Updated August 23, 2026

What Concord knows about you, and what it does with it.

Concord reads a company's own systems to decide what to do next. This says what it reads, where it goes, how long it stays, and how a company can take or permanently delete its record. One of those systems can be a mailbox. So some of what Concord reads was written by people who never agreed to anything. That has a clause of its own.

01

Who this is

Concord is operated by Predictive, in Montréal, Québec, Canada. For anything on this page, including a request to see or delete what we hold, write to charles@predictive.company. That address reaches the person responsible for privacy here, not a queue.

Two people, kept apart. A customer is a company that uses Concord. Inside that company, some people may sign — they can approve what Concord proposes. Almost everything Concord holds belongs to a customer, and we hold it on their behalf.

02

What we hold about a person

Very little, and all of it is for one job: knowing who may approve something.

Email address
The identity. It is how sign-in matches you to a company, and what the record names when you approve something.
Name
As your sign-in provider gives it. Shown on screen so a list of addresses reads like people.
Whether you may sign
Set by somebody at your company, and changeable by them at any time.
When you were added, and by whom
So the question "who let this person approve payments" has an answer.
What you approved, and when
Written into the record, permanently. See clause 07.
What you say to the company line
Realtime audio is processed only while you open the line. Concord stores final turns in the company correspondence record, not raw audio or partial transcripts.

We do not collect a password, because there is not one. Sign-in goes through Google or Microsoft, and we never see what you type there. We do not track you across other sites, we run no advertising, and we sell nothing.

Stripe processes a paid Concord subscription. Stripe receives the billing details you enter at checkout. Concord receives billing identifiers and status, not your card number.

03

What we read from a company's own systems

Nothing until somebody at that company connects a system, and then only what that system’s connection says it reads. Each connection lists this before it is switched on, and the console shows it afterwards.

Stripe
Settled charges, Open invoices, Subscription changes
HubSpot
Deal stages, Contacts
Slack
Direct mentions, Escalation channel
QuickBooks
Profit and loss, Accounts payable
Zendesk
Open tickets, Satisfaction
Your database
Product metrics, Account usage
Google Calendar
Committed hours
Linear
Cycle progress, Incidents
Gmail
Payment-detail changes, Messages that need a person
Microsoft 365 mail
Payment-detail changes, Messages that need a person

Those readings become facts— a figure, a subject, a date — and it is the facts that Concord reasons over. An invoice’s total becomes a fact; the invoice’s prose does not. Where a connection can write as well as read, the console says so. Nothing is written until somebody switches that kind of action on.

Two of the connections in that table read email. A mailbox is not like the others, and the next clause is entirely about why.

04

When one of those systems is a mailbox

Concord can read email: Gmail, or Microsoft 365 mail. A company connects one the same way it connects anything else. This is the one connection that needed a clause rather than a row.

Everything else on this page is a company’s own account of its own business — its invoices, its deals, its tickets, its bills. A mailbox is not that. It is full of letters written by other people: suppliers, customers, applicants, somebody who wrote once and never again. Those people are not our customer. They agreed to nothing, and most of them have never heard of Concord. If you have written to a company that connected its mailbox, this clause is about you.

The permission covers the whole mailbox. Google and Microsoft publish no way to grant only the messages Concord cares about. So a company grants every message in the account it connects. Concord uses two kinds and ignores everything else. One is a supplier saying their bank details have changed. The other is a message that needs a person to answer. That narrowing is a promise we keep, not a door either company shuts. We would rather say it that way round than claim a limit we were never given.

One limit here is not a promise. The permission can only read: it cannot send, reply, delete, label or file. Nothing will ever leave a connected mailbox in anybody’s name. That is what Google and Microsoft handed over, not restraint on our part.

What we keep is far smaller than what we can reach.No mailbox is copied and no message is filed away. A message Concord uses is boiled down to a few things for one day’s decision. Concord keeps who sent it, the subject line, when it arrived, and which phrase from its own short list it matched. On Microsoft 365 that also includes the opening of the message, which is what Microsoft hands over in place of the body. Those are re-read the next day rather than piled up.

What lasts is the decision and the reason written for it. It is filed against the message identifier Google or Microsoft gave, not against anything the sender wrote. Where a company has the model switched on, the model writes that reason. It has seen the sender and the subject line. So those words can end up in a record that cannot be edited afterwards. Clause 07 says why it cannot.

Two things are held back on purpose. An account number is never lifted out of a message. The new details a sender proposes stay there, where a person reads them. And a sender can mark their own mail urgent. Concord carries that through as the sender’s claim and never acts on it. Otherwise a stranger would decide how seriously their message is taken.

A message claiming that a supplier’s payment details have changed therefore produces a note for a person and nothing else. It cannot move where anybody gets paid, and no amount of agreement inside Concord can make it — that action does not exist.

If you wrote the message, clause 10 is yours to use even though you are not our customer.

05

Who else sees it

Concord uses processors for hosting, reasoning, mail, sign-in, and—only when an operator opens it—the realtime company line. The voice path is not on in the background.

Cloudflare
Runs Concord and holds its database. Everything described here lives there.
Stripe
Processes Concord subscription checkout and keeps the related billing record. Concord does not receive a card number.
Anthropic
Drafts scheduled proposals, answers setup questions, and can answer typed company correspondence when configured. Voice never silently falls back to it.
Google Gemini
Reasons over final typed or spoken turns and bounded company facts. Raw audio and partial transcripts are not sent to it.
LiveKit, Krisp, Deepgram, and Cartesia
Carry the open voice room, clean incoming audio, transcribe speech, and synthesize Concord’s reply. They are used only while an operator deliberately opens the line.
Resend
Sends the mail Concord sends — for example a letter about an overdue invoice.

The model is the one to read twice.When a company has enabled it, that company’s facts are sent to Anthropic’s API so a proposal can be drafted. Those facts include customer names, invoice amounts and ticket subjects. During setup, a question an operator deliberately asks and a limited summary of the current setup record are sent so the question can be answered. Saved sign-ins are not included. The data is not used to train a model. A company that has not enabled one sends nothing: the departments run on rules and setup keeps its written guide.

The company line has four media processors and one reasoning processor. LiveKit carries the room, Krisp cleans incoming audio once on the server, Deepgram transcribes it, Google Gemini reasons over the final turn and bounded company record, and Cartesia speaks the reply. The media worker has no database, payment credential, signing secret, or business tool. Its opaque capability expires after fifteen minutes. Ending the line revokes it. A spoken yes is stored as another turn; it is never a signature. The complete, versioned descriptions are on the sub-processor page.

A connected mailbox widens that. The widening is big enough to say on its own. If a company has both a mailbox and the model switched on, what Concord took out of a message goes to Anthropic too. That is the sender, the subject line, and on Microsoft 365 the opening of the message. That includes mail from people outside the company who never agreed to anything. There is no setting that keeps the model on and holds the mail back. The two ways to stop it are turning the model off and disconnecting the mailbox.

Beyond those three, the only other recipients are the systems a customer connected themselves. They receive nothing until that customer switches an action on. For example, a message posted to their own Slack, or a bill paid through their own QuickBooks.

We do not sell data, and we do not share it with anybody not named here. If the law ever forces us to hand something over, we will tell the affected customer unless we are forbidden from doing so. The versioned list of who else sees it is the complete account, including sign-in and every system a company can connect.

06

Decisions made without a person

This is what Concord is for. Concord makes decisions about a company’s business by automated processing — which invoice to chase, which bill to pay, which ticket to escalate.

The customer writes the rules those decisions run inside, and can read them. There is an amount above which a person must approve. Some actions always need a person, however small. Some categories the departments may not touch at all. Anything irreversible reaches a person. Everything that happens is recorded with the reasoning behind it.

A person at the customer’s company can see every decision, see why it was made, and reverse the rules that produced it. If a decision affected you and you want it explained or reconsidered, write to us and we will put you in front of a person.

That last sentence reaches further than it looks.Because a mailbox can be one of the things Concord reads, a decision can rest on something written by somebody outside the company altogether. Québec’s Law 25 protects that person as much as it protects our customer’s staff, and we are not going to read it any other way. A message you sent can produce a decision. If it did, you may ask what the decision was and what it rested on. You may also ask for a person to look at it again. You do not have to be a customer to ask.

07

The record and full-company deletion

Concord keeps a record of every decision, sealed so that it can be checked. Each entry’s seal covers its own contents and the entry before it. That is what makes the record worth anything. Change one line of history and every seal after it stops matching.

That has a consequence we would rather state than discover with you. We cannot quietly remove one entry from the middle of a record. Deleting a single line would break every seal after it. The record would then look like one that had been tampered with.

So full-company erasure deletes the tenant’s whole live record: people, settings, connections, business boards, correspondence, voice-session records, and the complete sealed decision record. It does not remove one historical line and leave the remaining seals looking intact. A person who runs the company can do this only after downloading anything they need, leaving Concord, stopping billing, and passing an enrolled second factor. It cannot be undone.

Leaving removes connected-system keys from the live database but keeps enrolled identity factors. Cloudflare recovery generations can retain the earlier encrypted rows until their plan window expires; any restore must reapply offboarding before service resumes. Those identity factors authorize full deletion. Full deletion removes them with the rest of the tenant.

App-managed laptop and R2 backups can retain the record after live deletion. Each copy is scheduled for deletion after thirty days. An offline laptop prunes overdue copies after its next successful backup. Backups contain no saved connection keys.

Cloudflare D1 also keeps provider-managed Time Travel recovery. Its window depends on the Cloudflare plan and can extend to thirty days. Concord cannot delete one recovery point. If a recovery is restored, the deletion must be applied again before service resumes.

If you are named in a company’s record and want that addressed, write to us. We will verify the request and work with that company instead of quietly rewriting its history.

Full-company deletion does not erase Stripe’s separate subscription billing record. Stripe keeps that record under its own legal and retention duties. Concord keeps no live tenant record merely to preserve it.

08

How long it stays

The live record
For as long as the company exists on Concord, unless the company requests full deletion. One historical line is never silently removed while the remaining seals are presented as intact.
App-managed disaster-recovery backups
Scheduled for deletion 30 days after they are made. Live deletion is immediate. An offline laptop completes overdue pruning after its next successful backup.
Cloudflare D1 Time Travel
Cloudflare retains provider-managed recovery points for the plan’s recovery window, up to 30 days. Any restored deletion must be applied again before service resumes.
The saved sign-in for a connection
Until disconnected. Encrypted while stored and removed from the live database when the connection is removed. Provider recovery generations age out under their disclosed window; a restore must reapply removal.
The people list
Until removed by somebody at that company. Taking away the ability to sign keeps the row, on purpose, so the change itself is visible.
Facts read from your systems
They are re-read each day rather than accumulated. What is held is the record of what was decided from them.
Messages in a connected mailbox
No copy is kept. What Concord takes from a message lasts one day, like any other fact. What stays is the decision the message led to, and the reason written for it, which can repeat the sender and the subject line.
Voice
Raw audio and partial transcripts are not stored by Concord. Final operator turns and final replies stay in the company correspondence record until full-company deletion.
Full-company deletion
After authority, second factor, offboarding and stopped billing are verified, the tenant and its whole live record are deleted atomically. This cannot be undone.
Stripe subscription billing
Stripe keeps its separate checkout and billing records under its own legal and retention duties. Full-company deletion removes Concord’s live tenant record.
09

Where it is, and how it is protected

Concord runs on Cloudflare’s network and its database is Cloudflare D1. Model and voice processor regions depend on the service and commercial plan; this product does not promise Canada-only processing. A company that requires a particular residency must settle that contract before enabling voice. The saved sign-in for a connected system is encrypted before it is stored. It is never shown back to anybody: not to us, not on any screen, not in any log. A connection’s own error messages are stripped of anything key-shaped before they are recorded.

Sign-in is by Google or Microsoft only. A session lasts twelve hours. If somebody’s ability to sign is taken away, their session ends the next time they load the console. It does not last the rest of the day.

10

What you can ask for

You can ask us to show you what we hold about you, correct it, or delete it. You can also ask us to send it to you in a portable form. The portable company file includes the operating boards, correspondence, established payables, warehouse facts, and the complete decision record. It also shows where each person’s authority came from and safe summaries of connections, billing, identity factors, and voice sessions. It never includes saved sign-ins, authenticators, or provider capabilities. You can ask for all of that whether you are in Québec, elsewhere in Canada, the United Kingdom or the European Union. You can object to how it is used, and you can complain to your data protection authority — in Québec, the Commission d’accès à l’information.

Write to charles@predictive.company. We will answer within thirty days. Most of what you ask about belongs to a customer rather than to us. Where it does, we will tell you which company holds it and help you reach them.

If data we hold is ever exposed in a way that risks serious harm, we will tell the affected customers and the relevant authority. We will tell them promptly, and with what we actually know rather than a reassurance.

11

When this changes

The date at the top is when this text last changed. If a change makes a real difference to what we do with a customer’s data, we will tell them before it takes effect. We will not rely on this page having been re-read.