Privacy Policy
Last updated: June 24, 2026
This policy is written in plain language so it is easy to read. It is a template provided for transparency, not legal advice — please have your own counsel review it before relying on it. Items in [BRACKETS] are placeholders the owner must finalize (for example, governing regions or age thresholds). Where this policy describes legal rights, those are honest commitments about how we intend to operate, not a claim to any specific certification.
CoreReflex ("CoreReflex," "we," "us") is the agentic AI film studio, operated by Girard Media. This policy explains what we collect when you use CoreReflex, why we collect it, who helps us process it, and the choices and rights you have. We try to collect only what the product actually needs to work.
01Who this covers
This policy applies to the CoreReflex web application, the studio editor, the marketing site at corereflex.com, and the optional Pro client-operations and voice features. If you use CoreReflex on behalf of an organization, that organization is the controller of the content you create and is responsible for the data it puts into the workspace.
02Data we collect
We collect the following categories of data, and only what we need to run the service:
- Account data. Your email address and a password that is stored only as a secure, salted hash (bcrypt-style one-way hashing). We never store your password in plaintext and cannot recover it — only reset it.
- Workspace content you create. Briefs, scripts, personas, projects, and the images, video, and audio CoreReflex generates for you. This is your content; it lives in your workspace.
- Client-operations (CRM) data — Pro features only. If you use the client-operations tools, the contacts, notes, tasks, meeting briefs, and bookings you enter. We only have this if you choose to use those features.
- Voice-agent transcripts — voice features only. If you use the voice features, the transcripts of those sessions, so the agent can function and you can review them.
- Billing data. Payments are handled by Stripe. We receive limited billing details (such as your plan, status, and the last digits or card brand Stripe returns) but we do not store full card numbers.
- Usage, audit, and operational logs. Records such as sign-ins, actions taken, credits metered, IP and device/browser data, and error logs. We use these for security, abuse prevention, billing accuracy, and reliability.
03Cookies and local storage
We keep this minimal and use no third-party advertising or cross-site tracking cookies:
- Session cookie (essential). A JWT-based authentication cookie that keeps you signed in. The product does not work without it.
- Local preferences. Small values stored in your browser to remember settings and improve your experience.
We do not run advertising pixels or sell your browsing behavior. Because we only use essential and preference storage, there is no third-party ad network tracking you across other sites through CoreReflex.
04How we use your data
- To provide and operate the service and to generate your media.
- To meter usage and credits so plans and billing are accurate.
- To secure accounts — including audit logging, session revocation, and abuse prevention.
- To respond to you and provide support.
- To comply with the law and enforce our terms.
We do not use your private workspace content to train models for other customers. See the cross-tenant section below for the one optional, opt-in exception.
05AI processing and subprocessors
CoreReflex runs on AI models we do not host ourselves. To generate your media, the prompts and the inputs necessary for that generation are sent to our processors. We share only what is needed to perform the requested task. Our current subprocessors are:
| Subprocessor | Purpose | Data shared |
|---|---|---|
| Google Cloud / Vertex AI | Runs the models: Gemini (planning and voice), Veo (video), Lyria (music), Imagen (images), plus embeddings and speech-to-text / text-to-speech. | Your prompts and the inputs needed to generate the requested output. |
| Stripe | Payment processing and subscription management. | Billing identifiers and payment details (Stripe holds card data, not us). |
| Cloudflare | DNS, CDN/edge delivery, and object storage. | Network/request data and stored media routed through the edge. |
| Google Fonts | Serves the web fonts used by our pages. | Standard request data (such as IP) needed to deliver the fonts. |
We will update this list as our subprocessors change. If you need a formal data-processing agreement for your organization, contact us.
06Cross-tenant learning (optional, opt-in)
CoreReflex has an optional, privacy-safe network-effect feature: votes can be turned into embeddings that improve recall and suggestions across the platform. This is off by default and is opt-in.
By default, a tenant's private content is not shared or used across other tenants. Enterprise Private mode disables any cross-tenant use entirely, so your content stays within your own workspace. You control whether you participate.
07Data location and security
Our core infrastructure is self-hosted: a PostgreSQL database and MinIO object storage running on a managed VPS fleet. We apply security practices appropriate to a product at our stage, including:
- TLS encryption for data in transit.
- Scoped, presigned credentials for accessing your media, rather than open buckets.
- Least-privilege service accounts so each component can reach only what it needs.
- Passwords stored only as one-way hashes, plus audit logging and session revocation.
No system can be guaranteed perfectly secure, but we work to protect your data and to improve our practices over time.
08How long we keep data (retention)
We keep your data while your account is active so the product works for you. When you request deletion or close your account, we delete or anonymize your data, except where we must retain certain records for legal, tax, or billing reasons (for example, invoice history). Operational logs are kept for a limited period for security and reliability.
09Your rights and choices
You can exercise the following at any time:
- Access and export. You can access your data, and contacts can be exported directly from the app.
- Correct. Update inaccurate account or workspace information from within the product.
- Delete. Accounts and contacts can be deleted from the app. You can also ask us to delete your data, subject to the retention exceptions above.
- Contact us. Send any privacy request to the address in the Contact section and we will act on it.
If you live in a region with data-protection laws such as the GDPR or CCPA, we are committed to honoring the rights those laws provide — including access, correction, deletion, portability, and the right to object to or restrict certain processing — to the extent they apply to you. We do not sell your personal information.
10Children
CoreReflex is not directed to children under [AGE] (at least 16). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
11International transfers
Because we rely on the subprocessors listed above, your data may be processed in the regions where those providers and our fleet operate ([REGIONS]). Where required, we rely on appropriate safeguards for cross-border transfers.
12Changes to this policy
We may update this policy as the product evolves. When we do, we will post the new version here and update the "Last updated" date at the top. Significant changes will be communicated where appropriate.
13Contact
For any privacy question or request, reach us at:
CoreReflex — Girard Media
bgirard@girardmedia.com