Privacy Policy
Last updated: March 12, 2026
1. Introduction
This Privacy Policy describes how Cognova ("we", "us", "our") collects, uses, and protects your personal information when you use our AI agent workspace at cognova.dev.
2. Information We Collect
Information You Provide
- Account information: Name, email address, and password when you register
- Workspace data: Workspace names, member invitations, and settings
- Conversations: Messages you send to AI agents and their responses
- Knowledge files: Documents and files you upload to agent knowledge bases
- Agent configurations: System prompts, tool bindings, and agent settings
- Payment information: Billing details processed through our payment provider (Stripe)
Information Collected Automatically
- Usage data: Credit consumption, feature usage, and interaction patterns
- Session data: Authentication cookies required for login functionality
- Server logs: IP addresses, request timestamps, and error logs for operational purposes
3. How We Use Your Information
We use your information to:
- Provide and operate the Service
- Process AI interactions through Anthropic's API
- Manage your account, workspace, and billing
- Send transactional emails (account verification, billing notifications)
- Monitor and improve Service performance and security
- Comply with legal obligations
We do not use your conversations or knowledge files to train AI models. We do not sell your personal information.
4. Data Sharing
We share your data only with the following service providers, solely for operating the Service:
| Provider | Purpose | Data Shared |
|---|---|---|
| Anthropic | AI processing | Conversation messages, agent system prompts, knowledge context |
| Railway | Hosting infrastructure | All Service data (encrypted at rest) |
| Resend | Transactional email | Email addresses, email content |
| Stripe | Payment processing | Billing and payment information |
We may also disclose information if required by law, legal process, or to protect the rights and safety of Cognova or others.
5. Data Retention
- Active accounts: Data is retained for the duration of your account
- Deleted accounts: Data is deleted within 30 days of account deletion
- Conversations: Retained until you delete them or your account
- Server logs: Retained for up to 90 days for operational purposes
6. Data Security
We implement industry-standard security measures including:
- Encryption in transit (TLS/HTTPS)
- Encryption at rest for database storage
- AES-256-GCM encryption for stored secrets and API keys
- Workspace-scoped access controls
- Session-based authentication
7. Your Rights
You have the right to:
- Access: Request a copy of your personal data
- Correction: Update inaccurate personal information
- Deletion: Request deletion of your account and data
- Export: Download your conversations and knowledge files
- Objection: Object to certain processing of your data
To exercise these rights, contact us at [email protected].
8. California Privacy Rights (CCPA)
California residents have additional rights under the CCPA:
- Right to know what personal information is collected and how it is used
- Right to delete personal information
- Right to opt-out of the sale of personal information (we do not sell your data)
- Right to non-discrimination for exercising privacy rights
9. International Users
If you are accessing the Service from outside the United States, your data may be transferred to and processed in the United States. By using the Service, you consent to this transfer. For EU users, please refer to our Data Processing Agreement.
10. Children's Privacy
The Service is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, contact us at [email protected].
11. Cookies
We use essential cookies for authentication and session management. For details, see our Cookie Policy.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification. The "Last updated" date at the top of the legal page reflects the most recent revision.
13. Contact
For privacy-related questions or requests, contact us at [email protected].