The short version
- Monitoring employee AI use is legal in the United States when the employer gives proper notice — and Coapro requires that notice to be recorded before anything is collected.
- A few states impose specific notice duties, and a few require extra care. The employer, not the software, carries those duties.
- In Europe, workplace monitoring is restricted and the EU AI Act imposes additional duties on both the employer and, for some uses, the vendor. Coapro is designed to keep those duties narrow.
- Coapro collects no biometric data — no face, fingerprint, voiceprint, or keystroke dynamics.
Who is responsible for what
The organization that deploys Coapro is the one that decides to monitor its own employees, sets the policy, and determines who can see the results. In privacy-law terms the employer is the controller and Coapro is a processor. That matters legally: the notice obligations below belong to your employer. What we do is make them impossible to skip silently.
Concretely: Coapro will not ingest any captured content until an administrator at the organization confirms, on the record that every person whose activity will be recorded was given clear written notice, that any required consent or consultation has happened, and that the data will not be used for undisclosed purposes. That confirmation is stored with the administrator’s name and the date, and the exact wording they agreed to. The software refuses to collect until it exists.
United States
Federal: the Electronic Communications Privacy Act (ECPA)
ECPA governs interception of electronic communications. Employers generally rely on the consent exception — under the federal rule, one party to a communication consenting is sufficient. Coapro’s notice-and-attestation flow exists to secure that consent and to produce a record of it: who attested, when, and to what wording. In a dispute, that record is what the employer can show.
State notice duties
A small number of states impose specific electronic-monitoring notice duties:
- Connecticut (Conn. Gen. Stat. §31-48d): prior written notice to affected employees and a conspicuous posting describing the types of monitoring.
- Delaware (19 Del. C. §705): notice of monitoring or interception policies each day the employee first accesses employer-provided email or internet services.
- New York (N.Y. Labor Law §52-c): written or electronic notice at hire and a conspicuous posting. New York’s duty has two limbs — the individual notice and the posting — and a product that delivers only the first leaves the employer half-compliant.
- Colorado: notice and data-rights duties under the Colorado Privacy Act for workforce data.
Because the employer — not Coapro — must be able to prove notice was given, the notice text and the attestation record are designed to be exportable by the customer.
State privacy rights
In California and a growing list of states, comprehensive privacy laws now apply to employee data — the California exemption for HR data ended years ago. That gives employees rights to know what is collected, to correct and delete it, and imposes purpose limits. Coapro supports those duties directly: every employee can see everything collected about them on their own page, and administrators can run export and erase requests against our records.
Recording-consent states
Roughly a dozen states require consent from every party to a communication rather than just one. Those rules were written for recorded conversations, and whether they reach a typed prompt is not settled. Coapro takes the conservative reading: because prompt text is content, we treat the stricter rule as applying where it does. The same attestation that satisfies federal consent makes this position defensible either way.
When AI is used in employment decisions
A separate body of law governs AI that influences hiring, discipline, or termination decisions — including Illinois’s 2026 amendments to its Human Rights Act and New York City’s bias-audit law. Those laws apply to the employer’s use of data in decisions, not to Coapro’s coaching function itself. Coapro’s coaching output is written to be developmental — practice areas, opportunities, steady performance — and does not produce scores or verdicts about employees. Whether coaching data feeds performance review is a decision for your employer, and the product records it as such.
European Union
GDPR
Workplace monitoring in the EU is lawful only with a proper legal basis — consent is rarely valid between employer and employee because of the power imbalance, so legitimate interests with a balancing test is the realistic route. EU member states add their own worker-protection rules; several (including Germany) require works-council consultation before technical monitoring systems are introduced. Coapro’s attestation explicitly requires the deploying organization to confirm that any required consultation and impact assessment is complete before collection begins.
Data minimisation and retention limits are core GDPR principles, and they shaped the product: by default Coapro stores the category of sensitive content detected, not the matched value; verbatim prompt content is deleted on a short configurable window by default; and every employee can see what is held about them.
The EU AI Act
The EU AI Act regulates AI systems by risk tier. Systems intended to monitor and evaluate the performance and behaviour of employees are classified high-risk, with obligations that have been in force since 2 August 2026. This matters for any vendor in this space, and it is worth being plain about where Coapro sits:
- Coapro’s monitoring half — policy enforcement, warning, blocking, and category-level logging — enforces an organization’s own written rules at the moment of send. It does not evaluate people.
- Coapro’s coaching half produces practice-area feedback and training, deliberately not evaluation: no scores, no rankings, no automated employment decisions. Automated training targeting is a feature that ships switched off, and requires a deliberate, recorded decision to enable.
Employers deploying monitoring AI in the EU have their own duties under the Act — informing workers’ representatives and affected workers before the system is put into service, human oversight, and log retention. The emotion-recognition prohibition applies in the workplace, and Coapro collects no emotional or affective data — nothing in the product infers how a person feels.
What Coapro does not collect
This section is deliberately concrete, because a reviewer who sees “keyboard hook” will ask:
- No biometric data — no facial recognition, no fingerprints, no voiceprints, and no keystroke dynamics. The agent reads what was typed into an AI composer; it never characterises how an individual types.
- No monitoring on non-AI surfaces — documents, spreadsheets, email, and general browsing are not read.
- No file contents — attachments record name, size, and type only.
- No secrets stored — detected credentials are redacted by server-side filters before anything is persisted.
Frequently asked
Is employee AI monitoring legal?
In the United States, generally yes, when the employer gives proper notice and stays within disclosed purposes. In the EU, it requires a lawful basis, member-state employment-process compliance, and impact assessment. What the software can do — and what Coapro does — is make sure the organization has stated the required facts on the record before collection begins.
Does my employer see what I typed?
See our Privacy Policy, especially the section written for employees. The short answer: managers see patterns, not prompts; verbatim text is restricted to defined administrative roles, and every access is logged.
Does Coapro work in Europe?
Deployment in the EU requires the employing organization to complete its own works-council consultation and impact assessment where those apply. Coapro’s attestation records that these steps happened, but the software cannot perform them on the customer’s behalf.
Scope of this page
This page is general information, not legal advice, and it is not a compliance determination for any specific deployment. Statutory requirements vary by state and by member state; organizations should confirm their own obligations with counsel before deploying monitoring. Data-processing terms live in our Terms and Privacy Policy.