1. Who this policy covers
This policy covers people who visit the site or join the Core waitlist, and people who use Core as members of a company or other organization with a Core account (an “organization”).
When an organization connects its tools to Core, Cadex handles the content from those tools on the organization’s behalf and under its instructions. If an organization has a signed agreement with Cadex that differs from this policy, the agreement governs how that organization’s data is handled.
2. Information Cadex collects
On cadexcore.ai
- Waitlist form. Your name, work email and team size, plus your company and the tools your team uses if you add them. Signups go to Cadex’s customer relationship management (CRM) system.
- Request details. Each visit sends your IP address, your browser type, the page requested and other technical details. Vercel, which hosts the site, uses them to deliver pages and protect the site. To limit abuse, the site also counts form submissions from each IP address in server memory, and each count resets after an hour.
- Analytics. Vercel Web Analytics records the pages viewed, the referring site, your browser, operating system and device type, and your approximate location (country, region and city). Vercel states that Web Analytics uses no third-party cookies, and that it identifies visitors by a hash of the incoming request and discards visitor sessions after 24 hours.
In Cadex Core
- Account information. Core uses Clerk for sign-in. Clerk and Core keep your name, your email address, the organizations you belong to and your role in each. To help secure your account, Clerk also records the device, browser, IP address and other details of each sign-in.
- Content from connected tools. The tools an organization can connect include Slack, ClickUp, Notion, Google Drive, Gmail, Google Calendar, Microsoft 365, GoHighLevel and Meta Ads. Core reads what each connection allows, which can include documents, messages, emails, calendar events, tasks, CRM records and advertising results, along with who can see each item in the source tool. It refreshes this content on a schedule.
- Files and websites. Files that members upload, and the pages Core fetches from websites the organization adds.
- Questions and agent activity. The questions members ask, the answers and sources Core returns, and a record of what AI agents do, such as posting a message or creating a task.
- Chat apps. If your organization uses Core in Slack or Telegram, the messages you send Core there and your account ID in that app. To link a Telegram account, Core briefly keeps the chat ID or phone number used to make the link.
- Messages to Cadex. Emails, feedback and bug reports you send, along with your contact details.
Connected content can include information about people who don’t use Core, like the sender of an email or a contact in a CRM. The organization that connects a tool is responsible for having the right to share that information with Cadex.
3. Meta Ads data
Organizations can connect Meta Ads to ask Core about their advertising results. This section covers the data Core receives from Meta’s APIs through that connection (“Meta data”).
What Core accesses
A member of the organization connects Meta through Meta’s own authorization screen and approves the ads_read permission. Core doesn’t request permission to read Facebook posts, friend lists, Pages, Instagram accounts or messages. With ads_read, Core reads:
- the ad accounts that member can access, with each account’s ID, name and currency;
- daily results for each ad: the date, the names and IDs of the campaign, ad set and ad, the amount spent, impressions, clicks, and the actions Meta reports (leads or purchases, for example) with their value.
How Core uses it
- Core stores Meta data in the organization’s workspace and refreshes it on a schedule. Each refresh reads the most recent 28 days again, because Meta can revise recent results.
- When a member asks about advertising results, the question goes to Anthropic’s models. Core calculates the figures from the stored data and passes the result to the model, which writes the answer. That result includes the metric, the total, the currency, the date range, the ad accounts involved and any campaign, ad set or ad named in the question.
- A question asked in Slack or Telegram gets its answer there. If the organization sets up an AI agent to report on advertising results, the agent posts its report to the tool the organization chooses.
- Core keeps Meta data as reporting figures, apart from the search index and knowledge graph that hold other connected content.
Who receives it
Service providers process Meta data for Core: Vercel for hosting, Supabase for the database and Anthropic for the AI models. Nango, which manages Core’s connections, stores the access token Meta issues, and Core’s requests to Meta and Meta’s responses pass through it. Cadex uses Meta data only to provide reporting and answers to the organization that connected it.
Limits on how it’s used
Cadex doesn’t:
- sell, license or rent it, or share it with data brokers, ad networks or other advertising services;
- use it to target ads, build profiles of individual people, train AI models or carry out surveillance, or to decide anyone’s eligibility for credit, employment, housing or insurance;
- combine it with other organizations’ data, or use it for any organization other than the one that connected it;
- share it outside that organization, except with the service providers named above, with the tools the organization directs answers to, with a new owner of Core as described under How information is shared, or when the law requires it.
Disconnecting Meta
An organization can disconnect Meta in Core. Disconnecting stops syncing and tells Nango to delete the stored access token. Figures Core has already synced stay in the workspace until the organization asks Cadex to delete them or closes its account.
You can also remove Core’s access in the business integrations section of your Facebook settings. That stops new Meta data from arriving. To have what’s already stored deleted, follow the steps in How to delete your data.
4. Google user data
When a member connects Google Drive, Gmail or Google Calendar, Core reads files, email and calendar events within the permissions that member grants, so members can search that content and ask questions about it.
Cadex Core’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In line with that policy, Cadex:
- uses Google user data only to provide and improve the search, answer and AI agent features members use in Core;
- doesn’t use it for advertising, sell it, use it to decide creditworthiness or for lending, or use it to develop, improve or train general-purpose AI or machine learning models;
- transfers it only as needed to provide or improve those features (including to the service providers listed under How information is shared), for security purposes such as investigating abuse, to comply with the law, or as part of a merger, acquisition or sale of assets with your prior consent;
- lets people at Cadex read it only with your permission for specific items, when needed for security (to investigate a bug or abuse, for example), to comply with the law, or for internal operations once it has been aggregated and anonymized.
5. How Cadex uses information
Cadex uses the information described above to:
- run the site and the waitlist, including contacting you about Cadex Core and early access;
- provide Core, which covers syncing connected tools, building each organization’s search index and knowledge graph, answering questions and running AI agents;
- secure the site and Core, prevent abuse and fix problems;
- send you messages about your account, the service and changes to either;
- understand how the site and Core are used, so Cadex can maintain and improve them;
- meet legal obligations and enforce Cadex’s terms.
For Meta data and Google user data, the narrower limits in the two sections above apply. Cadex doesn’t use connected content, uploaded files or members’ questions to train AI models.
Where the law requires a legal basis for processing, Cadex relies on its contract with the organization, its legitimate interest in running and securing the site and Core, your consent where Cadex asks for it, and the need to meet legal obligations.
6. AI processing
Core uses Anthropic’s models to answer questions and run AI agents, and to organize connected content into each organization’s knowledge graph. For each task, Core sends the model the text that task needs. To answer a question, that means the question and the passages that match it, which Core picks from content the person asking can see, using the access settings it records from each source tool.
Voyage AI turns text from connected tools, uploaded files, added websites and questions into embeddings, the numeric representations Core uses to find related passages, and Core stores those embeddings. When a question needs current information from the web, Core sends search terms to Tavily.
AI output can be wrong or incomplete. The Terms of Service cover how to treat it.
8. How long Cadex keeps information
Waitlist signups. Cadex’s CRM holds them until you ask to be removed or they’re no longer needed to contact you about Core.
Workspace data. Content in an organization’s workspace, including Meta data and Google user data, is kept while the organization’s account is open. When the account closes, Cadex deletes the workspace and its data within 30 days.
Disconnected tools. Disconnecting a tool stops syncing, tells Nango to delete the access token and deletes content from that connection that only the disconnecting member could see. Content other members can see, and Meta Ads figures, stay until the organization asks Cadex to delete them or closes its account.
Members who leave. When someone is removed from an organization or their account is deleted, Core removes their membership and personal connections, along with the content only they could see.
Activity log. Entries for questions and AI agent runs are deleted after 180 days, and entries for file uploads, downloads and other routine events after 30 days. Records of administrative actions, like an administrator disconnecting a tool or deleting a file, are kept while the account is open.
Telegram link requests. These expire after 10 minutes, and expired requests are deleted.
Logs and backups. Copies held by Cadex’s service providers are deleted on those providers’ schedules.
Other information is kept as long as Cadex needs it for the purposes in this policy, or longer where the law requires.
9. How to delete your data
To ask Cadex to delete your data, email discovery@cadexhq.com with the subject “Data deletion request” and include:
- your name, and the email address you use with Core or used to join the waitlist;
- your organization’s name, if you use Core;
- what you want deleted, for example your waitlist signup, your account or data from a connected tool;
- for Meta Ads data, which ad accounts the request covers.
What happens next:
- You’ll get a reply confirming receipt. Cadex may ask for details to check that the request came from you.
- Deleting an organization’s shared data, like its documents, takes a request from one of its administrators. If you aren’t an administrator, Cadex asks one to confirm. The member who connected a Meta ad account can have that connection’s Meta data deleted without this step.
- The data is deleted within 30 days of your request, or of the administrator’s confirmation when one is needed. Copies in backups are removed as those backups expire.
- Cadex emails you when the deletion is complete and tells you about anything it kept and why, such as records the law requires it to keep.
To stop further collection, disconnect the tool in Core or remove Core’s access in the tool’s own settings. For Meta, that’s the business integrations section of your Facebook settings, and for Google, the third-party connections page of your Google Account. Removing access stops new data from arriving but leaves the data Core already holds, so send a deletion request as well.
10. Your choices and rights
Depending on where you live, you may have the right to ask Cadex to:
- tell you what personal information it holds about you and give you a copy;
- correct information that’s wrong;
- delete your information;
- limit how it uses your information, or object to that use;
- withdraw consent you gave earlier.
To make a request, email discovery@cadexhq.com. Cadex may need to verify your identity first and won’t discriminate against you for making a request. If your request is declined, you can reply to ask Cadex to reconsider. Where the law provides, you can also complain to your data protection authority.
Because workspace data is handled on the organization’s behalf, requests about it may be referred to that organization.
To leave the waitlist or stop getting Cadex emails, reply to one of those emails or write to discovery@cadexhq.com.
12. Security
Security measures for the site and Core include:
- encrypted connections (TLS) to the site and Core;
- a separate workspace for each organization, with results filtered by each member’s access in the source tools;
- access tokens for connected tools held by Nango, outside Core’s database;
- access to production systems limited to the people at Cadex who need it.
No method of sending or storing information is completely secure, so Cadex can’t guarantee the security of your information. If a breach affects it, you and the authorities will be notified as the law requires.
13. Children
The site and Core are meant for adults using them for work and aren’t directed to anyone under 18. Cadex doesn’t knowingly collect information from children. If you believe a child has provided information through the site or Core, email discovery@cadexhq.com and it will be deleted.
14. Where information is processed
Cadex is based in the United States. Information may be processed there and in other countries where Cadex’s service providers operate, and their data protection laws may differ from those where you live.
15. Changes to this policy
This policy may be updated, and the date at the top of the page shows when it last changed. Before a material change to how Core handles workspace data takes effect, Cadex tells organization administrators by email or in Core.
16. Contact
Send questions about this policy or your information to:
Cadex Systems3301 N University Drive, Suite 100
Coral Springs, FL 33065
discovery@cadexhq.com