Effective 27 August 2026. Applies to the Cobalt web application.
Cobalt is a private, internal reporting application operated by Bluecore Residential. It is not a consumer product and is not open to public sign-up. Access is limited to people Bluecore Residential has invited, and every account is created by an administrator.
This policy explains what personal information Cobalt collects about those users, why, and what we do with it. It covers the Cobalt application only.
Cobalt offers “Sign in with Google” as an optional alternative to an email address and password. Using it is never required; signing in with a password remains available to everyone.
We request two standard, non-sensitive permissions: your email address and your
basic profile (email and profile). We do not request
access to Gmail, Drive, Calendar, Contacts, photos, or any other Google service, and we cannot
read them.
When you sign in, Google sends Cobalt a small profile record. We keep only part of it:
| Sent by Google | Do we store it? | What it is used for |
|---|---|---|
| Email address | Yes | Matching you to your existing Cobalt account. |
| Whether that email is verified | No — checked, not stored | We refuse the sign-in unless Google confirms the address is verified. |
| Google account identifier | Yes | Tying your Cobalt account to one specific Google account, so a different Google account cannot later claim your email address. |
| First and last name | Yes | Keeping the name shown in Cobalt current. |
| Profile picture | No | Not used. Profile pictures in Cobalt are uploaded separately. |
| Locale / language | No | Not used. |
We do not store Google access tokens or refresh tokens. They are used once, during sign-in, and then discarded. Cobalt therefore has no standing access to your Google account and cannot read anything from it between sign-ins.
Cobalt's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Signing in with Google never creates an account. If the Google address you use does not already match a Cobalt account, you are refused and told to contact an administrator. Google sign-in is a way to open a door you already have a key to — it is not a way in.
You can stop using Google sign-in at any time and sign in with a password instead. To remove the link between your Cobalt account and your Google account entirely, ask a Cobalt administrator to unlink it; the stored Google identifier and the name we received from Google are deleted at that point. You can also revoke Cobalt's access from your Google account directly at myaccount.google.com/permissions.
Whether or not you use Google sign-in, Cobalt stores:
Most of what Cobalt stores is not about individuals at all — it is operational data about the properties Bluecore Residential manages.
Cobalt sets a single session cookie, which is what keeps you signed in. It is strictly necessary for the application to work. There are no advertising cookies, no analytics cookies, and no third-party tracking of any kind anywhere in the application.
We do not use this information for advertising, we do not sell it, and we do not use it to build profiles for any purpose beyond operating Cobalt.
Other Cobalt users at Bluecore Residential can see your name, email address and role, and anything you post in the application, subject to their own permissions.
Beyond that, we share personal information only with the service providers that run Cobalt on our behalf — our cloud hosting provider, our file-storage provider (for uploaded profile pictures), the service that delivers our invitation and password-reset emails, our error-monitoring provider, and the workplace messaging service our automated reports post to — and only to the extent needed to run it. We do not sell personal information or disclose it for anyone else's marketing. We may also disclose information where the law requires it.
We keep your account and its associated records for as long as your account exists. When someone leaves, their account is normally deactivated rather than deleted, so that historical records stay attributable and reports remain accurate. To request deletion, use the contact below.
Cobalt is served over HTTPS and requires an account to access. Passwords are stored only as salted hashes. Access is limited by role and by property assignment, and administrators can deactivate an account immediately.
If we change what we collect or how we use it, we will update this page and the date at the top of it.
Cobalt is operated by Bluecore Residential.
Because access is by invitation only, questions about this policy or about your information are best raised with your Cobalt administrator, who can also unlink your Google account or deactivate your access on request.