Privacy notice
Last updated: 5 October 2026
This notice explains what personal data Corantr Media Desk (corantr.com) collects, why, who we share it with, how long we keep it, and your rights. It covers corantr.com, the Desk, our help desk and assistant, our emails, the WordPress plugin, and our connection for AI assistants.
Who we are
Corantr Media Desk is run by Hynca Consulting Ltd, a company registered in England and Wales (company number 17137404). For the personal data described in this notice, we are the controller.
Questions about privacy, or to use your rights: privacy@corantr.com.
The short version
- We collect what we need to run your account, write for your sites, take payment, help you and keep things secure.
- We don't sell personal data, and we don't use it for advertising profiles.
- We don't send your account details (your name, email address, password or payment details) to AI providers.
- Analytics and advertising cookies are only used on our public website, and only if you agree. They are never used inside the Desk.
- You can see, correct, export or delete your data. Write to privacy@corantr.com.
What we collect, why, and our lawful basis
| What | Why | Lawful basis |
|---|---|---|
| Your account: name, email address, password (stored hashed, never readable), and two-factor settings if you turn them on | To give you an account and keep it secure | Contract |
| Your organisation and team: organisation name, members and their roles, invitations | To run a shared account | Contract |
| Billing: your plan, its status, credits, referrals and invoice references. Stripe holds your card details; we never see or store them | To take payment and keep financial records | Contract; legal obligation (tax and accounting records) |
| Your sites: each site's address, voice, audience, areas, topics, news feeds, the list of its published pages and categories, samples of its own published writing, and any logo you upload | To write in your voice and link to the right pages | Contract |
| What the Desk writes and your decisions: pieces, posts and scripts, your edits, your reasons for rejecting a piece, the rules learned from them, and a record of every approval (who, when, and a fingerprint of the exact text approved) | To provide the service, and to keep an approval record you and we can rely on | Contract; legitimate interests (an accurate audit trail) |
| Briefs you write: anything you type into a brief | To write the piece you asked for | Contract |
| Setting up a site: your answers to the set-up questions (for example who your customers are, your goals and what to avoid), and what you ask the Desk's assistant to change | To set the site up and write for it; answers are also checked automatically for misuse and for sites we don't take on | Contract; legitimate interests (preventing misuse) |
| Help: help desk tickets and replies, and conversations with our help assistant | To answer your questions | Contract (customers); legitimate interests (visitors) |
| Search data (only if you connect it): for a site whose owner connects Google Search Console, the searches the site appeared for and how its pages did (clicks, impressions, position), the Google account's email address, and a read-only access token (stored encrypted). For every site, rising searches in its subjects (Google Trends data for its topic keywords) | To help choose what to write | Contract |
| AI assistant connections: API tokens (stored hashed) and apps you connect by signing in (for example Claude or ChatGPT), with when they were last used | So your assistant can use the Desk on your behalf | Contract |
| Marketing emails: your email address, the lists you're on, how you joined and when you left | To send articles and product news you've chosen to receive | Consent (visitors), or legitimate interests under the "soft opt-in" (customers) |
| Security: sign-in attempts, IP addresses, and Cloudflare Turnstile bot checks (on sign-in, sign-up, password reset, the email sign-up and the help assistant; see Cloudflare's Turnstile privacy policy) | To protect accounts and the service | Legitimate interests |
| Website analytics (only if you agree): pages visited, rough location, device and browser, via Google Analytics | To understand which pages help people | Consent |
News stories and publishers' articles that the Desk reads are published material. We use the facts in them to write, and we credit and link the source. To check facts and add context, the Desk also searches the web for other reports of the same story and reads them the same way. The Desk respects each publisher's robots.txt and doesn't read paywalled articles.
AI providers
The Desk uses AI models to find, write and check pieces, and to make images. The providers receive only what's needed for the task:
- news text, your sites' set-up and public writing, the pieces being written, and anything you put in a brief;
- your edits and reasons, when the Desk learns from them;
- questions you ask the help assistant, your answers to the set-up questions, and what you ask the Desk's assistant;
- the platform research we run each week (public information about social platforms).
They don't receive your name, email address, password or payment details. Avoid putting personal data in a brief unless the piece needs it.
Under our agreements with them, our AI providers don't use what we send them to train their models.
Who we share it with
We use these service providers ("sub-processors"). Each processes data only on our instructions.
| Provider | What for | Where |
|---|---|---|
| Laravel Cloud (Laravel Holdings Inc.) | Hosting, database, file storage and queues | UK (London) |
| Anthropic | AI models for writing, checking, research and the help assistant | USA |
| OpenAI | AI models for header images | USA |
| Stripe | Payments and invoices | UK, EU and USA |
| Resend | Sending email | EU |
| Cloudflare | DNS, email forwarding, security and bot checks (Turnstile privacy policy) | Worldwide network |
| Website analytics, only with your consent; Search Console data, only for sites whose owner connects it | USA | |
| DataForSEO | Search trends for each site's topic keywords (keywords only, no personal data) | Estonia (EU), with a team in Ukraine |
Where personal data goes outside the UK, it's protected by UK adequacy regulations (including the UK Extension to the EU–US Data Privacy Framework, for providers certified under it) or by the UK's International Data Transfer Addendum to the EU standard contractual clauses.
We may also share data where the law requires it, or with professional advisers. If the business is ever sold, data would pass to the new owner under this notice.
How long we keep it
| What | How long |
|---|---|
| Your account, sites and pieces | While your organisation has a plan. If the plan ends, we keep everything for 90 days, so you can come back or export your pieces. We then delete the sites, pieces, team links and tokens, within 30 days. |
| Approval records | 6 years from the decision. They keep a snapshot of who decided on what, after the content itself is deleted. Regulated firms rely on this record. |
| Billing and financial records | 6 years, as tax law requires |
| Help assistant conversations | 90 days, unless passed to a person. If they are, they're kept with the ticket. |
| Help desk tickets | 2 years after the last reply |
| Marketing list records | While you're subscribed. After you leave, we keep your address only as a record not to email you again. |
| Article text read from publishers | About 7 days. The facts drawn from stories are kept about 30 days. |
| Your user account | Until you delete it (Settings → Profile → Delete account), or until we delete your organisation's content and you belong to no other organisation |
Marketing emails
We have two optional lists: new blog articles and product updates (new features and major releases).
- Customers are added when they verify their email address, under the "soft opt-in" for existing customers.
- Website visitors confirm by email before they get anything.
Every marketing email has a one-click unsubscribe link, and you can change your choices under Settings → Emails. Emails about your account, approvals, payments and security aren't marketing, and are always sent.
Cookies
Necessary cookies (always on):
corantr_media_desk_sessionkeeps you signed in.XSRF-TOKENprotects forms.remember_web_…keeps you signed in if you choose "Remember me".hmd_consentremembers your cookie choice, for 6 months.__cf_bm(Cloudflare, 30 minutes) and Cloudflare Turnstile tell people from bots. To do this, Turnstile reads your IP address, browser details (user agent and TLS fingerprint) and the page you're on, only to tell people from bots. Cloudflare does this for us, and also uses those signals on its own account to improve its bot detection: Cloudflare's Turnstile privacy policy explains.
Optional cookies, on the public website only and only if you agree:
- Analytics: Google Analytics, through Google Tag Manager, sets
_gaand_ga_…cookies for up to 2 years. We use Google Consent Mode: nothing is stored until you agree. - Marketing: cookies to measure our adverts, if and when we run them.
These are never used inside the Desk. Change your choice at any time with "Cookie settings" at the bottom of every page on corantr.com.
Customers' own content
When the Desk writes for your website or publication, you decide what's published, and you are responsible for your site's content. We act as your processor for any personal data in that content: the people you write about, or members' details you include. Our terms of service include the data processing terms that apply.
Your rights
You have the right to:
- Access: ask for a copy of your data.
- Rectification: correct anything that's wrong.
- Erasure: ask us to delete your data.
- Restriction: limit how we use it.
- Objection: object to uses based on legitimate interests, and to direct marketing at any time.
- Portability: get your data in a reusable format.
- Withdraw consent at any time, for example for analytics cookies or marketing emails.
Write to privacy@corantr.com. We'll reply within one month. We may need to confirm who you are first.
If you're unhappy with how we've handled your data, please tell us first. You can also complain to the Information Commissioner's Office: ico.org.uk, 0303 123 1113.
Children
The Desk is for businesses and organisations, and isn't meant for anyone under 18.
Security
Data is encrypted in transit (HTTPS). Passwords and tokens are stored hashed. Sign-in is rate-limited and protected against bots, and two-factor sign-in is available. Only staff who need access have it.
Changes
We'll update this notice when what we do changes, and show the date at the top. If a change matters to you, we'll tell you by email first.