Trust centre
Where your data goes, and who touches it.
Everything Corrobly stores is stored in London. Text is processed by a short list of providers under no-training terms, and call audio is never recorded. This page lists where data is, the sub-processors and how to reach us.
Where your data is
Data is stored in London. The application's functions run on Vercel in London, and static files are served from Vercel's global edge network. All customer data is stored in London (UK). AI processing uses US providers under no-training terms: Anthropic for analysis, Voyage AI for search and, only when a member turns on a live transcript, Deepgram for transcription.
Signed in, this page also shows where your own workspace's data is processed, provider by provider.
What we commit to
- No recording: call audio is never recorded or stored, and no bot joins a call.
- Consent first: a live transcript starts only after the person running the call confirms everyone agreed, and that is logged.
- No training: customer data is never used to train models, by us or our providers.
- Retention and deletion: admins set how long raw notes are kept, and calls, deals or the whole workspace can be deleted.
The detail is on the Security page.
Sub-processors
As of 30 September 2026. The same list is in the Security page and in our data processing agreement.
| Provider | Purpose | Location | Data |
|---|---|---|---|
| Vercel | Application hosting, functions and page-view analytics on the public site | London, UK for functions; global edge network for static files | Requests in transit, function logs, and anonymous page views on the marketing pages (never on app pages) |
| Supabase | Postgres database and sign-in | London, UK | All stored workspace data and account details |
| Anthropic | AI analysis of note text and deal documents (Claude API) | Outside the UK (United States) | Note text, transcript context, question guide, deal facts, report drafts, an excerpt of each dropped item to suggest what it is, the full text of documents a member has confirmed, and the text of call transcripts a member imports, sent per request |
| Deepgram | Live transcription of call or in-person meeting audio, streamed from your browser | Outside the UK (United States) | Call or meeting audio in transit only, never stored by us; the deal's and the workspace's vocabulary (names and acronyms, including names found in deal sources a member confirmed) as recognition hints when a capture starts; transcript text returned. Model improvement is opted out on every stream |
| Resend | Transactional email: invites, pilot, DPA and waitlist requests, shared report emails, workflow email steps, follow-up emails a member approved and recording notices to call attendees | Outside the UK (United States) | Recipient email address and message content |
| Cloudflare (Turnstile) | Bot check on sign-in and the waitlist form | Outside the UK (United States) | Visitor IP address and browser signals during the check |
| Voyage AI | Search embeddings for Ask Corrobly | Outside the UK (United States) | Typed notes, transcript turns, evidence snippets, report sections, the extracted text of confirmed deal documents and the questions typed into Ask. Opted out of Voyage AI model training |
| Sign-in with Google where enabledOpt-in | Outside the UK | Sign-in identity | |
| Microsoft | Sign-in with Microsoft where enabledOpt-in | Outside the UK | Sign-in identity |
Before a sub-processor is added, removed or changed, every workspace owner is emailed at least 30 days ahead, with the date it takes effect. This notice cannot be switched off.
Certifications
Certifications: not yet. We describe what we do in plain terms instead, here and on the Security page.
Security pack, DPA and GDPR documents are available on request. Request them here.
Security contact
Report a vulnerability or ask a security question at security@corrobly.com. We answer within two working days.
If a security incident affects your data, we contain it first, then tell your workspace owners and admins without undue delay, and within 48 hours, with what happened, what it touched and what we are doing, and we report to the ICO within 72 hours where the law requires it.