AI & data security
The models behind Coassemble's AI features, how your data is handled, and how the AI allowances work.
We use AI to make course creation faster, easier and more accessible, without compromising your data security. Below are answers to common questions about how we use AI and protect your information.
Which AI models does Coassemble use?
We use trusted third-party models from Google, integrated directly with Google's AI services:
- Text: Gemini Flash, for document transformation, course generation, text refinement and translation.
- Images: Gemini 2.5 Flash Image, for AI image generation. This replaced the earlier Imagen model, which Google is retiring.
- Narration: Google's Chirp voices for AI narration.
You can review Google Gemini's terms of service and data policies here.
How do the AI allowances work?
There are two, and they're counted in different units, which is the thing most often misread:
- Narration tokens. One token equals one character of generated narration. Standard and premium voices draw from the same pool. A course with a translation narrates each language separately, so it uses roughly twice the tokens of the same course in one language.
- Image generation events. One event equals four pictures. When you generate an image, Coassemble produces four options and selecting one uses a single event.
Both are hard capped. When you reach 100% of either, generation stops for the rest of the month and starts again when the allowance resets. Nothing else in your workspace is affected: courses stay live, learners keep taking them, and you can keep building and editing. There's no overage charge.
Your current usage is on the Usage limits page in Settings, and the publish panel shows an estimate before you generate narration.
How does AI image generation work?
Image generation uses Gemini 2.5 Flash Image and is triggered manually, so you control when images are created and when your allowance is spent. Generated images reflect your course topic rather than just the screen they sit on, and generation shows its progress as it works through a course. You'll see how many events you have left in the generation window.
Does Coassemble use my data to train AI models?
No. Your data and course content are not used to train our AI models. When you use a feature like transforming a document, your document is securely stored in object storage, and we keep the course context in our database so the AI can generate relevant content for you.
Who owns content created with AI?
You do. You retain full ownership of all content created in Coassemble, whether it's generated with AI or built from scratch.
How does Coassemble protect my data?
We apply the same security standards to our AI features as we do across the whole platform. Your data is encrypted in transit (TLS 1.2) and at rest (AES-256), access-controlled, and handled in line with industry best practice. You can review our security controls in the Coassemble Trust Centre.
Where is customer data stored?
By default, customer data is stored and processed on US-based infrastructure, currently in Oregon, USA. Region-locked servers in the EU, US or APAC are available on the Partner plan for teams with data residency requirements.
Is Coassemble GDPR compliant?
Yes. Coassemble complies with GDPR requirements, though we don't currently hold a formal GDPR certification.
Does Coassemble have SOC 2 certification?
Yes. Coassemble holds SOC 2 Type 1 and Type 2 reports. You can access them through the Coassemble Trust Centre.
Does Coassemble offer a Data Processing Agreement (DPA)?
Yes. We can provide a DPA where appropriate, including provisions covering data processing for AI features. Contact our team to arrange one.
Can I use my own AI model instead?
Teams with stricter requirements can bring their own model key, or run a private model deployment, so AI processing happens under their own arrangement rather than ours.