Last updated August 4, 2026
Privacy Policy
This Privacy Policy explains how Corealo LLC ("Corealo," "we," "us," or "our") collects, uses, and protects personal information in connection with Operator, our AI operating system for owner-operated businesses, and related websites and services (collectively, the "Services").
1. Who we are
Corealo LLC is the company that builds and operates Operator. If you have questions about this policy or your personal information, contact us at privacy@corealo.com.
2. Information we collect
Depending on how you use the Services, we may collect:
- Account information, such as name, email address, business name, role, and authentication credentials.
- OAuth tokens and related connection metadata when you authorize Operator to access third-party systems such as accounting, banking, payroll, email, or other operational tools.
- Financial metadata, including balances, transaction categories, invoice status, payroll readiness indicators, and other financial signals needed to generate operating insights. We process this information to provide the Services; we do not sell it.
- Operational business information, such as inbox signals, opportunities, schedules, staffing context, and other business records connected to Operator.
- Cookies and similar technologies used for session management, security, preferences, and product analytics.
- Analytics about how the Services are used, including device/browser information, approximate location derived from IP address, pages viewed, and feature interactions.
3. How we use information
We use the information we collect to:
- Provide, maintain, and improve Operator and related Services.
- Generate AI-assisted recommendations, daily command briefs, and operational insights.
- Authenticate users and secure connected integrations.
- Communicate about product updates, support, and service notices.
- Monitor reliability, prevent abuse, and comply with law.
4. Encryption and security
We use encryption in transit and at rest, restrict internal access on a least-privilege basis, and apply additional protections to OAuth tokens and other sensitive credentials. No method of transmission or storage is completely secure, but we design Operator with security as a core requirement. Learn more on our Security page.
5. No sale of personal data
Corealo does not sell personal data. We do not share personal information for cross-context behavioral advertising. We may use service providers that process data on our behalf to host, secure, or analyze the Services, subject to contractual confidentiality and data protection obligations.
6. Sharing
We may share information only:
- With vendors that help us operate the Services.
- With third-party systems you choose to connect through OAuth.
- If required by law, legal process, or to protect rights and safety.
- In connection with a merger, acquisition, or similar corporate transaction.
7. Data retention and deletion
We retain personal and business information for as long as needed to provide the Services, meet legal obligations, resolve disputes, and enforce agreements. You may request deletion of your personal data by contacting privacy@corealo.com. Upon a verified request, we will delete or anonymize personal data except where retention is required by law or necessary for legitimate business records.
8. Cookies and analytics
We use cookies and analytics to keep sessions secure, remember preferences, understand product usage, and improve Operator. You can control cookies through your browser settings; disabling certain cookies may affect Service functionality.
9. Your choices
Depending on your location, you may have rights to access, correct, delete, or export personal information, or to object to certain processing. To exercise these rights, email privacy@corealo.com.
10. Changes
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date and, where appropriate, provide additional notice.
11. Contact
Corealo LLC
Privacy inquiries: privacy@corealo.com