VeraxConsole
← All vendors

Coda AI

low risk

Document Collaboration & Productivity Platformcoda.ioverified 2024-05-22

Data-handling profile

Trains on input
No — does not train on customer inputs
Retention
Customer data is retained as long as the account is active or as needed to provide services; users can delete content at any time, triggering permanent deletion from production servers within 30 days.
Data region
United States (primary), with options for enterprise customers to request specific data residency in certain regions (e.g., EU) via enterprise contracts.
Certifications
SOC 2 Type IIISO/IEC 27001ISO/IEC 27018HIPAA compliant (via BAA)
DPA available
Yes
Breach history
No major public history of unauthorized data breaches involving customer PII.
EU AI Act
As a provider of AI-integrated productivity tools, Coda is subject to the transparency requirements of the EU AI Act; they explicitly state they do not use customer data to train their underlying AI models.

Sources

Every fact above is drawn from the vendor's public documentation, reviewed by a human, and version-stamped. Monitored daily for changes.

Watch this vendor

Get an email the day Coda AI changes what it does with your data. Your address is never shown publicly or shared.

Change history

No material changes recorded since monitoring began.