Privacy Notice
This notice describes what the hosted ArtzAIn service at app.cognexuslabs.ai collects about you and the organisation you work for, why, who else handles it, where it lives and how long it stays. It is written for the people who will actually read it: the engineer who signs up, and the privacy, security and compliance reviewers who come after.
1. Who is responsible
CogNEXUS Labs LLC is the controller for your account, billing and operational data. For the content your agents submit to the Decision API, and the decision records produced from it, you (or the organisation you act for) decide what is sent and why; we process it on your behalf to provide the service. Data-rights requests: [email protected]. Security disclosure: [email protected]. Everything else: [email protected].
2. What we collect, by surface
- Account. Your email address, a display name if you give one, and a password hash (bcrypt; we never store the password itself). If you turn on two-factor authentication, the TOTP secret and recovery codes. Email verification state, team memberships and roles, and the time and IP address of sign-up.
- Google sign-in (optional). When you choose “Continue with Google” we ask Google for the
openid,emailandprofilescopes only, and use the email address and name to create or match your account. We do not ask for access to anything else in your Google account, and you can use a password instead at any time. - API usage and decision records. For every request to the Decision API: the key that made it, the tenant, timestamp, outcome and latency, and the payload your software submitted (the proposed action, its context and the policy result) as a decision record in the audit log. Also sealed into the same log: policy-bundle promotions, licence-status transitions, plan changes and kill-switch actions (the last two recorded as decisions in their own right). Other account actions, such as creating or revoking an API key, live in ordinary application records, not in the audit log.
- Server logs. The IP address, user agent, requested path, status and timestamp of each request, in our container logs (CloudWatch, kept for 30 days). They exist to keep the service running and to investigate abuse and incidents.
- Billing. Your plan, subscription state, and the Stripe customer and subscription identifiers that link your account to Stripe's records. Card numbers, billing address and tax ID are collected by Stripe on its own pages; they never reach our servers.
- Enterprise enquiry form. The form on cognexuslabs.ai posts to this service. We receive the name, company, work email, role, company size and message you enter, plus the submitting IP address. It is emailed to us, and we keep enquiry records for 90 days.
- Support. Whatever you send to our addresses, read by the people who answer.
3. Why, and on what basis
| Purpose | Legal basis |
|---|---|
| Providing the service you signed up for: accounts, the API, the audit log, exports, the dashboard | Performance of a contract |
| Keeping the service secure and available: logs, rate limiting, abuse and incident investigation | Legitimate interests (ours and our customers') |
| Billing, tax and accounting | Contract, and legal obligation |
| Transactional email: verification, password reset, billing and payment notices | Contract |
| Google sign-in | Consent (you choose it; withdraw by using a password instead) |
| Answering enquiries and support | Legitimate interests, or steps you ask for before a contract |
No marketing sequences, no advertising, no profiling. The decisions the service makes are about actions proposed by your software under your policies, not about you as a person; we make no automated decisions with legal or similar effect about individuals.
4. Who else handles it (subprocessors)
| Provider | What it does for this service | Where |
|---|---|---|
| Amazon Web Services | Hosting: compute (ECS), the database (RDS for PostgreSQL), the audit signing keys (EFS), secrets (Secrets Manager) and logs (CloudWatch) | us-west-2 (Oregon, United States) |
| Stripe | Payments, subscriptions, invoices and tax. Card data never touches the service. | United States |
| Resend | Transactional email sent from mail.cognexuslabs.ai: verification, password reset, billing notices, enquiry forwarding | United States |
Optional sign-in only (openid, email, profile) | United States | |
| Cloudflare | DNS, proxy and web application firewall in front of the service; it sees request metadata (IP address, headers) to do that | Global edge network |
That is the whole list for this service. If we add a provider, we will update this page before it handles your data.
5. Where your data lives
The service runs in AWS us-west-2 (Oregon, United States); the database, the audit log and backups stay in that region. If you are subject to rules about transfers out of your jurisdiction (for example the EU or the UK), email [email protected] before relying on the service for personal data, and we will put the appropriate transfer mechanism and a data processing agreement in place first.
6. How long we keep it
| What | How long |
|---|---|
| Audit history (decision records and governance events) | Your plan includes N days of audit history in the dashboard, API and exports. Sealed decisions are retained for seven years regardless of plan; older history is available by upgrading or on request. N for each plan is in the plan table in the Terms of Service (section 4). |
| Account data | For as long as the account exists. Deleting the account pseudonymises it (section 8). |
| Server logs | 30 days |
| Database backups | 7 days, rolling |
| Enterprise enquiry records | 90 days |
| Billing records | As long as tax and accounting law requires, at Stripe and in our books |
| Support email | While the conversation is active, and a reasonable period afterward so that we can pick it up again |
Retention never deletes a sealed decision record, and we do not alter sealed records on request; that is what makes the audit log evidence.
7. How we protect it
Traffic between you and the service is encrypted in transit with TLS. The database and the volume that holds the audit signing keys are encrypted at rest. Every decision is written to a hash-chained audit log whose seals are signed with an Ed25519 key that is generated inside the service and never leaves it, so the log can be verified offline with the artzain CLI without trusting us. Passwords are stored as bcrypt hashes, and two-factor authentication is available on every account. Our build pipeline signs production container images. No system is perfectly secure; if you find a weakness, email [email protected] and we will respond.
8. Your rights, and how to use them
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, receive a copy in a portable form, have it deleted, restrict or object to how we use it, withdraw consent where consent is the basis, and complain to a supervisory authority. To exercise any of them, email [email protected] from your account email; we reply within 30 days, and we may ask you to confirm your identity first.
Audit history is yours to take at any time during your access window: Audit Log → export in the dashboard, GET /api/v1/audit/export, or artzain audit export.
Account deletion is self-serve (Team & Settings → Account security), and it pseudonymises the account rather than erasing it: your email, name, password and two-factor secrets are removed, your API keys are revoked and your conversations and connector tokens are dropped, while sealed audit records keep their numeric actor id, so that the chain still verifies and an auditor can see that an account, no longer identifiable, produced them. The reasoning is written up in the operator manual (chapter 8, Teams, RBAC and access, under “Account deletion stance”), which the dashboard's Docs panel renders. Transfer ownership of any team you solely own, and cancel any active subscription, first.
9. Cookies, and what lives in your browser
The service sets one sign-in cookie of its own, __Host-cognexus_session, which holds your session; it is marked HttpOnly and Secure, is sent only to this site, and expires after 30 days or when you sign out. For up to ten minutes while you connect a service or sign in with Google, it also sets a cookie that ties that round trip to your browser. Your browser's local storage holds a copy of your profile (cognexus_user) so that the dashboard can show your name, your theme choice (cognexus_theme), a random identifier (cognexus_session_id) that links the reports you generate to your browser, and a few small interface preferences such as which tour or checklist you have dismissed. Session storage holds short-lived flow state, such as the email you typed on the password-reset page. Signing out clears the session cookie and the stored profile. The service worker caches the application shell and its scripts so that the dashboard loads offline; it never caches API responses.
No third-party analytics, advertising or session-replay scripts run on these pages. Stripe Checkout, the Stripe billing portal and Google's sign-in pages are their own sites with their own cookies and notices, and Cloudflare may set a cookie of its own when it presents a security challenge.
10. Children
The service is for businesses and professionals. It is not directed at anyone under 18 and may not be used by them.
11. Changes
If this notice changes in a way that affects how we use information already collected, we will tell you by email and in the dashboard before the change applies, and update the date below. Smaller clarifications are simply published here.
12. Contact
Controller: CogNEXUS Labs LLC. [email protected] for data-rights requests, [email protected] for security disclosure, [email protected] for everything else.
Effective 26 September 2026.