Effective August 4, 2026

Supplemental privacy disclosure for connected AI services

This disclosure supplements the Privacy Policy below for Cora's official MCP and other connected AI features. It does not replace the rest of the policy.

Data you choose to share

When you connect Cora to a third-party AI client, such as ChatGPT from OpenAI or Claude from Anthropic, Cora asks you to approve specific access. Depending on the permissions you grant and the request you make, the client may receive the following information from your Cora account:

  • Account and profile information, including your email address, onboarding answers, fitness goals, preferences, experience, equipment, and constraints you record.
  • Sleep, recovery, activity, and wearable-derived metrics, including heart rate, resting heart rate, heart rate variability, cardio activity, and related trends.
  • Completed and planned workouts, exercises, sets, reps, loads, training plans, workout templates, and cardio goals.
  • Meals, food descriptions, calories, macronutrients, nutrition targets, and planned meals.
  • Weight and other body measurements you store in Cora.
  • Habits, routines, journals, check-in answers, reminders, and Cora coaching requests and responses.

Cora returns information only when the connected client asks for it on your behalf and the request falls within the access you approved.

Read and write access

Read access lets the client retrieve Cora data and use it to answer your questions or request coaching from Cora. If you approve write access, the client can send instructions to create, update, replace, complete, cancel, or delete supported records in your Cora account. Supported actions include logging meals and workouts, managing training plans, habits, routines, journals, check-ins, and reminders. Cora accepts only actions allowed by the permissions on that connection.

Who receives the data

Tool results go to the third-party AI client you connected. That provider processes prompts, tool calls, and results under its own privacy policy and account settings. PurplePill AI, Inc. does not operate those third-party services or control copies they retain after Cora sends the requested result.

Retention and revocation

Cora keeps your source records and records created through a connected client as described in the Privacy Policy below. The AI provider may keep information it received according to its own policy. You can disconnect a client in Cora under Settings and Connected Apps, or remove Cora in the client's settings. Revocation blocks new access after any active token or session expires. Disconnecting does not delete information already sent to the provider or undo records the client wrote to Cora; those records must be removed through the applicable service.