Coda AI
low riskDocument Collaboration & Productivity Platformcoda.ioverified 2024-05-22
Data-handling profile
- Trains on input
- No — does not train on customer inputs
- Retention
- Customer data is retained as long as the account is active or as needed to provide services; users can delete content at any time, triggering permanent deletion from production servers within 30 days.
- Data region
- United States (primary), with options for enterprise customers to request specific data residency in certain regions (e.g., EU) via enterprise contracts.
- Certifications
- SOC 2 Type IIISO/IEC 27001ISO/IEC 27018HIPAA compliant (via BAA)
- DPA available
- Yes
- Breach history
- No major public history of unauthorized data breaches involving customer PII.
- EU AI Act
- As a provider of AI-integrated productivity tools, Coda is subject to the transparency requirements of the EU AI Act; they explicitly state they do not use customer data to train their underlying AI models.
Sources
- https://coda.io/trust
- https://coda.io/privacy
- https://coda.io/legal/terms
- https://help.coda.io/en/articles/8394464-how-coda-ai-uses-your-data
Every fact above is drawn from the vendor's public documentation, reviewed by a human, and version-stamped. Monitored daily for changes.
Change history
No material changes recorded since monitoring began.