knowingly collect their information.
13Changes
We'll update this page when our practices change, and email customers about important changes before they take effect. See also our Terms of Service.