This policy describes how Cognia ("we", "us") handles personal data when you use the Cognia service. We have designed Cognia to follow the principles of data minimization, transparency, and user control.
Information we collect
- Account information — name, email address, authentication factors (hashed password and TOTP secret), and the organization you belong to.
- Captured memories — content you save through the Cognia browser extension, integrations, or API. This may include URLs, page text, screenshots, and the metadata you attach.
- Usage analytics — pages visited, features used, performance timings, and crash reports. Optional and controlled by cookie consent.
- Billing information — handled by Stripe; we store only the subset of metadata needed to operate subscriptions.
How we use it
- To provide and maintain the Cognia service.
- To run AI-driven analysis on captured memories so we can generate summaries, tags, and search results — strictly within the scope of the prompt that produced the request.
- To process payments and manage subscriptions through Stripe.
- To detect, prevent, and respond to abuse, fraud, and security incidents.
- To send transactional emails (auth, billing, security notifications). Marketing emails are opt-in.
Sharing
We do not sell personal data. We share data only with the subprocessors listed on our subprocessors page, each bound by a data-processing agreement, and with law enforcement when compelled by valid legal process.
Your rights (GDPR / CCPA)
Subject to applicable law, you have the right to access, correct, delete, restrict, and port your personal data, and to object to certain processing.
- Self-serve — the GDPR section in your in-app settings exposes data export and account deletion.
- By email — write to privacy@cogniahq.tech and we will respond within 30 days.
Retention
Memories are retained until you delete them or close your account; deleted memories are purged within 30 days of deletion. Audit logs are retained per your organization's policy — 90 days, 365 days, or unlimited (Enterprise). Backups roll on a 30-day window.
Cookies
We use three categories of cookies:
- Strictly necessary — required for authentication, security, and core functionality. Always on.
- Analytics — opt-in. Helps us understand which features are useful and where we should invest.
- Marketing — opt-in. Helps us measure outreach campaigns.
You can review and change your preferences any time via the consent banner; your stored choice is honored across sessions.
Children
Cognia is not intended for children under 16 and we do not knowingly collect personal data from children.
Changes
We may update this policy. Material changes will be communicated by email and a notice in-product at least 30 days before they take effect.