Legal
Privacy Policy
Last updated: July 2, 2026
The short version
- Your workspace content belongs to you. We store and process it to run the product — we don't sell it, and we don't use it to train AI models.
- Workspaces are isolated: only their members — and any AI agents a member connects, within that agent's role — can see what's inside.
- If you connect an AI client (like Claude or Cursor) over MCP, the data it reads is also processed by that AI provider under their terms — that part is your choice and their policy.
- Payments go through Stripe; we never see or store card numbers.
- We use a small set of infrastructure providers (listed below) and essential cookies only.
The rest of this page says the same things with the detail a privacy policy needs. "Collabicle", "we", and "us" refer to the operator of collabicle.com; "the Service" means the Collabicle web application and its MCP server.
1. Data we collect
Account data. Your name, email address, and a hashed password when you sign up with email — or your name, email, and profile picture from Google if you sign in with Google. We never receive your Google password.
Workspace content. Everything you and your team create in a workspace: wiki pages, documents and uploaded files, projects and tasks, table records, chat messages, events, artifacts, automations (including their code), and workspace settings such as secrets you store for automations.
Billing data. Your subscription plan, billing status, and invoice history. Card details are collected and stored by Stripe, our payment processor — they never touch our servers.
Usage & audit data. Activity needed to operate the product: presence (who's online), notification state, and — importantly — an audit log of every MCP tool call made by a connected AI agent (which identity acted, which tool, in which workspace, and when). Aggregated, de-identified usage statistics help us understand product health.
Support conversations. If you message us through the live chat widget or by email, we keep the conversation so we can help you and improve the product.
Technical data. Standard logs any web service generates: IP address, browser type, and timestamps, used for security and debugging.
2. How we use data
We use the data above to:
- provide, operate, and secure the Service;
- sync your workspaces in real time across members and connected agents;
- process subscriptions and send transactional email (such as password resets and workspace invites);
- answer support requests and notify you of important changes;
- debug problems, prevent abuse, and enforce our Terms of Service;
- understand aggregate product usage so we can improve it.
We do not sell your personal data or workspace content, show you third-party advertising, or use your content to train AI models.
3. Workspaces & who sees what
Collabicle is organized into workspaces with hard data boundaries. Content in a workspace is visible to that workspace's members according to their roles, and to no one else. Workspace admins control membership, roles, and invites; if you join a workspace, its admins can see the content you create there.
Our staff does not browse your workspace content. Limited access can occur only when it's necessary to operate the Service — for example investigating an incident, debugging a problem you reported, or complying with a legal obligation — and is restricted to what the situation requires.
4. AI agents & MCP access
Collabicle includes a built-in MCP (Model Context Protocol) server that lets you connect AI clients — such as Claude, Claude Code, or Cursor — to your workspace. This is always opt-in: an agent gets access only when a member authorizes it through an OAuth sign-in, and it acts with role-based permissions tied to that authorization.
- Scope. A connected agent can only use tools its role allows, deny-by-default. It sees the workspace it was authorized for — nothing else.
- Audit. Every tool call is logged with the acting identity, tool name, workspace, and time. Workspace admins can review this activity, and access can be revoked at any time.
- Third-party AI providers. When an agent reads workspace data, that data is transmitted to the AI provider you chose (for example Anthropic, or the vendor behind your MCP client) and processed under their privacy policy and terms. Collabicle does not control what a third-party AI provider does with data you choose to send it — review their policies before connecting.
5. Services we rely on
We use a small number of infrastructure providers (subprocessors) to run Collabicle. Each receives only what its job requires:
- Convex — our backend database and real-time sync layer; stores workspace content and account data.
- Vercel — hosts the web application.
- Stripe — payment processing and subscription billing.
- Google — optional sign-in (OAuth) if you choose it.
- Resend — transactional email delivery (password resets, invites, notifications).
- bunny.net — file storage and CDN delivery for uploaded files on some deployments.
- Tinybird — aggregated MCP usage analytics built from the audit log (identifiers and metadata about tool calls, not your content).
If we add or change a provider in a way that affects your data, we'll update this page.
7. Security
Data is encrypted in transit (TLS) and at rest by our infrastructure providers. Access inside the product is governed by workspace membership and roles; agent access is additionally gated per tool and fully audit-logged. Automation code runs in an isolated sandbox. We follow the principle of least access internally.
No system is perfectly secure. If we learn of a breach affecting your personal data, we will notify you without undue delay and describe what happened and what we're doing about it.
8. Data retention & deletion
We keep your data for as long as your account or workspace is active. Content you delete in the product is removed from the live database; residual copies in backups expire on a rolling basis.
If you want your account or an entire workspace permanently deleted, contact us at ibrahim@collabicle.com and we'll complete the deletion within 30 days, except where we're legally required to retain specific records (for example, invoices).
9. Your rights
Depending on where you live (for example under the GDPR or similar laws), you may have the right to access, correct, export, restrict, or delete your personal data, and to object to certain processing. You can exercise most of these directly in the product — your profile and content are editable — and for anything else, email us and we'll handle it.
Note that for content inside a team workspace, the workspace admins decide what stays and goes within that workspace — if you leave a team, the work you contributed typically remains with the team, as it would in any collaboration tool.
10. International transfers
Our infrastructure providers may store and process data in countries other than your own, including the United States. Where required, transfers rely on appropriate safeguards such as standard contractual clauses provided by those vendors.
11. Children
Collabicle is not directed at children under 16, and we don't knowingly collect personal data from them. If you believe a child has created an account, contact us and we'll delete it.
12. Changes to this policy
We'll update this policy as the product and the law evolve. For material changes we'll notify you in the product or by email before they take effect. The "last updated" date at the top always reflects the current version.
13. Contact
Questions, requests, or concerns about privacy: ibrahim@collabicle.com. We read everything.