coral-code
Product Privacy License
CoralOS, Inc. / Legal

Coral Code Privacy Policy

Most repository records stay on your machine. Model-powered features can send selected project context to the service you configure.

Effective
21 August 2026
Controller
CoralOS, Inc.
Privacy contact
cloudprivacy@coralos.ai
On this page Scope Data flow Information How we use it Services and sharing Your choices Retention and security Your rights Contact

1. Scope and who we are

This policy explains how CoralOS, Inc. ("CoralOS," "we," "us," or "our") handles information through the coral-code plugin for JetBrains products, the bundled coral-code command-line tools and agent integrations, and the coralcode.dev website (collectively, "Coral Code").

CoralOS, Inc. is a Delaware corporation. We act as the controller for personal information that we collect for our own purposes. If an organization uses Coral Code under an enterprise agreement, that agreement or a data processing addendum may assign different controller and processor roles.

Do not submit secrets, regulated data, personal information, or third-party code to a model or service unless you have authority to do so and have reviewed that service's terms and privacy practices.

2. How Coral Code handles project data

Local processing

Coral Code indexes and records project information inside your JetBrains environment. Its local records can include file and symbol relationships, source snippets, test and coverage information, execution paths and captured parameters, prompts and responses, agent messages, proposed edits, model choices, and token or quota observations. Coral Code uses these records to show project context, coordinate agents, preserve evidence, and help you review work.

Coral Code stores local records in its configured local database, project or user configuration, IDE logs, and JetBrains Password Safe. CoralOS does not receive those local records merely because you install or open the Plugin.

Remote model and embedding requests

Coral Code does not send project content to an external model merely because you install the Plugin. When you sign in or configure a provider and start a model-powered or embedding feature, Coral Code sends the information needed for that request to the route you selected. That information can include prompts, relevant source code, file names and paths, test or coverage context, tool definitions and results, agent messages, and request metadata.

Available routes can include Coral Cloud, direct OpenAI, Anthropic or DeepSeek APIs, an optional Jina embedding service, or locally launched Codex, Claude, or Junie clients that connect under your existing provider account. The selected provider's terms and privacy policy govern its processing.

Credentials

Coral Cloud credentials saved through the Plugin use JetBrains Password Safe. Direct provider credentials can come from environment variables, project configuration, or other developer-managed settings. Coral Code uses credentials to authenticate the service you selected. We do not ask you to send credentials to support.

3. Information we collect

Depending on the features and services you use, we may process:

  • Account and transaction information: name, email address, sign-in provider identifiers, plan, quota, billing status, and transaction records associated with Coral Cloud or a Marketplace purchase.
  • Project and interaction content: prompts, source code and snippets, file names and paths, symbols, tests, coverage, runtime observations, captured values, agent messages, tool results, edits, and generated output that a remote request includes.
  • Technical and usage information: Plugin and IDE version, operating system, model and provider selection, request timing and status, token counts, quota use, error information, IP address, and security logs generated when you access a CoralOS service.
  • Support and feedback: messages, attachments, contact details, and diagnostic information you choose to send us.
  • Website information: standard request data such as IP address, browser type, requested page, and time of access processed by our hosting and content-delivery providers. coralcode.dev does not run CoralOS advertising or general-purpose analytics scripts as of the effective date. It loads web fonts from Google, which can receive standard connection information.

JetBrains processes Marketplace accounts, installations, licensing, purchases, and related records under its own privacy notice. CoralOS receives only the information that JetBrains makes available to plugin vendors under the Marketplace relationship.

4. How we use information

We use information to:

  • provide the Plugin, Coral Cloud connections, model requests, account features, support, and requested integrations;
  • authenticate users, calculate quota or usage, process transactions, and maintain service records;
  • secure services, prevent abuse, diagnose errors, and enforce applicable terms;
  • respond to support requests and feedback; and
  • comply with law and protect the rights, safety, and property of users, CoralOS, and others.

Where applicable law requires a legal basis, we rely on performance of a contract, your consent or instructions, our legitimate interests in operating and securing the service, and compliance with legal obligations. You can withdraw consent for future processing where consent is the basis, but that does not affect processing that already occurred.

CoralOS does not sell personal information or use project content for targeted advertising. CoralOS does not use project content to train CoralOS models unless you join a separate program that explains the use and asks you to opt in. A third-party model provider may apply different rules, so review the provider terms for the route you select.

5. Services, sharing, and transfers

We disclose information only as needed to provide a feature you request, operate the business, or comply with law. Recipients can include:

  • Coral Cloud and its infrastructure, payment, authentication, security, support, and model-processing providers;
  • the model, embedding, or agent provider you configure, including OpenAI, Anthropic, DeepSeek, Jina/Elastic, Codex, Claude, or Junie services;
  • JetBrains for Marketplace distribution, licensing, purchases, moderation, and support;
  • professional advisers, authorities, or counterparties when required for legal, security, corporate, or transaction purposes; and
  • a successor in a merger, financing, acquisition, reorganization, or sale of relevant assets, subject to applicable law.

These recipients may process information outside your country. Where required, we use an approved transfer mechanism or rely on another lawful basis for the transfer. Provider policies and account settings determine where direct third-party routes process and store requests.

Useful provider notices include the Coral Cloud privacy policy, OpenAI privacy policy, Anthropic Privacy Center, DeepSeek privacy policy, Elastic privacy statement for Jina services, and JetBrains Privacy Notice.

6. Your choices and controls

  • You can use non-model local features without signing in to Coral Cloud.
  • You choose whether to sign in, add a provider credential, select a provider, or start a remote model or embedding request.
  • You can remove a Coral Cloud credential from the Plugin and remove direct provider credentials from the environment or configuration where you stored them.
  • You control agent permissions and remain responsible for reviewing file changes, tool use, and generated output.
  • You can contact us to request access, correction, deletion, or another right that applies to information controlled by CoralOS.

Disabling a credential stops future requests through that route. It does not delete information that the provider already processed. Use the provider's account controls or contact the provider for those records.

7. Retention and security

Local records remain in the configured local database, files, logs, or Password Safe until you delete them, clear the relevant storage, or an applicable product retention rule removes them. Uninstalling the Plugin may not remove every local database, configuration, log, or credential entry.

We keep CoralOS account, service, security, support, and transaction records for as long as needed to provide the service, meet legal or accounting duties, resolve disputes, prevent abuse, and enforce agreements. We delete or de-identify information when it is no longer needed, subject to backups and legal holds.

We use administrative, technical, and organizational safeguards appropriate to the information and service. No system or transmission method is completely secure. You remain responsible for repository access controls, credential handling, provider configuration, backups, and deciding which content a model may receive.

8. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of personal information; object to or withdraw consent for certain processing; and appeal a denied request. You may also complain to your local data protection authority.

We do not discriminate against you for exercising a privacy right. We may verify your identity and authority before completing a request. Legal exceptions can limit a right, including where we must keep records for security, fraud prevention, legal claims, or regulatory duties.

Coral Code is a professional developer tool and is not directed to children under 16. We do not knowingly collect personal information from children through Coral Code. Contact us if you believe a child provided personal information.

9. Changes to this policy

We may update this policy when the product, providers, or law changes. We will post the revised policy here and change the effective date. We will provide additional notice when applicable law requires it.

10. Contact us

Send privacy requests to cloudprivacy@coralos.ai. Send product and support questions to coral-code@coralos.ai.

CoralOS, Inc. 108 W. 13th Street, Suite 100 Wilmington, Delaware 19801-1145 United States

Copyright 2026 CoralOS, Inc.

coral-code Privacy License Contact