ArtzAIn
Terms Privacy Sign in
Legal · Hosted service

Privacy Notice

This notice describes what the hosted ArtzAIn service at app.cognexuslabs.ai collects about you and the organisation you work for, why, who else handles it, where it lives and how long it stays. It is written for the people who will actually read it: the engineer who signs up, and the privacy, security and compliance reviewers who come after.

This notice covers the hosted service only. The website at cognexuslabs.ai has its own notice at https://cognexuslabs.ai/privacy. If you have a signed commercial agreement or data processing agreement with CogNEXUS Labs LLC, it prevails wherever the two differ.

1. Who is responsible

CogNEXUS Labs LLC is the controller for your account, billing and operational data. For the content your agents submit to the Decision API, and the decision records produced from it, you (or the organisation you act for) decide what is sent and why; we process it on your behalf to provide the service. Data-rights requests: [email protected]. Security disclosure: [email protected]. Everything else: [email protected].

2. What we collect, by surface

  • Account. Your email address, a display name if you give one, and a password hash (bcrypt; we never store the password itself). If you turn on two-factor authentication, the TOTP secret and recovery codes. Email verification state, team memberships and roles, and the time and IP address of sign-up.
  • Google sign-in (optional). When you choose “Continue with Google” we ask Google for the openid, email and profile scopes only, and use the email address and name to create or match your account. We do not ask for access to anything else in your Google account, and you can use a password instead at any time.
  • API usage and decision records. For every request to the Decision API: the key that made it, the tenant, timestamp, outcome and latency, and the payload your software submitted (the proposed action, its context and the policy result) as a decision record in the audit log. Also sealed into the same log: policy-bundle promotions, licence-status transitions, plan changes and kill-switch actions (the last two recorded as decisions in their own right). Other account actions, such as creating or revoking an API key, live in ordinary application records, not in the audit log.
  • Server logs. The IP address, user agent, requested path, status and timestamp of each request, in our container logs (CloudWatch, kept for 30 days). They exist to keep the service running and to investigate abuse and incidents.
  • Billing. Your plan, subscription state, and the Stripe customer and subscription identifiers that link your account to Stripe's records. Card numbers, billing address and tax ID are collected by Stripe on its own pages; they never reach our servers.
  • Enterprise enquiry form. The form on cognexuslabs.ai posts to this service. We receive the name, company, work email, role, company size and message you enter, plus the submitting IP address. It is emailed to us, and we keep enquiry records for 90 days.
  • Support. Whatever you send to our addresses, read by the people who answer.

3. Why, and on what basis

PurposeLegal basis
Providing the service you signed up for: accounts, the API, the audit log, exports, the dashboardPerformance of a contract
Keeping the service secure and available: logs, rate limiting, abuse and incident investigationLegitimate interests (ours and our customers')
Billing, tax and accountingContract, and legal obligation
Transactional email: verification, password reset, billing and payment noticesContract
Google sign-inConsent (you choose it; withdraw by using a password instead)
Answering enquiries and supportLegitimate interests, or steps you ask for before a contract

No marketing sequences, no advertising, no profiling. The decisions the service makes are about actions proposed by your software under your policies, not about you as a person; we make no automated decisions with legal or similar effect about individuals.

4. Who else handles it (subprocessors)

ProviderWhat it does for this serviceWhere
Amazon Web ServicesHosting: compute (ECS), the database (RDS for PostgreSQL), the audit signing keys (EFS), secrets (Secrets Manager) and logs (CloudWatch)us-west-2 (Oregon, United States)
StripePayments, subscriptions, invoices and tax. Card data never touches the service.United States
ResendTransactional email sent from mail.cognexuslabs.ai: verification, password reset, billing notices, enquiry forwardingUnited States
GoogleOptional sign-in only (openid, email, profile)United States
CloudflareDNS, proxy and web application firewall in front of the service; it sees request metadata (IP address, headers) to do thatGlobal edge network

That is the whole list for this service. If we add a provider, we will update this page before it handles your data.

5. Where your data lives

The service runs in AWS us-west-2 (Oregon, United States); the database, the audit log and backups stay in that region. If you are subject to rules about transfers out of your jurisdiction (for example the EU or the UK), email [email protected] before relying on the service for personal data, and we will put the appropriate transfer mechanism and a data processing agreement in place first.

6. How long we keep it

WhatHow long
Audit history (decision records and governance events)Your plan includes N days of audit history in the dashboard, API and exports. Sealed decisions are retained for seven years regardless of plan; older history is available by upgrading or on request. N for each plan is in the plan table in the Terms of Service (section 4).
Account dataFor as long as the account exists. Deleting the account pseudonymises it (section 8).
Server logs30 days
Database backups7 days, rolling
Enterprise enquiry records90 days
Billing recordsAs long as tax and accounting law requires, at Stripe and in our books
Support emailWhile the conversation is active, and a reasonable period afterward so that we can pick it up again

Retention never deletes a sealed decision record, and we do not alter sealed records on request; that is what makes the audit log evidence.

7. How we protect it

Traffic between you and the service is encrypted in transit with TLS. The database and the volume that holds the audit signing keys are encrypted at rest. Every decision is written to a hash-chained audit log whose seals are signed with an Ed25519 key that is generated inside the service and never leaves it, so the log can be verified offline with the artzain CLI without trusting us. Passwords are stored as bcrypt hashes, and two-factor authentication is available on every account. Our build pipeline signs production container images. No system is perfectly secure; if you find a weakness, email [email protected] and we will respond.

8. Your rights, and how to use them

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, receive a copy in a portable form, have it deleted, restrict or object to how we use it, withdraw consent where consent is the basis, and complain to a supervisory authority. To exercise any of them, email [email protected] from your account email; we reply within 30 days, and we may ask you to confirm your identity first.

Audit history is yours to take at any time during your access window: Audit Log → export in the dashboard, GET /api/v1/audit/export, or artzain audit export.

Account deletion is self-serve (Team & Settings → Account security), and it pseudonymises the account rather than erasing it: your email, name, password and two-factor secrets are removed, your API keys are revoked and your conversations and connector tokens are dropped, while sealed audit records keep their numeric actor id, so that the chain still verifies and an auditor can see that an account, no longer identifiable, produced them. The reasoning is written up in the operator manual (chapter 8, Teams, RBAC and access, under “Account deletion stance”), which the dashboard's Docs panel renders. Transfer ownership of any team you solely own, and cancel any active subscription, first.

9. Cookies, and what lives in your browser

The service sets one sign-in cookie of its own, __Host-cognexus_session, which holds your session; it is marked HttpOnly and Secure, is sent only to this site, and expires after 30 days or when you sign out. For up to ten minutes while you connect a service or sign in with Google, it also sets a cookie that ties that round trip to your browser. Your browser's local storage holds a copy of your profile (cognexus_user) so that the dashboard can show your name, your theme choice (cognexus_theme), a random identifier (cognexus_session_id) that links the reports you generate to your browser, and a few small interface preferences such as which tour or checklist you have dismissed. Session storage holds short-lived flow state, such as the email you typed on the password-reset page. Signing out clears the session cookie and the stored profile. The service worker caches the application shell and its scripts so that the dashboard loads offline; it never caches API responses.

No third-party analytics, advertising or session-replay scripts run on these pages. Stripe Checkout, the Stripe billing portal and Google's sign-in pages are their own sites with their own cookies and notices, and Cloudflare may set a cookie of its own when it presents a security challenge.

10. Children

The service is for businesses and professionals. It is not directed at anyone under 18 and may not be used by them.

11. Changes

If this notice changes in a way that affects how we use information already collected, we will tell you by email and in the dashboard before the change applies, and update the date below. Smaller clarifications are simply published here.

12. Contact

Controller: CogNEXUS Labs LLC. [email protected] for data-rights requests, [email protected] for security disclosure, [email protected] for everything else.

Effective 26 September 2026.

© 2026 CogNEXUS Labs LLC · Terms · Privacy · cognexuslabs.ai