COBALT
Bluecore Residential

Privacy Policy

Effective 27 August 2026. Applies to the Cobalt web application.

Cobalt is a private, internal reporting application operated by Bluecore Residential. It is not a consumer product and is not open to public sign-up. Access is limited to people Bluecore Residential has invited, and every account is created by an administrator.

This policy explains what personal information Cobalt collects about those users, why, and what we do with it. It covers the Cobalt application only.

Signing in with Google

Cobalt offers “Sign in with Google” as an optional alternative to an email address and password. Using it is never required; signing in with a password remains available to everyone.

What we ask Google for

We request two standard, non-sensitive permissions: your email address and your basic profile (email and profile). We do not request access to Gmail, Drive, Calendar, Contacts, photos, or any other Google service, and we cannot read them.

What Google sends us, and what we keep

When you sign in, Google sends Cobalt a small profile record. We keep only part of it:

Sent by GoogleDo we store it?What it is used for
Email address Yes Matching you to your existing Cobalt account.
Whether that email is verified No — checked, not stored We refuse the sign-in unless Google confirms the address is verified.
Google account identifier Yes Tying your Cobalt account to one specific Google account, so a different Google account cannot later claim your email address.
First and last name Yes Keeping the name shown in Cobalt current.
Profile picture No Not used. Profile pictures in Cobalt are uploaded separately.
Locale / language No Not used.

We do not store Google access tokens or refresh tokens. They are used once, during sign-in, and then discarded. Cobalt therefore has no standing access to your Google account and cannot read anything from it between sign-ins.

Cobalt's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Signing in with Google never creates an account. If the Google address you use does not already match a Cobalt account, you are refused and told to contact an administrator. Google sign-in is a way to open a door you already have a key to — it is not a way in.

Disconnecting Google

You can stop using Google sign-in at any time and sign in with a password instead. To remove the link between your Cobalt account and your Google account entirely, ask a Cobalt administrator to unlink it; the stored Google identifier and the name we received from Google are deleted at that point. You can also revoke Cobalt's access from your Google account directly at myaccount.google.com/permissions.

Other information Cobalt holds about you

Whether or not you use Google sign-in, Cobalt stores:

Most of what Cobalt stores is not about individuals at all — it is operational data about the properties Bluecore Residential manages.

Cookies

Cobalt sets a single session cookie, which is what keeps you signed in. It is strictly necessary for the application to work. There are no advertising cookies, no analytics cookies, and no third-party tracking of any kind anywhere in the application.

How we use this information

We do not use this information for advertising, we do not sell it, and we do not use it to build profiles for any purpose beyond operating Cobalt.

Who else sees it

Other Cobalt users at Bluecore Residential can see your name, email address and role, and anything you post in the application, subject to their own permissions.

Beyond that, we share personal information only with the service providers that run Cobalt on our behalf — our cloud hosting provider, our file-storage provider (for uploaded profile pictures), the service that delivers our invitation and password-reset emails, our error-monitoring provider, and the workplace messaging service our automated reports post to — and only to the extent needed to run it. We do not sell personal information or disclose it for anyone else's marketing. We may also disclose information where the law requires it.

How long we keep it

We keep your account and its associated records for as long as your account exists. When someone leaves, their account is normally deactivated rather than deleted, so that historical records stay attributable and reports remain accurate. To request deletion, use the contact below.

Security

Cobalt is served over HTTPS and requires an account to access. Passwords are stored only as salted hashes. Access is limited by role and by property assignment, and administrators can deactivate an account immediately.

Your choices

Changes to this policy

If we change what we collect or how we use it, we will update this page and the date at the top of it.

Contact

Cobalt is operated by Bluecore Residential.

Because access is by invitation only, questions about this policy or about your information are best raised with your Cobalt administrator, who can also unlink your Google account or deactivate your access on request.

← Back to sign in