Legal
Privacy Policy
Last updated July 14, 2026
This policy explains what personal data Cortex AI OS processes, why, and the rights you have over it. It covers this website and the Cortex platform; where you use Cortex through your employer, your employer is the data controller and this policy supplements their notices.
01What we collect
- Account data — name, work email, role, and authentication identifiers when you sign up or your organization provisions you.
- Platform content — the prompts, documents, configurations, and run outputs your organization processes through its tenant. This data belongs to your organization.
- Usage & device data — pages visited, features used, browser and device metadata, collected to operate and improve the service.
- Contact data — anything you send through our demo, contact, or support channels.
02How we use it
We use personal data to operate the platform (authentication, tenancy, support), to secure it (audit trails, anomaly detection, abuse prevention), to bill for it, and to communicate with you about the service. Marketing communication is opt-in and separately unsubscribable.
03We do not train models on your data
Customer prompts, documents, and run outputs are never used to train machine-learning models — ours or anyone else's — on any plan. Model providers we route to are bound to the same restriction through their enterprise terms.
04Legal bases
Where GDPR or similar laws apply, we process personal data to perform our contract with you or your organization, to meet legal obligations, and under legitimate interests in securing and improving the service. Where consent is the basis (e.g. marketing), you can withdraw it at any time.
05Sharing
We share personal data only with the subprocessors listed in our Subprocessor Register (each under a data-processing agreement), with your organization's administrators, or where the law requires it. We do not sell personal data.
06Security & retention
Data is encrypted in transit and at rest; platform actions are recorded in a tamper-evident audit ledger. Account data is retained for the life of the account plus the period our legal obligations require; platform content follows your organization's configured retention. Business-plan tenants can set custom retention and residency.
07Your rights
Depending on your jurisdiction you may have rights to access, correct, export, restrict, or delete your personal data, and to complain to a supervisory authority. Requests go to privacy@cortexaios.com; where your employer is the controller we will route the request to them.
08Contact
Privacy questions and requests: privacy@cortexaios.com.
Questions about this document: legal@cortexaios.com · See also the Trust Center