Privacy Policy
Coloop LTD ~ Effective 13 September 2026

This policy explains what personal data Coloop LTD ("Coloop", "we") collects when you use Vigilator, why, who we share it with and what rights you have. Coloop LTD is registered in England and Wales (company number 11837491, registered office Sportsman Farm, St. Michaels, Tenterden, United Kingdom, TN30 6SY) and is the controller of the data described in sections 2 to 4. Questions and requests go to noah@vigilator.ai.

1. Two roles

For your account, your organisation's settings and your use of the website we are the controller. For the content your agents and members submit through the service, which may contain personal data about your own users, customers or staff, your organisation is the controller and we are its processor: we handle that content only on your instructions to provide the service, as set out in the Terms of Service.

2. What we collect

  • Account data: name, email address, a hashed password, and if you enable them, passkey public keys and two-factor settings. We never see your password in clear text.
  • Organisation data: organisation name, members and their roles, teams, classification tags, workload and notification settings, API key names and hashed keys, webhook endpoint URLs, and the billing contact email.
  • Service content: the interrupt requests, agent messages, tool calls, live session transcripts, decisions, comments and audit log entries your agents and members create. What this contains is decided by you and your agents.
  • Presence and activity: when you were last active, whether you have marked yourself away, and which tabs are open, used to route work to people who are present.
  • Usage and device data: pages visited, actions taken in the app, browser and device type, approximate location from IP address, and error reports, collected through our analytics provider.
  • Billing data: plan, seat count, metered usage and invoice history. Card details are entered directly with Stripe and never reach our servers.
  • Communications: emails you send us and support requests.

3. Why we use it and on what basis

  • Providing the service (accounts, organisations, routing and storing requests, sending notification and verification emails, billing): performance of our contract with you.
  • Securing the service (session management, two-factor authentication, checking chosen passwords against known breach lists, rate limiting, abuse detection, audit logging): our legitimate interest in keeping the service and its customers safe.
  • Improving the service (product analytics, error tracking): our legitimate interest in understanding how Vigilator is used and where it fails.
  • AI features: when your organisation enables Argus, the content of a request is sent to a third-party language model to produce a summary, classification or suggestion. This happens only on your organisation's instruction and is processing on your behalf.
  • Legal obligations: keeping billing records and responding to lawful requests.

We do not sell personal data and do not use it for advertising.

4. Who we share it with

We use the following providers to run Vigilator. Each processes data only as needed for the purpose shown.

ProviderPurposeLocation
VercelApplication hosting and deliveryUK (London) for compute; global edge network
PlanetScalePrimary databaseUK (London)
Redis CloudReal-time event delivery between serversUK (London)
ResendTransactional emailUnited States
Autumn and StripeSubscriptions, metering and paymentsUnited States
SvixDelivery of webhooks you configureUnited States
InngestBackground job processingUnited States
OpenRouter and the model providers it routes toAI features (Argus), only when enabled by your organisationUnited States and others
PostHogProduct analytics and error trackingEuropean Union
Have I Been PwnedChecking a chosen password against known breaches. Only a partial hash of the password is sent, never the password.United States
Better AuthAuthentication tooling and security monitoringUnited States

We may also disclose data where the law requires it, to enforce our terms, to protect the rights and safety of users, or as part of a merger or sale of our business, in which case this policy continues to apply.

5. International transfers

Your data is stored in the United Kingdom. Some of the providers above process data in the United States. Where that happens we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, or on the provider's adequacy certification, so that the data remains protected to UK standards.

6. Retention

  • Account data: for as long as your account exists, then deleted within 30 days of you deleting it.
  • Organisation data and service content: for as long as the organisation exists, then deleted within 30 days of the organisation being deleted.
  • Webhook delivery history: 90 days, held by Svix.
  • Analytics and error data: 12 months.
  • Billing records: 6 years after the transaction, as required by UK tax law.
  • Backups: encrypted database backups may hold deleted data for up to 30 days after deletion.

7. Security

Data is encrypted in transit everywhere and at rest in our database and backups. Passwords are stored as salted hashes. We offer two-factor authentication and passkeys and check new passwords against known breach lists. Access to production systems is limited to the people who operate them, and every administrative action inside an organisation is written to its audit log. No system is perfectly secure; if we learn of a breach affecting your data we will tell you without undue delay.

8. Cookies and local storage

We use only what the service needs to work:

  • Session cookies (set by our authentication library) keep you signed in. They are essential and expire when the session does.
  • Preference cookies and browser storage remember your theme, sidebar state and dismissed onboarding steps. They never leave your browser.
  • Analytics cookies from PostHog identify your browser across visits so we can understand usage and reproduce errors. They are served from our own domain and their data stays in the EU.

We do not use advertising cookies or third-party trackers. You can clear or block cookies in your browser; blocking the session cookie will sign you out.

9. Your rights

Under UK data protection law you can ask us to access, correct, delete or export your personal data, to restrict or object to our processing of it, and to withdraw consent where we rely on it. Most of this you can do yourself: your account page lets you change your details, manage sessions and delete your account; organisation owners can export the audit log and delete the organisation. For anything else email noah@vigilator.ai and we will respond within one month. You can also complain to the Information Commissioner's Office at ico.org.uk.

If your personal data is in another organisation's content, that organisation is the controller; contact them first and we will support their response.

10. Children

Vigilator is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.

11. Changes

We will update this policy when our practices or providers change. Material changes are announced by email to your account address or by a notice in the application before they take effect. The effective date at the top of this page tells you when it was last changed.