Contents

Collivo — Privacy Policy

Effective date: 10 August 2026 · Version: 2.0 · Last updated: 10 August 2026


This Privacy Policy applies to all Personal Information collected by Collivo Labs Pty Ltd (we, us or our) through the Collivo platform, our website at www.collivo.com (Website), and our related applications and services (together, the Services).

1.What information do we collect?

The kind of Personal Information that we collect from you will depend on how you use the Services. The Personal Information which we collect and hold about you may include:

1.1. Information you provide directly

  • Account and identity data — your name and email address (used for registration and authentication), and your company name and job title (collected at sign-up to organise your workspace).
  • Profile information — your avatar/profile photo and display preferences (such as theme and notification settings).
  • Workspace content — documents, files, notes, whiteboards, task boards, AI chat history, and AI-generated images, and any other data you create, upload, or import into the platform within your workspaces.
  • Communications within the platform — messages, direct messages between users, comments, reactions, mentions, and shared content, together with associated metadata such as read receipts.
  • Requests and support communications — access-request messages, and any information you provide when you contact us for support.
  • Feedback — ratings (e.g. thumbs up/down) and suggestions you submit about AI responses or the service.

1.2. Information we collect automatically

  • Usage and activity data — workspace activity, collaboration patterns, feature interactions, and an activity log of actions you take on the platform.
  • Device, browser, and connection data — IP address, browser type, operating system, and time zone/locale.
  • Approximate location — general location inferred from your IP address.
  • Cookies and local storage — essential session, authentication, and security (CSRF) cookies, and locally stored interface preferences. (See the Cookies section below.)
  • Log and diagnostic data — error reports, timestamps, and system events used to operate, secure, and troubleshoot the service.
  • Authentication and session data — session and token data used to keep you signed in and protect your account.

1.3. Information we generate or infer

  • AI-inferred insights — summaries, inferred work patterns, topics, decisions, and learnings about you that our AI generates from your activity to provide and personalise the service.
  • Search embeddings — vector representations of your content created to power search and AI features. These embeddings are computed within our own infrastructure.

1.4. Information from connected third-party services

When you choose to connect a third-party account, we collect, with your authorisation:

  • Connection credentials — encrypted OAuth access and refresh tokens, and the connected account's email address and avatar.
  • Ingested content — as permitted by the scopes you grant: the content of email messages and their attachments (Gmail/Outlook), including sender and recipient addresses, subject lines, and message bodies; the contents of files you select (Google Drive/SharePoint/OneDrive/Box); code and repository data (GitHub); and calendar events.
  • What happens to imported content if you disconnect — content you import becomes part of your workspace and remains there if you later disconnect the account it came from. Disconnecting revokes our access to the source account; it does not remove the copy you already imported, which may by then have been edited or built upon. You can delete imported content yourself at any time, and it is otherwise retained as described in section 7. Calendar data is treated differently — see below.
  • Calendar data, including third parties' information — when you sync a calendar, we collect event details such as attendee names and email addresses, organiser information, meeting links, and locations. This may include personal information about people who are not users of our platform. Calendar data is deleted if you disconnect your calendar integration, or within 30 days after your calendar authentication expires and you do not resync your calendar with the Collivo platform.
  • Single sign-on data — when you sign in via our identity provider (WorkOS), we receive your name, email address, profile photo, and organisation membership.

Use of data from Google services. Where you connect a Google account, Collivo's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Because our Gmail and Google Drive integrations use restricted scopes, our use of that data also adheres to the Google Workspace API User Data and Developer Policy, including its Limited Use requirements. Specifically:

  • What we access. With the scopes you grant: the content of your Gmail messages and their attachments; the contents of the Google Drive files you select; your Google Calendar events (described above); and your Google account's email address, name, and profile picture.
  • How we use it. Only to provide and improve the user-facing features you have connected it to, which are visible and prominent in the product — importing email threads and files into your workspace, syncing your calendar, and making that content available to the AI features you invoke.
  • AI and machine-learning models. We do not use information received from Google APIs — or any data aggregated, anonymised, or derived from it — to create, train, fine-tune, or improve any AI or machine-learning model. When you ask an AI feature to work with Google-derived content, we send that content to our AI providers solely to generate your response, under API terms that prohibit training on it and limit how long they may retain it (see section 3).
  • Advertising. We do not use it for advertising. We do not transfer it to advertising platforms, data brokers, or information resellers, and we do not use it to determine credit-worthiness or for lending purposes.
  • Human access. We do not allow humans to read it, except: with your affirmative consent to view specific messages or files; where necessary for security purposes, such as investigating abuse; to comply with applicable law; or where the data has been aggregated and anonymised for internal operations. For information received from Google APIs, this narrower rule applies in place of the general personnel access described in section 6.3 of this policy and section 7.7 of our Terms of Service.
  • Sale. We never sell it.

2.How your information is shared with our sub-processors

To deliver core functionality, certain content you provide is transmitted to trusted third-party processors:

  • AI assistant (chat) — your prompts, document context, and AI reasoning steps are sent to the large language model providers that generate the response: by default Anthropic, OpenAI, and Groq directly, and additional vetted providers routed through our AI gateway (OpenRouter). See section 3 for how these providers handle your data.
  • Image generation — your image-generation prompts are sent to our image-generation provider (Together AI) to create images.
  • Web search — search queries you trigger are sent to our web-search provider (Brave) to return results.
  • Observability — we do not use a third-party AI-observability or monitoring service, and your prompts, AI responses, and reasoning traces are not sent to one.
  • Infrastructure — we host and store data with cloud infrastructure providers (Amazon Web Services for hosting, storage, and secrets, and MongoDB Atlas for our database), and host our marketing site — including its cookieless, aggregated traffic analytics — with Vercel.
  • Payment providers — if you purchase a paid plan, your billing details, transaction history, and any contact details required to process payment are collected and processed securely by a third-party payment provider (Stripe).
  • Waitlist (marketing site) — if you join our waitlist, your email address is collected through a third-party waitlist provider (Waitlister).

We maintain a current list of our sub-processors, which is published on our website at https://www.collivo.com/subprocessors.

3.AI processor safeguards and data retention

We configure our AI features so that third-party AI providers do not train on your content, and we limit how long they may retain it:

  • Chat and assistant. By default, your prompts and inputs are sent to the language-model providers that generate the response — Anthropic, OpenAI, and Groq directly, and additional vetted providers routed through our AI gateway (OpenRouter). None of these providers train on your content. The direct providers may retain your prompts and outputs only briefly for safety and abuse monitoring (up to 30 days) before deletion; the gateway-routed providers are configured for Zero Data Retention and do not store them at all. Your organisation's admin can enable Zero Data Retention for the organisation (off by default), which disables the direct providers so that all AI requests run only through the zero-data-retention providers. These providers are located in the United States and, for some gateway-routed models, in the European Union (France, Finland, Spain, the Netherlands, or Sweden) or Israel (see "Overseas transfer" below). These protections depend on the settings we enable and on each provider's own policies, and we do not control third-party systems.
  • Image generation. Image-generation prompts and images are processed by Together AI with Zero Data Retention enabled and no training on your prompts or images, and the model developer has no access to your prompts or images.
  • This concerns the third-party providers, not Collivo. We still store your workspace content (including AI chat history and AI-generated images) in your workspace in order to provide the Services, as described in section 1 and section 7.
  • Web search. When you use the assistant's web-search feature, your search query is sent to Brave to return results. Brave retains a record of API search queries for up to 90 days for billing and troubleshooting purposes, and states that it does not collect identifiers that link a search query to an individual.
  • Observability. We do not use a third-party AI-observability or monitoring service. Your prompts, AI responses, and reasoning traces are not sent to any third party other than the providers described in this section.

We put Data Processing Agreements in place with our sub-processors where they are available, which limit use of your data to providing the service, require appropriate security, and provide for deletion on termination. A small number of AI providers make their services available only on standard terms and do not enter into a separate agreement; for these, we rely on their published data-processing and privacy terms together with the no-training and zero-data-retention settings we configure (described above), which we consider provide a comparable level of protection given how limited and, where zero data retention applies, non-retained the processing is. AI features are a core part of the Services and cannot be turned off while you continue to use them. You do, however, control when you use the AI assistant and image generation; your organisation's admin can enable Zero Data Retention (described above); and you can request deletion of your processed data — or stop using the Services — by contacting us at the email address in this policy.

4.Types of information

The Privacy Act 1988 (Cth) (Privacy Act) defines types of information, including Personal Information and Sensitive Information.

Personal Information means information or an opinion about an identified individual, or an individual who is reasonably identifiable: whether the information or opinion is true or not; and whether the information or opinion is recorded in a material form or not.

If the information does not disclose your identity or enable your identity to be ascertained, it will in most cases not be classified as "Personal Information" and will not be subject to this privacy policy.

Sensitive Information is defined in the Privacy Act as including information or opinion about such things as an individual's racial or ethnic origin, political opinions, membership of a political association, religious or philosophical beliefs, membership of a trade union or other professional body, criminal record or health information.

Sensitive Information will be used by us only: for the primary purpose for which it was obtained; for a secondary purpose that is directly related to the primary purpose; and with your consent or where required or authorised by law.

5.How we collect your Personal Information

5.1. We may collect Personal Information from you whenever you input such information into the Services, the Website, related app, or provide it to us in any other way.

5.2. Cookies. We use only essential cookies (for authentication, session management, and security/CSRF protection) and store certain interface preferences locally in your browser. We do not currently use third-party analytics, advertising, or marketing cookies. Essential cookies are necessary for the platform to function and persist only for the duration of your session or login token. As a general rule, it is not possible to identify you personally from our use of essential cookies. Our marketing website uses Vercel's built-in Web Analytics to measure traffic; it does not set cookies or any persistent identifier, is not designed to identify you personally, and does not track you across other websites or applications — see our sub-processors page for details. If we introduce analytics or marketing cookies in future, we will update this policy and obtain consent where required.

5.3. Sensitive Information. We do not seek or require Sensitive Information, and none of our sign-up or profile fields ask for it. However, because you control what you create, upload, import, or submit, your content — including material imported from connected accounts — may contain Sensitive Information. Where you choose to include Sensitive Information in your content, you consent to us collecting, storing, and processing it as part of that content to provide the Services and in accordance with this policy, and you are responsible for having any rights or consents needed to include it (including any Sensitive Information about other people). We ask that you not include Sensitive Information in AI image-generation prompts (see our Acceptable Use Policy). We otherwise handle Sensitive Information as described in section 4, and only where permitted by law — including with your consent or where the collection is required or authorised by law.

5.4. Where reasonable and practicable we collect your Personal Information from you only. However, sometimes we may be given information from a third party (for example, when you connect a third-party account, or when another user includes your information in their workspace); in cases like this we will take reasonable steps to make you aware of the information that was provided by a third party.

6.Purpose of collection

6.1. We collect Personal Information to provide you with the best service experience possible, to provide and improve our services, and to keep in touch with you about developments in our business. We take reasonable steps to notify individuals of the matters required by the Privacy Act at or before the time we collect their Personal Information, including through this policy and any collection notices made available at the relevant point of collection. Where consent is required by law, including in relation to Sensitive Information or certain direct marketing activities, we will obtain that consent before collecting, using or disclosing the relevant Personal Information.

6.2. We collect and use your Personal Information for the following specific purposes:

  • Account and identity data (name, email, company name, job title) — to create and manage your account, authenticate your identity, and organise your workspace.
  • Profile information (avatar, display preferences) — to personalise your experience and maintain your workspace settings.
  • Workspace content (documents, files, notes, task boards, AI chat history, AI-generated images) — to provide the core functionality of the platform, including storage, retrieval, collaboration, and AI-assisted features within your workspace.
  • Communications within the platform (messages, comments, mentions) — to facilitate collaboration between users and deliver platform notifications.
  • Support communications — to respond to your enquiries, troubleshoot issues, and improve our customer support.
  • Feedback (ratings and suggestions) — to evaluate and improve the quality and reliability of our AI features and overall service.
  • Usage and activity data — to monitor platform performance, understand how features are used, and improve the service.
  • Device, browser, and connection data — to ensure platform compatibility, maintain security, and diagnose technical issues.
  • Approximate location (inferred from IP address) — to apply appropriate regional settings and comply with applicable legal obligations.
  • Cookies and local storage — to manage authentication sessions and store your interface preferences.
  • Log and diagnostic data — to operate, secure, and troubleshoot the platform.
  • AI-inferred insights and search embeddings — to power personalised AI features, including intelligent search, summaries, and workspace recommendations.
  • Third-party connected service data (emails, files, repositories, calendar events, SSO data) — to enable integrations you have expressly authorised and to provide connected features within your workspace.
  • Payment and billing data — to process transactions, manage your subscription, and comply with financial record-keeping obligations.

6.3. We disclose Personal Information only to service providers (sub-processors) who assist us in operating the Services — such as cloud hosting and storage, our database provider, authentication, our AI gateway and image-generation provider, web search, and payment processing — and only to the extent necessary for them to perform their function. Your Personal Information may also be accessed by a limited number of our authorised personnel, under access controls, acting in the normal course of their duties. We maintain a current list of our sub-processors, which is published on our website at https://www.collivo.com/subprocessors.

6.4. Service provider obligations. For our service providers generally, before a service provider handles your Personal Information we put in place a Data Processing Agreement (or equivalent standard data-processing terms) that, consistent with the Australian Privacy Principles, requires the provider to: (a) process Personal Information only on our documented instructions and only for the specified purpose; (b) not use it for any secondary purpose, including training AI models, except as permitted by this policy; (c) implement appropriate technical and organisational security measures; (d) keep it confidential; (e) assist us in responding to access, correction and deletion requests; (f) notify us without undue delay of any data breach affecting your Personal Information; (g) delete or return it on termination of their services; and (h) impose substantially equivalent obligations on any of their own sub-processors. We take reasonable steps to satisfy ourselves that our service providers comply with these obligations. A small number of AI model and image-generation providers make their services available only on standard published terms and do not enter into a separate Data Processing Agreement; for those providers we rely on their published data-processing and privacy commitments together with the technical safeguards we configure (including the no-training and zero-data-retention settings), which — given the limited and, where zero data retention applies, non-retained nature of the processing — we consider provide a level of protection consistent with these principles.

6.5. Overseas transfers. Some of our service providers are located, or process data, outside Australia (primarily in the United States); in addition, the model providers that power the AI assistant may process your prompts in the European Union (France, Finland, Spain, the Netherlands, and Sweden) or Israel (under the zero-data-retention configuration described in section 3). Where we transfer Personal Information overseas, we take reasonable steps to ensure the recipient handles it in a manner consistent with the Australian Privacy Principles — relying on each provider's data-protection terms (a Data Processing Agreement where the provider offers one, or otherwise its published data-processing and privacy terms together with the safeguards we configure, such as zero-data-retention and no-training settings), and on any recognised transfer safeguards a provider makes available (such as Standard Contractual Clauses, where offered). See the Overseas transfer section below for further detail.

6.6. Direct marketing. We will only send you direct marketing material if you have expressly opted in through the registration process, and only material of a type you would reasonably expect to receive from us. We do not use Sensitive Information in direct marketing. You can manage your marketing preferences at any time by clicking the unsubscribe link in any communication. We will process opt-out requests within 5 business days and maintain records of your consent preferences in accordance with the Privacy Act.

7.Security, access, correction and retention

7.1. Security. We store your Personal Information in a way that reasonably protects it from unauthorised access, misuse, modification or disclosure, including encryption in transit and at rest and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7.2. Retention and deletion. We retain your Personal Information and workspace content for as long as your account (or your organisation's account) is active and as needed to provide the Services. When you delete content, or when your account is closed, we delete the associated Personal Information, subject to: (a) residual copies that remain in our encrypted backups, which are overwritten on our standard backup cycle within 30 days; (b) information we are required or permitted to retain by law (for example, billing and transaction records, which may be kept for up to 7 years, and material we are legally required to preserve, such as for child-safety reporting or law-enforcement purposes); and (c) your ability to delete individual items at any time. We do not restore backups to reinstate data you have deleted, except where necessary for disaster recovery, and if a restoration reintroduces deleted data we re-delete it promptly. We take reasonable steps to destroy, anonymise, or de-identify Personal Information that we no longer require, including through automated retention controls.

7.3. Access and correction. You may request access to, correction of, or deletion of the Personal Information we hold about you by contacting us (see below); we have processes in place to action such requests. The Australian Privacy Principles permit you to obtain access to the Personal Information we hold about you in certain circumstances (Australian Privacy Principle 12) and to correct inaccurate Personal Information subject to certain exceptions (Australian Privacy Principle 13). Where Personal Information forms part of your organisation's workspace, some requests may be directed to, or require the involvement of, your organisation administrator.

8.Children and minimum age

The Services are intended only for users who are at least 18 years old. We do not direct the Services to, or knowingly collect Personal Information from, anyone under 18. If you believe a person under 18 has provided us with Personal Information, please contact us, and if we become aware that we have collected Personal Information from a person under 18 (or under 13), we will take reasonable steps to delete that information and close the account, except where we are required to retain certain records by law.

9.Complaint procedure

If you have a complaint concerning the manner in which we maintain the privacy of your Personal Information, please contact us using the contact details set out at the bottom of this policy. All complaints will be considered by our team, and we may seek further information from you to clarify your concerns. If we agree that your complaint is well founded, we will, in consultation with you, take appropriate steps to rectify the problem. If you remain dissatisfied with the outcome, you may refer the matter to the Office of the Australian Information Commissioner.

10.Overseas transfer

Your Personal Information is processed primarily in the United States (where our core infrastructure and most of our AI providers operate). Depending on the AI model you use, your prompts may also be processed by providers located in the European Union (France, Finland, Spain, the Netherlands, and Sweden) or Israel. Our current providers and their locations are listed on our Sub-processors page at https://www.collivo.com/subprocessors. We rely on the mechanisms described in sections 6.4 and 6.5 of this policy — a Data Processing Agreement where a provider offers one, or otherwise the provider's published data-protection terms together with the safeguards we configure (such as zero-data-retention and no-training settings), plus any recognised transfer safeguards a provider makes available (such as Standard Contractual Clauses, where offered) — to protect your Personal Information when it is transferred overseas. Where your Personal Information is sent to a recipient in a country with data protection laws at least substantially similar to the Australian Privacy Principles, and where there are mechanisms available to you to enforce protection under that law, we will not be liable for a breach of the Australian Privacy Principles if your Personal Information is mishandled in that jurisdiction. Where your Personal Information is transferred to a jurisdiction without data protection laws as comprehensive as Australia's, we take reasonable steps to secure a contractual commitment from the recipient to handle your information in accordance with the Australian Privacy Principles.

11.GDPR and UK GDPR

In some circumstances, the European Union General Data Protection Regulation (GDPR) and the United Kingdom GDPR provide additional protections to individuals in the European Union, the European Economic Area, or the United Kingdom. Being located in one of those places does not, on its own, make those laws apply to a business outside the region — they apply only where the business targets or offers goods or services to people there, or monitors their behaviour.

We currently provide the Services from Australia for customers in Australia and the United States. We do not direct or market the Services to, or monitor the behaviour of individuals in, the European Union, the European Economic Area, or the United Kingdom, and accordingly the GDPR and UK GDPR do not currently apply to our processing.

If your organisation has specific regional or data-protection requirements, you are welcome to contact us at privacy@collivo.com to discuss them. The security and data-protection measures we apply — including encryption, access controls, contractual terms with our providers, and the AI safeguards described above — apply to all our customers and are set out throughout this policy. Should we take on customers or users in the EU, EEA, or UK, we would address the specific additional requirements those laws impose at that time and update this policy accordingly.

12.How to contact us about privacy

If you have any queries, or if you seek access to your Personal Information, or if you have a complaint about our privacy practices, you can contact us through: privacy@collivo.com.

13.Data breach notification

If we suspect a data breach affecting your Personal Information, we will assess it promptly — and in any event within 30 days of becoming aware of it — to determine whether it is likely to result in serious harm. If we have reasonable grounds to believe an eligible data breach has occurred, we will notify the Office of the Australian Information Commissioner and affected individuals as soon as practicable, in accordance with the Notifiable Data Breaches scheme under the Privacy Act, including the nature of the breach, the information affected, and the steps you can take in response.

Related: Terms of Service · Acceptable Use Policy · Sub-processors