CORA AI Privacy Policy
Effective date: 15 August 2026
YourLifePurpose Limited (“YourLifePurpose”, “YLP”, “we”, “us”, or “our”) explains in this Privacy Policy how we collect, use, disclose, protect, and retain personal information when you visit our website, purchase or use CORA AI, contact us, or participate in a corporate CORA AI account.
1. Who we are
YourLifePurpose Limited is based at 9 Regents Gardens, Westmoorings, Port of Spain, Trinidad and Tobago. Privacy questions may be sent to info@yourlifepurpose.com. Our privacy contact/data-protection role is Anthony Hadeed, CEO / Leadership, Career, and Life Coach.
2. Information we collect
Depending on how you use the service, we may collect:
- name, email address, telephone number, company, and account details;
- authentication, access, subscription, seat, billing-status, and support information;
- payment and transaction information. Card details are handled by Stripe or the payment provider and are not stored by CORA in full;
- conversation prompts, messages, generated summaries, saved reports, and other content you choose to submit;
- employee and corporate-administration information such as name, email, access status, subscription status, access-email status, last CORA login, and monthly conversation-usage counts;
- device, browser, IP-address, security, diagnostic, and service-usage information; and
- information you provide in communications, forms, surveys, assessments, or support requests.
Please do not submit highly sensitive information unless it is necessary for your use of the service and you have a lawful basis to do so.
3. How we use information
We may use personal information to:
- create and administer accounts and subscriptions;
- provide CORA AI, conversation history, summaries, assessments, and support;
- administer corporate seats, employee access, usage limits, billing, and security;
- process payments, refunds, cancellations, receipts, and billing communications;
- send access emails, service notices, and requested support messages;
- protect the service, investigate misuse, prevent fraud, and maintain records;
- understand service performance and improve features, subject to applicable law and appropriate safeguards;
- comply with legal obligations or respond to lawful requests.
4. Privacy principles and legal grounds
We aim to collect only information reasonably necessary for identified purposes, use it fairly and transparently, keep it accurate, protect it with appropriate safeguards, and retain it only as long as reasonably necessary. The applicable legal basis may include consent, performance of a contract, legal obligations, and legitimate business interests. The final legal basis for each processing activity should be confirmed before publication.
5. AI processing
Conversation content may be processed by the AI and technology providers used to operate CORA AI. The relevant providers and their respective safeguards as of the date of this document are OpenAI (https://openai.com/policies/usage-policies/) and/or Anthropic (https://support.claude.com/en/collections/4078535-safeguards). CORA AI should not be used to submit information that you are not authorised to share.
6. Corporate employee privacy
Corporate administrators may see employee name, email address, subscription status, CORA access status, access-email status, last CORA login, and monthly distinct-conversation usage information needed to administer company seats and access.
Through the CORA company portal, employers do not receive the employee’s private conversation text, prompts, or personal AI-generated conversation summaries, unless the employee deliberately shares them or disclosure is required by law.
Employers are responsible for providing employees with any additional workplace privacy notice required for their use of CORA AI.
7. When we disclose information
We may disclose information to service providers that help us provide hosting, AI infrastructure, payment processing, email, authentication, security, analytics, customer support, and technical operations. We may also disclose information when required by law, to protect rights and safety, in connection with a business transfer, or with your consent. The current provider list and transfer safeguards are:
- OpenAI: https://openai.com/policies/row-terms-of-use/
- Anthropic: https://privacy.claude.com/en/articles/9190861-terms-of-service-updates
- Stripe: https://stripe.com/legal/ssa-services-terms
- WordPress: ttps://wordpress.com/tos/
- Render: https://render.com/dpa
- Cloudflare: https://www.cloudflare.com/website-terms/
- GitHub: https://github.com/customer-terms/github-data-protection-agreement
8. International transfers
Some providers may process information outside Trinidad and Tobago and the United States of America. The current provider list and relevant international locations are:
- OpenAI: Australia, Brazil, Canada, France, Germany, India, Indonesia, Ireland, Italy, Japan, Mexico, Netherlands, Norway, Poland, Singapore, South Africa, South Korea, Spain, Sweden, Switzerland, United Arab Emirates, United Kingdom.
- Anthropic: European Union.
- Stripe: India (for local data localisation mandates), Canada, the United Kingdom, Australia, Japan, Germany, Luxembourg, Malaysia, the Philippines, and Colombia
- WordPress: Ireland, Europe, and Asia-Pacific
- Render: Germany and Singapore
- Cloudflare: European Economic Area, the United Kingdom, Canada, Japan, Australia, Singapore, and India
- GitHub: European Union, Australia, and Japan
8. Retention and security
We retain information only for as long as reasonably necessary for the purposes described above, legal obligations, dispute resolution, fraud prevention, and accounting. Retention periods by category are:
B2C CORA AI Questions and Answers
- CORA AI Application Standard: This type of data is retained for the duration of the active account to preserve coaching history, and then it is hard-deleted within 30 days of account closure.
- Vendor Alignment: OpenAI and Anthropic store all API prompts and completions for 30 days in a secure cache strictly for abuse monitoring and safety reviews before auto-deletion. Neither vendor trains foundation models on standard API data payloads.
B2B CORA AI Questions and Answers
- CORA AI Application Standard: This type of data is hard-purged within 30 days of contract termination, or instantly upon request by corporate clients.
- Vendor Alignment: We are in the process of implementing the OpenAI/Anthropic Zero Data Retention (ZDR) configuration.
B2C & B2B Subscriptions and Financial Transactions
- CORA AI Application Standard: This type of data is retained for 7 years to satisfy global audit, tax, and financial regulations (such as Canada’s CRA and US IRS rules).
- Vendor Isolation: We never pass financial or transaction data to the LLM APIs. This data bypasses OpenAI/Anthropic completely and lives exclusively within our online merchant payment provider, Stripe.
B2B Company AI Statistics
- CORA AI Application Standard: This type of data is retained for 3 years or the life of the corporate contract, whichever comes first, in order to display multi-year ROI dashboards.
- Anonymisation Note: Because this data consists of aggregated metrics (e.g., “Engineering department asked 400 questions this month”), it contains no personal information or raw text. It is completely safe from strict privacy deletion mandates
We use reasonable administrative, technical, and organisational safeguards. No online service can guarantee absolute security.
Note that if a B2C user attempts to “jailbreak” CORA AI or inputs text that triggers safety filters, OpenAI and Anthropic will override their standard deletion policies. They will flag and store policy violations for significantly longer (Anthropic retains flagged violations for up to 2 years for trust and safety validation). Toxic or illegal inputs forfeit regular swift deletion policies.
10. Your choices and rights
Subject to applicable law, you may ask us about the personal information we hold, request correction, raise an objection or concern, withdraw consent where consent is the basis, or request deletion where appropriate. We may need to verify your identity and may retain limited information where legally required.
11. Children
CORA AI is not directed at children under the age of 14 years. Do not use the service or submit a child’s personal information without appropriate authorisation and a lawful basis.
12. Changes and contact
We may update this Policy by posting a revised version with a new effective date. Questions or privacy requests may be sent to info@yourlifepurpose.com or mailed to YourLifePurpose Limited, 9 Regents Gardens, Westmoorings, Port of Spain, Trinidad and Tobago.