Your data has a visible route through Dudilly
A plain-language account of what Dudilly receives, why it is needed, which services are involved, and what stays under founder control.
Who operates Dudilly
Dudilly is a Coral AI Labs service. You create a Dudilly account; Coral systems run identity, agent coordination and other infrastructure behind the product. A separate Coral product account is not required to use Dudilly.
Coral AI Labs is the controller for Dudilly account, security and service-operation data. When a founder company supplies company materials, that company decides why those materials are used and Coral AI Labs processes them through Dudilly to provide the requested diligence service.
What Dudilly processes and why
Dudilly can process account identity, company profile information, founder-provided files, source references, private searchable representations of approved materials, workspace actions, agent messages, investor questions and answers, contact activity, plus security and diagnostic records.
Account and workspace processing is necessary to provide the service requested by the user. Security, abuse prevention, service accountability and proportionate product diagnostics rely on Coral AI Labs' legitimate interests. The onboarding acknowledgement confirms that you saw this notice; it is not treated as consent for the core service.
Company material and agent work
Founders choose which material enters a workspace, who is responsible for it, and what may appear in a published room. Draft material remains private. Dudilly records the lineage between a connected source, its searchable representation and the agent work it supports so removal can follow the same path.
Coral coordinates Dudilly's agent sessions. For a specific task, the minimum relevant prompt and evidence context may be sent to the selected model provider. Dudilly does not permit workspace material to be used for general-purpose model training. Model-generated suggestions do not change a founder workspace until the user approves the action.
Google and other connected sources
Google is used only when a user chooses Google sign-in or connects Google Drive. Founders can select individual files with the drive.file scope or use a master-folder connection using read-only Drive access. Dudilly inventories the selected folder and its descendants, then shows the discovered file and folder count before synchronising the approved material.
The original files remain in Google Drive. Dudilly does not edit, rename, move or publish them. OAuth credentials are protected before storage and access can be revoked through Dudilly or the user's Google account. Dudilly's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Service providers, location and retention
Dudilly uses Cloudflare for application hosting and storage, Coral systems for identity and agent coordination, the selected model provider for bounded agent tasks, and Google only for Google features the user selects. Dudilly records the applicable processor chain against each source and derived record rather than assuming every provider sees every item.
Workspace records are kept while the workspace is active or while needed for security, dispute resolution or legal obligations. Connected-source records are removed when the source is disconnected or the workspace is deleted; searchable representations are removed with their parent material. Provider regions and any international-transfer safeguards are recorded provider by provider and are not presented as verified until that review is complete.
Your choices and rights
You can choose source connections, approve files, control visibility, review agent proposals and decide when a room is published. Dudilly does not use solely automated processing to make a legal or similarly significant decision about a founder or investor.
Depending on the circumstances, you may have rights to access, correct, erase, restrict or object to processing, receive portable data, or complain to the Information Commissioner's Office. To make a request or ask a privacy question, email pete@coralos.ai.
Notice version 2026-08-12.1, effective 12 August 2026.