Effective August 4, 2026
This disclosure supplements the Privacy Policy below for Cora's official MCP and other connected AI features. It does not replace the rest of the policy.
When you connect Cora to a third-party AI client, such as ChatGPT from OpenAI or Claude from Anthropic, Cora asks you to approve specific access. Depending on the permissions you grant and the request you make, the client may receive the following information from your Cora account:
Cora returns information only when the connected client asks for it on your behalf and the request falls within the access you approved.
Read access lets the client retrieve Cora data and use it to answer your questions or request coaching from Cora. If you approve write access, the client can send instructions to create, update, replace, complete, cancel, or delete supported records in your Cora account. Supported actions include logging meals and workouts, managing training plans, habits, routines, journals, check-ins, and reminders. Cora accepts only actions allowed by the permissions on that connection.
Tool results go to the third-party AI client you connected. That provider processes prompts, tool calls, and results under its own privacy policy and account settings. PurplePill AI, Inc. does not operate those third-party services or control copies they retain after Cora sends the requested result.
Cora keeps your source records and records created through a connected client as described in the Privacy Policy below. The AI provider may keep information it received according to its own policy. You can disconnect a client in Cora under Settings and Connected Apps, or remove Cora in the client's settings. Revocation blocks new access after any active token or session expires. Disconnecting does not delete information already sent to the provider or undo records the client wrote to Cora; those records must be removed through the applicable service.